How to Inventory and Govern AI Agent Identities in Entra ID
Retrospective: this article looks back at events from May 2025, written in 2026 with the benefit of hindsight.
AI agents are a fast-growing category of identities with access to company data and systems. Here is how to inventory and govern them in Microsoft Entra ID.
Step 1: Find your agents
Look in several places:
- Entra Agent ID inventory (agents registered with agent identities).
- Microsoft 365 admin center → Agents (Copilot agents and integrated apps).
- Copilot Studio environments (Power Platform admin center).
- Azure AI Foundry projects.
- App registrations and service principals used by custom agents (often named "bot," "agent," "assistant," "GPT").
- Defender for Cloud AI security posture management for AI workloads in Azure and other clouds.
Step 2: Assign owners
Every agent needs a business owner and a technical owner. Unowned agents should be disabled after notice.
Step 3: Review permissions
For each agent, list:
- Data it can read (mailboxes, sites, databases).
- Actions it can take (send email, update records, call APIs, make payments).
- Whether it runs with its own identity or a user's delegated permissions.
Reduce to the minimum required. Prefer agent-specific identities over shared or user credentials.
Step 4: Apply policies
- Conditional Access and governance policies for agent identities where supported.
- Access reviews for agents with sensitive permissions.
- Purview DLP and sensitivity labels to limit what agents can process.
Step 5: Require human approval for high-impact actions
Payments, external email, deletion and permission changes should require human confirmation.
Step 6: Monitor
Log agent sign-ins and actions; alert on new permissions and unusual activity.
Verify
Quarterly: agent count, owner coverage, agents with high-impact permissions.
- Microsoft Entra Agent ID (May 2025): Giving AI Agents Their Own Identities Platform Changes
- AI Agent Identity Governance Checklist How-To & Hardening
- CIO Brief: AI Agents Are the Newest Privileged Users CIO Briefings