Microsoft Agent 365 Hits GA with Runtime Protection — Blocking AI Agent Actions Before Execution
Summary
Microsoft has officially launched Agent 365 to general availability as of May 1, 2026, bundling together several security capabilities designed to govern AI agents in enterprise environments. The flagship feature is “Agent 365 Runtime Protection,” now in public preview, which can intercept and block AI agent actions before they execute — essentially a security layer that sits between AI intent and real-world action.
The GA release bundles three major components: Defender for Cloud’s AI Security Posture Management, GitHub Advanced Security’s expanded AI code scanning, and Microsoft Purview’s AI Data Security Investigations. Together, these tools provide enterprises with visibility into what AI agents are doing, the ability to enforce policies on agent behavior, and forensic capabilities for investigating AI-related security incidents.
The Runtime Protection feature is particularly significant — it operates as a real-time guardrail that evaluates AI agent actions against organizational security policies before they’re carried out. If an agent attempts to access unauthorized data, make risky API calls, or take actions outside its approved scope, the system can block the action and alert security teams.
Sources
Commentary
This is exactly the kind of infrastructure the industry needs as AI agents go from demo toys to production systems handling real enterprise workflows. The idea of pre-execution blocking for AI agents is analogous to what firewalls did for network traffic — you need a checkpoint between intent and action.
Microsoft is smart to bundle this with their existing security stack. Organizations already invested in Defender and Purview get agent governance essentially built in. The timing is also notable — this launches just as Cloudflare and Stripe are enabling agents to autonomously create accounts and deploy apps. The accelerator and the brake pedal are shipping in the same week, which is probably the healthiest dynamic we could hope for in the AI agent space.


