Agents are already multiplying across Microsoft 365 tenants, and agent sprawl begins when growth outpaces governance. By launching a focused set of high-value pilots for Copilot with clear intent and governance from Day One, organizations can prove business value, establish a repeatable operating model, and scale only what the data supports.
Who This Is For
IT and security leaders at organizations that use Microsoft 365 Copilot who are seeing agents multiply faster than they can track and need a practical way to prove business value without losing control of the environment.
In Brief:
- Agent sprawl is the uncontrolled growth of AI agents without a shared inventory, clear ownership, or consistent controls. In many cases, these agents were created with approved tools to support legitimate business needs, but they were never formally documented or governed.
- Scenario selection often determines whether a pilot succeeds or stalls. The strongest candidates are those supported by data with a clearly defined, governable boundary and those tied to a business metric the organization already tracks.
- In a properly governed environment, each pilot agent should follow a consistent lifecycle: administrator review and approval in the Microsoft 365 admin center; inclusion in the Agent 365 registry for centralized visibility and governance; and a Microsoft Entra Agent ID where applicable to support identity-based access control, lifecycle management, and accountability.
- Enablement and observability keep governance effective. Sanctioned agents reduce unmanaged workarounds, while Agent 365 insights show which agents merit broader adoption.
Open Agent 365 in your Microsoft 365 admin center and try to account for every agent running in the environment. Most IT leaders can’t do it from memory, and the actual number is often higher than they expect, with new agents appearing regularly. Some were built in Copilot Studio, others arrived through vendor tools, and many began as practical business ideas that never endured a formal intake process.
That accumulation is agent sprawl, and the two most common responses tend to fall short. Pausing agent creation entirely can push employees toward unsanctioned tools and delay the value already available through Copilot. Expanding Copilot licenses broadly can lead to partially built agents and limited visibility into which are effective, governed, and worth keeping.
A well-designed pilot proves business value while establishing the governance model agents need before they prepare to scale.
In this blog, learn how to:
- Select high-value pilot scenarios
- Make each pilot agent governable from Day One
- Enable the teams responsible for adoption
- Use Agent 365 observability to determine which agents are ready to scale
Start With Scenarios You Can Measure
According to MIT’s NANDA initiative in “The GenAI Divide: State of AI in Business 2025,” roughly 95 percent of organizations investing in generative AI are seeing zero return, with most pilots stalling before they deliver measurable profit-and-loss impact. This makes pilot selection a critical early determinant of success.
When you examine what the agent needs to access, the answer often points to uncleansed data or multiple systems that must first be connected. As a result, the pilot stalls before it begins, while the agent still enters the environment.
A scenario qualifies for pilot status only after clearing two tests:
- Demonstrating measurable value tied to metrics already tracked outside IT
- Operating within a clearly defined and enforced data boundary
Select two to four scenarios that satisfy both criteria, and run a dedicated pilot for each. First, confirm the success metric exists and is monitored by a business function outside IT. Then use the pilot to determine whether the agent produces measurable improvement.
“Start with a focused, manageable scenario that can deliver value quickly,” says Veenus Maximiuk, senior solutions architect in Centric Consulting’s Enterprise Collaboration practice. “For example, a help desk ticket triage agent is a strong starting point when the knowledge source already resides in SharePoint, users are familiar with the platform, and the cost to operate the agent remains reasonable.”
Microsoft took the same approach with its own rollout, validating with pilot groups before enabling the rest of the organization. Each pilot can then follow a consistent path:
- Choose the scenario. Confirm the scenario satisfies both criteria before advancing it to pilot.
- Define the success measure. Identify the metric — like cycle time, deflection rate, or exceptions cleared per week — and align on it before development begins.
- Build governance in. Include intake, approval, registry, and agent identity where applicable as part of pilot setup rather than as follow-up work.
- Run the pilot and evaluate results. Use the success measure defined in Step 2 to decide whether to scale, refine, or retire the agent.
“Security and governance concerns are seen as the No. 1 barrier to Copilot adoption,” says Gartner Senior Director Analyst Max Goss. Citing a Gartner study, Goss notes that 70 percent of Copilot customers worry about agent sprawl, but only 14 percent believe they have the right governance in place.
The solution: pilots that are governable as they go live.
Make Every Pilot Agent Governable From Day One
This is where the pilot earns its keep. The intake and approval process you build for two agents is the same motion that governs 200.
For an agent built in Copilot Studio, the path begins with application lifecycle management, which works like any development lifecycle:
- Build in a development environment
- Promote through testing
- Submit for production
In an agentic Microsoft environment, an administrator then uses Agent 365 to go several steps further. They’ll review what the agent is trying to do, the data it needs, and the permissions required before rejecting or approving the agent and reallocating work as necessary.
“Agent 365 serves as a centralized control plane,” Maximiuk says. “It gives organizations the visibility they need into registered agents so they can understand what exists, who owns it, and how it is being governed.”
Distinguishing between registered and unregistered agents is key in preventing agent sprawl, with Agent 365 handling discovery, registry, and observability. Another Microsoft 365 tool, Microsoft Entra Agent ID, complements this by supporting identity management for agents, which helps organizations apply access controls and lifecycle governance more consistently.
Microsoft Entra Agent ID assigns each agent a unique identity, enabling Conditional Access and lifecycle management. Microsoft Purview complements this governance model by protecting the data layer. If Purview restricts access to specific data, Copilot Studio configuration cannot override those controls.
An agent that completes this path can be discovered, scoped, governed, and retired when needed. An agent that bypasses this process contributes to AI agent sprawl the moment it goes live.
The math argues for building now. A 2026 Gartner press release predicts the average global Fortune 500 enterprise will run more than 150,000 AI agents by 2028, up from fewer than 15 in 2025. Registry and identity cost far less at two agents than at 2,000, which is the same case we make for onboarding every agent like a new employee.
However, governance without adoption quickly becomes shelfware, so effective enablement is essential to making the pilot sustainable.
Enable the People Who Own the Work
Enablement is a critical control point for managing agent sprawl, not simply a change management activity. When a sanctioned agent doesn’t meet user needs, users may create an alternative agent independently, often without registering it or bringing it under the organization’s governance model.
Tie training directly to the selected scenarios rather than relying on generic Copilot sessions. For example, a sales team piloting a proposal agent needs hands-on experience with that specific agent, the content it uses, and the workflow it is intended to support.
Similarly, an internal help agent for policy questions and onboarding tasks may be identity-scoped and limited to non-privileged actions, but the IT and HR teams who currently handle those requests must still be involved while the agent is tuned. Pair that participation with adoption and enablement techniques. These include change communications, a champions network, and standing office hours that give users a safe forum to raise questions they may not ask in a group setting.
Before calling anything a pilot, confirm that the pilot group is genuinely available. Participants should be prepared to complete training, join working sessions, provide feedback, and engage in necessary conversations to improve the agent rather than simply being assigned to a distribution list.
Leadership sponsorship is equally important. In many organizations, IT owns the controls while the business owns budget and urgency, and those groups are not always aligned. A pilot with a visible executive sponsor is more likely to sustain momentum, while one without can lose support even when the technology performs well.
With the measures defined and the right stakeholders engaged, the final step is to close the loop.
Prove Value Before You Scale: The Real Check on AI Agent Sprawl
Agent 365 shows each agent’s purpose, origin, data reach, and usage patterns alongside Microsoft 365 admin center management and reporting controls. Use that insight to compare performance against the pilot’s success measures and decide whether to scale, refine, or retire the agent.
An invoice and purchase order reconciliation agent with a human checkpoint is a strong example. Finance already tracks exceptions cleared per week, so the pilot has a clear success measure. If the metric improves, the agent has a case for expansion. If not, refine or retire it before it adds to sprawl.
Other effective practices include:
- Refining grounding and access controls when results are inconsistent
- Treating retirement as both a governance and cost decision
- Expanding the pilot group if the sample size is too small
- Adding representative users to improve feedback and usage data
- Documenting governance exceptions with a clear business justification
- Scaling only agents that demonstrate measurable value
Together, these practices help prevent agent accumulation from becoming agent sprawl.
Is Your Next Pilot for Copilot Building Your Governance Model?
Getting ahead of agent sprawl happens only by making intentional pilots the default path to production, not by banning agents or slowing your teams down.
Choose scenarios you can measure. Govern from Day One through intake, the registry, and agent identity. Enable the people who own the work. Prove it before you scale.
Run those four moves once, and you have more than a successful pilot. You now have the operating model your next 50 agents will move through.