Govern Agent Identity and Access
Give every agent a first-class Entra identity, then govern what it authenticates as and what it can reach — assign a responsible owner, right-size access with packages and reviews, and enforce risk-based Conditional Access before it touches resources.
Core capabilities
-
Register every agent as a first-class Microsoft Entra Agent ID — Entra-registered, self-registered, or shadow — so it can be owned, governed, and access-controlled like any other principal
-
Assign each agent a responsible owner and use access packages and access reviews so agents hold only the access they need for as long as they need it
-
Enforce real-time access decisions on agents based on context, device, location, and risk before they reach resources or other agents
-
Detect identity-based risk on agents and feed risk signals into Conditional Access to block compromised agents
Supporting capabilities 1
-
Require agents to operate from compliant, Intune-managed devices as a Conditional Access signal