Service principals, managed identities and now Entra agent identities are all non-human identities in the same directory, and they multiply faster than anyone reviews them. This guide explains what each type is, which credential each should use, what Workload ID Premium and Agent 365 actually add, and which identity to choose for which workload, with every claim checked against Microsoft's documentation in September 2026.
Microsoft 365 Copilot and its agents are paid for in three different ways, and each one bills to a different place: per-user seats on the Microsoft 365 invoice, prepaid Copilot Credits allocated to Power Platform environments, and pay-as-you-go charges on an Azure subscription. This guide explains the three cost shapes, the controls Microsoft provides for each, and a chargeback model built on them, checked against Microsoft's documentation in September 2026.
NIST's AI Risk Management Framework is voluntary and ISO/IEC 42001 is certifiable, but they describe the same management cycle. This guide lines the two up, maps each theme to the Microsoft controls that produce evidence for it (Purview, Entra Agent ID, Agent 365, Defender for Cloud and Foundry), and is clear about what no tool can do for you. Checked against NIST, ISO and Microsoft documentation in September 2026.
Once you have decided to extend Microsoft 365 Copilot, there are three ways to do it, and they are not interchangeable. Copilot connectors change what Copilot knows, declarative agents change how it behaves, and custom engine agents replace its engine. This guide compares the three on licensing, governance and who carries the risk, with every claim checked against Microsoft's documentation in September 2026.
Copilot Studio and Microsoft Foundry are not competitors — they sit at different levels of abstraction, and three changes in 2026 have quietly retired most of the advice written about choosing between them. A decision framework built on who owns the runtime, where the data already lives, and who operates the agent on day ninety, with the cost shapes, governance asymmetries and interop paths verified against Microsoft's own documentation.
Microsoft Foundry is no longer a place to call models — it is a platform for hosting, grounding, governing and operating agents. A working architecture guide to prompt and hosted agents, Foundry IQ, Toolbox, MCP and A2A, model choice and Claude, agent identity and RBAC, private networking, evaluation and Agent 365 — with every capability marked GA, Preview or retiring, and the places Microsoft's own documentation contradicts itself named rather than smoothed over.
Microsoft's AI portfolio is not five versions of the same product — it is a layered enterprise architecture with an experience layer, two build platforms, a control plane, and the identity, data and threat controls underneath. A practical architecture guide to what each platform is for, which workloads belong where, how agent identity and authority actually flow, and what has to be true before an organization scales any of it.