Microsoft Scout and the governance questions behind an always-on agent
Copilot has always waited for you. You ask, it answers, it goes quiet. Microsoft Scout, announced at Build in June, does not wait. It stays on. It runs in the background across Teams, Outlook, OneDrive and SharePoint, and it acts on your behalf without being prompted each time. Microsoft calls this new category an Autopilot, and the definition is worth reading slowly: “always-on agents that work autonomously, with their own identity, and act on your behalf.”
The three words that should stop an admin are “their own identity.” Every Scout agent operates under “its own governed Entra identity, not a shared, anonymous service account,” so what it does is attributable to a known actor. That is Microsoft answering, in product, the question that auditors have been asking about agents for a year. Not “what did the assistant do”, but “who, exactly, did this”.
Credit where it is due, because the controls read well. Credentials are scoped to the task and kept out of logs. Agents “can only reach the resources and destinations you’ve approved.” Sensitive actions need a human to sign off before they run. Sensitivity labels are enforced in the moment, before anything is sent or written. On paper, that is a better-governed actor than most of the people in your tenant.
The always-on part is the governance change
The shift here is not the intelligence. It is the tense. A prompted agent only touches your content when someone asks it something. An always-on agent is a standing actor in your directory, working while nobody is looking. Every exposure that was latent with a prompted assistant becomes continuous with an autonomous one, because there is no longer a prompt in between to mark the moment it happened.
That turns a few things you have been deferring into things you have to answer.
Inventory is the first. In agent sprawl the question was how many agents exist. With Autopilots it becomes how many identities are acting on their own, because each one is now an object in Entra you can see, and therefore one you are expected to govern.
Lifecycle is the one nobody has a process for. An always-on agent with its own identity, tied to a person, is a joiner-mover-leaver problem. When that employee changes role or leaves, what happens to the agent that was acting on their behalf, under its own credential, against everything they could reach? If you cannot answer that today, that is the gap to close before these arrive at scale, not after.
Reach is the familiar one. “Within the permissions you approve” is only ever as safe as the permissions. It is the same oversharing problem I keep coming back to, with the stakes raised, because now the access is exercised continuously rather than on a prompt.
One honest caveat. Scout today is a private, experimental Frontier preview. It needs Frontier enrollment, Intune policy, an opt-in attestation, and a GitHub Copilot licence. Most tenants cannot touch it yet, so this is not a setup guide. It is a heads-up about the category, because Scout is the first Autopilot, not the last.
Microsoft got the hard part right. The identity model is the thing most people will skim past and it is the thing that matters. The part left to you is the unglamorous one: treating agent identities as first-class objects in your identity governance, with an owner, a lifecycle and a review, before they show up in numbers. The Autopilot era does not need your prompt. It needs your governance.