Microsoft has announced that Agent 365 will be available from its UAE data centre starting October. Agent 365 became generally available to commercial customers in May 2026, so the October update extends its availability to Microsoft’s UAE data centre.
Many organisations already have AI agents running across different parts of their business. Some may have been built through Microsoft Copilot Studio or Microsoft Foundry. Others may have been created by internal development teams, added through business applications or introduced by third-party platforms. This is the same pattern as shadow AI, where capability arrives through several routes before a central record of it exists.
Agent 365 is Microsoft’s control plane for observing, governing and securing these agents. The agents themselves can still be developed and run through platforms such as Copilot Studio, Foundry and other supported runtimes.
What Agent 365 does
Microsoft describes Agent 365 around three areas: observability, governance and security.
Agent 365 provides a central agent registry so administrators can see the agents operating across the organisation. It also provides information about agent activity, ownership and relationships. Governance controls cover lifecycle management, access and compliance, while Microsoft Entra, Purview and Defender add identity, data protection and security controls.
Agent 365 can work with Microsoft agents, custom agents and third-party agents. The process for bringing them into Agent 365 depends on how they were built.
Agents built with Microsoft platforms such as Copilot Studio, Foundry and Agent Builder have built-in observability support. Once an organisation starts an Agent 365 trial or has an active licence, these supported agents automatically send observability data to Agent 365.
Custom and third-party agents need to be integrated with Agent 365 observability by the developer or customer. The information available for these agents depends on what the integration sends. Microsoft also provides partner and registry integrations for bringing third-party agents into the Agent 365 registry.
This means an Agent 365 deployment will not automatically give an organisation a complete list of every agent in use. IT and security teams still need to identify agents running through other platforms and check how they are connected to the Microsoft environment.
Why the timing matters in the UAE
Microsoft says the UAE government aims to move 50% of government sectors, services and operations onto autonomous agentic AI models within two years. Amr Kamel, General Manager of Microsoft UAE, said AI adoption is moving quickly while organisational readiness is not keeping pace.
Inside an enterprise, agents can be added without a single team controlling every deployment. An agent may start with access to a small set of documents and later be connected to a SharePoint site, business application or API. Another department may create a separate agent for a similar process, while a third-party application may introduce an agent as part of an existing service.
This can leave organisations with multiple agents, different owners and different levels of access without a complete record of what is running.
IT and security teams need to know which agents exist, who owns them, what information they can access and which systems they can connect to. This includes agents created outside the central IT function, which is where an AI security service begins: discovery first, then a decision on each tool.
UAE availability is not the same as data residency
For organisations in government, banking, healthcare and energy, one of the main questions is where Agent 365 data is stored and processed.
Microsoft has confirmed that Agent 365 will be available from the UAE data centre starting October. This confirms local service availability, but it does not mean that every type of data associated with Agent 365 will be stored and processed in the UAE.
Microsoft’s current documentation states that Agent 365 observability stores customer content in the default geography of the customer’s Microsoft Entra tenant. It also states that, in limited circumstances, certain Agent 365 service-generated data, including data used for service metrics and analytics, may be replicated and stored in the United States for tenants outside the European Union. Microsoft also states that Agent 365 does not currently support Advanced Data Residency.
This does not mean that all Agent 365 data for a UAE tenant is replicated to the US. Microsoft identifies specific service-generated data that may be stored outside the tenant’s default geography.
Organisations with data residency requirements should therefore confirm where the relevant Agent 365 data is stored and processed before deployment. This should include observability data and other service-generated, diagnostic and operational data handled by the Microsoft services connected to Agent 365. The same principle applies to any cloud platform: the primary region is one setting among several, and secondary copies are configured separately. Personal data in scope also carries obligations under the UAE PDPL.
What goes into Agent 365 observability?
Agent 365 observability can record what happens during an agent run or session. Microsoft lists agent runs, tool usage, model or inference calls, timing, status and errors among the information that can be collected. Inputs and outputs can also be included when the source platform or agent developer sends them as part of the observability data.
For custom and third-party agents, the developer or customer controls what information is sent through the agent’s instrumentation. The amount and type of data available in Agent 365 will therefore depend on how that integration is configured.
This matters when an agent handles financial information, customer records, internal documents or other sensitive data. Observability data can contain more than basic technical logs. Where prompts and responses may carry regulated data, the controls described in AI data masking apply to this traffic as well.
Before enabling Agent 365 across a UAE tenant, organisations with regulatory or contractual requirements should confirm with Microsoft where the relevant data is stored and processed. The review should cover the specific services and data types involved, rather than assuming that UAE data centre availability means all related data stays in the UAE.
The 30-day retention period needs to be considered
Microsoft currently states that Agent 365 observability data is retained for 30 days and then automatically deleted.
For organisations that need longer audit or investigation records, 30 days may not be enough.
If an agent-related security incident is discovered several months after the activity occurred, the relevant observability data may no longer be available in Agent 365. Organisations that need longer retention will need to decide what data must be kept and where it should be stored. Forwarding the relevant events into a security operations platform is one option, with retention set against the framework the organisation reports on.
This should be decided before deployment where agent activity will be used for audits or security investigations.
Licensing is more complicated than the $15 price suggests
Agent 365 became generally available for the commercial segment on 1 May 2026 and is licensed per user rather than per agent. Microsoft currently lists Agent 365 at USD 15 per user per month as a standalone licence. It is also available as part of Microsoft 365 E7, which Microsoft lists at USD 99 per user per month.
The licensing requirements depend on the Microsoft licences an organisation already has.
For enterprise customers, Microsoft’s current licensing FAQ lists Microsoft 365 E5, or Microsoft 365 E3 or Office 365 E3 with EMS E3, together with the relevant Defender Suite and Purview Suite. For SMB customers, Microsoft lists Microsoft 365 Business Premium, with Defender Suite for SMB and Purview Suite for SMB required to unlock Agent 365 functionality. Frontline and education customers have separate requirements.
Microsoft also states that Agent 365 is not included in Microsoft 365 E3 or E5. These licences can form part of the prerequisites for purchasing Agent 365 separately, while Microsoft 365 E7 includes Agent 365.
The licence is tied to how users interact with agents. Microsoft says users who delegate their access to agents need to be licensed. Owners, sponsors or managers of agents operating with their own access also need the relevant Agent 365 licence. One Agent 365 licence can cover multiple agents associated with that user.
There is no separate per-agent charge under the Agent 365 licensing model. The services used to build and run agents can have their own licensing or consumption costs.
UAE customers should review their existing Microsoft 365, Defender and Purview licences before calculating the additional cost and confirm current UAE pricing with their Microsoft licensing partner.
What should organisations check before October?
A practical review can start with the agents already running in the organisation rather than waiting for the UAE data centre availability date.
Build an agent inventory. Include agents created through Copilot Studio, Foundry and Microsoft 365, along with custom agents and those introduced through third-party platforms. Third-party agents may require specific integration or synchronisation before their activity and metadata appear fully in Agent 365.
Identify an owner for each agent. The owner should know why the agent exists, what data it handles, which systems it can access and whether it still needs those permissions.
Review permissions and connections. Check the SharePoint sites, mailboxes, databases, APIs, business applications and other resources available to each agent. An agent may have more access than it needs. Where agents hold administrative access, the controls in privileged access management apply to non-human identities as well as to people.
Check the tenant geography. Confirm the default geography of the Microsoft Entra tenant and compare it with the organisation’s data residency requirements. For regulated deployments, confirm where the relevant Agent 365 data is stored and processed.
Review observability. Check what each agent sends to Agent 365 and whether prompts, responses or other sensitive information can be included. This is particularly important for custom and third-party integrations because the developer or customer controls the observability data that is sent.
Set the retention requirement. Compare the 30-day Agent 365 observability retention period with the organisation’s audit, compliance and incident response requirements.
Review the licensing position. Map the users who interact with, own, sponsor or manage agents against the Microsoft licences already assigned to them. This gives the organisation a more accurate licensing requirement than simply counting agents.
Preparing for UAE data centre availability
Before October, organisations can review which AI agents are already in use, who owns them, what they can access and what information is being sent to Agent 365.
For some businesses, this may show a controlled Microsoft environment. For others, it may uncover agents created by individual teams, unclear ownership, broad permissions or questions about where observability data is stored. Setting those boundaries in advance is the difference between an AI policy and an AI guardrail.
iConnect can support organisations with an Agent 365 readiness review covering the existing agent environment, ownership and access, Microsoft licensing, observability and data residency questions that need to be clarified with Microsoft. As a Microsoft Solutions Partner in Dubai, we deploy and manage Entra, Purview, Defender and Intune alongside the wider cybersecurity services these controls sit within.
For organisations already deploying AI agents across business functions, completing this review before October can help identify access, ownership, licensing and data handling issues before agent use expands further. Talk to our team to arrange a readiness review.