Product

Microsoft Entra Agent ID

Track documentation and Message Center changes for Microsoft Entra Agent ID.

Microsoft Learn documentation ↗

Latest Microsoft Entra Agent ID changes

Agent Token Claims

General

The documentation now shows different sample GUID values for the aud, appid, oid, sub, and tid claims.

Agent Token Claims

Authentication

The Agent ID token claims documentation no longer includes one `tid` claim table row.

Agent Tokens

Developer

The user delegation section now spells out “on-behalf-of (OBO)” on first use. No feature behavior or requirements changed in the supplied diff.

Authentication protocols in agents

Authentication

The page description was shortened by removing the phrase “Key concepts.” The documented OAuth 2.0 protocols and token exchange patterns remain unchanged.

Best Practices Agent Id

Microsoft identity platform

The best-practices documentation now uses the full “Microsoft Entra Agent ID” and “Microsoft Entra ID” names in two recommendations. The guidance itself is unchanged.

Best Practices Agent Id

Security

The documentation now recommends creating agent identities from an agent identity blueprint instead of using standard app registrations or service principals. It also adds .NET usage guidance and lists required roles and permission.

Call Api Azure Services

Security

The documentation updates its C# examples, separating app-only, on-behalf-of-user, and user-identification scenarios. Samples now configure agent identity options and pass the credential to the Blob client correctly.

Call Api Azure Services

Developer

The code sample now uses `<your-tenant-id>` instead of `<your-tenant>` for the `TenantId` value.

Call Api Custom

Developer

The documentation updates its C# examples, including distinct method names for UPN and object ID calls, a revised controller constructor signature, and clearer user-data method names.

Call Api Custom

Developer

The documentation now spells out “on-behalf-of (OBO)” on first use in the token scenario guidance. The referenced method is unchanged.

Call Api Microsoft Graph

Developer

The Agent ID Microsoft Graph documentation now labels sample variables as `usersAppOnly` and `usersOnBehalfOfUser`, clarifying the scenarios they represent.

Call Api Microsoft Graph

Developer

The documentation adds Microsoft Graph and Microsoft.Identity.Web imports, changes sample calls from Applications to Users, and clarifies that configured scopes must match the Graph resources used. Examples use User.Read and User.ReadBasic.All.

Call Api Microsoft Graph

Developer

The documentation adds an OpenID Connect using directive and renames two C# sample variables: `applications` to `applicationsForUser` and `me` to `meByOid`.

Call Api Microsoft Graph

Developer

The `TenantId` example value changed from `<my-test-tenant>` to `<your-tenant-id>` for clearer documentation.

Configure Third Party Agents

Developer

The third-party agents documentation now labels the sidecar setup link “Configure Microsoft Entra ID Auth SDK for agent identities” instead of “Configure Entra ID Auth SDK.”

Create Delete Agent Identities

Developer

The documentation updates the C# sample’s imports, endpoint structure, downstream API call, and model declarations to provide valid create-agent-identity code.

Create Delete Agent Identities

General

The documentation now uses `<your-tenant-id>` instead of `<my-test-tenant>` in the token endpoint and `TenantId` code examples.

Error Codes

Authentication

The error-code documentation now separates quota, blueprint, blueprint principal, agent identity, and agent identity creation errors, with clearer descriptions and table headings.

Get the service principal for Microsoft Graph

Authentication

The documentation replaces inconsistent tenant placeholders with `<your-tenant-id>` and standardizes `<agent-blueprint-clientid>` to `<agent-blueprint-client-id>` in code samples.

Howto Delete Agent Identity

General

The delete-agent-identity article no longer contains a TODO asking engineering to confirm whether cascade cleanup removes associated agent user accounts.

Inheritable Permissions

Fundamentals

The page no longer includes a TODO questioning support for enumerated scopes versus `allAllowed`/`none`. The diff provides no evidence of a product or feature change.

Integrate Aws Bedrock Agent

Security

The guide updates “Entra” to “Microsoft Entra” in the diagram alt text, setup heading, and TENANT_ID descriptions. No technical procedure or feature change is shown.

Integrate Aws Bedrock Agent

General

The documentation now spells out “on-behalf-of” before introducing the OBO acronym in the OAuth 2.0 authentication description.

Integrate N8n Agent

Microsoft identity platform

The n8n integration page now consistently calls the pattern “Microsoft Entra ID Auth SDK (sidecar)” instead of “Microsoft Entra Auth SDK.”

Key Concepts

Fundamentals

The key concepts page now labels the link “Microsoft Entra Agent ID OAuth protocols” instead of “oauth protocols.”

Manage agents in end user experience

General

The page’s `ms.topic` metadata was changed from `how-to #Required; leave this attribute/value as-is` to `how-to`. The topic classification remains unchanged.

Microsoft Entra Sdk For Agent Identities

Developer

The documentation now identifies app-only tokens as using client credentials, expands on-behalf-of to OBO, and consistently uses the `agent-identity-client-id` placeholder in request examples.

Microsoft Entra Sdk For Agent Identities

Developer

The documentation replaces “Entra ID Auth SDK” with “Microsoft Entra ID Auth SDK” in two descriptions. The endpoint formats and behavior are unchanged.

Plan Agent Identity Architecture

Architecture

The documentation now explains that agents should use an agent identity blueprint and the `#Microsoft.Graph.AgentIdentity` object, rather than standard app-registration APIs. It also lists supported creation channels, roles, permissions, and .NET usage.

Plan Agent Identity Architecture

Architecture

The agent identity architecture planning page now links to the correct interactive agent authentication article instead of the previous broken path.

Secure an Amazon Bedrock agent with Microsoft Entra Agent ID

Developer

The Amazon Bedrock integration guide now consistently uses “Microsoft Entra ID Auth SDK (sidecar)” in its description, explanations, container reference, and links. No behavior or availability change is described.

Security For Ai Overview

Fundamentals

The documentation now expands MCP, A2A, and OBO on first use to improve clarity and retrievability.

Validate agent identity tokens in a downstream API

Authentication

The documentation now refers to the “Microsoft Entra ID Auth SDK (sidecar)” instead of the “Microsoft Entra SDK auth sidecar.” The token-validation guidance is otherwise unchanged.

What Is Agent Id Platform

Microsoft identity platform

The page’s bullet describing platforms and services that create agents retains the same wording and examples, including Copilot Studio, AWS Bedrock, and n8n. No substantive content change is shown.

What Is Microsoft Entra Agent Id

Authentication

The page updates image accessibility text, refines wording about agent identities, and standardizes the name “Microsoft Entra ID Auth SDK (sidecar)” for third-party agent integrations.

Whats New Agent Id

Provisioning

The Agent ID documentation now refers to the linked SDK as the “Microsoft Entra ID Auth SDK” instead of “Entra ID Auth SDK.”

Grant Agent Access Microsoft 365

Developer

The documentation now lists how an agent with its own identity can communicate through Outlook email, OneDrive and SharePoint comments, Teams chats, and Teams channels, including the permissions required for inbound and outbound communication.

Agent On Behalf Of Oauth Flow

Standards

The documentation now explicitly states that child agent identities, like their parent blueprints, cannot initiate interactive `/authorize` flows. Interactive consent attempts return `AADSTS82014`; required delegated permissions must be preauthorized instead.

Agent On Behalf Of Oauth Flow

Standards

The documentation now explains that Tc must target the agent identity blueprint, while T1 targets the token-exchange resource and is validated as bound to the blueprint and child agent identity. It also states that agent identities cannot use interactive consent and must have delegated permissions preauthorized through inheritable blueprint permissions.

Howto Target Agent Identities

General

The documentation now lists two license options: Microsoft 365 E7, or Microsoft Agent 365 paired with Microsoft Entra P1 or Microsoft 365 E3.

Howto Target Agent Identities

General

The documentation replaces the Microsoft Entra ID P1/P2 license requirement and the note that an Agent 365 license would soon be required with a direct Agent 365 license requirement.

Licensing Agent Id

Fundamentals

The documentation replaces standalone Entra licensing options for agents with guidance that Microsoft Agent 365 is required. It states that Agent 365 is included with Microsoft 365 E7 and available as an add-on to Microsoft E5, A5, Business Premium, or Defender Suite plus Purview Suite.

Agent Owners Sponsors Managers

General

In Microsoft Agent ID, the agent's identity, blueprint, and blueprint principal may all have sponsors associated with them. In addition, agents can have an [agent's user account](agent-users.md) created in order to access user-oriented services. While the Entra user has a sponsor relationship, there are differences between the user account sponsors and sponsors of the agent identity, blueprint, or blueprint principal.

Licensing Identity Protection

Security

Starting soon, ID Protection for agents will require a [Microsoft Agent 365 license](https://www.microsoft.com/microsoft-agent-365#plans-and-pricing) to extend protection to agents through [Microsoft Entra Agent ID](../agent-id/what-is-microsoft-entra-agent-id.md#how-to-get-started).

Agent Id

Conditional Access

In this flow, the agent can't reuse the user's original token because it was issued for a different audience. Instead, the agent uses the OBO flow to exchange tokens with Microsoft Entra ID, obtaining a new token scoped to the target resource. This token exchange is also evaluated by Conditional Access, letting admins enforce granular controls over which resources agents can access on behalf of the user.

Agent Id Design Patterns

Architecture

Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.

AI-guided setup for Microsoft Entra Agent ID

Provisioning

Describes how to use an AI coding agent to automate the onboarding process for Microsoft Entra Agent ID, including blueprint creation, credential configuration, and agent identity provisioning.

Best Practices Agent Id

Monitoring

Learn operational best practices for designing, securing, and governing AI agent identities with Microsoft Entra Agent ID, including blueprint design, credential management, access controls, and monitoring strategies.

Licensing Identity Protection

Security

Starting soon, ID Protection for agents will require a [Microsoft Agent 365 license](https://www.microsoft.com/microsoft-agent-365#plans-and-pricing) to extend protection to agents through [Microsoft Entra Agent ID](../agent-id/what-is-microsoft-entra-agent-id.md#how-to-get-started).

Manage agent identities in your organization

Conditional Access

Learn how to manage agent identities across your organization. View, disable, govern, and monitor agents using the Microsoft Entra admin center and Conditional Access.

Manage agents in end user experience

General

Learn how to manage agent identities in the end user experience within Microsoft Entra. View, control, and take action on agents you own or sponsor with ease.

Microsoft Entra Agent ID logs

Authentication

Learn how audit and sign-in activities associated with agent identities are logged in Microsoft Entra ID.

Migrate Copilot Studio Agents To Agent Id

Governance

Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.

Plan Agent Identity Architecture

Architecture

Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.

Security For Ai Overview

Authentication

Learn how Microsoft Entra provides identity-based security controls for AI agents, applications, and services through authentication, governance, and Zero Trust policy enforcement.

Sidecar Local Development

Authentication

Run the Microsoft Entra SDK auth sidecar on your laptop with Docker Compose and Ollama to see autonomous and on-behalf-of agent authentication working end-to-end.

Validate Agent Tokens Downstream Api

Developer

Learn how to validate Microsoft Entra Agent ID tokens in a downstream API by checking the signature, issuer, audience, and agent identity marker claim.

What's new in Microsoft Entra Agent ID

Governance

Learn about new features and updates in Microsoft Entra Agent ID at general availability, including non-Microsoft integrations, migration guides, and enterprise governance.

Configure Third Party Agents

Developer

- [Configure Entra ID Auth SDK (sidecar) for agent identities](microsoft-entra-sdk-for-agent-identities.md)

Integrate N8n Agent

General

Deploy n8n on Azure Container Apps and secure AI agent workflows with Microsoft Entra Agent ID and Microsoft Graph MCP Server for Enterprise.

Key Concepts

Fundamentals

Traditional service principals were designed for static, deterministic workloads. Microsoft Entra Agent ID exists because service principals lack the governance infrastructure AI agents need. There's no enforced sponsorship, no agent-aware audit entries, and no blueprint-managed lifecycle. For more information, see [Agent identities, service principals, and applications](agent-service-principals.md).

To guide users on how to call APIs using agent identities in .NET.

Authentication

To call an API from an agent, you need to obtain an access token that the agent can use to authenticate itself to the API. We recommend using the *Microsoft.Identity.Web* SDK for .NET to call your web APIs. This SDK simplifies the process of acquiring and validating tokens. For other languages, use the [Microsoft Entra ID Auth SDK (sidecar)](/entra/msidweb/agent-id-sdk/overview).

What Is Agent Id Platform

Authentication

- **Authentication service**: An OAuth 2.0 and OpenID Connect (OIDC) standard-compliant authentication service that enables secure, standards-based authentication for agents. This service issues tokens that agents use to authenticate to resources and APIs, supporting both application-only and delegated access scenarios. There are three objects that form the core identity constructs in the platform: agent identity blueprint, agent identity, and agent's user account.

Whats New Agent Id

Provisioning

- [AI-guided setup](agent-id-ai-guided-setup.md) (New) - Automate onboarding with an AI coding agent that walks you through blueprint creation, credential configuration, and agent identity provisioning.

Whats New Ignite 2025

Fundamentals

- [Call API: Azure services](../agent-id/call-api-azure-services.md) (New)

Agent Access Packages

Governance

This article explains how access packages provide governance for agent identity access to resources.

Agent Id Creation Channels

Monitoring

Learn about the ways to create Microsoft Entra agent identity blueprints, agent identities, and agents' user accounts as well as monitor and control their introduction into your tenant.

AI-guided setup for Microsoft Entra Agent ID

Provisioning

Describes how to use an AI coding agent to automate the onboarding process for Microsoft Entra Agent ID, including blueprint creation, credential configuration, and agent identity provisioning.

Best practices for Microsoft Entra Agent ID

Monitoring

Learn operational best practices for designing, securing, and governing AI agent identities with Microsoft Entra Agent ID, including blueprint design, credential management, access controls, and monitoring strategies.

Configure Third Party Agents

Authentication

Learn how to integrate third-party AI agents with Microsoft Entra Agent ID for secure authentication using sidecar and federation patterns.

Create an agent identity blueprint

Microsoft identity platform

Learn how to create an agent identity blueprint that serves as a template for multiple agent identities using Microsoft Graph APIs and PowerShell.

Integrate N8n Agent

General

A Microsoft Entra documentation page was updated: Integrate N8n Agent.

Learn how agent identity deletion works

Fundamentals

Learn how deleting an agent identity blueprint triggers automatic cleanup of child agent identities in Microsoft Entra, and how to restore deleted objects.

Manage agent identities in your organization

Conditional Access

Learn how to manage agent identities across your organization. View, disable, govern, and monitor agents using the Microsoft Entra admin center and Conditional Access.

Manage agents in end user experience

General

Learn how to manage agent identities in the end user experience within Microsoft Entra. View, control, and take action on agents you own or sponsor with ease.

Microsoft Entra Agent ID design patterns

Architecture

Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.

Microsoft Entra Agent ID logs

Authentication

Learn how audit and sign-in activities associated with agent identities are logged in Microsoft Entra ID.

Microsoft Entra Agent ID sign-in process

Authentication

Learn about the Microsoft Entra Agent ID sign-in process, including consent pages, trust criteria, and how to manage agent permissions for secure access to AI agents using work accounts.

Microsoft Entra security for AI overview

Authentication

Learn how Microsoft Entra provides identity-based security controls for AI agents, applications, and services through authentication, governance, and Zero Trust policy enforcement.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…