update
May 28, 2026
By Teun
Microsoft previews Windows 365 for controlled AI agent workloads
Microsoft has introduced Windows 365 for Agents, a cloud PC platform in public preview for running AI agents in secure enterprise environments. The company says organizations can use existing controls in Entra ID and Intune to govern agent activity across apps, browsers, files, and legacy systems.
Microsoft has previewed Windows 365 for Agents, a cloud PC platform designed to run AI agents inside controlled enterprise environments. The system lets organizations direct agents with natural language so they can interact with applications, browsers, files, and enterprise systems, according to Microsoft.
The company said the goal is to let businesses automate workflows that depend on software and systems without APIs, including legacy and UI-based environments, while keeping enterprise security and control in place. Windows 365 for Agents is available in public preview.
⚡ New to this?
This matters because AI agents are software that can take actions for a user, not just generate text. If a company gives an agent access to email, files, and internal systems, it can do real work - but it can also make real mistakes or expose data. A cloud PC is a remote computer hosted by Microsoft, and Entra ID and Intune are Microsoft tools for identity and device management.
🦞 OpenClaw angle
If you are building self-hosted agents, treat the agent runtime like a production user account, not a chatbot session. Put each agent in a separate execution environment with strict identity, file, and network limits, and require approvals for actions like sending email, changing records, or publishing content.
Use your existing policy stack to log every tool call and every data source the agent touches. For legacy UI-only workflows, isolate the browser or desktop session from production systems so a bad prompt cannot spread across your internal apps.
Microsoft said organizations can define and manage agents independently, continuously, or on demand using existing identity, policy, and management tools such as Microsoft Entra ID and Intune. That means agents can be placed inside the same kinds of controls many companies already use for employees and devices.
The platform is built around what Microsoft calls security boundaries for multi-step workflows. According to Julie Hersum, Principal Consultant at Microsoft, running agents in a controlled environment helps isolate risk and enforce security boundaries so agents can operate autonomously while remaining governed by company policies and without affecting production systems.
That emphasis on boundaries reflects a broader security concern around AI agents. A recent Cloud Security Alliance report found that securing AI agents requires the same rigor and traceability applied to human users because agents act on behalf of humans by accessing data and making business-impacting decisions.
The report warned that without clear boundaries, agents can access unintended systems, go beyond their intended scope, and spread small mistakes through a workflow. The recommendation is a dedicated execution environment for autonomous activity that still keeps agents under human oversight by default.
Microsoft’s announcement also aligns with warnings from security leaders about data misuse in autonomous workflows. Gidi Cohen told Help Net Security that the larger enterprise risk is not only jailbreaks, but autonomous data misuse by AI agents operating in systems the enterprise does not fully see, understand, or govern yet.
Cohen said the bigger problem is data exposure when agents can use multiple systems and tools to take actions such as sending emails, updating records, or publishing content without constant supervision. In that setup, a mistake in how data is accessed or shared can quickly become a broader security issue.
Windows 365 for Agents is Microsoft’s attempt to give enterprises a controlled place to run those agentic workloads. The company is pitching the platform as a way to automate complex tasks across modern and legacy software while keeping identity, policy, and management controls in the loop.