On July 22, 2026, Manulife Financial signed a five-year agreement that will place Microsoft 365 Copilot on more than 30,000 employee desktops and make the insurer one of the first major adopters of the new Agent 365 control plane. But the deal’s lasting significance won’t be measured in seat licenses. It’s a high-stakes experiment in binding AI governance directly to Windows endpoint management, identity, and security—and a preview of what every IT team managing a large Microsoft environment will face within the next 18 months.
What Manulife Actually Bought: Copilot, E7, and a Fleet Manager for AI Agents
The partnership centers on three Microsoft technologies, each addressing a different layer of the AI stack.
Microsoft 365 Copilot will reach the vast majority of Manulife’s 37,000-plus employees, making this one of the largest Copilot deployments outside the tech sector. Users will be able to summarize meetings, draft documents, analyze spreadsheets, and search organizational knowledge from inside Word, Excel, Outlook, Teams, and other M365 apps. At this scale, however, Copilot stops being a productivity toy and becomes a search tool that can surface overshared files, outdated policies, and redundant customer records if permissions are not locked down.
Microsoft 365 E7: The Frontier Suite serves as the commercial and technical foundation. It packages Copilot, the Entra identity suite, Defender security tools, Intune device management, Purview compliance, and—crucially—Agent 365 into a single $99/user/month bundle. Manulife will not only consume these services but also use them to enforce a consistent AI policy. For Windows admins, the takeaway is that E7 is not a higher-tier Office edition; it’s a management plane that treats an AI assistant like any other endpoint-accessible corporate asset.
Agent 365 is the most consequential piece of the deal. Microsoft positions it as a “control plane” for registering, monitoring, and governing AI agents—whether built on Microsoft platforms or through third-party sources. Manulife intends to use it as an enterprise-wide registry, answering questions like: Which agents are operating in production? Who owns each agent? What data can it access? Can its actions be reconstructed during an investigation? Without those answers, an insurer could accumulate hundreds of automations that no single team fully understands.
Why This Matters for IT and Windows Teams Right Now
For organizations already on Microsoft 365, the Manulife rollout exposes several immediate pressure points.
Copilot Magnifies Existing Permission Gaps
A user who can technically access a sensitive document—even one stored in an abandoned SharePoint site or shared with a broad team—may find Copilot eagerly surfacing its contents in response to a natural-language query. The AI doesn’t create the exposure, but it accelerates discovery. Manulife will have to audit and tighten:
- Overshared SharePoint and Teams folders.
- Inconsistent sensitivity labels.
- Duplicate documents with conflicting information.
- Unmanaged third-party connectors.
If you’re planning your own Copilot rollout, run a data access review first. Treat Copilot as a spotlight on your information governance debt.
Endpoint Posture Becomes Part of AI Access Control
Manulife’s employees will reach Copilot and agents through Windows PCs, mobile devices, and browsers. That makes Intune device compliance, Defender endpoint detection, and conditional-access policies the gatekeepers for AI. A compromised laptop or stolen session token could let an attacker use the victim’s Copilot session to search corporate data or trigger agent actions.
Your Windows security baselines suddenly matter for AI governance. Make sure you:
- Enforce phishing-resistant MFA, especially for privileged roles.
- Maintain current Windows update compliance.
- Control local admin rights closely.
- Restrict unauthorized scripts and browser extensions.
- Require compliant devices for any Copilot-enabled tenant.
Agent Management Requires an Operational Process, Not Just a Dashboard
Agent 365 will give Manulife a central registry, but registration doesn’t equal control. Agents that can read databases, update records, or trigger workflows demand the same rigor as service accounts. You’ll need to define a lifecycle: risk classification, least-privilege identity, approval gates, monitoring for drift, and a retirement plan.
For IT shops, the practical checklist looks like this:
1. Inventory any existing automations that use AI models or can act semi-autonomously—even those built on Power Automate or Logic Apps.
2. Assign business and technical owners for each.
3. Restrict permissions to the minimum required.
4. Test behavior under normal, edge, and adversarial conditions.
5. Establish runtime monitoring for unexpected cost spikes, access anomalies, or output shifts.
If you wait until after a Copilot-enabled breach to build these steps, you’ll be explaining to your board why the AI sped up an attacker’s search, too.
The $1 Billion Value Target Raises the Bar for Measuring AI Success
Manulife expects its AI initiatives to produce more than $1 billion in enterprise value by 2027, with $300 million already achieved by end of 2025. Time saved by Copilot will be measured, but the company knows that “minutes saved” doesn’t automatically become cash. You’ll need to define role-specific KPIs—claims handler turnaround, developer deployment velocity, call center first-contact resolution—tied to actual financial outcomes.
For your own organization, start now by separating productivity metrics (prompts run, summaries generated) from business-value metrics (cycle time reduction, error-rate drops, revenue gains). If you can’t show the connection, your AI budget will face tough questions.
How Manulife Got Here: From Cloud Migration to Agentic Operations
Manulife’s relationship with Microsoft didn’t start with AI. The insurer had already adopted Azure, M365, GitHub Copilot, and Microsoft’s security stack as part of a broader modernization effort. Existing production AI systems—like a Sales Enablement tool in Singapore and John Hancock’s Quick Quote for life insurance—were built on Microsoft Foundry, giving the company confidence to standardize on the new E7 bundle.
Regulatory pressure also shaped the decision. Operating in 25 markets with 37 million customers, Manulife must handle personal, medical, and financial data under strict rules. A scattered AI pilot program risked violating those boundaries. The E7 suite offered a single identity and compliance layer across Copilot interactions, agent identities, and endpoint access—something that would take months to assemble from separate point solutions.
What You Should Do Right Now
Whether you’re a Windows administrator, an IT manager, or a security architect, the Manulife deal provides a concrete template for your own AI-readiness efforts. Pick one of these lanes and act:
If you’re planning a Copilot rollout:
- Conduct a SharePoint and Teams permission audit before any pilot license is assigned.
- Clean up obsolete sites and remove stale guest accounts.
- Apply sensitivity labels and retention policies consistently across M365 workloads.
- Test Copilot with a small group and examine what data it surfaces unexpectedly.
If you’re responsible for endpoint security:
- Review your conditional-access policies: would a noncompliant device be blocked from all AI-powered apps?
- Ensure Intune and Defender are integrated and actively reporting on the devices that will run Copilot.
- Strengthen credential hygiene: separate admin accounts, enforce phishing-resistant MFA, and restrict token lifetime.
If you manage automation or development platforms:
- Start building an agent inventory today. Even simple Power Platform flows that use AI Builder count.
- Define a risk-classification scheme: low, medium, high based on data sensitivity, autonomy, and customer impact.
- Pilot Agent 365 (or an equivalent governance tool) with a handful of agents to understand the registration, monitoring, and emergency-shutdown capabilities.
For everyone:
- Don’t assume Copilot will “just work” under existing security controls. Run a red-team exercise where a simulated attacker with stolen credentials tries to use Copilot to find sensitive data. You may be surprised by what surfaces.
What to Watch Over the Next Two Years
Manulife’s journey will offer free lessons for the industry. Pay attention to:
- Agent 365’s real-world granularity. Can it govern custom-built agents that use non-Microsoft models, or will the registry become a Microsoft-only club? Watch for public disclosures about policy enforcement, not just inventory.
- The transparency of AI value reporting. Manulife’s quarterly updates will likely cite AI contributions. Look for breakouts that distinguish real cost savings from capacity gains or risk reduction. If the numbers stay aggregated, skepticism is warranted.
- Endpoint incidents that involve AI. The first time a compromised Windows laptop is used to query Copilot for IP, it will make headlines. How Manulife’s stack detects and responds will influence industry best practices.
- Competitors’ reactions. Manulife’s top ranking in the Evident AI Insurance Index makes this deal a benchmark. If other insurers follow with similar governance-centric deployments, the Microsoft E7 and Agent 365 architecture could become a de facto standard, further tying Windows endpoint management to AI oversight.
For Windows administrators, the message is unambiguous: AI governance isn’t a policy memo your compliance team drafts. It’s a set of technical controls you enforce through Intune, Defender, Entra, and the agent registry. Manulife just gave you the playbook—time to read it.