Entra Agent ID: giving AI agents real identities
AI agents now get first-class identities in Entra, with Conditional Access and lifecycle controls following. Here's why identity teams should get involved early.
On this page
AI agents act on behalf of people and organisations. They read data, call APIs and increasingly take actions. Until recently they did it with whatever credentials were to hand: an app registration, a service account, or a user's own token. That's hard to govern.
Microsoft Entra Agent ID, now generally available, is an identity and authorisation framework for AI agents, built on OAuth 2.0 and supporting the Model Context Protocol (MCP) and agent-to-agent (A2A) scenarios.
What's arriving around it
- Sponsorship lifecycle (GA). Agent identities have a human sponsor. When that sponsor leaves, Lifecycle Workflows can transfer sponsorship to their manager, so no agent is left without an owner.
- Conditional Access for agents (preview). Policies can target agent user accounts using custom security attributes, agent risk, device compliance and network conditions.
- Registry changes. Microsoft has consolidated the Entra agent registry into Microsoft Agent 365. Check the current documentation if you registered agents through the earlier API.
What identity teams should do now
- Inventory existing agents and what they authenticate with. Shared service accounts and long-lived secrets are the first things to replace.
- Insist on a sponsor for every agent, just as every app registration should have owners.
- Apply least privilege. An agent with broad Graph permissions is a large, automated attack surface.
- Log and review. Treat agent sign-ins like any other workload identity and include them in your monitoring.
Shared credentials versus agent identities
Borrowed credentials
Service account, app secret or a user's token
- Hard to tell which agent did what
- Permissions sized for the busiest use
- Secrets that never expire
- No owner when the builder leaves
Agent ID
A dedicated identity per agent
- Every action attributable to one agent
- Scoped permissions and policies
- Sponsor with lifecycle handover
- Visible in the same tools as other identities
Questions to ask about any agent
- Is it acting as itself, or on behalf of a signed-in user?
- Which data and APIs can it reach, and does it need all of them?
- Who is the sponsor, and who takes over when they leave?
- Can it be switched off quickly if it misbehaves?
- Are its sign-ins and actions in your SIEM?
Is an agent identity just a service principal?
It's built on the same foundations, but with agent-specific features such as sponsorship and agent-aware policy. That's why Entra Backup and Recovery covers them alongside users and service principals.
Do I need this if we don't build agents?
Probably soon. Products you buy increasingly ship agents that act in your tenant. Knowing how they authenticate and what they can touch is part of approving them.