Take charge of agent sprawl
- Assign agent identities at scale so every agent has a built-in agent identity that will enable authentication, policy enforcement, and integration with your existing organizational policies.
- Keep your agent fleet under control with lifecycle management and IT-defined guardrails for both agents and the people who create and manage them.
- Manage identity risk with adaptive Conditional Access that helps block agents with anomalous activity or risky users.
The control plane for agents
Secure access for agents with familiar Microsoft Entra controls
Unify agent identity provisioning, metadata, and visibility
Ensure agents help maintain security and compliance posture
Bring agents into familiar identity governance processes
Detect and block threats by flagging suspicious agent interactions
Get network visibility and unified access policies
Get Entra Agent ID in Agent 365 or Microsoft 365 E7
Learn about the growth and impact of agents in large organizations
42%
76%
55%
78%
Explore Microsoft Entra
Stay up to date
Frequently asked questions
- Microsoft Entra Agent ID brings familiar controls—Conditional Access, lifecycle management, access governance, and network controls—to agents, enabling consistent policy enforcement when configured.
- Agents are AI_powered assistants that can perform tasks, make decisions, and access resources. Microsoft Entra treats agents as first-class identities, enabling secure authentication, lifecycle governance, and access control to protect sensitive data and systems.
- AI agents need identity and access management (IAM) to secure authentication, enforce least-privilege access, and maintain governance across their lifecycle. Without IAM, agents can become invisible, over-permissioned, or vulnerable to misuse, posing risks to sensitive data, systems, and compliance. Microsoft Entra enables centralized control and protection of agents for your organization.
Secure access for agent identities
- [1]Source: KPMG AI Quarterly Pulse Survey, September 2025. Survey results based on 130 U.S.-based C-suite and business leaders representing organizations with annual revenue of $1 billion or more.
- [2]
There is no licensing prerequisite for Agent 365. However, without the appropriate Microsoft 365 E3/E5 licensing, some security capabilities may be limited, including:
Label-based data security (for example, label honoring, inheritance, and label-based Data Loss Prevention (DLP)) requires the data you are grounding to be labeled—this typically requires Microsoft 365 E3+ for Microsoft 365 data, or Microsoft Purview pay-as-you-go (PAYG) for non‑Microsoft 365 data.
Conditional Access and Identity Protection for On Behalf Of (OBO) agents are evaluated against the user’s identity token—so the user must be licensed with Microsoft 365 E3 for Conditional Access and Microsoft 365 E5 for Identity Protection for these features to apply to their On Behalf Of (OBO) agents.
Identity Governance for On Behalf of (OBO) governs the human-to-agent delegation relationship. If your users are not licensed for Identity Governance, there is no delegation relationship to govern—so the user must have Identity Governance standalone or Microsoft Entra Suite.
Follow Microsoft Security