Your customers are already running AI agents. Not piloting, not evaluating. Running. Microsoft telemetry shows that more than 80% of Fortune 500 companies used active AI agents during the last 28 days of November 2025 (agents built with Copilot Studio or Agent Builder), and IDC projects 1.3 billion agents in circulation by 2028, roughly the population of India. Microsoft has now published its security playbook for this reality: the e-book "Agentic AI is Here. Secure It Now." We read it so you can sell it.

Here is what it says, what it ships, and what partners do with it on Monday morning.

The Numbers Your Next Security Conversation Needs

Microsoft backs the playbook with telemetry, not vibes:

- 1.3 billion AI agents by 2028 (IDC). For every human, multiple agents.
- More than 80% of business leaders expect agents integrated into operations within 12 to 18 months (Work Trend Index 2025).
- 29% of employees already use unsanctioned AI agents for work tasks (Hypothesis Group survey of 1,700+ data security professionals). That is shadow AI, and it is in your customer's tenant today.
- AI-generated identities grew 195% globally, and deepfake techniques can now defeat liveness tests (Microsoft Digital Defense Report 2025).
- Of 15.9 billion Microsoft account creation requests in H1 2025, more than 90% came from malicious bots. Microsoft blocks 1.6 million fake signup attempts every hour.

The attack surface is no longer just humans clicking bad links. It is agents acting at machine speed, with broad access, often outside every security framework designed for human users. A compromised agent with overprivileged access shrinks the window between initial breach and serious impact.

And it is not just Microsoft measuring this. UpGuard's 2025 State of Shadow AI report found unsanctioned AI use reaching into the executive suite itself, the very people meant to set policy. The 29% figure is not an outlier. It is the floor.

What Microsoft Agent 365 Actually Shipped

The playbook is built on five product families: Microsoft Defender, Entra, Intune, Purview and Sentinel, with Security Copilot running across all of them. Three moves matter for partners:

1. Microsoft Agent 365 is the control plane for agents. Observe what agents do across the estate, govern their access to resources and data, and secure them against AI-specific threats like prompt injection and model tampering. Agent 365 includes Entra capabilities for agent identity, Purview for data protection, and Defender for threat detection. Critically for your licensing motion: Agent 365 is included in Microsoft 365 E7, the Frontier Suite (generally available since May 1, 2026, at $99 per user per month), alongside Microsoft 365 Copilot, Entra Suite and Microsoft 365 E5. Several of the agent-specific Defender and Purview risk signals are still in public preview, so set customer expectations accordingly.

2. Security Copilot is included in Microsoft 365 E5 and E7 at no additional cost. This is the part your customers do not believe until you show them the invoice. Embedded agents do real work: the Phishing Triage Agent in Defender identifies 6.5x more malicious email, triages 78% faster and hits 77% more accurate verdicts, per Microsoft's randomized control trial from October 2025. The Conditional Access Optimization Agent in Entra finds 204% more missing Zero Trust baseline policies. St. Luke's University Health Network saves nearly 200 hours every month on phishing triage alone, with incident reports created in minutes instead of hours.

3. The Security Dashboard for AI gives the CISO one view of AI risk. Agents, AI apps, exposure trends, prioritized recommendations, ready for board-level conversations. If your customer's security lead cannot answer "where is AI running in our estate" in one meeting, this dashboard is the shortest path to that answer.

The European Angle: Regulation Sets the Deadline

Microsoft's playbook is global. Europe adds something the US market does not have: hard law with dates attached.

- The EU AI Act bites on August 2, 2026. Obligations for high-risk AI systems apply from that date, transparency rules for AI-generated content land alongside them, and GPAI obligations have applied since August 2025. Agent governance stops being a best practice and becomes a documented, auditable obligation with fines attached. The sales version: every European customer deploying agents needs governance in place, on a deadline you can print in a proposal.
- NIS2 already regulates the MSP itself. Managed service providers and managed security service providers are explicitly named in NIS2, in force since October 2024. If you run an MSP in the EU, you are a regulated entity, and so are many of your clients. Most MSPs still do not know they are in scope. The first ones to figure it out turn their own compliance into a service line.
- The Nordics are Europe's AI frontier. Eurostat puts 20% of EU enterprises on AI in 2025, up from 13.5% the year before. Denmark leads at 42.0%, followed by Finland (37.8%) and Sweden (35.0%), while Romania sits at 5.2%. Nordic partners operate in Europe's most mature AI market, so the agent governance problem lands on your desk first. What you build now becomes the reference for the rest of the continent.

The MSP data says the door is wide open. In Kaseya's 2026 State of the MSP report, covering more than 1,000 providers, 48% rank AI as the number one client need, ahead of security and backup. Yet only 13% generate meaningful revenue from AI services. Demand is a mile wide, monetization is a footpath. The partner who productizes agent governance first owns that gap.

The Business Case Is Already Modeled

Forrester's Total Economic Impact study of Microsoft's security portfolio (May 2026) modeled a composite organization across all five product families:

- 124% three-year ROI - 30% reduction in likelihood of a breach
- 25% reduction in cost to remediate breaches
- 20%+ reduction in technology spend through consolidation

Consolidation is the headline. Customers running fragmented, reactive security pay more and catch less. The unified platform is cheaper and better at the same time, which is the easiest security pitch you will make this year.

What Should Partners Do?

- [ ] Run the shadow AI conversation this quarter. With 29% of employees on unsanctioned agents, and independent research showing shadow AI reaching the executive suite, every customer has the problem. The only variable is whether they know it. Use the Security Dashboard for AI as the discovery tool.
- [ ] Lead with what E5 and E7 already include. Security Copilot at no additional cost changes the economics of every E5 renewal and every E7 upsell. Agent 365 inside E7 is the governance story for the agent era.
- [ ] Map agent governance to compliance. Purview inside Agent 365 covers data security and audit readiness for agents. In regulated verticals (finance, healthcare, public sector), this is the door opener.
- [ ] Position Defender Experts for the skills gap. Customers who cannot staff a 24/7 SOC buy managed XDR, incident response and advisory through the Defender Experts Suite. That is attach revenue with zero headcount for you.
- [ ] Anchor the ROI model. 124% ROI and 30% lower breach likelihood turn the security conversation from cost center to board decision. Bring the Forrester numbers.

Partner Play

No cotton wool: your customers are deploying agents faster than they are securing them, and most of them do not know what is running in their own estate. That gap is your pipeline.

On Monday morning:

  1. Pick ten customers on Microsoft 365 E3. The jump to E5 now carries Security Copilot included, and the jump to E7 carries Agent 365. That is not an upsell, it is the security answer they are already shopping for.
  2. Book one "agent discovery" workshop per week. Inventory what agents exist, what they access, and whether they are governed. You will find shadow AI in the first hour. The fix is Agent 365, and you are the one selling it.
  3. Attach the 200-hour story to every healthcare and public sector deal. St. Luke's is the reference case your customer's CISO repeats to their board.
  4. Bring the Forrester TEI numbers as a model, not a verdict. The study is Microsoft-commissioned and built on a fictional composite organization, and European customers will discount it the moment it is presented as fact. Use 124% ROI and 20%+ lower technology spend to open the consolidation conversation, then run the same math on the customer's own license stack. Their numbers close the deal, not Forrester's.
  5. Check the Agent 365 license prerequisites, effective June 1, 2026 for new purchases: Microsoft 365 E5 for enterprise, Business Premium for SMB, or the standalone Defender or Purview Suites. SMB nuance worth two minutes: Business Premium unlocks Agent 365 itself, but full functionality needs Defender and Purview Suite for SMB on top. Position the prerequisite SKU first, and Agent 365 becomes the reason to buy it.
  6. Put August 2, 2026 in every security proposal. The EU AI Act's high-risk obligations apply from that date, and NIS2 already covers your own MSP and half your client base. A compliance deadline with fines is the strongest close available in Europe this year. Every agent discovery workshop you book now lands before the deadline rush.
The agent era does not wait for your customer's security posture to catch up. Sell the catch-up.

Key Takeaways

- 1.3 billion AI agents by 2028 (IDC) and 80%+ of Fortune 500 already running them. This is present tense, not roadmap.
- 29% of employees use unsanctioned AI agents. Shadow AI is the discovery conversation that opens every security deal this year.
- Agent 365 is the control plane (observe, govern, secure) and is included in Microsoft 365 E7. Security Copilot is included in E5 and E7 at no additional cost.
- Measured impact: 6.5x more malicious email caught, 78% faster triage, 200 hours saved monthly at St. Luke's, 204% more Zero Trust gaps found in Entra.
- Forrester models 124% three-year ROI and 30% lower breach likelihood for the consolidated Microsoft security platform.
- Europe adds the deadline. EU AI Act high-risk obligations apply from August 2, 2026, and NIS2 already regulates MSPs and MSSPs directly. In Europe, agent governance is compliance, not preference. The Nordics lead adoption (Denmark 42% of enterprises, EU average 20%, Eurostat), so Nordic partners meet the problem first.
- The MSP gap is the opportunity: 48% of MSPs say AI is the number one client need, but only 13% monetize it meaningfully (Kaseya 2026, 1,000+ providers). Productized agent governance is unclaimed territory.
- The partner motion: E3 to E5 or E7 upgrades, agent discovery workshops, compliance-led Purview attach, and Defender Experts for the SOC skills gap.


Sources: Microsoft Security Blog: Secure agentic AI for your Frontier Transformation · Microsoft Security Blog: Secure agentic AI end-to-end · Microsoft: What Is Agentic AI Security? · Eurostat: 20% of EU enterprises use AI (2025) · European Commission: EU AI Act · European Commission: NIS2 Directive · Kaseya 2026 State of the MSP Report · Microsoft e-book "Agentic AI is Here. Secure It Now." (2026)

Where Cloud Factory fits in all this: we carry the operational weight for our partners, licensing, provisioning, support and GDAP, so your team can run the security conversations instead of the paperwork. And with Ascent, the upgrade plays in this article are mapped per customer in your own base, not as generic advice. Talk to Cloud Factory →

Keep reading: Microsoft FY27 Partner Incentives: What Changed and How to Get Paid Now · FY27 Kicks In: Every Partner Center Change from July 2026 That Moves Your Pipeline