This is the Trace Id: 8b47ce46bfcf3e96c7c0f04199bd3e9b
Skip to main content Why Microsoft Security AI-powered cybersecurity Cloud security Data security & governance Identity & network access Privacy & risk management Security for AI Unified SecOps Zero Trust Microsoft Defender Microsoft Entra Microsoft Intune Microsoft Priva Microsoft Purview Microsoft Sentinel Microsoft Security Copilot Microsoft Entra ID (Azure Active Directory) Microsoft Entra Agent ID Microsoft Entra External ID Microsoft Entra ID Governance Microsoft Entra ID Protection Microsoft Entra Internet Access Microsoft Entra Private Access Microsoft Entra Permissions Management Microsoft Entra Verified ID Microsoft Entra Workload ID Microsoft Entra Domain Services Azure Key Vault Microsoft Sentinel Microsoft Defender for Cloud Microsoft Defender XDR Microsoft Defender for Endpoint Microsoft Defender for Office 365 Microsoft Defender for Identity Microsoft Defender for Cloud Apps Microsoft Security Exposure Management Microsoft Defender Vulnerability Management Microsoft Defender Threat Intelligence Microsoft Defender Suite for Business Premium Microsoft Defender for Cloud Microsoft Defender Cloud Security Posture Mgmt Microsoft Defender External Attack Surface Management Azure Firewall Azure Web App Firewall Azure DDoS Protection GitHub Advanced Security Microsoft Defender for Endpoint Microsoft Defender XDR Microsoft Defender for Business Microsoft Intune core capabilities Microsoft Defender for IoT Microsoft Defender Vulnerability Management Microsoft Intune Advanced Analytics Microsoft Intune Endpoint Privilege Management Microsoft Intune Enterprise Application Management Microsoft Intune Remote Help Microsoft Cloud PKI Microsoft Purview Communication Compliance Microsoft Purview Compliance Manager Microsoft Purview Data Lifecycle Management Microsoft Purview eDiscovery Microsoft Purview Audit Microsoft Priva Risk Management Microsoft Priva Subject Rights Requests Microsoft Purview Data Governance Microsoft Purview Suite for Business Premium Microsoft Purview data security capabilities Pricing Services Partners Cybersecurity awareness Customer stories Security 101 Product trials How we protect Microsoft Industry recognition Microsoft Security Insider Microsoft Digital Defense Report Security Response Center Microsoft Security Blog Microsoft Security Events Microsoft Tech Community Documentation Technical Content Library Training & certifications Compliance Program for Microsoft Cloud Microsoft Trust Center Security Engineering Portal Service Trust Portal Microsoft Secure Future Initiative Business Solutions Hub Contact Sales Start free trial Microsoft Security Azure Dynamics 365 Microsoft 365 Microsoft Teams Windows 365 Microsoft AI Azure Space Mixed reality Microsoft HoloLens Microsoft Viva Quantum computing Sustainability Education Automotive Financial services Government Healthcare Manufacturing Retail Find a partner Become a partner Partner Network Microsoft Marketplace Marketplace Rewards Software development companies Blog Microsoft Advertising Developer Center Documentation Events Licensing Microsoft Learn Microsoft Research View Sitemap
SECURE ACCESS FOR AI AGENTS

Microsoft Entra Agent ID

Manage, govern, and protect agent identities and their access to resources—just as you do for employees—with identity, lifecycle, and access controls, now available in Microsoft Agent 365.
OVERVIEW

Take charge of agent sprawl

Define agent access controls and monitor agent activity. Govern agent identity sponsorship, access, and lifecycle. Help block access for risky agents and to risky resources.
  • Assign agent identities at scale so every agent has a built-in agent identity that will enable authentication, policy enforcement, and integration with your existing organizational policies.
  • Keep your agent fleet under control with lifecycle management and IT-defined guardrails for both agents and the people who create and manage them.
  • Manage identity risk with adaptive Conditional Access that helps block agents with anomalous activity or risky users.
background-img
Microsoft Agent 365

The control plane for agents

Stay in control as agents become part of everyday work with Agent 365 —the control plane for agents. Entra Agent ID capabilities are included for agents managed by Agent 365.
HOW IT WORKS

Manage, govern, and protect agents and access to resources

Microsoft Entra Agent ID provides identity and access management for agents, leveraging familiar capabilities like Conditional Access, identity governance, identity protection, and network controls.
SCENARIOS

Secure access for agents with familiar Microsoft Entra controls

Extend Microsoft Entra capabilities in the admin center to manage agent sprawl, gain transparency to agent actions, and help prevent attacks.

Unify agent identity provisioning, metadata, and visibility

Assign identities to agents and manage agent identities, including blueprints, tasks, and logs.
Back to tabs
PLANS AND PRICING

Get Entra Agent ID in Agent 365 or Microsoft 365 E7

Agent 365

$15.00
user/month, paid yearly
(Annual subscription—auto renews)

​See terms2
​Get the confidence to move from agentic AI experimentation to enterprise-scale operations by observing, governing, and securing every agent across your organization with Agent 365.
  • ​Distributed control plane for IT and security leaders to manage AI agents
  • Centralized IT hub to manage agents in Microsoft admin center
  • Unified agent registry for comprehensive inventory of agents fleet(i)
  • Includes agents from Microsoft AI platforms, agents from Agent 365 ecosystem partners via SDK, synced and self-registered agents from platforms that are not managed by Agent 365.
  • Usage insights and visual mapping of agent activity and connections
  • Access control and identity protection for agents with Microsoft Entra
  • Security posture and threat protection for agents with Microsoft Defender
  • Data security and compliance for agents with Microsoft Purview
Back to tabs
Market landscape

Learn about the growth and impact of agents in large organizations

As organizations rapidly adopt agents for the workplace, expectations and pressures also increase. Key concerns include agent discovery, governance, authorization, and risk reduction.1

42%

of organizations have now deployed at least some agents.

76%

of leaders expect employees to manage agents within 2 to 3 years.

55%

of organizations are seeing slight or significant adoption of agents.

78%

of organizations are concerned about cybersecurity for agents.

Frequently asked questions

  • Microsoft Entra Agent ID brings familiar controls—Conditional Access, lifecycle management, access governance, and network controls—to agents, enabling consistent policy enforcement when configured.
  • Agents are AI_powered assistants that can perform tasks, make decisions, and access resources. Microsoft Entra treats agents as first-class identities, enabling secure authentication, lifecycle governance, and access control to protect sensitive data and systems.
  • AI agents need identity and access management (IAM) to secure authentication, enforce least-privilege access, and maintain governance across their lifecycle. Without IAM, agents can become invisible, over-permissioned, or vulnerable to misuse, posing risks to sensitive data, systems, and compliance. Microsoft Entra enables centralized control and protection of agents for your organization.
A man and woman looking at a laptop.
GET STARTED

Secure access for agent identities

Agent ID capabilities are now available in Microsoft Agent 365 and Microsoft 365 E7 plans.
  1. [1]
    Source: KPMG AI Quarterly Pulse Survey, September 2025. Survey results based on 130 U.S.-based C-suite and business leaders representing organizations with annual revenue of $1 billion or more.
  2. [2]

    There is no licensing prerequisite for Agent 365. However, without the appropriate Microsoft 365 E3/E5 licensing, some security capabilities may be limited, including:
     

    • Label-based data security (for example, label honoring, inheritance, and label-based Data Loss Prevention (DLP)) requires the data you are grounding to be labeled—this typically requires Microsoft 365 E3+ for Microsoft 365 data, or Microsoft Purview pay-as-you-go (PAYG) for non‑Microsoft 365 data.

    • Conditional Access and Identity Protection for On Behalf Of (OBO) agents are evaluated against the user’s identity token—so the user must be licensed with Microsoft 365 E3 for Conditional Access and Microsoft 365 E5 for Identity Protection for these features to apply to their On Behalf Of (OBO) agents.

    • Identity Governance for On Behalf of (OBO) governs the human-to-agent delegation relationship. If your users are not licensed for Identity Governance, there is no delegation relationship to govern—so the user must have Identity Governance standalone or Microsoft Entra Suite.

Follow Microsoft Security