AI Agent Identity Governance Checklist
Retrospective: this article looks back at events from May 2025, written in 2026 with the benefit of hindsight.
Use this checklist to govern AI agent identities in your organization.
Inventory
- All agents discovered across Entra Agent ID, Microsoft 365, Copilot Studio, Azure AI Foundry and custom apps.
- Third-party AI agents connected to Microsoft 365 or cloud accounts identified.
- Each agent has a business owner and technical owner.
Identity
- Each agent uses its own identity, not a shared account or a person's credentials.
- Secrets replaced with managed identities or federation where possible.
- Agent identities follow naming conventions.
Permissions
- Permissions documented per agent.
- Least privilege applied; broad scopes (for example, all mailboxes, all sites) justified.
- High-impact actions require human approval.
- Agents can't grant themselves or others new permissions.
Data protection
- Sensitivity labels and DLP restrict what agents can access and output.
- Agents can't access highly confidential data unless approved.
Network
- Agents running in your infrastructure have restricted outbound access (allowlisted endpoints).
Monitoring
- Agent sign-ins and actions logged and retained.
- Alerts for permission changes, unusual volumes and new external destinations.
- A tested way to disable an agent quickly (kill switch).
Lifecycle
- Agents reviewed quarterly.
- Unused agents disabled and removed.
- New agents follow an approval process.
Policy
- AI agent policy aligned with your AI acceptable use policy and regulatory obligations.
- Microsoft Entra Agent ID (May 2025): Giving AI Agents Their Own Identities Platform Changes
- How to Inventory and Govern AI Agent Identities in Entra ID How-To & Hardening
- CIO Brief: AI Agents Are the Newest Privileged Users CIO Briefings