Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Microsoft Agent 365 vs Zenity

Microsoft Agent 365

Microsoft 365 control plane to discover, manage, govern, and secure AI agents

Zenity AI Agent Security & Governance Platform

Security and governance platform for AI agents, aimed at security teams

Short answer

Microsoft Agent 365 is a Microsoft 365 control plane with an agent registry and Entra agent identities; Zenity is a security platform that, it says, finds agents across platforms and can block actions on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 1, Source 2, Source 3, Source 4, Source 5, Source 6 Agent 365 is licensed per user; Zenity’s main AWS listing uses custom pricing.⁠Source 4, Source 7

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Agent 365 keeps an inventory of agents, including Copilot Studio agents, applies rules to what agents can do, and records agent activity; Zenity says it does too.⁠Source 2, Source 5, Source 8, Source 9, Source 10, Source 11
Where they differ
Agent 365 uses Entra Agent ID for agent identities.⁠Source 3 Zenity says it can check agent actions against rules and block actions on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 6, Source 11
Running both
Zenity says its integration with Agent 365 covers agents built on Copilot Studio, Microsoft 365 Copilot, and Microsoft Foundry.⁠Source 12
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not included
  • Not publicly documented

Microsoft Agent 365

  • Build agents: Not includedUse your chosen framework⁠Source 13
  • Host and run agents: Not includedYou host your agent⁠Source 14
  • Identity and access: OfferedEntra Agent ID⁠Source 3
  • Registry and governance: OfferedAgent registry in admin center⁠Source 2
  • Traffic between agents, tools, and models: PreviewTooling Gateway for MCP servers⁠Source 15
  • Agents across organizations: Not publicly documented

Zenity

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: Not publicly documented
  • Registry and governance: OfferedAI Observability agent inventory⁠Source 5
  • Traffic between agents, tools, and models: OfferedTool-call blocking for coding agents⁠Source 16
  • Agents across organizations: Not publicly documented

At a glance

TopicMicrosoft Agent 365Zenity
Who it’s forIT and security leaders managing AI agents.⁠Source 17Security teams that discover and inventory agents and enforce policies, per Zenity.⁠Source 18
Agents it coversMicrosoft and third-party agents.⁠Source 1 Microsoft’s separate Copilot Studio and Microsoft Foundry can provide built-in integration for some scenarios; agents outside Microsoft 365 channels and Entra Agent ID need extra steps.⁠Source 17, Source 19, Source 20Zenity says it covers agents in Copilot Studio, ChatGPT Enterprise, and Agentforce, homegrown agents built on Azure AI Foundry, AWS Bedrock, or Google Vertex AI, and coding agents such as Cursor.⁠Source 5, Source 16
Identity and controlMicrosoft Entra agent identities, managed with Conditional Access; admins can also apply policy templates to agents.⁠Source 3, Source 21Runtime rules can check agent actions; Zenity says they can reference Okta attributes.⁠Source 11
Pricing modelLists at $15 per user per month, or in Microsoft 365 E7.⁠Source 7 Basic identity and inventory come with Microsoft Cloud subscriptions; enterprise customers need Microsoft 365 E5, or E3 with the Defender and Purview suites.⁠Source 7Custom pricing on its main AWS Marketplace listing.⁠Source 4 A separate Security Hub Extended listing shows usage prices per resource and per million tokens.⁠Source 22
AvailabilityGenerally available since 1 May 2026, for the Commercial segment.⁠Source 23Zenity announced Azure Marketplace (now Microsoft Marketplace) availability in March 2025 and AWS in January 2026.⁠Source 24, Source 25, Source 26

What each one is

Microsoft Agent 365

Microsoft Agent 365 is a Microsoft 365 service that provides a centralized control plane to discover, manage, govern, and secure AI agents.⁠Source 1 It is administered across the agent registry in the Microsoft 365 admin center, Microsoft Entra, and Microsoft Purview.⁠Source 23

Zenity AI Agent Security & Governance Platform

Zenity is a SaaS security and governance platform for AI agents.⁠Source 4 Zenity describes three layers: Surface maps what an agent can reach and how it’s configured, Enforce lets safe actions through and stops unsafe ones, and Protect catches what slips through.⁠Source 18

The differences that matter

  1. How agents get into the inventory

    Microsoft Agent 365

    Microsoft says its separate Copilot Studio and Microsoft Foundry can provide built-in integration for some scenarios; agents outside Microsoft 365 channels need extra steps.⁠Source 17, Source 19, Source 20

    Zenity

    Zenity says AI Observability scans your environment and catalogs agents with their configuration, permissions, and tool access, flagging ones outside sanctioned deployment channels.⁠Source 5

    Agent 365 registry sync, in preview, imports agents from platforms such as Amazon Bedrock and Google Vertex AI; an administrator starts the sync by hand.⁠Source 19, Source 27

  2. Agent identity

    Microsoft Agent 365

    Agent identities live in Microsoft Entra Agent ID, managed with Conditional Access, permission grants, and consent.⁠Source 3

    Zenity

    Zenity says its Runtime Boundaries rules can reference Okta attributes such as active status, role, department, and job title.⁠Source 11

    Microsoft says Agent 365 inventories agents while Entra Agent ID provides their identities and permissions.⁠Source 28 Whether Zenity issues agent identities itself isn’t in Zenity’s public docs.

  3. Controlling what agents do

    Microsoft Agent 365

    Admins can block agents organization-wide, apply policy templates from Entra, Purview, SharePoint Online, and Defender, and control agents’ tool access tenant-wide.⁠Source 1, Source 21, Source 29

    Zenity

    Runtime Boundaries can check agent actions in real time; Zenity says it can block actions only on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 6, Source 11

    Microsoft says blocking a SharePoint or Foundry agent only affects its availability in Microsoft Copilot Chat.⁠Source 29 Zenity says its Custom Agents integration supports inline enforcement through an Evaluate API.⁠Source 30

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicMicrosoft Agent 365Zenity
Network exposureNotifications (preview) need an endpoint Agent 365 sends to.⁠Source 31 Agent 365’s private networking is not publicly documented.Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 32
IdentityAgent identities are Microsoft Entra service principals, managed with Conditional Access and consent; the inventory also lists agents without one.⁠Source 3, Source 33Zenity says rules can reference Okta attributes such as role.⁠Source 11 Issuing agent identities isn’t in Zenity’s public docs.
Access changes and revocationBlock agents organization-wide (Copilot Chat only for SharePoint and Foundry agents), or disable an Entra blueprint’s agents in one operation.⁠Source 3, Source 29Zenity says its kill switch immediately disables an agent’s tool and data access.⁠Source 11 It says rules can shut agents down.⁠Source 11
Audit trailSupported agents’ activity shows in Defender, Purview, and the admin center; Purview’s agent audit logs need E7 or Agent 365.⁠Source 1, Source 10, Source 13Zenity says it logs agent messages and tool calls, and can stream audit log events to Splunk or Microsoft Sentinel.⁠Source 5, Source 30
ComplianceNot yet a Core Online Service; runs on SOC- and ISO-audited services.⁠Source 10 Microsoft announced FedRAMP High authorization is pending.⁠Source 1Zenity says it has SOC 2 Type II, is ISO 27001 compliant, and announced FedRAMP “In Process” in March 2026.⁠Source 34, Source 35

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Microsoft Agent 365 and Zenity compared on 18 criteria
Microsoft Agent 365Zenity
What it is
What it is and who it’s forMicrosoft 365 service that provides a centralized control plane to discover, manage, govern, and secure AI agents, for IT and security leaders.⁠Source 1, Source 17SaaS security and governance platform for AI agents across SaaS, homegrown cloud platforms, and end-user devices, which Zenity aims at security teams.⁠Source 4, Source 18
MaturityGenerally available since 1 May 2026 for the Commercial segment.⁠Source 23 Registry sync and multi-tenant management are in preview.⁠Source 19, Source 36, Source 37Zenity announced AWS Marketplace availability in January 2026 and GA of Microsoft Foundry runtime controls in March 2026.⁠Source 26, Source 38
Control
Agent registry and discoveryAn agent registry in the Microsoft 365 admin center lists Microsoft and non-Microsoft agents, including ones without an Entra agent identity.⁠Source 2, Source 33Zenity says AI Observability scans for agents in SaaS platforms, custom builds, and on laptops, listing each with its permissions and tool access.⁠Source 5
Identity and access controlAgent identities live in Entra Agent ID, managed with Conditional Access, permission grants, and consent.⁠Source 3 Entra admin roles control access to agent management.⁠Source 39Zenity says Boundaries rules can reference Okta attributes such as active status, role, and department.⁠Source 11 Issuing agent identities isn’t in Zenity’s public docs.
Ownership, policy, and revocationA required sponsor per Entra agent identity, policy templates, and 30-day soft delete.⁠Source 3, Source 21, Source 29Zenity says rules can allow an action, block it, or shut the agent down, but it blocks inline only on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 6, Source 11
Audit log and observabilitySupported agents’ activity shows in Defender, Purview, and the admin center.⁠Source 10, Source 13 Agent 365 keeps it 30 days; Purview’s agent audit logs need E7 or Agent 365.⁠Source 1, Source 10Zenity says it logs messages, tool calls, retrievals, and handoffs.⁠Source 5 It says its audit log events can stream to Splunk or Microsoft Sentinel.⁠Source 30
Connection
How agents connectThe SDK works with agents on Azure, AWS, Google Cloud, or on premises.⁠Source 13 Agent 365’s private networking is not publicly documented.Zenity says agents emitting OpenTelemetry or gen_ai spans can connect, with an Evaluate API for inline enforcement.⁠Source 30 Network needs: not in Zenity’s public docs.
Agents across organizationsMultitenant Entra blueprints let a published agent join a customer’s tenant.⁠Source 3 Multi-tenant management, in preview, governs agents across tenants you administer.⁠Source 37Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 32
Protocol supportTenant-wide tool control; your own MCP servers in preview.⁠Source 1, Source 15 Microsoft documents A2A for its separate Foundry and standard-harness Copilot Studio, not Agent 365.⁠Source 40, Source 41Zenity says OpenTelemetry agents can connect; agent hooks can block dangerous coding-agent tool calls.⁠Source 16, Source 30 Whether Zenity supports A2A isn’t publicly documented.
Frameworks, models, and clouds supportedMicrosoft and third-party agents.⁠Source 1 SDK docs name LangChain, CrewAI, LlamaIndex, and the OpenAI Agents SDK, and agents keep their own host.⁠Source 14, Source 19Zenity says it covers agents in Copilot Studio and Agentforce, homegrown agents on Foundry, Bedrock, or Vertex AI, and agents emitting OpenTelemetry.⁠Source 5, Source 30
Operations
Deployment options and data residencyHonors the EU Data Boundary; its observability service stores customer content in the tenant’s default geography.⁠Source 10 Self-hosting it: not publicly documented.Software as a service, deployed on AWS per its AWS Marketplace listing.⁠Source 4 Regions, data residency, and self-hosting: not in Zenity’s public docs.
Compliance attestationsNot yet a Core Online Service; runs on SOC- and ISO-audited services.⁠Source 10 Microsoft announced FedRAMP High authorization is pending.⁠Source 1Zenity says the company holds SOC 2 Type II certification and is ISO 27001 compliant.⁠Source 34 It announced FedRAMP “In Process” status in March 2026.⁠Source 35
Support and SLANo specific SLA for the Frontier preview program.⁠Source 42 An SLA or support plan specific to the generally available service is not publicly documented.Zenity’s terms commit to at least 99.9% monthly uptime, with commercially reasonable efforts.⁠Source 43 Support requests go through Zendesk in business hours.⁠Source 43
Time and effort to get runningEnterprise customers need Microsoft 365 E5, or E3 with Defender Suite and Purview Suite, and at least one user with an Agent 365 license.⁠Source 7, Source 23Zenity says its Cursor plugin installs in Cursor desktop and its Security Hub integration starts from that console.⁠Source 44, Source 45 Prerequisites: not in Zenity’s public docs.
Pricing model and public pricesPer user, not per agent: lists at $15 per user per month standalone, or in Microsoft 365 E7.⁠Source 7 Microsoft Cloud subscriptions include foundational capabilities.⁠Source 7Main AWS listing: custom pricing.⁠Source 4 Security Hub Extended listing: $130 per resource a month (Observability), $16 per million tokens a month (Runtime Protection).⁠Source 22
Building
Agent building toolsMicrosoft says the Agent 365 SDK isn’t an agent-building framework.⁠Source 13 For low-code building, its docs point to Microsoft’s separate Copilot Studio.⁠Source 8Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 32
Model accessMicrosoft says the SDK doesn’t call or select models; the agent keeps making its own model calls.⁠Source 13, Source 14Zenity says AIDR combines deterministic rules with LLM-based detections.⁠Source 46 Which models it uses isn’t in Zenity’s public docs.
Integrations and ecosystemLaunched with preintegrated partner agents and agents built on agent factories such as n8n.⁠Source 36, Source 47 Work IQ MCP tools for Mail, Calendar, and Teams are in preview.⁠Source 48Zenity says it integrates with Microsoft Agent 365 and AWS Security Hub Extended and is on the Cursor Marketplace.⁠Source 12, Source 44, Source 45

Which to choose

Choose Microsoft Agent 365 if

  • You use Microsoft’s separate Copilot Studio or Microsoft Foundry, which Microsoft says can provide built-in Agent 365 integration for some scenarios.⁠Source 19, Source 20
  • You want agent identities in Entra, managed with the same Conditional Access, consent, and lifecycle controls as the rest of your tenant.⁠Source 3
  • You want named accountability: each Entra agent identity needs a sponsor, and admins can block or delete agents without owners.⁠Source 2, Source 3
  • You want per-user licensing that covers all of a user’s agents, with no consumption-based costs yet.⁠Source 7

Choose Zenity if

  • You want what Zenity says it offers: one inventory and activity record for agents in Copilot Studio, ChatGPT Enterprise, and Agentforce.⁠Source 5
  • Your security team wants what Zenity says it offers: agents found by scanning, including on laptops or outside sanctioned channels.⁠Source 5
  • You want what Zenity says it offers: agent actions checked against rules, and a kill switch for tool and data access.⁠Source 11
  • You need the coverage Zenity says it gives coding agents such as Claude Code, Cursor, GitHub Copilot, and ChatGPT Codex.⁠Source 16, Source 30

Questions buyers ask

How is each one priced?

Agent 365 lists at $15 per user per month standalone, or comes in Microsoft 365 E7; agents aren’t licensed.⁠Source 7 Zenity’s main AWS Marketplace listing uses custom pricing; a Security Hub Extended listing shows usage prices, such as $130 per resource a month for Observability.⁠Source 4, Source 22

Can either one govern agents built outside Microsoft?

Agent 365 works with third-party agents, though agents built outside Microsoft 365 channels and Entra Agent ID need extra steps.⁠Source 1, Source 17 Zenity says it inventories and tracks agents in Agentforce and homegrown builds on Bedrock or Vertex AI, and can enforce rules on coding agents.⁠Source 5, Source 16

Do they support MCP and A2A?

Agent 365 can control tool access; registering your own MCP servers is in preview.⁠Source 1, Source 15 Zenity says its hooks can block dangerous coding-agent tool calls.⁠Source 16 Microsoft documents A2A for its separate Foundry and standard-harness Copilot Studio, not Agent 365.⁠Source 40, Source 41 Whether Zenity supports A2A isn’t publicly documented.

Can either one work with agents at other organizations?

Multitenant Entra blueprints let a published agent join a customer’s tenant, and multi-tenant management, in preview, governs agents across tenants you administer.⁠Source 3, Source 37 Microsoft’s separate Foundry agents can call A2A agents hosted elsewhere.⁠Source 41 Reaching agents a partner or another tenant owns isn’t in Zenity’s public docs.

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

54 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Microsoft Agent 365 - Service Descriptions | Microsoft Learn Microsoft · checked Back:abcdefghijklm

  2. Source 2: Agent Registry in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Microsoft · checked Back:abcde

  3. Source 3: Agent 365 identity | Microsoft Learn Microsoft · checked Back:abcdefghijklm

  4. Source 4: AWS Marketplace: Zenity Zenity · checked Back:abcdefgh

  5. Source 5: AI Observability | See Every Agent, Know What it Touches | Zenity Zenity · checked Back:abcdefghijkl

  6. Source 6: Zenity's Coverage of the 2026 OWASP Top 10 for LLM Apps Zenity · checked Back:abcd

  7. Source 7: Licensing Documents Microsoft · checked Back:abcdefgh

  8. Source 8: Get started with Microsoft Agent 365 | Microsoft Learn Microsoft · checked Back:ab

  9. Source 9: Agent overview in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Microsoft · checked Back to text

  10. Source 10: Data handling, data residency, and compliance in Agent 365 observability | Microsoft Learn Microsoft · checked Back:abcdefg

  11. Source 11: Runtime Boundaries | The Runtime Boundary for Autonomous AI | Zenity Zenity · checked Back:abcdefghijk

  12. Source 12: Zenity Now Integrates with Microsoft Agent 365 Zenity · checked Back:abc

  13. Source 13: Agent 365 SDK frequently asked questions | Microsoft Learn Microsoft · checked Back:abcdef

  14. Source 14: Microsoft Agent 365 SDK overview | Microsoft Learn Microsoft · checked Back:abc

  15. Source 15: Bring your own (BYO) MCP server in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Microsoft · checked Back:abc

  16. Source 16: Coding and Personal Agents | Zenity Zenity · checked Back:abcdef

  17. Source 17: Microsoft Agent 365: The Control Plane for Agents Microsoft · checked Back:abcde

  18. Source 18: Platform | AI Agent Security & Governance Platform | Zenity Zenity · checked Back:abc

  19. Source 19: Choose an Agent 365 Integration Option | Microsoft Learn Microsoft · checked Back:abcdef

  20. Source 20: What is Microsoft Foundry? - Microsoft Foundry | Microsoft Learn Microsoft · checked Back:abc

  21. Source 21: Policy templates | Microsoft Learn Microsoft · checked Back:abc

  22. Source 22: AWS Marketplace: Zenity AI Security & Governance Platform for Security Hub Extended Zenity · checked Back:abc

  23. Source 23: Microsoft Agent 365 overview | Microsoft Learn Microsoft · checked Back:abcd

  24. Source 24: Zenity Now Available in the Microsoft Azure Marketplace Zenity · checked Back to text

  25. Source 25: Introducing Microsoft Marketplace - Thousands of solutions. Millions of customers. One Marketplace. - The Official Microsoft Blog Zenity · checked Back to text

  26. Source 26: Zenity Now Available on AWS Marketplace, Bringing End-to-End Security to Amazon Bedrock AgentCore and Enterprise AI Agents Everywhere Zenity · checked Back:ab

  27. Source 27: Connected platforms in Microsoft Agent 365 | Microsoft Learn Microsoft · checked Back to text

  28. Source 28: Protect agent identities with Microsoft Entra | Microsoft Learn Microsoft · checked Back to text

  29. Source 29: Governance and Lifecycle actions for agents available in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Microsoft · checked Back:abcd

  30. Source 30: From Triage to Full Coverage: The Shift AI Agent Security Took in August Zenity · checked Back:abcdefgh

  31. Source 31: Agent Messaging Endpoint | Microsoft Learn Microsoft · checked Back to text

  32. Source 32: Zenity Documentation (login) Zenity · checked Back:abc

  33. Source 33: Agent Registry convergence with Microsoft Agent 365 | Microsoft Learn Microsoft · checked Back:ab

  34. Source 34: Zenity Trust Center Zenity · checked Back:ab

  35. Source 35: Zenity Achieves FedRAMP “In Process” Status for AI Agent Security Zenity · checked Back:ab

  36. Source 36: Microsoft Agent 365, now generally available, expands capabilities and integrations | Microsoft Security Blog Microsoft · checked Back:ab

  37. Source 37: Manage agents across multiple tenants in the Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Microsoft · checked Back:abc

  38. Source 38: Zenity Announces Availability of Inline Agent Runtime Security for Agents Built on Microsoft Foundry Zenity · checked Back to text

  39. Source 39: Agent management roles and permissions in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Microsoft · checked Back to text

  40. Source 40: Connect to an agent over the Agent2Agent (A2A) protocol - Microsoft Copilot Studio | Microsoft Learn Microsoft · checked Back:ab

  41. Source 41: Connect to an A2A agent endpoint from Foundry Agent Service - Microsoft Foundry | Microsoft Learn Microsoft · checked Back:abc

  42. Source 42: Preview Agent 365 features through the Frontier program | Microsoft Learn Microsoft · checked Back to text

  43. Source 43: Zenity Subscription Terms and Conditions (EULA linked from Zenity's AWS Marketplace listings) Zenity · checked Back:ab

  44. Source 44: Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace Zenity · checked Back:ab

  45. Source 45: Zenity Selected for AWS Security Hub Extended to Secure Enterprise AI Agents Zenity · checked Back:ab

  46. Source 46: AI Detection and Response (AIDR) | See the Threat, Stop the Action | Zenity Zenity · checked Back to text

  47. Source 47: Ecosystem partner agents available in Agent 365 | Microsoft Learn Microsoft · checked Back to text

  48. Source 48: Connect existing agents to Microsoft Agent 365 | Microsoft Learn Microsoft · checked Back to text

  49. Source 49: Agent 365 connector: Monitor, hunt, and investigate AI agent activity in Microsoft Sentinel | Microsoft Community Hub Microsoft · checked Back to text

  50. Source 50: Your company's private network Blocks.ai · checked Back to text

  51. Source 51: Network requirements Blocks.ai · checked Back to text

  52. Source 52: Solutions: Agent sprawl Blocks.ai · checked Back to text

  53. Source 53: Solutions: Partner networks Blocks.ai · checked Back to text

  54. Source 54: Pricing Blocks.ai · checked Back to text