AI-Powered Autonomous Validation on Windows 365 for Agents
Validate at the Speed of AI
As enterprises accelerate AI adoption, one challenge continues to stand in the way of transformation: trust. At the same time, the rate of change is accelerating, fueled by frontier-level AI models such as MDASH and Mythos — allowing bad actors to exploit vulnerabilities more quickly, but also allowing software companies to patch at the same speed.
Organizations are deploying applications, operating system updates, security patches, AI copilots, and business workflows faster than ever. Yet validation remains largely manual, fragmented, and difficult to scale. In many environments, validating change still takes weeks.
At WorkspaceDNA, we believe every change should be validated before it impacts users. The more change, the greater the risk of something breaking — and we don’t just mean the application being deployed. Inter-app dependencies and Conditional Access policies affect how applications behave. Windows updates break critical legacy apps.
Today, we're excited to share how WorkspaceDNA is building on Windows 365 for Agents to bring ATP360, your agentic application owner, to the enterprise.
ATP360 allows multi-app workflows — spanning legacy in-house apps with no APIs alongside off-the-shelf apps — to be tested on Cloud PCs that are identical to those used in production: the same configuration and compliance policies, the same gating Conditional Access policies, a true digital twin.
Microsoft Entra Agent ID gives the agent its own governed identity, and Microsoft Agent 365 extends full auditability over what was accessed and how the AI reasoned — just like a user identity, but designed for a computer-using agentic workload.
Consider the case of a large managing general agent (MGA) writing property insurance under delegated authority on behalf of the underwriters who carry the risk. The MGA sells property insurance covering the risk, handles claims from policyholders directly, and refers the claims it approves to the underwriter, who makes the final call and pays the valid ones.
A storm takes the roof off a house and the insured files a new claim. Over the following weeks, that single claim passes through a claims handler, a loss adjuster, a supervisor, and sometimes an external underwriter. It accumulates photographs of the damage, contractor estimates, receipts, and a third-party assessor’s report. It moves through a twelve-state workflow with branches, holding states, reversals, and conditions that must be satisfied before it can advance: a loss adjuster must approve the claim against policy wording before it goes to an underwriter, the policy excess must be collected before it can be settled, and every decision must carry a written reason. At least three times, the claim leaves the organization entirely and comes back.
The application at the center of it is a Windows desktop line-of-business app. A .NET Framework code base with a WinForms front end over an Access database, deployed by Microsoft Intune or Configuration Manager, and 32-bit by necessity because the data is reached through the Jet provider. It was built in-house back in 2003 and dragged forward through successive upgrades to Framework 4.8. It has no API. There is no mailbox integration, no folder watching, and no structured inbound feed of any kind. A person reads what arrived and keys it in by hand.
It is, in other words, exactly the sort of long-lived internal application that nobody is enthusiastic about and nobody can switch off or easily replace. Most large enterprises have several such applications. They run claims, dispatch, underwriting, accounts, case management, and stock control. They are rarely covered by automated testing, because the things that make them business-critical — the user interface, the workflow rules, the role-based permissions — are precisely the things an API-level test cannot reach.
The harder problem is that the work does not stay inside one window.
That in-house application is called Claims Manager. Follow a single claim through it, from first notification to closure, and count the applications a handler touches along the way:
Outlook — the first notification arrives as an email, supporting evidence follows the same way, the approved claim pack goes out to the underwriter, and the decision comes back
A PDF reader — contractor estimates, signed forms, and assessor reports arrive as PDFs and have to be read before anything can be recorded
An image viewer — photographs of the damage, opened and compared against the estimate
Word — letters to the insured, and the covering documents assembled for the underwriter submission
Excel — the claim value and performance reports, which the application produces by driving Excel through COM to draw its charts
Fax — still in the loop for third-party assessors and for some underwriters
Claims Manager itself — where the file is built, the workflow advances, and the append-only audit trail is written
No single system owns that sequence. The workflow lives in the seams between applications: in a person’s judgment about whether an inbound item belongs to a claim already open or starts a new one, and in the plain fact that step four happens in a different window from step three. Validating a change to any one of those applications means validating the whole chain, because the failure that matters is rarely inside a single app. It is at the handoff between them.
That is the shape of the problem. A workflow that spans a legacy desktop application, an email client, an office suite, and a document viewer — governed by rules that exist nowhere but the UI — cannot be validated by anything that does not work the way a person works: reading the screen, opening the attachment, moving between windows, and checking that what came out of the other end is what should have.
Which means it needs a desktop. A real, managed, identity-backed Windows desktop.
WorkspaceDNA is developing an AI-powered autonomous validation agent designed to run on Windows 365 for Agents.
Powered by WorkspaceDNA's ATP360 autonomous validation technology, the agent will act as the MGA’s agentic application owner, validating changes to its line-of-business applications, Windows updates, endpoint configurations, and business workflows before they reach production.
Windows 365 for Agents provides a purpose-built, enterprise-managed Cloud PC environment for running AI agents securely and at scale. By combining this trusted Microsoft foundation with WorkspaceDNA's autonomous validation capabilities, organizations can test and validate change across complex enterprise environments more efficiently.
Rather than relying solely on brittle scripts or extensive manual testing, the validation agent can understand context, execute tasks, verify outcomes, and generate reviewable evidence before deployment decisions are made, so will make light work of the MGA’s Claims Manager line-of-business application.
Many enterprise workloads still depend on user interfaces, desktop applications, browsers, legacy systems, and workflows that cannot always be validated through APIs alone, as the claims department example above shows.
Windows 365 for Agents provides managed Cloud PCs where ATP360 can interact with applications and workflows within an enterprise-governed environment, with the agent’s own identity provided by Microsoft Entra Agent ID and governance extended through Microsoft Agent 365. With identity and access supported by Microsoft Entra ID and management through Microsoft Intune, organizations can extend familiar security, compliance, and governance controls to agentic work.
This creates new possibilities for enterprise validation, including:
Testing the impact of Windows updates on critical or legacy line-of-business apps before rollout
Validating application deployments
Running user acceptance testing
Verifying business-critical workflows
Generating audit-ready validation evidence
Scaling validation without proportionally increasing operational overhead
At WorkspaceDNA, we have a simple philosophy:
|
AI performs the work. Humans retain control. |
Our validation agent is being designed around responsible AI principles and a human-in-the-loop operating model. Autonomous agents execute validation, identify potential issues, and provide recommendations, while production decisions remain firmly in the hands of IT and business stakeholders.
The goal is not to remove governance.
The goal is to make governance faster, smarter, and driven by evidence.
As organizations adopt Windows 11, Microsoft Intune, Windows 365, Azure Virtual Desktop, and new AI capabilities, alongside legacy line-of-business applications critical to business operation, the risk of breaking something increases even as the pace and complexity of change continue to rise.
Validation has become a critical bottleneck. Application owners are often disengaged, and even when they are engaged, they do not scale to the rate of change.
WorkspaceDNA helps organizations understand the unique DNA of their digital workspace, model the ripple effect of change, and identify potential issues before users are impacted. ATP360 extends that vision through autonomous enterprise validation as your agentic application owner.
By running these capabilities on Windows 365 for Agents, WorkspaceDNA can execute validation within a secure, scalable, enterprise-managed Cloud PC environment designed specifically for AI agents.
Microsoft provides the trusted platform for agentic work. WorkspaceDNA brings the autonomous validation intelligence that helps organizations determine whether change is ready to move forward.
We believe autonomous validation will become a foundational capability for modern enterprise IT.
As AI agents become part of the digital workforce, organizations will need the same confidence, governance, and evidence they expect from human-led processes — delivered at the speed and scale of AI.
WorkspaceDNA on Windows 365 for Agents represents an important step toward that future. A future where changes across the Microsoft digital workplace can be validated before they impact users.
And where organizations can move faster without sacrificing visibility, governance, or control.