The non-human identity governance divide.
Every Microsoft 365 tenant is filling with non-human identities. Only E5 got the controls to govern them. Microsoft’s own licensing FAQ names E3 plus Copilot users as ineligible for Agent 365.
Microsoft spent two years telling every business that AI agents were the future of work. Copilot for everyone, agents in every workflow, build them in Copilot Studio, wire them into Teams. The E3 mid-market heard the message and adopted.
Then Microsoft built the control plane to secure those agents, and locked E3 customers out of it.
Agent 365 is that control plane: registry, access control, visualisation and security for the agents running in your tenant. To license it, your information workers need Microsoft 365 E5. This is not an inference from a pricing page. Microsoft’s licensing FAQ spells out who does not qualify:
Users who do not meet these prerequisites (for example, ME3 + Copilot users) are ineligible.
Microsoft licensing FAQ, Agent 365 prerequisitesNot “limited functionality”. Not “reduced feature set”. Ineligible. The clean path in is E7, the new Frontier Suite at $99 per user per month, against $39 for E3. So the organisations Microsoft pushed hardest into Copilot are now running AI agents inside their tenants with no way to govern them, unless they are willing to more than double their per-seat spend.
What the gate actually costs
Take a 200-user business on E3. Today it pays around $7,800 a month. To reach the agent control plane through E7, that becomes roughly $19,800 a month. Even the standalone route, Agent 365 at $15 per user per month, is $3,000 a month on top of the E5 uplift you would have to buy first, because E5 is the prerequisite.
That is not a licensing footnote. That is Microsoft deciding that knowing what AI is doing in your own tenant is a premium feature.
The per-tenant alternative
Sabiki AIRM starts at $149 per tenant per month. Not per user. Per tenant. It connects to the Microsoft 365 you already have, agentless, through the Graph API, and it works exactly the same on E3 as it does on E5.
One scope point before the list: AIRM governs non-human identities (NHIs), the industry’s term for AI agents, service principals, OAuth apps and connectors. Your people, and their licences, are untouched. Here is what that buys:
- Discovery. Every non-human identity in the tenant: service principals, app registrations, OAuth-connected apps, connectors, Copilots and AI agents. Including the ones nobody owns and the credentials nobody has rotated in years.
- Risk you can defend. Every identity scored on two axes, what it is doing now and how bad it would be if compromised, so the quiet app with tenant-wide write access ranks where it belongs.
- Compromise Simulation. A permission-aware attack model against any identity, with a 0 to 100 blast score and human-readable attacker actions. No live data touched.
- Identity Graph. Lateral-movement and attack paths across the tenant, with crown-jewel highlighting, exportable for the board.
- Anomaly Intelligence. Seventeen behavioural signals per identity, scan over scan. Permission-scope drift on agents you already approved. Dormant identities that suddenly wake up.
- Agent Identity Activity. What each agentic identity actually did inside the environment, and which humans drove it. Cross-boundary data access, where an agent reaches into another user’s OneDrive. Sensitive filename watchlists. Jailbreak and prompt-injection attempts. Broad-sweep prompts that touch dozens of documents at once. Agent lifecycle, so you know when an identity appeared and who created it.
- Compliance evidence. Every finding mapped to eleven frameworks including the EU AI Act, DORA, ISO 42001 and NIST AI RMF, in an audit-ready pack.
- Triage that respects your team. 419 identities become 411 routine approvals and eight that need a human. Nothing changes in your tenant unless a person clicks.
And on one of those, we would argue Microsoft cannot match us at any price.
The identity that never touches a browser
Almost every AI monitoring tool on the market, Microsoft’s included, watches the endpoint or the browser. Microsoft’s own guidance for third-party AI visibility says it plainly: the Purview browser extension has to be deployed to Windows users to discover visits to third-party AI sites, and devices have to be onboarded to Purview for visibility into what is shared with them. Agent 365 governance has its own gate: external and SaaS agents that are not onboarded through Microsoft’s SDK cannot be governed at the agent identity level at all.
Microsoft’s third-party AI visibility needs a browser extension and an onboarded device. Its agent governance needs the agent onboarded through Microsoft’s SDK. Neither of those touches the agent that was connected by a user clicking Accept last Tuesday. AIRM sees it on the first scan, with nothing installed anywhere.
That is the difference between tracking agents and tracking agent identities. Claude, Perplexity, Notion, a custom GPT, an internal automation someone wired up last quarter: they do not appear on an endpoint and they do not leave a browser trail. They appear as an identity in your tenant, with permissions somebody granted, doing things nobody is reviewing. That is the layer we were built for.
If you run E3 tenants for a living
For MSPs the arithmetic is even simpler. Your E3 client base is exactly the segment Microsoft has priced out of agent governance, and those clients are adopting agents anyway. A per-tenant control that works on the licences they already own is a service line you can take to every one of them this quarter, without asking a single client to triple their Microsoft spend first.
Microsoft secures Microsoft, and it does it well. It has simply decided that if you are on E3, securing the rest is not your privilege to have. We disagree.
Find out what’s already running in your tenant.
The free Sabiki AI Readiness Assessment works on any Microsoft 365 tenant, E3 or E5, agentless, in under fifteen minutes. Start there, and find out what is already connected to yours.
Get your free AI Readiness Score →Sources
- Microsoft licensing FAQ: Agent 365 prerequisites (Microsoft 365 E5 required for information workers; ME3 + Copilot users ineligible)
- Microsoft 365 blog: Microsoft 365 E7 and Agent 365 general availability (E7 $99 per user per month; Agent 365 $15 per user per month standalone)
- Microsoft 365 enterprise price list, July 2026 (E3 $39 per user per month)
- Microsoft Learn: Use Microsoft Purview to manage data security & compliance for other AI apps (browser extension and device onboarding requirements)
- Microsoft Learn: Connect existing agents to Microsoft Agent 365 (SDK onboarding; agent-identity-level governance gate for external and SaaS agents)