OVERVIEW
Take charge of agent sprawl
Define agent access controls and monitor agent activity. Govern agent identity sponsorship, access, and lifecycle. Help block access for risky agents and to risky resources.
- Assign agent identities at scale so every agent has a built-in agent identity that will enable authentication, policy enforcement, and integration with your existing organizational policies.
- Keep your agent fleet under control with lifecycle management and IT-defined guardrails for both agents and the people who create and manage them.
- Manage identity risk with adaptive Conditional Access that helps block agents with anomalous activity or risky users.
What's new
Microsoft Agent 365: The control plane for agents
Stay in control as agents become part of everyday work with Agent 365 —the control plane for agents. Entra Agent ID capabilities are included for agents managed by Agent 365.
SCENARIOS
Secure access for agents with familiar Microsoft Entra controls
Extend Microsoft Entra capabilities in the admin center to manage agent sprawl, gain transparency to agent actions, and help prevent attacks.
Unify agent identity provisioning, metadata, and visibility
Assign identities to agents and manage agent identities, including blueprints, tasks, and logs.
Ensure agents help maintain security and compliance posture
Enforce real-time policies for agent access to resources, can help block risky agents, and define granular access control policies based on security attributes once configured.
Bring agents into familiar identity governance processes
Automate governance from deployment to expiration, enable sponsors are assigned and maintained, and enforce access assignments as intentional, auditable, and time bound.
Detect and block threats by flagging suspicious agent interactions
Detect and flag unusual or unauthorized activities, trace agents with compromised tokens, and remediate compromised agents.
Get network visibility and unified access policies
Log agent network activity for audits and threat detection. Apply web categorization to APIs and MCP servers. Restrict file uploads and downloads. Automatically block malicious destinations.
PLANS AND PRICING
Get Entra Agent ID in Agent 365 or Microsoft 365 E7
Market landscape
Learn about the growth and impact of agents in large organizations
As organizations rapidly adopt agents for the workplace, expectations and pressures also increase. Key concerns include agent discovery, governance, authorization, and risk reduction.1
42%
of organizations have now deployed at least some agents.
76%
of leaders expect employees to manage agents within 2 to 3 years.
55%
of organizations are seeing slight or significant adoption of agents.
78%
of organizations are concerned about cybersecurity for agents.
Related products
Explore Microsoft Entra
Secure access for any identity to any AI or resource.
RESOURCES
Stay up to date
Discover essential resources for agent access management.
Frequently asked questions
- Microsoft Entra Agent ID brings familiar controls—Conditional Access, lifecycle management, access governance, and network controls—to agents, enabling consistent policy enforcement when configured.
- Agents are AI_powered assistants that can perform tasks, make decisions, and access resources. Microsoft Entra treats agents as first-class identities, enabling secure authentication, lifecycle governance, and access control to protect sensitive data and systems.
- AI agents need identity and access management (IAM) to secure authentication, enforce least-privilege access, and maintain governance across their lifecycle. Without IAM, agents can become invisible, over-permissioned, or vulnerable to misuse, posing risks to sensitive data, systems, and compliance. Microsoft Entra enables centralized control and protection of agents for your organization.
GET STARTED
Secure access for agent identities
Agent ID capabilities are now available in Microsoft Agent 365 and Microsoft 365 E7 plans.
- [1]Source: KPMG AI Quarterly Pulse Survey, September 2025. Survey results based on 130 U.S.-based C-suite and business leaders representing organizations with annual revenue of $1 billion or more.
- [2]
There is no licensing prerequisite for Agent 365. However, without the appropriate Microsoft 365 E3/E5 licensing, some security capabilities may be limited, including:
- Label-based data security (for example, label honoring, inheritance, and label-based Data Loss Prevention (DLP)) requires the data you are grounding to be labeled—this typically requires Microsoft 365 E3+ for Microsoft 365 data, or Microsoft Purview pay-as-you-go (PAYG) for non‑Microsoft 365 data.
- Conditional Access and Identity Protection for On Behalf Of (OBO) agents are evaluated against the user’s identity token—so the user must be licensed with Microsoft 365 E3 for Conditional Access and Microsoft 365 E5 for Identity Protection for these features to apply to their On Behalf Of (OBO) agents.
- Identity Governance for On Behalf of (OBO) governs the human-to-agent delegation relationship. If your users are not licensed for Identity Governance, there is no delegation relationship to govern—so the user must have Identity Governance standalone or Microsoft Entra Suite.
Follow Microsoft Security