Non-human identity

The non-human identity governance divide.

Sabiki Security·September 2026·7 min read
Every tenant is filling with non-human identities. Only E5 got the controls.

Every Microsoft 365 tenant is filling with non-human identities. Only E5 got the controls to govern them. Microsoft’s own licensing FAQ names E3 plus Copilot users as ineligible for Agent 365.

Microsoft spent two years telling every business that AI agents were the future of work. Copilot for everyone, agents in every workflow, build them in Copilot Studio, wire them into Teams. The E3 mid-market heard the message and adopted.

Then Microsoft built the control plane to secure those agents, and locked E3 customers out of it.

Agent 365 is that control plane: registry, access control, visualisation and security for the agents running in your tenant. To license it, your information workers need Microsoft 365 E5. This is not an inference from a pricing page. Microsoft’s licensing FAQ spells out who does not qualify:

Users who do not meet these prerequisites (for example, ME3 + Copilot users) are ineligible.

Microsoft licensing FAQ, Agent 365 prerequisites

Not “limited functionality”. Not “reduced feature set”. Ineligible. The clean path in is E7, the new Frontier Suite at $99 per user per month, against $39 for E3. So the organisations Microsoft pushed hardest into Copilot are now running AI agents inside their tenants with no way to govern them, unless they are willing to more than double their per-seat spend.

Cost comparison for a 200-user business on Microsoft 365 E3. The Microsoft path via E7: $19,800 total per month, priced per user at $99 times 200 users. Sabiki AIRM: from $149 total per month for the same 200 users, priced per tenant, flat. Drawn to scale: Microsoft plus $12,000 a month, Sabiki AIRM starting from $149 a month flat per tenant.

What the gate actually costs

Take a 200-user business on E3. Today it pays around $7,800 a month. To reach the agent control plane through E7, that becomes roughly $19,800 a month. Even the standalone route, Agent 365 at $15 per user per month, is $3,000 a month on top of the E5 uplift you would have to buy first, because E5 is the prerequisite.

That is not a licensing footnote. That is Microsoft deciding that knowing what AI is doing in your own tenant is a premium feature.

The per-tenant alternative

Sabiki AIRM starts at $149 per tenant per month. Not per user. Per tenant. It connects to the Microsoft 365 you already have, agentless, through the Graph API, and it works exactly the same on E3 as it does on E5.

One scope point before the list: AIRM governs non-human identities (NHIs), the industry’s term for AI agents, service principals, OAuth apps and connectors. Your people, and their licences, are untouched. Here is what that buys:

And on one of those, we would argue Microsoft cannot match us at any price.

The identity that never touches a browser

Almost every AI monitoring tool on the market, Microsoft’s included, watches the endpoint or the browser. Microsoft’s own guidance for third-party AI visibility says it plainly: the Purview browser extension has to be deployed to Windows users to discover visits to third-party AI sites, and devices have to be onboarded to Purview for visibility into what is shared with them. Agent 365 governance has its own gate: external and SaaS agents that are not onboarded through Microsoft’s SDK cannot be governed at the agent identity level at all.

A consented OAuth agent doesn’t use a browser. It doesn’t run on a laptop. It signs in server-side, straight into your tenant, as a user.

Microsoft’s third-party AI visibility needs a browser extension and an onboarded device. Its agent governance needs the agent onboarded through Microsoft’s SDK. Neither of those touches the agent that was connected by a user clicking Accept last Tuesday. AIRM sees it on the first scan, with nothing installed anywhere.

That is the difference between tracking agents and tracking agent identities. Claude, Perplexity, Notion, a custom GPT, an internal automation someone wired up last quarter: they do not appear on an endpoint and they do not leave a browser trail. They appear as an identity in your tenant, with permissions somebody granted, doing things nobody is reviewing. That is the layer we were built for.

If you run E3 tenants for a living

For MSPs the arithmetic is even simpler. Your E3 client base is exactly the segment Microsoft has priced out of agent governance, and those clients are adopting agents anyway. A per-tenant control that works on the licences they already own is a service line you can take to every one of them this quarter, without asking a single client to triple their Microsoft spend first.

Microsoft secures Microsoft, and it does it well. It has simply decided that if you are on E3, securing the rest is not your privilege to have. We disagree.

Find out what’s already running in your tenant.

The free Sabiki AI Readiness Assessment works on any Microsoft 365 tenant, E3 or E5, agentless, in under fifteen minutes. Start there, and find out what is already connected to yours.

Get your free AI Readiness Score →

Sources

  • Microsoft licensing FAQ: Agent 365 prerequisites (Microsoft 365 E5 required for information workers; ME3 + Copilot users ineligible)
  • Microsoft 365 blog: Microsoft 365 E7 and Agent 365 general availability (E7 $99 per user per month; Agent 365 $15 per user per month standalone)
  • Microsoft 365 enterprise price list, July 2026 (E3 $39 per user per month)
  • Microsoft Learn: Use Microsoft Purview to manage data security & compliance for other AI apps (browser extension and device onboarding requirements)
  • Microsoft Learn: Connect existing agents to Microsoft Agent 365 (SDK onboarding; agent-identity-level governance gate for external and SaaS agents)
← Back to the blog