- What Microsoft shipped: Agent 365, generally available to commercial customers on May 1, 2026, gives every AI agent an identity in Entra, a registry, and a least-privilege policy. It answers who an agent is and what it is allowed to touch.
- What it does not answer: whether that agent is behaving normally, or has been talked into working for someone else. Identity and policy are the front door. They do not watch what the agent does once it is inside.
- What Caver does now: it integrates with Agent 365 and Entra Agent ID, ingesting agent sign-ins, Conditional Access decisions, and sign-in risk into
OCSF 6005, then runs behavioral detection over it: prompt injection, tool and capability drift, runaway tool loops, credential and API-key abuse, and cost or token spikes. When Microsoft blocks an agent, its risk score in Caver rises automatically. - Why it matters: your agents do not only live in Microsoft. They run in Claude Code, Cursor, Codex, and Copilot, and against OpenAI, Anthropic, and Azure. Caver normalizes all of it into one lake you own, on premise, air gapped if you need it. One platform for every agent, everywhere.
AI agents just became first-class citizens of the enterprise. On May 1, 2026, Microsoft made Agent 365 generally available to commercial customers, and with it every agent an organization runs can now carry a real identity in Entra, sit in a registry, and operate under a least-privilege policy. That is a genuine step forward. For the first time, the agent your finance team spun up last week is a named, governed thing instead of a shadow process with a borrowed API key.
Identity solves a real problem. It is also only half of the problem. Agent 365 answers who an agent is and what it is permitted to touch. It does not answer the question a security team actually loses sleep over: is this agent, right now, doing what it is supposed to, or has it been hijacked? A least-privilege policy is a fence around the yard. It does nothing about the agent that was tricked, through a poisoned document or a malicious tool result, into misusing the access it legitimately holds.
What Agent 365 gives you, and where it stops
Give Microsoft credit for the front door. Agent 365 and Entra Agent ID mean an agent authenticates, gets evaluated by Conditional Access, and can be assigned a sign-in risk the same way a human account is. That is the right foundation, and it produces exactly the kind of telemetry a security team should be collecting: agent sign-ins, the policy decisions made against them, and a risk signal when something looks off.
What that foundation does not do is watch the agent's actual behavior. Conditional Access can decide whether an agent may sign in. It cannot tell that the agent, once signed in, is being steered by an instruction buried in a support ticket it just read, or that it has fallen into a tool-calling loop that is quietly draining a budget, or that it is forwarding an API key it was never meant to touch. Those are runtime behaviors, and they happen inside the agent, downstream of the login. Identity is where the story starts, not where it ends.
Microsoft tells you who your agents are and what they may access. Caver tells you what they are doing with it.
What Caver adds: behavioral detection on the agent itself
Caver now integrates with Agent 365. It ingests the telemetry Microsoft produces, agent sign-ins, Conditional Access decisions, and sign-in risk, and normalizes every event into OCSF 6005, the GenAI event class the Open Cybersecurity Schema Framework defined for exactly this. Your Microsoft agent activity lands in the same open lakehouse, in the same schema, next to your endpoint, network, and identity telemetry. Then the detectors run.
1. It pulls the Microsoft signal
Agent identity, Conditional Access verdicts, and sign-in risk come straight from Agent 365 and Entra Agent ID into Caver. Nothing to re-instrument. If Microsoft has already made a call on an agent, Caver knows about it.
2. It runs behavioral detection on top
Over that stream, Caver watches for the attacks identity alone cannot see: prompt injection, tool and capability drift, runaway tool loops, credential and API-key abuse, and cost or token spikes. These are the ways an agent that passed the front door still goes wrong, and they only show up in behavior, not in the sign-in.
3. Microsoft's verdict raises Caver's score
The two layers reinforce each other. When Microsoft blocks an agent or flags its sign-in as risky, that decision flows into Caver and its risk score rises automatically. You get Microsoft's judgment and Caver's behavioral read in one place, correlated, instead of two consoles telling you half a story each.
Agents do not only live in Microsoft
Here is the part that matters most, and the reason a Microsoft-only view was never going to be enough. Your agents are not all in Microsoft. They run in Claude Code, Cursor, Codex, and Copilot. They call OpenAI, Anthropic, and Azure. A control that only sees the agents holding an Entra identity is blind to most of the fleet the moment a developer opens a terminal.
Caver watches all of them. The same behavioral detection that runs over Agent 365 telemetry runs over every other platform, and every event, wherever it came from, is normalized into the one OCSF lake you own. On premise. Air gapped if you need it. The sensitive content stays out; the security verdict goes in. Whether an agent authenticated through Entra or was launched by hand against a raw API, it becomes one more monitored surface in the same place.
Microsoft governs the agents that carry its identity. Caver ingests that, adds behavioral detection Microsoft does not do, and extends the exact same watch to every agent that never touches Microsoft at all. One platform for every agent, everywhere.
The RedEye take
Agent 365 is the clearest signal yet that AI agents are now infrastructure, and infrastructure gets governed. That is good, and identity is the right place to begin. But identity is a gate, and a gate does not tell you what walks through it does next. The attacks that actually hurt, an agent talked into exfiltrating a key, an agent looping through a tool until the bill explodes, an agent quietly acting outside its intent, all live past the gate, in behavior, where a login-time control cannot reach.
That is the layer Caver adds, and it does not stop at the Microsoft boundary because your agents do not either. It is the same Caver that gives you cheaper storage and faster queries than the legacy SIEM stack, extended to the telemetry source most organizations are not collecting yet: what their agents are actually doing, on every platform, in a lake they own. Microsoft answered who and what. Caver answers whether it is behaving, everywhere it runs.
Secure every agent, everywhere
Caver integrates with Microsoft Agent 365 and watches every agent Microsoft cannot see, from Claude Code to Cursor to Codex, in one open lake you own. Behavioral detection on the agents themselves, not just the front door.
See it at getcaver.com