What happened
Microsoft detailed (Sept 14-17, 2026, via Microsoft Mechanics and Microsoft Security Blog) new Agent 365 admin controls: a cross-vendor agent registry (Microsoft, AWS Bedrock, Google Cloud, Databricks Genie, Anthropic Claude agents), default blocking and Execution Container isolation of unsanctioned local/shadow agents, reusable security policy templates spanning Entra/Purview/Defender/Intune, and agent cost monitoring/spend limits.
Why it matters
Extends Microsoft's agent-identity control plane to multi-vendor agent estates and adds hard isolation (Execution Containers) for shadow AI, directly responding to disclosed agent-escape incidents (OpenAI/Hugging Face, Anthropic SQLi/PyPI cases) referenced in Microsoft's own Sept 17 security blog.
Applicability
Microsoft 365/Entra enterprise customers standardizing agent governance across multi-cloud agent deployments; relevant now given active exploitation of agent isolation gaps.