In this blog post MCP A2A and Semantic Memory Capabilities Every CIO Should Track we will explain how three important Microsoft Agent Framework capabilities could change the cost, usefulness and risk of business AI.

Many organisations already have promising AI pilots. The problem is that these pilots often cannot access the right systems, collaborate with other AI tools or remember useful context between interactions. They look impressive in a demonstration but struggle to complete a real business process.

Microsoft Agent Framework is designed to close that gap. It provides a common foundation for building AI agents that can perform tasks, use business systems and work together. We covered the broader platform in what Microsoft Agent Framework means for real-world AI delivery. The next question for CIOs is which capabilities deserve attention now.

The simple explanation

Think of an AI agent as a new digital employee. Intelligence alone is not enough. It needs approved tools, colleagues it can communicate with and enough memory to understand the situation.

  • MCP gives the agent tools. Model Context Protocol is a standard way for an agent to connect to systems such as document libraries, service desks, customer platforms and databases.
  • A2A gives the agent colleagues. Agent-to-Agent communication allows specialised agents to discover one another, exchange information and coordinate work.
  • Semantic memory gives the agent useful recall. It helps the agent retrieve relevant past information based on meaning, rather than relying only on exact keywords or the current chat.

Together, these capabilities can turn a chatbot that answers questions into an agent system that completes controlled, multi-step work.

Business request
 |
 v
Microsoft Agent Framework
 |
 +-- Semantic memory finds relevant context
 +-- A2A delegates work to a specialist agent
 +-- MCP connects to an approved business system
 +-- Controls record, review or approve the action

MCP could reduce the cost of connecting AI to your business

Connecting an AI application to ten business systems traditionally means designing and maintaining ten separate integrations. Every change to an application, security method or programming interface can create more work.

MCP provides a common method for agents to discover what an approved system can do and request those functions. For example, an IT support agent could use MCP connections to look up an Intune device record, which shows whether a company laptop is compliant, and then create a service desk ticket.

The business benefit is not simply faster development. Standard connections can reduce duplicated integration work, make components easier to replace and lower the risk of becoming trapped in one AI platform.

However, MCP is a connection standard, not an automatic security guarantee. A poorly controlled connection could still give an agent access to too much information or allow it to perform an unsafe action. Authentication, limited permissions, approval points and activity logs remain essential.

Our review of recent MCP security improvements explains why identity and oversight matter as these connections become more widely used.

A2A could prevent another generation of disconnected AI tools

Most businesses will not have one all-knowing agent. They are more likely to have specialised agents for finance, operations, customer service, security and internal support.

A2A is an open method for those agents to discover each other’s capabilities and exchange tasks, even when they were built by different teams or run on different platforms. An operations agent might ask a finance agent to check a spending limit, then send an approved request to a procurement agent.

This matters because many CIOs are already seeing AI tool sprawl. Different departments buy separate assistants, each with its own data, controls and supplier. A2A creates the possibility of connecting useful agents without rebuilding everything inside one application.

It also introduces a new governance question: when one agent calls another, who is accountable for the final action? Your architecture must preserve the user’s identity, permissions and audit trail across the full chain.

For a deeper technical and governance comparison, see using A2A and MCP together for safer business AI systems.

Semantic memory could make agents genuinely useful over time

An agent that forgets previous interactions creates repeated work. Employees must re-enter preferences, explain customer history and describe what has already been attempted.

Semantic memory addresses this by storing selected information and retrieving it when its meaning is relevant. A support agent could remember that a customer uses a particular product configuration, even if the new request uses different wording.

This is different from saving every conversation forever. A well-designed system separates short-term conversation history, approved long-term memories and trusted business knowledge. It also provides rules for correcting, deleting and expiring information.

That distinction affects cost and risk. Sending large conversation histories to an AI model increases processing costs and can introduce irrelevant information. Retrieving a smaller set of useful memories can produce more consistent answers with less processing.

Microsoft Agent Framework supports memory through replaceable context providers, meaning organisations can choose how information is stored and retrieved. Microsoft Foundry also offers managed memory services, although some managed memory and A2A features remain in preview as of August 2026. CIOs should confirm production support, data location and service commitments before relying on them for critical processes.

We explore the design issues in more detail in how Microsoft Foundry Agent Memory makes AI agents more useful.

What this could look like in a 200-person business

Consider a 200-person professional services company receiving hundreds of internal support requests each month. Employees often ask similar questions about laptop access, software approvals and Microsoft 365 permissions.

A support agent could use semantic memory to understand the employee’s previous issues and device context. It could use A2A to request a risk check from a security agent, then use an approved MCP connection to create or update the service ticket.

Low-risk requests could be resolved automatically. Higher-risk actions, such as changing access permissions, could pause for human approval.

The measurable outcomes would be fewer repetitive support tasks, faster employee response times and a complete record of which systems and agents were involved. Those are more useful success measures than simply counting chatbot conversations.

Five questions CIOs should ask now

  1. What business process are we improving? Start with a measurable problem such as support time, processing cost, customer response time or compliance effort.
  2. What can the agent access and change? Document every system, data source and action. Apply minimum necessary access and require human approval for sensitive changes.
  3. What is the memory policy? Decide what may be remembered, how long it is retained, where it is stored and how people can correct or delete it.
  4. Can we see what happened? Require logs that show which agent acted, which tools it called, what information it used and whether a person approved the outcome.
  5. Can we replace a component later? Test whether models, memory stores and specialist agents can be changed without rebuilding the entire solution.

Governance must arrive before scale

For Australian organisations, agent controls should sit alongside the Essential Eight, the Australian government’s recommended cybersecurity baseline. Multi-factor authentication, restricted administrator privileges, application control, patching and reliable backups remain relevant when agents can access business systems.

The Essential Eight does not cover every AI-specific risk. Privacy obligations also apply when agents process personal information. Memory retention, data location, user transparency and human review should therefore be addressed before production deployment, not after an incident.

Microsoft Agent Framework has now reached version 1.0, making it worth serious evaluation. That does not mean every organisation needs a multi-agent system immediately. It means CIOs can begin testing these standards against controlled, commercially useful workflows while the surrounding managed services continue to mature.

CloudProInc brings more than 20 years of enterprise IT experience to this work. As a Melbourne-based Microsoft Partner and Wiz Security Integrator, we help organisations connect AI planning with Azure, Microsoft 365, identity, device management and cybersecurity rather than treating AI as an isolated experiment.

If you are unsure whether MCP, A2A or semantic memory belongs in your AI roadmap, we are happy to review the opportunity and the risks with you. No oversized project and no strings attachedโ€”just a practical view of what is ready, what needs controls and what can wait.


Discover more from CPI Consulting

Subscribe to get the latest posts sent to your email.