The AI Administrator role is updated to support Agent 365, enabling delegated agent management without Global Admin involvement for routine tasks. Rollout starts March 2026. AI Admins gain expanded permissions for agent lifecycle management, tenant-wide consent (excluding Microsoft Graph app permissions), and risk monitoring via Identity Protection, enhancing security and compliance.
Introduction
We are updating the AI Administrator role to support Agent 365. This update enables delegated, day-to-day agent management while preserving enterprise security and least-privilege principles.
The AI Admin role is designed for managing agent lifecycles and agentic users. By removing the dependency on Global Administrators for routine, agent-scoped actions, this change helps eliminate operational bottlenecks, supports scale, and maintains clear separation of duties. Global Admin elevation remains required only for rare, high-risk scenarios.
When this will happen:
General Availability: Rollout begins early March 2026; expected completion by late March 2026
How this affects your organization:
Who is affected
What will happen
What is not included
What you can do to prepare:
Review or update role assignments
Learn more: About administrator roles in the Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn
Compliance considerations
| Question | Explanation |
|---|---|
| Does the change alter how existing customer data is processed, stored, or accessed? | AI Administrators gain expanded permissions to manage agents and agent credentials, which may indirectly affect how agents access tenant data. |
| Does the change introduce or significantly modify AI or agent capabilities that interact with customer data? | The update expands AI Administrator authority over agent lifecycles and tenant-wide consent, increasing control over agent behavior and data access. |
| Does the change alter how admins can monitor or demonstrate compliance activities? | AI Administrators can now view agents flagged as risky through Identity Protection, improving visibility and compliance monitoring. |
| Does the change include an admin control, and can it be controlled through Entra ID role membership? | All new capabilities are governed by assignment of the AI Administrator role in Microsoft Entra ID. |