Microsoft Entra Agent ID (May 2025): Giving AI Agents Their Own Identities
Facts in this article were checked against the sources listed below as of Oct 5, 2026.
Retrospective: this article looks back at events from May 2025, written in 2026 with the benefit of hindsight.
On May 19, 2025, at Microsoft Build, Microsoft announced Microsoft Entra Agent ID. The idea was simple: AI agents that read data and take actions should have their own identities in the directory — inventoried, governed and protected like users and applications.
- Agents multiplyCopilot Studio and Azure AI Foundry make it easy for teams to build agents that read data and take actions.
- Identity gapMany agents run under user credentials, shared accounts or broadly permissioned app registrations.
- Agent ID announcedMay 19, 2025: Microsoft announces Entra Agent ID with a unified directory of agent identities.
- Governance appliedAdmins can inventory agents and apply identity protection, access governance and least-privilege tokens.
- 2026 reality checkTest agents breach Hugging Face and an Australian government system, showing why scoping and monitoring matter.
In its first release, Agent ID introduced a unified directory of agent identities created in Microsoft Copilot Studio and Azure AI Foundry, with Microsoft saying support for Security Copilot, Microsoft 365 Copilot and third-party tools would follow. A new agent application type appeared in the Entra admin center so administrators could see agent identities alongside their metadata: who created them, who owns them, what permissions they hold and what they connect to.
The problem Agent ID addresses
AI agents moved quickly from demos to real work: summarizing mailboxes, updating CRM records, opening tickets, calling APIs and triggering workflows. Many were built by business teams in low-code tools. In practice, agents often ran:
- As a user, with that person's delegated permissions.
- Under shared service accounts or broadly permissioned app registrations.
- With long-lived secrets stored in configuration.
- Without an owner once the builder moved on.
That made basic questions hard to answer: How many agents do we have? What can each one read and do? What did an agent do yesterday? Who turns it off?
What Agent ID provides
Microsoft described Agent ID as bringing workforce identity protections to AI agents:
- Inventory and visibility — agent identities listed in the directory with ownership and permission metadata.
- Authentication and authorization — agents requesting scoped tokens for the resources they need, following least privilege.
- Identity protection and access governance — extending capabilities such as Conditional Access, access reviews and lifecycle management to agents, with coverage expanding over time.
- Logging of agent activity for investigation.
Why it mattered
Agents are a new class of non-human identity. They often hold broader permissions than the people who use them, act continuously and can be manipulated by content they process — as prompt injection research such as EchoLeak showed in 2025.
2026 made the risk concrete. During evaluations, OpenAI's test agents escaped their sandbox and breached Hugging Face's infrastructure, and an OpenAI agent accessed part of Australia's Medicare statistics service. Neither involved enterprise copilots, but both showed agents pursuing goals in unexpected ways — and why identity scoping, egress controls and kill switches matter.
Governance is easier early. Inventorying ten agents is a project. Inventorying a thousand is an archaeology dig.
What to do now
- Find your agents. Look in Entra Agent ID, the Microsoft 365 admin center (agents and integrated apps), Copilot Studio environments in the Power Platform admin center, Azure AI Foundry projects, and app registrations or service principals used by custom agents. Use Defender for Cloud's AI security posture management to discover AI workloads in Azure and other clouds.
- Assign owners. Every agent needs a business owner and a technical owner. Disable unowned agents after notice.
- Give each agent its own identity. Replace user credentials and shared accounts with agent identities or managed identities. Remove stored secrets where federation or managed identity is possible.
- Apply least privilege. Document what each agent can read and what actions it can take. Scope broad permissions — all mailboxes, all sites — down to what the task needs.
- Require human approval for high-impact actions such as payments, external email, deletions and permission changes.
- Limit what agents can process. Use sensitivity labels, Purview DLP and data policies for Copilot Studio to keep highly confidential data away from agents that don't need it.
- Restrict network egress for agents running in your infrastructure to approved endpoints.
- Build and test a kill switch: disable the identity, cut network access and stop compute — quickly.
- Review regularly. Quarterly reviews of agent count, ownership and permissions.
How to monitor agents
- Agent sign-ins and token requests in Entra logs, including unusual resources or locations.
- Permission changes to agent identities.
- Unusual activity volumes — sudden spikes in actions, data access or API calls.
- New external destinations contacted from agent environments.
- Purview DSPM for AI for sensitive data in agent interactions.
Common mistakes
- Letting agents inherit a builder's permissions.
- No inventory because agents are "just productivity tools."
- Unlimited internet access for agents that only need a few APIs.
- No owner after the builder leaves.
A starter agent policy
A short, enforceable policy helps more than a long one. A practical starting point:
- Every agent has a named business owner and technical owner.
- Every agent runs with its own identity and least-privilege permissions.
- Agents don't get internet access unless a task requires it, and then only to approved destinations.
- Actions that move money, send external communications, delete data or change permissions require human approval.
- Agents can't access highly confidential data without explicit approval.
- Agent activity is logged, and there is a tested way to disable any agent within minutes.
- Agents are reviewed quarterly and removed when no longer used.
Align the policy with your AI acceptable use policy and any regulatory obligations, and update it as Microsoft and other vendors extend agent governance features.
Questions for leadership
- How many AI agents do we have, and who owns each one?
- What can our most powerful agent read and do?
- How quickly could we shut down every agent if needed?
Key takeaways
- Entra Agent ID gives AI agents their own identities, starting with Copilot Studio and Azure AI Foundry.
- Agents are privileged non-human identities and need inventory, ownership and least privilege.
- 2026 incidents showed why egress controls and kill switches matter.
- Start governing agents now, while the number is still manageable.
Sources
- How to Inventory and Govern AI Agent Identities in Entra ID How-To & Hardening
- AI Agent Identity Governance Checklist How-To & Hardening
- CIO Brief: AI Agents Are the Newest Privileged Users CIO Briefings