City Power & Light is undergoing an ISO 27001 audit. The compliance officer needs to demonstrate that their AI agents in Microsoft 365 meet specific data handling and access control requirements. The administrator must identify which agents have compliance gaps — such as missing data handling policies, excessive permissions, or unreviewed access to sensitive resources. Which Agent 365 feature should the administrator use?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Agent 365's compliance gap evaluation is like a built-in auditor that scans your agents and says 'here's what's out of policy.' Instead of hunting manually through logs, you get a structured report showing exactly which agents are missing what controls.
Full explanation below image
Full Explanation
Agent 365 includes compliance gap evaluation capabilities that systematically assess deployed agents against organizational policies and compliance requirements. The feature identifies specific gaps such as agents with excessive permissions (violating least privilege), agents accessing sensitive resources without a documented data handling policy, agents that have not been reviewed within a required review cycle, or agents lacking appropriate governance configurations. This provides administrators with a structured view of compliance posture across all agents, which can be used to generate evidence for audits like ISO 27001.
Option A, Microsoft Entra ID Governance Access Reviews for agent service principals, is a valuable tool for periodically validating that agent identities still require their assigned permissions. However, Access Reviews are specifically about verifying permission assignments — they do not evaluate broader compliance gaps such as missing data handling policies, lack of security configurations, or unreviewed resource access patterns.
Option C, Microsoft Purview Compliance Manager ISO 27001 assessment, evaluates the organization's overall Microsoft 365 tenant configuration against ISO 27001 controls. It is a general compliance assessment tool for the tenant, not an agent-specific compliance gap analysis tool that maps gaps to individual agents.
Option D, manually exporting logs and reviewing against a checklist, is time-consuming, error-prone, and does not scale. While it might be a fallback, the question asks for the proper administrative tool — which is Agent 365's built-in compliance gap evaluation, designed specifically for this purpose.
Exam tip: For evaluating compliance gaps specifically for AI agents in Microsoft 365, Agent 365 compliance gap evaluation is the purpose-built tool. Distinguish it from broader Compliance Manager assessments (which are tenant-wide) and Entra Access Reviews (which only check permissions, not holistic compliance).