Microsoft has now written the definition of a shadow agent into its own admin guidance. Read it carefully: it is a precise description of everything the registry will never contain.

Why the Agent 365 Definition Matters Now

Microsoft’s Center of Excellence guidance for agents is unusually direct. Shadow agents, it says, are agents built or run outside the governance program: unmanaged, with no registered owner, no reviewed access, no monitoring. Left alone, “they’re where your next incident starts.” The Microsoft 365 admin center registry now carries three headline tiles: total agents, agents without owners, and unmanaged agents, the last defined as agents created or managed outside Agent 365, without its risk protection and observability.

This is the right definition. It is also a confession. A registry can count the agents that were registered, and the registered agents that lost their owner. It cannot count the agents that never asked for an identity. The “unmanaged” tile is a lower bound, and the gap between that tile and the real estate is the position nobody is marking.

Metric Value Source
Organizations reporting an AI agent security incident this year 88% Ospiri research
Added breach cost where shadow AI was a factor up to +$670K IBM Cost of a Data Breach Report 2025
Breaches involving shadow AI roughly 1 in 5 IBM Cost of a Data Breach Report 2025
Registry sync cadence for non-Microsoft platforms Manual, on-demand; scheduled sync “in a future release” Microsoft Learn, Agent 365 registry sync (preview)

Price that last row against the first three. The registry is a point-in-time snapshot of the agents that were easy to enumerate, refreshed when an admin clicks a button. The exposure compounds continuously.

Four Tiers of “Known,” Only One of Them Automatic

The Entra agent registry sorts your estate by how the agent got in, not by what the agent can reach. That distinction decides what Agent 365 can see. We have written before about the two types of shadow agents; the registry adds a finer grain.

Tier How it enters the registry Identity Refresh Example
Native Automatic on creation (Copilot Studio agents created after May 2026 get an Entra Agent ID) Yes Continuous A sales-coach agent built in Copilot Studio
Legacy native Manual migration by an admin (older Copilot Studio agents still use app registrations) Only after migration On migration A 2025-era Copilot Studio agent nobody revisited
Synced Admin-built platform connection, then a manual “Sync agents” click Metadata only On click An Agentforce or Bedrock agent in a connected region
Unregistered Never None Never Claude Desktop with a local MCP server on a developer laptop, Cursor in agent mode, a Goose install, a Bedrock agent in an unconnected account

One tier is automatic. Two require an admin to act, and go stale until the admin acts again. The fourth is the one Microsoft’s definition describes, and it is the only tier that grows without anyone in IT touching a console.

Anatomy of the Residue

Let’s step back. Agent 365 licenses the approved and locks down the rest. That is authorization, and it works: Conditional Access can target an Entra Agent ID, Purview labels travel with the data a registered agent retrieves, and risk signals from Defender, Entra and Purview roll up into one pane on an E7 or A365 license. None of that is in dispute.

The problem is the residue: agents that exist in your estate and not in the registry. Here is how one gets there, in the order we see it in the signature pipeline:

  1. The pre-migration agent. A Copilot Studio agent built before Entra Agent IDs were automatic still runs on an app registration. It has an owner and a purpose, but not the identity the new controls target, and nobody filed the migration ticket.
  2. The sync-lag agent. Registry sync pulled 40 Agentforce agents last Tuesday. Wednesday a maker cloned one, changed its data source, and published. The registry shows Tuesday’s world until someone clicks Sync again.
  3. The other-cloud agent. Registry sync supports Bedrock, Vertex AI, Agentforce and Databricks Genie today. The framework your data science team picked is not on that list, so its agents are structurally invisible, not merely lagging.
  4. The endpoint-native agent. An engineer runs Claude Desktop, Cline or Cursor with a stdio MCP server pointed at a production credential in a local config. There is no tenant object to register. Microsoft’s own discovery guidance points to Defender and Intune signals on Windows endpoints here, which tells you where the control has to live: on the device, not in the directory.
  5. The registered agent running unregistered code. A native-tier agent with a clean Entra Agent ID loads a skill file pulled off GitHub that afternoon. The identity is managed. The behavior is not.

Case five should worry a risk desk most, because it scores green on every registry filter.

The Registry Residue Formula

Here is how to put a number on the gap. Score each business unit on four factors, 1 to 5:

Registry Residue = (Unregistered Share × Data Reach) + (Sync Lag × Change Velocity)

Factor What it measures How to score it
Unregistered Share Fraction of agent processes observed on endpoints that have no registry entry Endpoint inventory count minus registry count, divided by endpoint count
Data Reach Sensitivity of what unregistered agents can touch Local credential files, mapped drives and production connection strings score high
Sync Lag Days since the last successful registry sync per connected platform Read it off the Registry sync page; unconnected platforms score 5
Change Velocity New or modified agents per week in the business unit Makers publishing weekly score high; a frozen estate scores low

The first factor is the one most teams cannot fill in, because they only have the registry side of the subtraction. That missing denominator is the whole coverage-honesty problem in one cell.

Authorization Is Not Observation

Agent 365 answers “which agents are we permitting?” Governance also needs “which agents are actually running, and what did they just do?” Those are different control planes, and conflating them is the same known-knowns trap API security fell into: strong controls over the inventory you declared, none over the inventory you didn’t.

Control point Agent 365 / Entra Agent ID Endpoint-level agent observability
Unit of control The identity you issued The process that executed
Sees a Copilot Studio agent Yes, natively Yes, when a desktop client touches local data
Sees Claude Desktop, Cursor, Goose with local MCP No tenant object to register Yes, at the kernel
Sees an unsigned skill loaded by a registered agent No, identity is unchanged Yes, file and process activity are visible
Enforcement Block the identity, revoke access Block the action, on the device, at execution time
Evidence Assertion: this agent was permitted Attestation: this agent did this, at this time, to this file

The watermark-versus-kernel distinction applies exactly here. The registry is a declaration of intended state. The endpoint is the record of actual state. A governance program needs both, and the registry alone tells you nothing about the residue by construction.

What CISOs Should Do This Quarter

Step Action Output Effort
1 Export the Agent 365 registry to CSV and record the three tile counts Registry-side denominator, dated 1 hour
2 Run endpoint discovery for agent processes, MCP servers and skill files across a sample of 200 laptops Estate-side numerator; first Unregistered Share estimate 2 weeks
3 Score each business unit on the Registry Residue formula Ranked residue book, owners named 3 days
4 Stand up agent observability on the endpoints where the residue lives, and feed Entra Agent IDs into it where they exist Registered and unregistered agents in one telemetry stream 1 quarter

Step four is where a Copilot firewall layer belongs: not as a replacement for Agent 365, but as the observation plane it was never built to be.

The Bottom Line

Microsoft Agent 365 licenses the agents you approved and locks down the ones you registered; the shadow agent it defines is, by that same definition, the one it cannot see. A registry is an authorization plane, and authorization without observation is a list of permissions with no record of behavior. The residue between what the tile says and what runs on your endpoints is a live position, and right now most enterprises are carrying it unmarked.

If your team is sizing agent governance for the Q4 planning cycle, request a working session. We will walk through your environment, compute your first Registry Residue score against a real endpoint sample, and scope a deployment that puts registered and unregistered agents in one stream. Budget 90 minutes.