Free live webinar · Oct 8 — Get your Microsoft 365 AI-ready before Copilot reads the wrong file. Reserve a seat →
Polaris Governance

Field note

Orphaned agents: Microsoft ships a "missing owner" filter for a reason

The new Agents dashboard in the Microsoft 365 admin center gives "agents without owners" one of its four top governance cards. Platform vendors don't build UI for hypothetical problems — a short piece on why agents orphan, and why an ownerless agent is worse than an ownerless site.

Open the new Agents overview in the Microsoft 365 admin center and four governance cards sit at the top of the dashboard: pending agent requests, agents at risk, agents with exceptions — and agents without owners, with an “Assign owner” action attached (Agent overview in the Microsoft 365 admin center). The same page lists rules-based management that can “automatically enforce lifecycle policies, such as flagging ownerless agents.”

Platform vendors don’t build dashboard cards for hypothetical problems. When Microsoft gives ownerless agents a quarter of the governance dashboard and an automation hook, it’s telling you what it expects to find in real tenants: agents nobody owns, at scale, as a routine condition.

How an agent loses its owner

The same three ways sites and groups did — a problem old enough that M365 admins have run ownerless-resource cleanups for years. The maker leaves the company. The team reorganizes and the agent transfers to nobody. Or the “quick experiment” quietly becomes something a whole department relies on, and there was never an owner to lose — nobody ever formally had it.

We watched the third mode dominate when we scanned a real tenant: dozens of Copilot Studio agents scattered across roughly nineteen environments — default environments, personal-productivity environments, per-maker dev spaces. Self-service creation is the point of these tools, and it works. But every agent created in thirty seconds by someone solving a local problem is an agent with, at best, one informal owner and no succession plan. That’s not negligence; it’s the default. The sprawl mechanics are the subject of The agents you can’t see.

Why ownerless agents are worse than ownerless sites

An ownerless site mostly just sits there. An ownerless agent keeps working:

  • It keeps answering — with stale instructions, grounded on content nobody is curating, wearing the credibility of a chat interface and a citation.
  • It keeps its access. Its connections and permissions persist, and its configuration can change with nobody positioned to notice that it has drifted from whatever was originally approved.
  • It breaks the accountability chain. When an access review or an audit asks “is this still needed, and who approved it?”, an ownerless agent has no one to answer. That question — who attests? — is the hinge of governance generally, and we’ve argued it’s the question your whole estate is quietly failing. Agents just fail it faster, because they were born informal.

And there’s a compounding problem the filter can’t reach: Microsoft’s card covers agents in the registry. In the same scan, a separate look at the organization’s Azure estate found AI Foundry agents that appeared in no Microsoft 365 admin surface at all. An unowned agent on an unseen plane is orphaned twice — no owner to flag, and no filter watching the place where it lives.

What to do with the filter

Use it — it’s the right instinct, natively shipped. Just aim it properly:

  1. Inventory across every plane first. The filter can only flag what the registry sees. Reconcile Power Platform environments, M365 surfaces, and Azure subscriptions before trusting any ownerless count.
  2. Make ownership a lifecycle invariant, not metadata. An owner assigned at creation, reassigned on departure — enforced, the way Microsoft’s own rules-based flagging nudges you toward, not recorded once and forgotten.
  3. Make retirement a decision someone owns. Most orphaned agents shouldn’t be adopted; they should be reviewed and switched off. An agent nobody will claim is telling you something about whether it should keep running.

Microsoft shipped the filter because agent abandonment at scale is already normal. The question left for you is the one the dashboard can’t answer: is the number on the card the number in your estate?


Polaris Governance Hub runs inside your own Microsoft 365 tenant and inventories agents across Copilot Studio, M365 surfaces, and Azure AI Foundry — with ownership, configuration drift, and honest coverage reporting. We’re taking a small number of design partners. See what’s actually in your estate.

More field notes · Full archive · RSS · How the product works