Photo: Kindel Media / Pexels
Azure AI Foundry embeds identity management, policy enforcement, and fleet-wide oversight directly into multi-agent workflows for large organizations.
Running an AI agent in a demo is easy. Running one in a regulated enterprise environment, where it handles sensitive data, operates autonomously for hours, and needs to pass a security audit, is a different problem entirely. Microsoft is betting that Azure AI Foundry is the answer.
On June 3, 2026, Microsoft announced a wave of new capabilities for Foundry, its enterprise platform for developing, deploying, and managing AI agents at scale.
What Microsoft actually shipped #
The headline additions include the general availability of publishing agents directly to Microsoft 365 Copilot and Teams. That means organizations can now push agents into the tools their employees already live in, without duct-taping together a custom deployment pipeline.
Also landing in public preview are Autopilot agents and Agent-to-Agent, or A2A, functionality. A2A allows individual agents to coordinate with each other inside a larger workflow, which matters because real enterprise processes rarely fit inside a single task.
Every agent created on Foundry now gets its own identity through Microsoft Entra ID, Microsoft’s identity and access management platform. Automatic registration in Microsoft Agent 365 follows that credentialing step, giving IT and compliance teams a centralized place to see every agent running across the organization.
Publishing an agent doesn’t happen with a single click. Foundry routes the process through a governed pipeline that requires identity verification, admin approvals, and organizational visibility checks before the agent becomes available in Microsoft 365 Copilot.
The roadmap through late 2026 #
Model deployment policies are scheduled for general availability by August 2026. These policies restrict which models can be deployed based on pre-approved criteria, giving enterprises a compliance lever they’ve been asking for as foundation model options multiply.
A new Foundry Control Plane is also on the roadmap, designed to provide fleet-wide oversight across all deployed agents.
By September 2026, long-running hosted agents will gain resilience capabilities in preview. The specifics matter here: durable identities and lease-based recovery mean that an agent working through a multi-hour process doesn’t just disappear if something goes wrong mid-task.
The platform also supports per-session isolation with persistent file systems for hosted agents. Each agent session gets its own sandboxed environment. Paired with scale-to-zero economics, where agents consume no resources when idle, the cost and risk profiles both improve for organizations running workloads that aren’t constant.
Microsoft is also adding managed access toolboxes and durable state storage for long-running agents, two features that address a practical problem: agents that work across extended timeframes need to store context somewhere reliable, and that storage needs to be secure and auditable.
Why the governance-first approach matters #
Foundry’s architecture places security, auditability, and policy enforcement into the workflow from the moment an agent is created. For heavily regulated industries like finance, healthcare, and legal services, that’s not a nice-to-have. It’s a prerequisite for deployment at all.
Azure Policy enforcement and content safety filters round out the compliance toolkit, giving administrators controls over what agents can do, what content they can process, and what actions require human review.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our