Microsoft Entra Agent ID

Microsoft

Vendor

Entra identity platform for AI agents: agent identities and blueprints with Conditional Access, ID Protection and governance.

Curated by Tiberiu ArvaVerified

Proprietary

Strengths

  • Agent identity blueprints for fleets
  • Conditional Access templates for agents
  • Federates Bedrock and n8n agents

Practitioner note

Default choice for Microsoft-centric tenants; budget for Agent 365 licensing, because the base Agent ID platform does not include agent Conditional Access or access packages.

Governance posture

Reviewed 2026-09-30
UnknownData residency

Agent ID docs reviewed do not state agent-specific data residency controls; follows the Entra tenant's home geography (not confirmed for Agent ID).

YesDeployment model

Microsoft-managed SaaS within Microsoft Entra; third-party agents integrate via the Auth SDK sidecar or workload identity federation. (saas)

Source
YesAudit logging

All agent authentication and activity is logged in Entra sign-in and audit logs.

Source
PartialSOC 2

Microsoft Entra ID is listed in Microsoft's Office 365 SOC 2 Type 2 scope for GCC/GCC High/DoD; Agent ID is not listed separately.

Source
UnknownISO 27001

Azure ISO 27001 page lists service families (Azure, Microsoft 365) without naming Entra Agent ID; scope detail sits in the Service Trust Portal.

NoISO 42001

Not among the Microsoft AI services listed in scope for ISO/IEC 42001 (list covers Copilot, Copilot Studio, Foundry and others).

Source
N/AEU AI Act

Identity and access-control tooling for agents, not itself an AI system placed on the market; AI Act obligations rest with the provider/deployer of the governed agents. (role: not-applicable)

YesLicense risk

Proprietary Microsoft SaaS tied to Entra and Agent 365 licensing. (medium)

Source

EU AI Act obligations

Risk tier: Not applicable · as of 2026-08-23

Source-backed information mapped from Microsoft Entra Agent ID's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.