Agent Identity & Access Management

Updated

Give every agent a first-class identity, then govern what it authenticates as and what it can reach — registering agents in Microsoft Entra, assigning owners, right-sizing access with packages and reviews, and enforcing risk-based Conditional Access.

An agent is only as safe as the identity it runs under. Once agents become first-class identities in the tenant, the question shifts from "what agents exist" to "what can each one authenticate as, and what is it allowed to reach." This topic makes that domain concrete: it starts from the agent identity itself — every agent registered as a first-class Microsoft Entra principal — then gives each one a responsible owner, grants access through packages and reviews so entitlements stay right-sized and time-bound, and enforces Conditional Access that weighs context, device, and identity risk before an agent touches a resource or another agent.

How to address Agent Identity & Access Management

  1. Govern Agent Identity and Access

    Give every agent a first-class Entra identity, then govern what it authenticates as and what it can reach — assign a responsible owner, right-size access with packages and reviews, and enforce risk-based Conditional Access before it touches resources.

Control coverage

Control coverage for Agent Identity & Access Management — where its 5 capabilities land across your security control domains and the AI surfaces they protect. Select any control domain to reveal the capabilities behind it.
Control domain
Agents
Users
Infrastructure
Endpoints
Data
Coverage
Identity & Access
5
Discovery
1

Capabilities for discovering and inventorying AI assets, workloads, shadow AI usage, connected applications, and data sources — providing visibility as the foundation for securing what you can see.

Governance
1

Organisational and technical controls for managing the lifecycle of AI models, agents, and workloads — including inventory, policy, and accountability frameworks.

Threat Detection
1

Capabilities that identify, alert on, and help respond to threats targeting AI models, inference endpoints, training pipelines, and supporting infrastructure.