Manulife is rolling out Microsoft 365 Copilot to more than 30,000 employees, but the real headline isn’t the number of seats—it’s the governance framework the insurer is putting in place to keep AI agents from running amok.
The company signed a five-year deal to adopt Microsoft 365 E7 Frontier Suite and, crucially, Microsoft Agent 365, a central control plane for registering, monitoring, and managing AI agents across the organization.
This isn’t just a license purchase. It’s a bet that enterprise AI can’t scale safely without a unified way to govern automated workers that have identities, access permissions, and the capacity to act on business systems.

What Actually Changed

On July 24, 2026, Manulife and Microsoft announced the expanded partnership. The financial services giant will:

  • Adopt Microsoft 365 E7 Frontier Suite, a bundle that combines productivity AI (Copilot) with identity, security, compliance, and endpoint management capabilities from E5, plus the Entra identity suite.
  • Roll out Copilot to 30,000+ employees, embedding the assistant across Word, Excel, Outlook, PowerPoint, Teams, and other Microsoft 365 apps.
  • Deploy Microsoft Agent 365 as a central system for observing and managing AI agents. Agent 365 provides a single pane of glass to inventory agents, enforce policies, audit activity, and revoke access if something goes wrong.
  • Build an internal enterprise AI platform on Azure and Microsoft Foundry, giving data scientists and developers a governed environment to create, fine-tune, and deploy generative and agentic AI applications.

The deal also encompasses existing AI tools already in production: a sales enablement tool powered by Foundry models, the Quick Quote underwriting assistant at John Hancock, knowledge tools handling over 110 million customer calls annually, and AI-assisted software development that Manulife says has boosted developer productivity by 30%.

What It Means for You

The Manulife story matters to anyone running Windows and Microsoft 365 in an organization—whether you’re an everyday user, an IT pro, or a business leader thinking about AI adoption.

For Employees

If you work for a company that adopts Copilot at this scale, expect changes in how documents are found, shared, and summarized. Copilot operates within your existing permissions, but that also means bad permission hygiene gets exposed faster. An AI can surface a sensitive file just as easily as it can find a marketing one-pager. Training on responsible prompting and verification will become as routine as phishing awareness.

For IT Administrators and Security Teams

Agent 365 is likely to land on your plate as a new management surface. Think of it less as a bot maker and more as an identity and governance control pane. Every AI agent in your environment will need:
- An owner
- A scoped identity (likely an Entra service principal)
- Explicit data access permissions
- Audit logs that you can review
- A kill switch if it misbehaves

This is a shift from managing users and devices to managing digital workers. Prepare for conversations about least privilege, data classification, and monitoring that extend beyond human employees. If you’re already managing Copilot, the jump to Agent 365 means adding observability for autonomous actions, not just assisted search and generation.

For Developers and Data Scientists

An internal AI platform on Azure Foundry promises standardization: approved models, reusable retrieval components, cost controls, and safety review paths. That can speed up development, but it also means your projects will be subject to centralized governance. Independent experimentation might shrink; instead, you’ll be expected to use the platform’s templates and approved tools. On the plus side, you’ll spend less time reinventing retrieval patterns or fighting for access to secured data.

For Business Leaders and Compliance Officers

The deal underscores that AI governance can’t be an afterthought. Manulife’s global chief AI officer, Jodie Wallis, framed it plainly: “Responsible innovation has to be built into how we operate—not treated as a separate layer of oversight.” For regulated industries, that means AI deployments must pass muster with privacy, fairness, and auditability checks from day one. The E7 suite tries to collapse those controls into a single license, but governance still requires policy and people. Technology can flag anomalous agent behavior; it can’t decide whether an underwriting recommendation is appropriate.

How We Got Here

Two years ago, enterprise AI was mostly about chatbots and assistants that summarized reports or drafted emails. Those tools stayed close to the user: a person asked, the AI responded, the person decided.
Then autonomous agents entered the picture. An agent can be given a goal, access to business systems, and instructions to perform multi-step tasks with limited human intervention. For a bank, that might mean an agent running a pre-approval check; for an insurer, it could mean gathering underwriting information and flagging exceptions.
That shift created a governance vacuum. Traditional apps have known codebases and defined service accounts. AI agents, by contrast, combine prompts, retrieval systems, models, connectors, and identity permissions that can change with every piece of data they touch. Without a central inventory, an organization can quickly lose track of who built what, what data an agent can see, and whether its actions remain compliant.
Microsoft launched the E7 Frontier Suite and Agent 365 to fill that gap. The products reached general availability on July 22, 2026, as announced on the Microsoft 365 blog. Manulife’s adoption is the first large, public deployment of the full stack. It signals that Microsoft sees the future of its enterprise ecosystem not just as a place where people use AI, but as a managed environment where agents operate alongside them—all governed through the same identity and security fabric.

What to Do Now

If your organization is exploring AI agents or expanding Copilot, Manulife’s approach offers a checklist—not a guarantee of success. Here’s what IT leaders can start on today:

  1. Inventory every AI tool and agent. You can’t govern what you don’t know exists. Catalog both sanctioned and shadow AI tools, even if you’re not yet using Agent 365.
  2. Tie every agent to an identity and an owner. Ensure each agent has a clearly assigned business owner and a distinct Entra identity (or equivalent) with documented permissions.
  3. Enforce least privilege. Audit what data agents can access. Do not grant broad read/write access just because it’s easier. Regularly review and revoke unused or excessive permissions.
  4. Log agent activity. Centralize logs so you can reconstruct what an agent did, when, and with what data. This is critical for audits, incident response, and regulatory exams.
  5. Classify data before exposing it to AI. Use tools like Microsoft Purview sensitivity labels and data loss prevention policies. Copilot and agents will surface whatever a user or identity has access to; if your data is poorly labeled, the AI will happily surface sensitive content.
  6. Test for accuracy, bias, and misuse. Stand up red-team exercises that prompt agents with adversarial inputs. Check whether agent outputs remain grounded in authoritative sources, and set up automated testing pipelines wherever possible.
  7. Train employees early. Teach users not to treat AI output as truth without verification. Remind them that they remain accountable for decisions, especially in customer-facing or regulated tasks.
  8. Measure value with operational metrics. Don’t count “hours saved” without linking to real business outcomes—cost reduction, revenue uplift, error reduction, or throughput improvement.

If you’re considering the E7 suite, start evaluating it against your current E5 deployment. Factor in the added complexity: bundling security, compliance, and AI management into one license means you’ll need mature administration across all those domains.

Outlook

Manulife’s five-year commitment puts a corporate giant behind Microsoft’s governed-AI thesis. Expect to see other large, regulated firms—especially in finance and healthcare—follow suit, though each will need to reconcile its own legacy systems and policies.
Microsoft will likely use the Manulife case study to push E7 and Agent 365 at its upcoming Ignite conference. For enterprises already in the Microsoft stack, the question is no longer whether to adopt AI, but whether to adopt it with or without a central governance layer. The answer is becoming obvious.