Licensing is an architecture input, not a procurement detail. The agreement you buy through decides where Azure commitments, cost allocation and billing scopes can sit, and the Microsoft 365 plan decides which identity, endpoint, email and data controls you can design with. This guide maps EA, MCA and CSP to Azure billing structure, and E3, E5, the $12 suites and E7 to the security designs each one unlocks, checked against Microsoft's documentation in September 2026.
NIST's AI Risk Management Framework is voluntary and ISO/IEC 42001 is certifiable, but they describe the same management cycle. This guide lines the two up, maps each theme to the Microsoft controls that produce evidence for it (Purview, Entra Agent ID, Agent 365, Defender for Cloud and Foundry), and is clear about what no tool can do for you. Checked against NIST, ISO and Microsoft documentation in September 2026.
Microsoft Copilot respects existing permissions, which means it finds existing oversharing faster than any user ever did. This guide explains where excess access comes from, what SharePoint Advanced Management and Microsoft Purview actually do about it, why Restricted SharePoint Search is retiring, and a phased remediation plan, with every status checked against Microsoft's documentation in September 2026.
Once an AI agent can write to systems, send email or move money, "a human approves it" is not a design. This guide classifies agent actions by consequence and reversibility, maps each class to an approval pattern, and sets out what the audit record must hold to survive a review, grounded in what Microsoft 365 Copilot, Copilot Studio, Microsoft Foundry and Purview actually provide as of September 2026.
Copilot Studio and Microsoft Foundry are not competitors — they sit at different levels of abstraction, and three changes in 2026 have quietly retired most of the advice written about choosing between them. A decision framework built on who owns the runtime, where the data already lives, and who operates the agent on day ninety, with the cost shapes, governance asymmetries and interop paths verified against Microsoft's own documentation.
Microsoft's AI portfolio is not five versions of the same product — it is a layered enterprise architecture with an experience layer, two build platforms, a control plane, and the identity, data and threat controls underneath. A practical architecture guide to what each platform is for, which workloads belong where, how agent identity and authority actually flow, and what has to be true before an organization scales any of it.