Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Kong AI Gateway vs Microsoft Agent 365
Kong AI Gateway
Gateway that governs LLM, MCP, and agent-to-agent traffic
Microsoft Agent 365
Microsoft 365 control plane to discover, manage, govern, and secure AI agents
Short answer
Kong AI Gateway is a gateway for LLM, MCP, and A2A traffic; Microsoft Agent 365 is a Microsoft 365 control plane for agents built and run elsewhere.Source 1, Source 2, Source 3, Source 4, Source 5 Kong’s data plane nodes check traffic against policy; Agent 365 keeps an agent registry, uses Entra agent identities, and is licensed per user.Source 2, Source 6, Source 7, Source 8
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
- Where they overlap
- Both can limit which tools agents use and record agent activity: Kong per caller at the gateway, Agent 365 tenant-wide.Source 3, Source 9, Source 10, Source 11, Source 12
- Where they differ
- Kong also routes LLM traffic to model providers; the Agent 365 SDK doesn’t call models.Source 5, Source 13 Agent 365 keeps an organization-wide agent registry; Kong’s, in Konnect Catalog, is in beta.Source 6, Source 14, Source 15
- Running both
- Microsoft says Agent 365 works with agents built or acquired from third-party sources.Source 3 Neither vendor publicly documents using the two together.
Kong AI Gateway
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
Microsoft Agent 365
- Agents across organizations: Not publicly documented
At a glance
What each one is
Kong AI Gateway
Kong AI Gateway is one gateway for LLM, MCP, and agent-to-agent (A2A) traffic, with shared authentication, observability, and policy features.Source 1, Source 2 In 2.x, an agent is added as an AI Agent entity that exposes it at a gateway endpoint and can carry policies.Source 10, Source 21
The differences that matter
Where policy is enforced
Kong AI GatewayIn 2.x, data plane nodes you run receive LLM, MCP, and A2A traffic, check it against policy, and forward what’s allowed.Source 2
Microsoft Agent 365Through Microsoft 365 and Entra: Conditional Access on agent identities, policy templates, and an organization-wide block (only in Copilot Chat for SharePoint and Foundry agents).Source 7, Source 22, Source 23
Kong’s control plane is never in the path of user data traffic.Source 2 Agent 365 routes MCP servers you register through its Tooling Gateway, in preview.Source 16
Agent registry
Kong AI GatewayIn 2.x, agents are added as entities scoped to one gateway instance; Konnect Catalog’s organization-wide agent inventory is in beta, not for production.Source 2, Source 10, Source 15
Microsoft Agent 365Agent 365’s registry lists Microsoft and non-Microsoft agents; agents built outside Microsoft 365 channels and Entra Agent ID need extra steps to appear.Source 14, Source 24
In Kong’s Catalog beta, agents can be added by pasting an A2A card.Source 15 Agent 365 registry sync, in preview, imports agents from platforms such as Amazon Bedrock.Source 19
Identity and access
Kong AI GatewayThe gateway can require callers to use an API key or OpenID Connect, then check a per-agent allow or deny list.Source 10
Microsoft Agent 365Agent identities live in Microsoft Entra Agent ID, managed with Conditional Access, permission grants and consent, and lifecycle operations.Source 7
Kong’s lists check the caller’s AI Consumer identity.Source 10, Source 25 Each Entra agent identity needs a sponsor, a business representative accountable for the agent.Source 7
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Kong AI Gateway | Microsoft Agent 365 | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | One gateway that governs LLM, MCP, and A2A traffic.Source 1, Source 2 All three run through one data plane, with shared authentication, observability, and policy features.Source 2 | A Microsoft 365 service that provides a centralized control plane to discover, manage, govern, and secure AI agents, for IT and security leaders.Source 3, Source 24 |
| Maturity | Version 2.0 announced generally available on 1 September 2026; 2.2.0 released 30 September 2026.Source 9, Source 33 Konnect Catalog’s agent inventory is in beta.Source 15 | Generally available since 1 May 2026 for the Commercial segment.Source 18 Registry sync and multi-tenant management are in preview.Source 19, Source 20 |
| Control | ||
| Agent registry and discovery | In 2.x, each AI Agent entity, A2A or plain HTTP, is scoped to one gateway instance.Source 2, Source 10 Konnect Catalog’s agent inventory is in beta.Source 15 | Agent registry in the Microsoft 365 admin center: one inventory of Microsoft and non-Microsoft agents, including agents without an Entra agent identity.Source 6, Source 14 |
| Identity and access control | An agent can require API key or OpenID Connect authentication before routing.Source 10 An allow or deny list of identities can apply before traffic reaches it.Source 10 | Agent identities live in Microsoft Entra Agent ID, managed with Conditional Access, permission grants, and consent.Source 7 The inventory also lists agents without one.Source 14 |
| Ownership, policy, and revocation | Agent policies include input validation, logging, and rate limits.Source 10 Kong’s AI PII Sanitizer scrubs requests to AI models: a Plus add-on, included on Enterprise.Source 17, Source 34 | Entra agent identities need a sponsor.Source 7 Admins can block agents (SharePoint and Foundry ones only in Copilot Chat), approve activations, and apply templates.Source 22, Source 23 |
| Audit log and observability | A2A audit logs: task IDs, method calls, latencies, errors.Source 11 A2A telemetry can go to Konnect and OpenTelemetry; bodies go to Konnect only if you opt in.Source 2, Source 10 | Supported agents’ activity shows in Defender, Purview, and the admin center; Agent 365 keeps it 30 days.Source 4, Source 12 Purview audit of agent activity needs E7 or Agent 365.Source 3 |
| Connection | ||
| How agents connect | Each agent is an upstream URL the gateway proxies to.Source 10 In 2.x, data plane nodes you run forward allowed traffic and stay connected to Konnect.Source 2 | The SDK works with agents on Azure, AWS, Google Cloud, or on premises.Source 4 Notifications, in preview, go to a messaging endpoint URL you register.Source 26 |
| Agents across organizations | Not publicly documented (checked 2 October 2026) | A published agent can be added to a customer tenant with tenant-local Entra identities.Source 7 Managing agents across tenants you administer is in preview.Source 20 |
| Protocol support | A2A over JSON-RPC and REST bindings.Source 10 MCP revisions 2025-03-26, 2025-06-18, 2025-11-25, and 2026-07-28 (from version 2.1).Source 35 | Tenant-wide tool control; your own MCP servers in preview.Source 3, Source 16 Microsoft’s separate Foundry and Copilot Studio support A2A; Agent 365 itself doesn’t document it.Source 36, Source 37 |
| Frameworks, models, and clouds supported | Kong says it governs A2A traffic without changing how agents are built.Source 38 Agents that don’t use A2A can pass through as plain HTTP.Source 10 | Microsoft and third-party agents.Source 3 SDK docs name frameworks such as LangChain, CrewAI, and the OpenAI Agents SDK, and agents keep their own host.Source 5, Source 19 |
| Operations | ||
| Deployment options and data residency | 2.x: a Konnect-managed control plane in a region you choose, data plane nodes you run.Source 2, Source 39 Kong also sells Kong-managed Dedicated Cloud and serverless gateways.Source 17, Source 40, Source 41 | Honors the EU Data Boundary; the observability service stores customer content in the tenant’s default geography.Source 12 Self-hosting it is not publicly documented. |
| Compliance attestations | From 2.2, FIPS mode uses only FIPS 140-3 approved algorithms; not submitted for NIST validation.Source 31 Kong lists ISO 27001, SOC 2, and PCI DSS for Kong Inc.Source 32 | Not yet a Core Online Service; runs on SOC- and ISO-audited services.Source 12 Microsoft announced it meets reviewed FedRAMP High controls; authorization is pending.Source 3 |
| Support and SLA | Konnect targets 99.9% availability; Dedicated Cloud Gateways list a 99.99% SLA, serverless gateways none.Source 17 Enterprise support SLAs: 30 min to 2 hours.Source 17 | No specific SLA for the Frontier preview program.Source 42 An SLA or support plan specific to the generally available service is not publicly documented. |
| Time and effort to get running | A quickstart script creates a Konnect control plane and a local Docker data plane.Source 13 To route A2A traffic, create an AI Agent entity and attach policies.Source 21 | Enterprise customers need Microsoft 365 E5, or E3 with Defender Suite and Purview Suite, and at least one user with an Agent 365 license.Source 8, Source 18 |
| Pricing model and public prices | Plus: from $25 a month plus usage; per control plane, $200 hybrid, $500 Dedicated Cloud, $25 serverless.Source 17 Enterprise: custom, billed annually.Source 17 | Per user, not per agent: lists at $15 a month standalone, or in Microsoft 365 E7.Source 8 Microsoft Cloud subscribers get foundational capabilities at no extra cost.Source 8 |
| Building | ||
| Agent building tools | Kong says it can generate MCP tools and servers from Kong-managed APIs.Source 1 Tools for building agents in Kong AI Gateway are not publicly documented. | Microsoft says the Agent 365 SDK isn’t an agent-building framework.Source 4 For low-code building, its docs point to Microsoft’s separate Copilot Studio.Source 43 |
| Model access | One API to providers including OpenAI, Anthropic, Amazon Bedrock, Gemini, Azure AI, Mistral, and Ollama, with credentials you supply.Source 2, Source 13, Source 44 | Microsoft says the SDK doesn’t call or select models; the agent keeps making its own model calls.Source 4, Source 5 |
| Integrations and ecosystem | A Policies Hub of policies and integrations.Source 28 AI Vault works with AWS, GCP, Azure, and HashiCorp Vault secrets backends.Source 2 | Launched with preintegrated partner agents and agents built on partner agent factories.Source 45, Source 46 Work IQ MCP tools, in preview, cover Mail, Calendar, Teams, and more.Source 47 |
Which to choose
Choose Kong AI Gateway if
- You want one gateway for LLM, MCP, and A2A traffic, with shared authentication, observability, and policy features.Source 1, Source 2
- You want per-agent access lists, input validation, and rate limits applied at a gateway that proxies to your agents.Source 10
- You want to run the data plane yourself (2.x), or a fully self-hosted AI gateway from Kong’s separate Gateway Enterprise offering.Source 2, Source 17
- You want one API to many model providers, such as OpenAI, Anthropic, Gemini, and Mistral, using credentials you supply.Source 2, Source 13, Source 44
Choose Microsoft Agent 365 if
- Your agents are in Microsoft’s separate Copilot Studio or Microsoft Foundry, which Microsoft says can integrate with Agent 365 for some scenarios.Source 19, Source 48
- You want agent identities in Microsoft Entra, managed with the same Conditional Access, consent, and lifecycle controls used elsewhere in Entra.Source 7
- You want one registry for Microsoft and non-Microsoft agents that also counts agents created or managed outside Agent 365.Source 6, Source 14
- You want named accountability: each Entra agent identity needs a sponsor, and admins can block or delete agents without owners.Source 6, Source 7
Questions buyers ask
Do they support MCP and A2A?
Kong AI Gateway detects A2A over JSON-RPC and REST and accepts four MCP revisions.Source 10, Source 35 Agent 365 can control tool access tenant-wide, including Microsoft MCP servers; registering your own is in preview.Source 3, Source 16 A2A is documented for Microsoft’s separate Copilot Studio and Microsoft Foundry, not Agent 365.Source 36, Source 37
Which identity providers do they work with?
Kong’s OpenID Connect option can authenticate users through Okta, Azure AD, Google, or any OIDC-compliant provider; callers can also use API keys.Source 10, Source 27 Agent 365 agent identities live in Microsoft Entra; agents can authenticate users with Entra ID, which can federate to another provider.Source 7, Source 49
Can either one connect agents across organizations?
Kong AI Gateway proxies to agents registered as upstream URLs.Source 10 A cross-organization trust model for Kong is not publicly documented. A published agent can join a customer’s tenant through a multitenant Entra blueprint.Source 7 Cross-organization agent-to-agent calls through Agent 365 are not publicly documented.
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
54 public sources, each with the date we checked it. Every one opens in a new tab.
Source 2: AI Gateway architecture - Kong Docs Back:abcdefghijklmnopqrstu
Source 3: Microsoft Agent 365 - Service Descriptions | Microsoft Learn Back:abcdefghijkl
Source 4: Agent 365 SDK frequently asked questions | Microsoft Learn Back:abcdefg
Source 5: Microsoft Agent 365 SDK overview | Microsoft Learn Back:abcdef
Source 6: Agent Registry in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Back:abcdef
Source 7: Agent 365 identity | Microsoft Learn Back:abcdefghijklmno
Source 9: Kong AI Gateway 2.0 Is Now GA - And It's Already Moving Faster Back:abc
Source 10: AI Agents - Kong AI Gateway docs Back:abcdefghijklmnopqrstuvw
Source 11: Route A2A traffic through AI Gateway - Kong Docs Back:abc
Source 12: Data handling, data residency, and compliance in Agent 365 observability | Microsoft Learn Back:abcdef
Source 14: Agent Registry convergence with Microsoft Agent 365 | Microsoft Learn Back:abcdefg
Source 16: Bring your own (BYO) MCP server in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Back:abcde
Source 18: Microsoft Agent 365 overview | Microsoft Learn Back:abcd
Source 19: Choose an Agent 365 Integration Option | Microsoft Learn Back:abcde
Source 20: Manage agents across multiple tenants in the Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Back:abc
Source 21: Route A2A agent traffic through AI Gateway - Kong Docs Back:ab
Source 23: Governance and Lifecycle actions for agents available in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Back:abc
Source 24: Microsoft Agent 365: The Control Plane for Agents Back:ab
Source 26: Agent Messaging Endpoint | Microsoft Learn Back:ab
Source 27: AI Auth Strategies - Kong AI Gateway docs Back:ab
Source 29: Request Termination - Configuration Reference - Policy | Kong Docs Back to text
Source 30: Konnect and Dev Portal audit logs - Kong Docs Back to text
Source 31: FIPS 140-3 compliance in AI Gateway - Kong Docs Back:ab
Source 33: Kong AI Gateway changelog - Kong Docs Back to text
Source 34: AI PII Sanitizer - Policy | Kong Docs Back to text
Source 35: MCP version support - Kong AI Gateway docs Back:ab
Source 36: Connect to an agent over the Agent2Agent (A2A) protocol - Microsoft Copilot Studio | Microsoft Learn Back:ab
Source 37: Connect to an A2A agent endpoint from Foundry Agent Service - Microsoft Foundry | Microsoft Learn Back:ab
Source 38: The Agent Gateway for Secure, Observable Agent-to-Agent Communication (Kong) Back to text
Source 40: Dedicated Cloud Gateways - Kong Docs Back to text
Source 42: Preview Agent 365 features through the Frontier program | Microsoft Learn Back to text
Source 43: Get started with Microsoft Agent 365 | Microsoft Learn Back to text
Source 45: Ecosystem partner agents available in Agent 365 | Microsoft Learn Back to text
Source 46: Microsoft Agent 365, now generally available, expands capabilities and integrations | Microsoft Security Blog Back to text
Source 47: Connect existing agents to Microsoft Agent 365 | Microsoft Learn Back to text
Source 48: What is Microsoft Foundry? - Microsoft Foundry | Microsoft Learn Back to text
Source 49: Integrate Microsoft Entra Agent ID with third-party identity providers | Microsoft Learn Back to text