Microsoft has now written the definition of a shadow agent into its own admin guidance. Read it carefully: it is a precise description of everything the registry will never contain.
Why the Agent 365 Definition Matters Now
Microsoft’s Center of Excellence guidance for agents is unusually direct. Shadow agents, it says, are agents built or run outside the governance program: unmanaged, with no registered owner, no reviewed access, no monitoring. Left alone, “they’re where your next incident starts.” The Microsoft 365 admin center registry now carries three headline tiles: total agents, agents without owners, and unmanaged agents, the last defined as agents created or managed outside Agent 365, without its risk protection and observability.
This is the right definition. It is also a confession. A registry can count the agents that were registered, and the registered agents that lost their owner. It cannot count the agents that never asked for an identity. The “unmanaged” tile is a lower bound, and the gap between that tile and the real estate is the position nobody is marking.
| Metric | Value | Source |
|---|---|---|
| Organizations reporting an AI agent security incident this year | 88% | Ospiri research |
| Added breach cost where shadow AI was a factor | up to +$670K | IBM Cost of a Data Breach Report 2025 |
| Breaches involving shadow AI | roughly 1 in 5 | IBM Cost of a Data Breach Report 2025 |
| Registry sync cadence for non-Microsoft platforms | Manual, on-demand; scheduled sync “in a future release” | Microsoft Learn, Agent 365 registry sync (preview) |
Price that last row against the first three. The registry is a point-in-time snapshot of the agents that were easy to enumerate, refreshed when an admin clicks a button. The exposure compounds continuously.
Four Tiers of “Known,” Only One of Them Automatic
The Entra agent registry sorts your estate by how the agent got in, not by what the agent can reach. That distinction decides what Agent 365 can see. We have written before about the two types of shadow agents; the registry adds a finer grain.
| Tier | How it enters the registry | Identity | Refresh | Example |
|---|---|---|---|---|
| Native | Automatic on creation (Copilot Studio agents created after May 2026 get an Entra Agent ID) | Yes | Continuous | A sales-coach agent built in Copilot Studio |
| Legacy native | Manual migration by an admin (older Copilot Studio agents still use app registrations) | Only after migration | On migration | A 2025-era Copilot Studio agent nobody revisited |
| Synced | Admin-built platform connection, then a manual “Sync agents” click | Metadata only | On click | An Agentforce or Bedrock agent in a connected region |
| Unregistered | Never | None | Never | Claude Desktop with a local MCP server on a developer laptop, Cursor in agent mode, a Goose install, a Bedrock agent in an unconnected account |
One tier is automatic. Two require an admin to act, and go stale until the admin acts again. The fourth is the one Microsoft’s definition describes, and it is the only tier that grows without anyone in IT touching a console.
Anatomy of the Residue
Let’s step back. Agent 365 licenses the approved and locks down the rest. That is authorization, and it works: Conditional Access can target an Entra Agent ID, Purview labels travel with the data a registered agent retrieves, and risk signals from Defender, Entra and Purview roll up into one pane on an E7 or A365 license. None of that is in dispute.
The problem is the residue: agents that exist in your estate and not in the registry. Here is how one gets there, in the order we see it in the signature pipeline:
- The pre-migration agent. A Copilot Studio agent built before Entra Agent IDs were automatic still runs on an app registration. It has an owner and a purpose, but not the identity the new controls target, and nobody filed the migration ticket.
- The sync-lag agent. Registry sync pulled 40 Agentforce agents last Tuesday. Wednesday a maker cloned one, changed its data source, and published. The registry shows Tuesday’s world until someone clicks Sync again.
- The other-cloud agent. Registry sync supports Bedrock, Vertex AI, Agentforce and Databricks Genie today. The framework your data science team picked is not on that list, so its agents are structurally invisible, not merely lagging.
- The endpoint-native agent. An engineer runs Claude Desktop, Cline or Cursor with a stdio MCP server pointed at a production credential in a local config. There is no tenant object to register. Microsoft’s own discovery guidance points to Defender and Intune signals on Windows endpoints here, which tells you where the control has to live: on the device, not in the directory.
- The registered agent running unregistered code. A native-tier agent with a clean Entra Agent ID loads a skill file pulled off GitHub that afternoon. The identity is managed. The behavior is not.
Case five should worry a risk desk most, because it scores green on every registry filter.
The Registry Residue Formula
Here is how to put a number on the gap. Score each business unit on four factors, 1 to 5:
Registry Residue = (Unregistered Share × Data Reach) + (Sync Lag × Change Velocity)
| Factor | What it measures | How to score it |
|---|---|---|
| Unregistered Share | Fraction of agent processes observed on endpoints that have no registry entry | Endpoint inventory count minus registry count, divided by endpoint count |
| Data Reach | Sensitivity of what unregistered agents can touch | Local credential files, mapped drives and production connection strings score high |
| Sync Lag | Days since the last successful registry sync per connected platform | Read it off the Registry sync page; unconnected platforms score 5 |
| Change Velocity | New or modified agents per week in the business unit | Makers publishing weekly score high; a frozen estate scores low |
The first factor is the one most teams cannot fill in, because they only have the registry side of the subtraction. That missing denominator is the whole coverage-honesty problem in one cell.
Authorization Is Not Observation
Agent 365 answers “which agents are we permitting?” Governance also needs “which agents are actually running, and what did they just do?” Those are different control planes, and conflating them is the same known-knowns trap API security fell into: strong controls over the inventory you declared, none over the inventory you didn’t.
| Control point | Agent 365 / Entra Agent ID | Endpoint-level agent observability |
|---|---|---|
| Unit of control | The identity you issued | The process that executed |
| Sees a Copilot Studio agent | Yes, natively | Yes, when a desktop client touches local data |
| Sees Claude Desktop, Cursor, Goose with local MCP | No tenant object to register | Yes, at the kernel |
| Sees an unsigned skill loaded by a registered agent | No, identity is unchanged | Yes, file and process activity are visible |
| Enforcement | Block the identity, revoke access | Block the action, on the device, at execution time |
| Evidence | Assertion: this agent was permitted | Attestation: this agent did this, at this time, to this file |
The watermark-versus-kernel distinction applies exactly here. The registry is a declaration of intended state. The endpoint is the record of actual state. A governance program needs both, and the registry alone tells you nothing about the residue by construction.
What CISOs Should Do This Quarter
| Step | Action | Output | Effort |
|---|---|---|---|
| 1 | Export the Agent 365 registry to CSV and record the three tile counts | Registry-side denominator, dated | 1 hour |
| 2 | Run endpoint discovery for agent processes, MCP servers and skill files across a sample of 200 laptops | Estate-side numerator; first Unregistered Share estimate | 2 weeks |
| 3 | Score each business unit on the Registry Residue formula | Ranked residue book, owners named | 3 days |
| 4 | Stand up agent observability on the endpoints where the residue lives, and feed Entra Agent IDs into it where they exist | Registered and unregistered agents in one telemetry stream | 1 quarter |
Step four is where a Copilot firewall layer belongs: not as a replacement for Agent 365, but as the observation plane it was never built to be.
The Bottom Line
Microsoft Agent 365 licenses the agents you approved and locks down the ones you registered; the shadow agent it defines is, by that same definition, the one it cannot see. A registry is an authorization plane, and authorization without observation is a list of permissions with no record of behavior. The residue between what the tile says and what runs on your endpoints is a live position, and right now most enterprises are carrying it unmarked.
If your team is sizing agent governance for the Q4 planning cycle, request a working session. We will walk through your environment, compute your first Registry Residue score against a real endpoint sample, and scope a deployment that puts registered and unregistered agents in one stream. Budget 90 minutes.