| Feature | E3 | E3+Cop | E5 | E5+Cop | E7 | Notes |
|---|---|---|---|---|---|---|
| Copilot Chat — web-grounded (free) | ● | ● | ● | ● | ● | Copilot Chat — free for all eligible M365 users since 2025. Web grounding + Enterprise Data Protection, file upload, image gen, Pages |
| Copilot Chat — work-data grounding (Graph) | ● | ● | ● | ● | ● | Chat answers from your emails/files/meetings — requires M365 Copilot (Premium). Adds Researcher/Analyst, app Copilot, meeting recaps |
| Build agents — web-grounded (Agent Builder) | ● | ● | ● | ● | ● | Agent Builder — web-knowledge agents are free in Copilot Chat, no Copilot licence |
| Build / run agents on org data | ● | ● | ● | ● | ● | Included for licensed Copilot users; otherwise pay-as-you-go (Copilot Credits / capacity packs) — metered, not blocked by E3/E5 |
| SharePoint Agents | ● | ● | ● | ● | ● | SharePoint Agents |
| Copilot Studio for M365 (internal users) | ● | ● | ● | ● | ● | CS for M365 — external channels require PP CS add-on |
| Graph & Connector Access | ● | ● | ● | ● | ● | Included in M365 Copilot; without it, agent access to Graph/work data is metered via Copilot Credits (PAYG) |
| Copilot Dashboard | ● | ● | ● | ● | ● | Copilot Dashboard |
| Agent 365 — Registry, Map, Monitoring | ● | ● | ● | ● | ● | Agent 365 — E7 only |
| Agent 365 — Lifecycle Management | ● | ● | ● | ● | ● | Agent Actions — E7 only |
| Agent Map | ● | ● | ● | ● | ● | Agent Map — E7 only |
| Agent Tool Controls | ● | ● | ● | ● | ● | Tool Controls — E7 only |
| Agent Policy Templates | ● | ● | ● | ● | ● | Policy Templates — E7 only |
| Agent Registry Sync (multi-cloud) | ● | ● | ● | ● | ● | Registry Sync — E7 only |
| Feature | E3 | E3+Cop | E5 | E5+Cop | E7 | Notes |
|---|---|---|---|---|---|---|
| SharePoint Advanced Management (SAM) | ● | ● | ● | ● | ● | SAM — included with Copilot M365; otherwise standalone add-on |
| RAC + RCD + Oversharing reports | ● | ● | ● | ● | ● | Included in SAM |
| Sensitivity Labels (manual) | ● | ● | ● | ● | ● | Sensitivity Labels — AIP basic in E3 |
| Auto-labeling (rules-based classification) | ● | ● | ● | ● | ● | Auto-labeling — E5 |
| Conditional Access for Sites | ● | ● | ● | ● | ● | CA for Sites — E5 (Entra P2) |
| Feature | E3 | E3+Cop | E5 | E5+Cop | E7 | Notes |
|---|---|---|---|---|---|---|
| DLP (Exchange, SPO, Teams, M365 apps) | ● | ● | ● | ● | ● | DLP — E3 baseline |
| DLP on Copilot prompts | ● | ● | ● | ● | ● | DLP & Copilot |
| Teams DLP | ● | ● | ● | ● | ● | Teams DLP — E5 |
| Endpoint DLP (block AI domains) | ● | ● | ● | ● | ● | Endpoint DLP — E5 + MDE |
| Agent DLP | ● | ● | ● | ● | ● | Agent DLP — E7 only |
| Audit Standard (90 days) | ● | ● | ● | ● | ● | Audit — E3 |
| Audit Premium (7 years, advanced events) | ● | ● | ● | ● | ● | Audit Premium — E5 |
| DSPM for AI (oversharing posture) | ● | ● | ● | ● | ● | DSPM — E5 Purview |
| Agent DSPM | ● | ● | ● | ● | ● | Agent DSPM — E7 only |
| Insider Risk Management | ● | ● | ● | ● | ● | IRM — E5 |
| Agent Insider Risk Management | ● | ● | ● | ● | ● | Agent IRM — E7 only |
| Communication Compliance | ● | ● | ● | ● | ● | E5 Compliance |
| Agent Comm Compliance | ● | ● | ● | ● | ● | Agent Comm Compl. — E7 only |
| Agent Data Lifecycle Management | ● | ● | ● | ● | ● | Agent DLM — E7 only |
| Agent Information Protection | ● | ● | ● | ● | ● | Agent Info Prot. — E7 only |
| Feature | E3 | E3+Cop | E5 | E5+Cop | E7 | Notes |
|---|---|---|---|---|---|---|
| Defender for Endpoint P1 | ● | ● | ● | ● | ● | MDE P1 — in E3 (P2 is in E5) |
| Defender for Endpoint P2 (EDR, Hunting) | ● | ● | ● | ● | ● | MDE P2 — E5 |
| Defender for Cloud Apps (MDCA full) | ● | ● | ● | ● | ● | MDCA — E5 Security; shadow IT discovery |
| Agent MDCA Integration | ● | ● | ● | ● | ● | Agent MDCA — E7 only |
| Security Copilot | ● | ● | ● | ● | ● | Security Copilot — included in E5 |
| Entra ID P1 (CA, MFA, SSPR) | ● | ● | ● | ● | ● | Entra P1 — E3+ |
| Entra ID P2 (PIM, ID Protection, Risk CA) | ● | ● | ● | ● | ● | Entra P2 — E5 |
| Agent Conditional Access | ● | ● | ● | ● | ● | Agent CA — E7 only |
| Agent ID Protection Integration | ● | ● | ● | ● | ● | Agent ID Prot. — E7 only |
| Agent Identity Governance | ● | ● | ● | ● | ● | Agent ID Gov. — E7 only |
| Agent Global Secure Access | ● | ● | ● | ● | ● | Agent GSA — E7 only (Entra Internet/Private Access) |
| Sentinel Benefit (data ingestion) | ● | ● | ● | ● | ● | Sentinel Benefit — E5 |
| Feature | E3 | E3+Cop | E5 | E5+Cop | E7 | Notes |
|---|---|---|---|---|---|---|
| Copilot Studio PP add-on (ext. channels, CEA) | ● | ● | ● | ● | ● | CS Security — standalone PP add-on, capacity billing |
| PPAC DLP policies (channels, auth, sources) | ● | ● | ● | ● | ● | DLP Policies — effective only when CS agents are deployed |
| Managed Environments | ● | ● | ● | ● | ● | Managed Env. — premium PP feature |
| Power Platform CoE Starter Kit | ● | ● | ● | ● | ● | CoE Kit — free; requires PP + Power BI |
| Setting | Purpose | Location |
|---|---|---|
| Trial License Control | Block free trial sign-ups without admin permission | Azure PowerShell |
| Control Agents with AI Features | Block generative AI (LLM) usage in Copilot agents tenant-wide | PPAC → Settings |
| Copilot Studio Authors Control | Restrict who can author agents to a security group | PPAC → Settings |
| Environment Routing | Route makers to specific environment groups (own Dev env) | PPAC → Settings |
| AI Builder Credits Control | Decide whether tenant-level AI credits can be used by environments | PPAC → Settings |
| Copilot Data Collection | Enable or block sharing prompts/requests with Microsoft | PPAC → Settings |
| Copilot Feedback Control | Enable or block user feedback to Microsoft | PPAC → Settings |
| Message Capacity | Allocate Copilot message capacity to each environment | PPAC → Capacity |
| Setting | Purpose | Location |
|---|---|---|
| Telemetry / App Insights Control | Block agent makers from connecting to Application Insights | PPAC → DLP Policies |
| Authentication Control | Disable "No-Auth" & "Generic OAuth" as agent auth providers | PPAC → DLP Policies |
| Channel Control | Block channels: Direct Line, Facebook, M365/Teams, Omnichannel | PPAC → DLP Policies |
| Knowledge Source Control | Block SharePoint, OneDrive, documents or public websites as knowledge | PPAC → DLP Policies |
| Skills Control | Block makers from using Skills in Copilot Studio | PPAC → DLP Policies |
| HTTP Requests Control | Prevent HTTP requests to reduce data-exfiltration risk | PPAC → DLP Policies |
| Event Triggers Control (autonomous) | Block autonomous / event-driven agent triggers | PPAC → DLP Policies |
| Setting | Purpose | Location |
|---|---|---|
| Generative AI Control (Bing Search) | Allow or block Bing Search grounding in agents | Environment → Generative AI |
| AI Prompts Control | Enable or block AI prompts in Power Platform | Environment → Features |
| Copilot in Power Apps | Enable or block Copilot in Power Apps | Environment → Features |
| Block Solutions w/ Unmanaged Custom. | Prevent importing unmanaged customizations | Environment → Features |
| Sharing Agents (Editor / Viewer) | Manage whether agents can be shared with Editor/Viewer roles | Environment Groups (Managed Env) |
| Environment Auditing | Enable auditing in production environments | Environment → Settings → Auditing |
| Maker Welcome Message | Display privacy / compliance message to makers | Environment Groups (Managed Env) |
| Setting | Purpose | Location |
|---|---|---|
| Agent Authentication | Configure No Auth / Entra ID / Certificates | CS → Agent → Settings → Security |
| Agent Web Channel Security | Manage secrets / tokens for the Direct Line web channel | CS → Agent → Settings → Security |
| Dimension | 100 — Initial | 200 — Managed | 300 — Defined | 400 — Predictable | 500 — Optimising |
|---|---|---|---|---|---|
| Inventory & Discovery | No inventory. Agents unknown to IT. | Partial list in spreadsheet. Some agents discovered reactively. | TAC + PPAC CoE Kit inventory. All agents registered, named, owned. E3 | Agent 365 Registry with automated discovery. Missing owner alerts. Copilot | Agent Map + Registry Sync across M365, Azure, partner ecosystems. Real-time. E7 |
| Naming & Ownership | No standards. Agents named ad hoc. No clear owner. | Informal ownership. Some naming patterns emerging per team. | Naming convention enforced (Contoso-HR-Agent-v1). Owners documented. E3 | Ownership enforced via CCS policy. Orphaned agents auto-flagged. Copilot | Agent Identity Governance — lifecycle workflows, ML-assisted access reviews. E7 |
| Publishing Control | Anyone can publish to any channel. No approval process. | Informal review. Some channels blocked reactively after incidents. | PPAC DLP: channels, auth, knowledge sources blocked by policy. TAC app permission policies. E3 | CCS publisher-type rules. Agent policies automate allow/block decisions. Copilot | Agent Tool Controls. Full channel governance with Entra CA integration per agent. E7 |
| Data Protection | No DLP. Sensitive data freely accessible to agents. | Sensitivity labels manually applied to some content. DLP rules exist for email. | DLP on Copilot prompts. Sensitivity labels on SPO. SAM oversharing assessment run. E3 +SAM w/ Copilot | DSPM for AI. Auto-labeling. Endpoint DLP blocks AI domain uploads. E5 | Agent DLP + Agent Information Protection. Per-agent data classification policy. E7 |
| Identity & Access | Agents run with shared or no credentials. No MFA. | Some agents use Entra ID. MFA partially enforced. No PIM for admins. | Entra ID P1: Conditional Access + MFA enforced globally. Agent auth policy via PPAC DLP. E3 | Entra ID P2: PIM, risk-based CA, Access Reviews for agent roles. E5 | Agent Conditional Access + Agent ID Protection. Entra Agent ID for all agents. Identity Governance lifecycle. E7 |
| Audit & Monitoring | No logging. Incidents discovered by users, not IT. | Basic M365 activity reports. Audit Standard enabled but rarely reviewed. | Audit Standard + Purview Activity Explorer for AI. App Insights on CS agents. Sentinel rules for CS events. E3 +Azure | Audit Premium (7 yr). Copilot Dashboard. DSPM risk reports. Regular review with metrics. E5 | Agent Usage Insights (advanced). Agent DSPM. Agent IRM. Defender context mapping agent–device–MCP. E7 |
| Shadow IT & External AI | No visibility. Unknown AI tools in use across org. Meeting bots join unchallenged. | MDCA occasionally checked. Some AI tools manually blocked via web filter. | Shadow AI page in Agent 365 (E3, preview). TAC meeting bot detection. Entra OAuth audit. E3 | MDCA full: shadow IT discovery, OAuth governance, sanctioned app catalogue. Endpoint DLP blocks AI domains. E5 | Agent MDCA Integration. Defender context mapping. Cross-cloud registry sync (AWS Bedrock, GCP). E7 |
| ALM & Lifecycle | No versioning. Prod changes done directly. No rollback. | Manual exports as backup. Dev/Prod somewhat separated but inconsistently. | PPAC environment isolation (Dev/Test/Prod). CoE Kit tracks solutions. Basic ALM. E3 | In-product pipelines / Azure DevOps CI/CD. Managed Environments. Staged rollout. PP Premium | Agent Lifecycle Management via Agent 365. Policy Templates. Automated retirement of inactive agents. E7 |
| People & Process | No training. No COE. No responsible AI framework. | IT handles ad hoc requests. Some awareness of risks. No formal COE. | COE established. Naming, disclaimer, approval process documented. Quarterly governance review. E3 | COE runs CoE Starter Kit dashboards. Training programme active. Secure Score as KPI. E3 | Continuous improvement loop. Feedback to agent owners. Responsible AI embedded in SDLC. Metrics drive investment. E3 |
| Do you know how many agents are active in your tenant? | No → Level 100 | Partially → Level 200 | Yes, in a registry → Level 300+ |
| Is there a documented approval process for publishing agents? | No → Level 100 | Informal → Level 200 | Documented & enforced → Level 300+ |
| Can you show which AI tools users are accessing outside M365? | No → Level 100–200 | Partial (web filter only) → Level 200 | Yes, via MDCA → Level 400 |
| Are governance actions automated (e.g. orphaned agent deactivation)? | No → Level 100–200 | Some scripts → Level 300 | CCS/PPAC policies → Level 400+ |
| Do you have per-agent DLP, DSPM, and identity governance? | No → Level 100–300 | E5 tooling active → Level 400 | Agent-specific (E7) → Level 500 |