Skip to content
Identity and access

Non-human identities in the directory of record.

Entra Agent ID extends Microsoft's directory to agents, so a non-human identity is issued, scoped, and reviewed in the same place as a person rather than as a service principal nobody tracks. Our work is agent identity in the directory of record, with scope, ownership, and review.

Entra Agent ID gives agents an identity in the same directory that already holds your people. Where Entra is authoritative, that makes the lifecycle question answerable today.

What it is

Entra Agent ID extends Microsoft's directory to agents, so a non-human identity is issued, scoped, and reviewed in the same place as a person rather than as a service principal nobody tracks.

It is for organizations where Entra is already the directory of record and agents are arriving through Microsoft tooling, which is a common combination and a fortunate one.

identity owner expires one owner recorded, five unaccounted L1 L2 L3 L4

What it does

Agents in the same directory as people

One place to enumerate, one review to run, one lifecycle to enforce.

Scope granted rather than inherited

An agent gets permissions deliberately, instead of assuming those of whoever created it.

Where it fits

L1, identity and access, governing L4. Its advantage is proximity: the agent identity lives in the directory that already answers for people, so a single access review can cover both populations rather than two processes that never quite reconcile.

Where it earns its place

A Microsoft-centred estate adopting agents

The directory is already authoritative, which makes this the cheapest available path to a real lifecycle.

An organization with service principals nobody owns

Agents in the directory are enumerable. Service principals accumulated over a decade are not.

Proof

92%

Of security leaders say they lack full visibility into the machine identities already running in their environment.

2026 CISO AI Risk Report, 235 large-enterprise leaders.

AI Innovator Finalist, 2026

AI Innovator Finalist, 2026

Atlassian Partner Awards, 2026

Questions we get

We use Okta, not Entra. Does this matter?
Only if Entra is also in play, which it often is. The failure to avoid is two directories both claiming to be authoritative for agents.
Does this cover agents outside Microsoft tooling?
Coverage depends on how the agent authenticates. That is worth establishing per agent rather than assumed across the estate.

Find out who can reach what.

Fixed scope. The assessment starts at the identity layer: human and non-human access, the accounts nobody owns, and what has to be true before an agent gets one. You get the findings, the ownership gaps, and the order to close them in.