Short answer: yes for a scoped pilot, not yet for a company-wide rollout without groundwork. Now that it is listed on the Microsoft Store, Hermes Agent (Nous Research, open source, MIT) can be pushed through Intune like any other Store app. It already talks to Teams, Microsoft Graph and Microsoft Foundry through Entra ID. Governance (secrets, access control, audit) is still on IT.
I'm a Data & AI Tech Lead who puts agents into production for large companies (200+ agents in production at SUEZ). I read the Microsoft-facing code of Hermes Agent and proposed two fixes, now under review by the maintainers. Here is what matters for a Microsoft 365 shop.
What the Microsoft Store listing changes
Until now, installing Hermes Agent on Windows meant a PowerShell script or a terminal command. No IT department signs off on that for 500 laptops.
A Store app deploys through Intune with the "Microsoft Store app (new)" type (winget-based):
- targeting by Entra ID group (a pilot group, not the whole company);
- "available" in Company Portal or "required";
- updates tracked automatically.
Two cautions: check the package publisher before approving it, and test Autopilot, where Store apps are only partially supported. Store certification checks for malware and store-policy compliance; it is neither a security audit nor a GDPR review.
What Hermes Agent already does with Microsoft
| Microsoft piece | What exists in Hermes Agent | What you need to plan |
|---|---|---|
| Teams (chat) | Native Bot Framework adapter: personal chats, group chats, channels | Entra ID app registration, public HTTPS endpoint, user allowlist |
| Teams (approvals) | Sensitive commands arrive as an Adaptive Card: approve once, for the session, always, or deny | Default deny when no allowlist is set: keep it |
| Teams (meetings) | Meeting pipeline over Microsoft Graph: subscriptions, transcripts, summary posted to a channel or chat | Admin consent, regular Graph subscription renewal |
| Microsoft Foundry | Keyless Entra ID auth (DefaultAzureCredential chain: service principal, managed identity, Azure CLI…) |
Model and hosting region choice |
| Sovereign clouds (GCC High, DoD, 21Vianet) | Configurable authority | Fix proposed so Graph calls follow the right cloud (see below) |
The most mature part, in my view, is command approval in Teams. When the agent wants to run a command flagged as dangerous, it posts a card with four buttons, and only allowlisted users can click. Without an allowlist, the click is rejected. That is exactly what you want from a tool with terminal access.
What is missing for a company-wide rollout
- No documented admin tooling: the docs describe no central admin console, SSO or audit log.
-
Secrets in a file: Teams and Graph credentials are read from a
.envfile on the gateway host. - ID-based access control: access to the Teams bot is an allowlist of Entra ID object IDs, not a group.
- Demanding Teams setup: app registration, admin consent, a stable public URL with a valid certificate, secret rotation. Plan a few hours with Azure experience.
- An agent that acts on the machine: it can run commands and scripts. Without Intune rules or an isolated backend (Docker, for example), that is shadow AI waiting to happen.
Two fixes I proposed
Reading the Microsoft-facing code, I found two concrete defects and proposed a fix for each. Both are under review by the maintainers, not merged yet.
1. Microsoft Graph in sovereign clouds (PR #135618). The docs explain how to point authentication at login.microsoftonline.us for GCC High, but the Graph client always sent its requests to graph.microsoft.com. A token issued for a national cloud is not accepted by the global service, so every request was rejected. The fix derives the Graph root from the configured scope, limited to the four Graph roots Microsoft publishes. No new setting, and the token is never sent anywhere else.
2. Localized meeting summaries (PR #135619). In webhook mode, empty summary sections (decisions, action items, risks) printed an English "None", while Graph mode already used the translated value. The fix uses the same translation in both modes.
Each fix comes with a test that fails without it and passes the project's checks.
My pre-pilot checklist
- Scope: one use case, one Entra ID pilot group, an "available" (not "required") Intune assignment.
- Model: Microsoft Foundry with Entra ID auth (no API key to store), in a European region.
- Teams: a dedicated app registration, a user allowlist, never tenant-wide open access, mention-only replies in channels.
- Execution: command approval on, execution in an isolated backend rather than directly on the laptop.
-
Secrets: a
.envfile with restricted permissions, scheduled rotation of Entra ID secrets. - Meetings: documented admin consent, a scheduled job renewing Graph subscriptions.
- Training: pilot users trained on uses and limits. In the EU, Article 4 of the AI Act, rewritten by Regulation (EU) 2026/1744 in force since 27 July 2026, now asks employers to "promote" AI literacy (not legal advice).
Key takeaways
- The Microsoft Store listing makes Hermes Agent deployable through Intune: that is the real news for IT.
- The Teams, Graph and Foundry integration already exists and is serious, especially Adaptive Card command approval.
- Governance (secrets, access, audit) remains the company's job: run a scoped pilot before any rollout.
Zakaria Khchiche, Data & AI Tech Lead (Paris), AI trainer at Spar-x. 200+ agents in production at SUEZ; engagements for TotalEnergies, Groupe SNCF, La Banque Postale, Volvo Group. Open-source contributor (Microsoft Agent Framework, Mistral, OGX).
LinkedIn: https://www.linkedin.com/in/zakariakhchiche/ · Website: https://zakariakhchiche.github.io/
Want your team to build agents like these? I run a hands-on generative AI and agents-in-production training (in French, with Spar-x, Qualiopi-certified, eligible for OPCO funding in France): https://zakariakhchiche.github.io/formation-ia-generative/ and a free AI Act article 4 kit: https://zakariakhchiche.github.io/kit-ai-act/ · Quote request: https://mte.typeform.com/spar-xv3?typeform-source=www.spar-x.fr
Top comments (0)