Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
DIY vs Microsoft Agent 365: an in-house build or a Microsoft 365 control plane for AI agents
Build it yourself (DIY)
Building agent connections and controls in-house from open protocols, existing infrastructure, and open-source tools
Microsoft Agent 365
Microsoft 365 control plane to discover, manage, govern, and secure AI agents
Short answer
DIY is not a product: you build the registry and access controls yourself, on openly licensed protocols such as A2A and MCP that leave authorization to the implementer.Source 1, Source 2, Source 3, Source 4 Microsoft Agent 365 is a Microsoft 365 service: a control plane for agents built and run elsewhere, with Entra agent identities and per-user licensing.Source 5, Source 6, Source 7, Source 8, Source 9
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
- Where they overlap
- Both are ways to govern agents and their tools: Uber’s MCP gateway uses a registry as its control plane; Agent 365 is a control plane with an agent registry.Source 5, Source 10, Source 11
- Where they differ
- DIY also covers building and deploying agents, with frameworks such as LangGraph and Google’s Agent Development Kit.Source 12, Source 13 Microsoft says the Agent 365 SDK doesn’t build, host, deploy, or execute agents.Source 7
- Running both
- Microsoft says to build an agent with your chosen framework, then bring it into Agent 365 with its SDK.Source 6
DIY
Microsoft Agent 365
- Agents across organizations: Not publicly documented
At a glance
What each one is
Build it yourself (DIY)
DIY means governing agents without a dedicated product: MCP and A2A wired together in-house, existing gateways and identity providers stretched to agents, an in-house platform, self-hosted open source, or no central approach; Uber says that before its gateway, teams built integrations independently and duplicated infrastructure.Source 10
The differences that matter
Agent identity
DIYYou pick the identity system: A2A leaves identity to the HTTP layer, and MCP makes authorization optional.Source 15, Source 17
Microsoft Agent 365Agent identities live in Microsoft Entra Agent ID, managed with Conditional Access, permission grants and consent, and lifecycle operations.Source 8
At Pinterest, almost every MCP call is governed by end-user JWTs and service-mesh identities; Uber’s gateway applies Access Control System policies to humans, services, and agents.Source 10, Source 22
Agent registry
DIYUber and Pinterest each built their own MCP registry; A2A prescribes no standard API for curated registries.Source 1, Source 10, Source 22
Microsoft Agent 365One registry in the Microsoft 365 admin center lists Microsoft and non-Microsoft agents, including agents without an Entra agent identity.Source 11, Source 23
The official MCP Registry is in preview and does not support private servers; its docs recommend hosting your own private registry for those.Source 18
Agents at other companies
DIYA2A is designed for agents built by different companies on separate servers; each server authorizes requests under its own policies.Source 2, Source 24
Microsoft Agent 365A published agent can be added to a customer tenant with tenant-local Entra identities; managing agents across tenants you administer is in preview.Source 8, Source 21
Agent-to-agent calls across organizations through Agent 365 are not publicly documented. Microsoft’s separate Foundry and standard-harness Copilot Studio agents can call A2A agents hosted elsewhere.Source 25, Source 26
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| DIY | Microsoft Agent 365 | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | An in-house build on open protocols such as A2A, an open standard for interoperability between agent systems, and MCP, which A2A calls complementary.Source 2 | A Microsoft 365 service that provides a centralized control plane to discover, manage, govern, and secure AI agents.Source 5 |
| Maturity | Varies by component: MCP’s latest specification revision is 2026-07-28.Source 4 The official MCP Registry is in preview; breaking changes or data resets may occur.Source 18 | Generally available since 1 May 2026 for the Commercial segment.Source 19 Registry sync and multi-tenant management are in preview.Source 20, Source 21 |
| Control | ||
| Agent registry and discovery | Built in-house: Uber and Pinterest each built an MCP registry.Source 10, Source 22 A2A prescribes no standard API for curated registries.Source 1 | An agent registry in the Microsoft 365 admin center lists Microsoft and non-Microsoft agents.Source 11, Source 23 Sync from platforms such as Amazon Bedrock is in preview.Source 20 |
| Identity and access control | A2A leaves identity to the HTTP layer and calls authorization implementation-specific.Source 2, Source 15 MCP authorization is optional.Source 17 | Entra Agent ID identities, managed with Conditional Access, permission grants, and consent.Source 8 Declared permissions need an administrator’s consent.Source 8 |
| Ownership, policy, and revocation | MCP tells implementers to build consent and authorization flows.Source 4 Pinterest requires an owning team, registry entry, and review for non-experimental MCP servers.Source 22 | Entra agent identities need a sponsor.Source 8 Admins can block agents (SharePoint and Foundry ones only in Copilot Chat), approve activations, and apply templates.Source 30, Source 32 |
| Audit log and observability | A2A docs advise auditing significant events and tracing, for example with OpenTelemetry.Source 15 Pinterest’s MCP servers log inputs, outputs, and invocation counts.Source 22 | Supported agents’ spans show in Defender, Purview, and the admin center; Agent 365 keeps them 30 days.Source 6, Source 31 Purview’s agent audit logs need E7 or Agent 365.Source 5 |
| Connection | ||
| How agents connect | Streamable HTTP MCP servers expose an endpoint; A2A agents over HTTP declare an HTTPS URL in production.Source 2, Source 27 AWS PrivateLink privately connects a VPC to services.Source 33 | The SDK works with agents on Azure, AWS, Google Cloud, or on premises.Source 6 Notifications, in preview, go to a messaging endpoint URL you register.Source 28 |
| Agents across organizations | A2A is built for agents from different companies on separate servers; its docs highly recommend API management across organizational boundaries.Source 15, Source 24 | A published agent can be added to a customer tenant with tenant-local Entra identities.Source 8 Managing agents across tenants you administer is in preview.Source 21 |
| Protocol support | MCP defines stdio and Streamable HTTP transports and allows custom ones.Source 34 A2A maps its operations to JSON-RPC, gRPC, and HTTP/REST bindings.Source 2 | Tenant-wide tool control covers Microsoft MCP servers.Source 5 Bring-your-own MCP servers are in preview.Source 16 A2A in Agent 365 itself is not publicly documented. |
| Frameworks, models, and clouds supported | A2A gives agents built on different frameworks, languages, or vendors a common language.Source 2 Google’s ADK says it is model-agnostic and deployment-agnostic.Source 13 | Microsoft and third-party agents; SDK integration names LangChain, CrewAI, and the OpenAI Agents SDK.Source 5, Source 20 Premium capabilities may vary by agent type and platform.Source 9 |
| Operations | ||
| Deployment options and data residency | Wherever you run it: Pinterest optimized for MCP servers in its internal cloud.Source 22 A2A docs leave protecting stored data to your own policies.Source 15 | Honors the EU Data Boundary; its observability service stores customer content in the tenant’s default geography.Source 31 Self-hosting it: not publicly documented. |
| Compliance attestations | A2A docs tell implementers to comply with relevant regulations such as GDPR, CCPA, and HIPAA.Source 15 MCP leaves access controls and data protections to implementers.Source 4 | Not yet a Core Online Service.Source 31 Microsoft says Agent 365 meets all FedRAMP High controls its assessor reviewed; final authorization is pending (announced).Source 5 |
| Support and SLA | Depends on the component: MCP SDKs are tiered partly by maintenance commitments; the official MCP Registry, in preview, gives no uptime guarantees.Source 35, Source 36 | No specific SLA for the Frontier preview program.Source 37 An SLA or support plan specific to the generally available service is not publicly documented. |
| Time and effort to get running | A curated A2A registry is a service you deploy and maintain.Source 1 Pinterest built a unified deployment pipeline after new MCP servers took too much setup.Source 22 | Enterprise customers need Microsoft 365 E5, or E3 with Defender Suite and Purview Suite.Source 9 SDK-connected agents need an Entra blueprint.Source 8 |
| Pricing model and public prices | The A2A and MCP specifications are openly licensed, A2A’s under Apache 2.0.Source 2, Source 3 Build and running costs are not publicly documented. | Per user, not per agent: lists at $15 a month standalone, or in Microsoft 365 E7.Source 9 Microsoft Cloud subscribers get foundational capabilities at no extra cost.Source 9 |
| Building | ||
| Agent building tools | You build them: LangGraph and Google’s open-source ADK are frameworks for building and deploying agents, and A2A has SDKs in six languages.Source 12, Source 13, Source 38 | Microsoft says the Agent 365 SDK isn’t an agent-building framework.Source 6 For low-code building, its docs point to Microsoft’s separate Copilot Studio.Source 39 |
| Model access | Your choice: Google’s ADK, for example, says it is optimized for Gemini and model-agnostic.Source 13 | Microsoft says the SDK doesn’t call or select models; the agent keeps making its own model calls.Source 6, Source 7 |
| Integrations and ecosystem | The official MCP Registry, in preview, has a REST API for clients and aggregators to discover MCP servers.Source 18 | Launched with preintegrated partner agents and agents built on partner agent factories.Source 40, Source 41 Work IQ MCP tools, in preview, cover Mail, Calendar, Teams, and more.Source 42 |
Which to choose
Choose DIY if
- You don’t run Microsoft 365: Agent 365 is a Microsoft 365 service, and enterprise customers first need E5, or E3 with add-ons.Source 5, Source 9
- You need agents at other companies to work with yours: A2A is designed for agents from different companies on separate servers.Source 24
- You want access checked by systems you already run, as Pinterest does with mesh identities and Uber with its Access Control System.Source 10, Source 22
- You want no vendor contract for the core protocols: the A2A and MCP specifications are openly licensed.Source 2, Source 3
Choose Microsoft Agent 365 if
- You build agents in Microsoft’s separate Copilot Studio or Microsoft Foundry, which Microsoft says offer built-in integration for some scenarios.Source 20, Source 43
- You want agent identities in Microsoft Entra, managed with the same Conditional Access, consent, and lifecycle controls used elsewhere in Entra.Source 8
- You want one registry for Microsoft and non-Microsoft agents that also counts agents created or managed outside Agent 365.Source 11, Source 23
- You have a Microsoft Cloud subscription: agent identity, inventory visibility, and core admin governance actions come at no additional cost.Source 9
Questions buyers ask
Can Microsoft Agent 365 govern agents built outside Microsoft?
Does Microsoft Agent 365 support MCP and A2A?
For MCP, it controls which tools agents can access tenant-wide, including Microsoft MCP servers, and registering your own MCP servers is in preview.Source 5, Source 16 A2A in Agent 365 itself is not publicly documented; Microsoft’s separate Foundry and standard-harness Copilot Studio agents can call A2A agents.Source 25, Source 26
Do I need Microsoft 365 to use Microsoft Agent 365?
How do the costs compare?
Agent 365 lists at $15 per user per month standalone, paid yearly, or comes in Microsoft 365 E7; agents aren’t licensed, and there are no consumption-based costs yet.Source 9, Source 45 For DIY, the specifications are openly licensed; build and running costs are not publicly documented.Source 2, Source 3
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
50 public sources, each with the date we checked it. Every one opens in a new tab.
Source 2: Agent2Agent (A2A) Protocol Specification Back:abcdefghijklmno
Source 3: modelcontextprotocol/modelcontextprotocol LICENSE (GitHub) Back:abcde
Source 4: Specification - Model Context Protocol 2026-07-28 Back:abcdef
Source 5: Microsoft Agent 365 - Service Descriptions | Microsoft Learn Back:abcdefghijklmn
Source 6: Agent 365 SDK frequently asked questions | Microsoft Learn Back:abcdefgh
Source 7: Microsoft Agent 365 SDK overview | Microsoft Learn Back:abcdef
Source 8: Agent 365 identity | Microsoft Learn Back:abcdefghijklm
Source 10: Designing MCP Gateway Uber's MCP Management Platform - Uber Blog Back:abcdefg
Source 11: Agent Registry in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Back:abcde
Source 14: Integrating with Model Context Protocol (MCP) - Keycloak Back:ab
Source 15: Enterprise Features - A2A Protocol Back:abcdefghij
Source 16: Bring your own (BYO) MCP server in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Back:abcd
Source 17: Authorization - Model Context Protocol specification 2026-07-28 Back:abcd
Source 18: The MCP Registry - Model Context Protocol Back:abcd
Source 19: Microsoft Agent 365 overview | Microsoft Learn Back:abcd
Source 20: Choose an Agent 365 Integration Option | Microsoft Learn Back:abcdef
Source 21: Manage agents across multiple tenants in the Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Back:abcd
Source 22: Building an MCP Ecosystem at Pinterest - Pinterest Engineering Blog Back:abcdefghi
Source 23: Agent Registry convergence with Microsoft Agent 365 | Microsoft Learn Back:abcd
Source 25: Connect to an agent over the Agent2Agent (A2A) protocol - Microsoft Copilot Studio | Microsoft Learn Back:ab
Source 26: Connect to an A2A agent endpoint from Foundry Agent Service - Microsoft Foundry | Microsoft Learn Back:ab
Source 27: Streamable HTTP - Model Context Protocol specification 2026-07-28 Back:ab
Source 28: Agent Messaging Endpoint | Microsoft Learn Back:ab
Source 29: Enterprise-Managed Authorization - Model Context Protocol extensions Back to text
Source 30: Governance and Lifecycle actions for agents available in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Back:ab
Source 31: Data handling, data residency, and compliance in Agent 365 observability | Microsoft Learn Back:abcdef
Source 33: What is AWS PrivateLink? - Amazon Virtual Private Cloud Back to text
Source 34: Transports - Model Context Protocol specification 2026-07-28 Back to text
Source 36: MCP Registry Aggregators - Model Context Protocol Back to text
Source 37: Preview Agent 365 features through the Frontier program | Microsoft Learn Back to text
Source 39: Get started with Microsoft Agent 365 | Microsoft Learn Back to text
Source 40: Ecosystem partner agents available in Agent 365 | Microsoft Learn Back to text
Source 41: Microsoft Agent 365, now generally available, expands capabilities and integrations | Microsoft Security Blog Back to text
Source 42: Connect existing agents to Microsoft Agent 365 | Microsoft Learn Back to text
Source 43: What is Microsoft Foundry? - Microsoft Foundry | Microsoft Learn Back to text
Source 44: Integrate Microsoft Entra Agent ID with third-party identity providers | Microsoft Learn Back to text
Source 45: Microsoft Agent 365: The Control Plane for Agents Back:ab