đź“‹ Microsoft Entra Documentation Changes

Daily summary for changes since December 10th 2025, 7:38 PM PST

Report generated on December 11th 2025, 7:38 PM PST

📊 Summary

15
Total Commits
0
New Files
4
Modified Files
0
Deleted Files
7
Contributors

📝 Modified Documentation Files

+10 / -4 lines changed
Commit: update links
Changes:
Before
After
 
## Agent identities basics
 
Historically, AI agents would rely upon tools to interact with various applications and systems, and each of those tools would have their own identities in those applications and systems. [Microsoft Entra Agent ID](../agent-id/identity-platform/what-is-agent-id.md) introduces identities for the agents themselves, with four new types of object: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. Through the [agent identity blueprint](../agent-id/identity-platform/agent-blueprint), the agent can create one or more agent identities, and optionally an agent user for each agent identity.
 
![Diagram of the relationship of Microsoft Entra Agent ID objects in a single tenant](./media/agent-id-governance-overview/agent-identity-objects-single-tenant.png)
 
For a multi-tenant agent, an agent identity blueprint principal can be brought into the tenant with resources so it can create agent identities in that tenant.
 
![Diagram of the relationship of Microsoft Entra Agent ID objects in multiple tenants](./media/agent-id-governance-overview/agent-identity-objects-multiple-tenant.png)
 
The agent identity and the agent user allows AI agents to take on digital identities within Microsoft Entra. Once agent identities are created, these agent identities are able to be governed using lifecycle and access features. Sponsors can be assigned to agent identities after creation. Sponsors of agent identities are human users accountable for making decisions about its lifecycle and access. For more information about the role of a sponsor of agent identities, see: [Administrative relationships for agent IDs](../agent-id/identity-platform/agent-owners-sponsors-managers.md).
 
## Agent identities in other Microsoft products
 
These can be created in [Microsoft Foundry](/azure/ai-foundry/agents/concepts/agent-identity), [Microsoft Copilot Studio](/microsoft-copilot-studio/admin-use-entra-agent-identities), or other platforms.
 
## Assigning access to agent identities
 
 
 
## Agent identities basics
 
Historically, AI agents would rely upon tools to interact with various applications and systems, and each of those tools would have their own identities in those applications and systems. Some of those tools would use service principals to authenticate to Microsoft services via Microsoft Graph or Microsoft Azure APIs. [Microsoft Entra Agent ID](../agent-id/identity-platform/what-is-agent-id.md) introduces support for identities for the agents themselves, with four new types of object: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. Through the [agent identity blueprint](../agent-id/identity-platform/agent-blueprint.md), the agent can create one or more agent identities, and optionally an agent user for each agent identity. Each agent identity and agent user can have distinct access rights.
 
![Diagram of the relationship of Microsoft Entra Agent ID objects in a single tenant](./media/agent-id-governance-overview/agent-identity-objects-single-tenant.png)
 
For a multi-tenant-capable agent, an agent identity blueprint principal can be brought into the tenant with resources so it can create agent identities in that tenant, similar to how a multi-tenant application can have a service principal in each tenant.
 
![Diagram of the relationship of Microsoft Entra Agent ID objects in multiple tenants](./media/agent-id-governance-overview/agent-identity-objects-multiple-tenant.png)
 
The agent identity and the agent user allows AI agents to take on digital identities within Microsoft Entra. Once agent identities are created, these agent identities are able to be governed using lifecycle and access features. Sponsors can be assigned to agent identities after creation. Sponsors of agent identities are human users accountable for making decisions about its lifecycle and access. For more information about the role of a sponsor of agent identities, see: [Administrative relationships for agent IDs](../agent-id/identity-platform/agent-owners-sponsors-managers.md).
 
## Use of agent identities in other Microsoft products
 
* Microsoft Foundry automatically provisions and manages agent identities throughout the agent lifecycle. When the first agent in a Foundry project is created, Microsoft Foundry provisions a default agent identity blueprint and a default agent identity for the project, and agents in the project authenticate by using the shared project's agent identity. Publishing an agent automatically creates a dedicated agent identity blueprint and agent identity, and the agent will authenticate by using the unique agent identity. Foundry supports use of the agent identity for authentication in Model Context Protocol (MCP) and Agent-to-Agent (A2A) tools. For more information, see [Agent identity concepts in Microsoft Foundry](/azure/ai-foundry/agents/concepts/agent-identity).
 
* You can configure an Azure App Service or Azure Functions app to use the Microsoft Entra agent identity platform to securely connect to resources as an agent. For more information, see [How to use an agent identity in App Service and Azure Functions](/azure/app-service/overview-agent-identity).
 
* Agents created in Microsoft Copilot Studio can be configured to automatically be assigned to an agent identity. When an agent identity is first created in a Power Platform environment after enabling this setting, a Microsoft Copilot Studio agent identity blueprint, and an agent identity blueprint principal, are automatically created. For more information, see [Automatically create Entra agent identities for Copilot Studio agents (preview)](/microsoft-copilot-studio/admin-use-entra-agent-identities).
Modified by Lesia Nalepa on Dec 11, 2025 10:46 PM
đź“– View on learn.microsoft.com
+3 / -3 lines changed
Commit: Fix acrolinx score issues in manage-agent.md
Changes:
Before
After
 
# Manage Agents in end user experience (Preview)
 
The Manage agents feature in Microsoft Entra lets you view, and control, [agent identities you own or sponsor](agent-owners-sponsors-managers.md). [Agents identities](what-is-agent-id.md) are special identities, such as bots or automated processes, that act on behalf of users or teams. With the manage agents feature, you can easily see which agents you’re responsible for, review their details, and take action to enable, disable, or request access for them.
 
> [!NOTE]
> This feature is in public preview. Functionality might change before general availability.
 
1. If you haven’t opted in to the new homepage yet, select **Use new version** in the banner.
> [!NOTE]
> If you’re already using the new homepage, the banner will still appear with the message “You’re using the new version of the account homepage” and a **Use previous version** button.
1. In the left menu, select **Manage agents (Preview)**.
> [!NOTE]
> This will only appear if you're an owner or sponsor of at least one agent identity.
 
1. Choose either the **Agents you sponsor** or **Agents you own tab** to view your agents.
:::image type="content" source="media/manage-agent/manage-agents-list.png" alt-text="Screenshot of the managed agents page in the My Account portal.":::
 
# Manage Agents in end user experience (Preview)
 
The Manage Agents feature in Microsoft Entra lets you view, and control, [agent identities you own or sponsor](agent-owners-sponsors-managers.md). [Agents identities](what-is-agent-id.md) are special identities, such as bots or automated processes, that act on behalf of users or teams. With the manage agents feature, you can easily see which agents you’re responsible for, review their details, and take action to enable, disable, or request access for them.
 
> [!NOTE]
> This feature is in public preview. Functionality might change before general availability.
 
1. If you haven’t opted in to the new homepage yet, select **Use new version** in the banner.
> [!NOTE]
> If you’re already using the new homepage, the banner still appears with the message "You’re using the new version of the account homepage" and a **Use previous version** button.
1. In the left menu, select **Manage agents (Preview)**.
> [!NOTE]
> This menu item will only appear if you're an owner or sponsor of at least one agent identity.
 
1. Choose either the **Agents you sponsor** or **Agents you own tab** to view your agents.
:::image type="content" source="media/manage-agent/manage-agents-list.png" alt-text="Screenshot of the managed agents page in the My Account portal.":::
+1 / -1 lines changed
Commit: Update Azure Files link for managed identities
Changes:
Before
After
| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|
| Azure Event Hubs | [Authenticate a managed identity with Microsoft Entra ID to access Event Hubs Resources](/azure/event-hubs/authenticate-managed-identity)|
| Azure File Sync | [How to use managed identities with Azure File Sync](/azure/storage/file-sync/file-sync-managed-identities)|
| Azure Files | [Access Azure file shares using Microsoft Entra ID with Azure Files OAuth over REST](/azure/storage/files/authorize-oauth-rest)|
| Azure Health Data Services workspace services | [Authentication and authorization for Azure Health Data Services](/azure/healthcare-apis/authentication-authorization)|
| Azure Health Data Services de-identification service | [Use managed identities with the de-identification service](/azure/healthcare-apis/deidentification/managed-identities)|
| Azure Image Builder | [Azure Image Builder overview](/azure/virtual-machines/image-builder-overview#permissions) |
| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|
| Azure Event Hubs | [Authenticate a managed identity with Microsoft Entra ID to access Event Hubs Resources](/azure/event-hubs/authenticate-managed-identity)|
| Azure File Sync | [How to use managed identities with Azure File Sync](/azure/storage/file-sync/file-sync-managed-identities)|
| Azure Files | [Access SMB Azure file shares using managed identities with Microsoft Entra ID (preview)](/azure/storage/files/files-managed-identities)|
| Azure Health Data Services workspace services | [Authentication and authorization for Azure Health Data Services](/azure/healthcare-apis/authentication-authorization)|
| Azure Health Data Services de-identification service | [Use managed identities with the de-identification service](/azure/healthcare-apis/deidentification/managed-identities)|
| Azure Image Builder | [Azure Image Builder overview](/azure/virtual-machines/image-builder-overview#permissions) |
Modified by Kiran-MSFT on Dec 11, 2025 3:25 PM
đź“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: (AzureCXP) fixes MicrosoftDocs/entra-docs-pr
Changes:
Before
After
The first step to perform an access review is to find and open the access review.
 
>[!IMPORTANT]
> There could be delays in receiving email and it some cases it could take up to 24 hours. Add [email protected] to your safe recipients list to make sure that you're receiving all emails.
 
1. Look for an email from Microsoft that asks you to review access. Here's an example email to review your access to a group.
 
The first step to perform an access review is to find and open the access review.
 
>[!IMPORTANT]
> There could be delays in receiving email and in some cases it could take up to 24 hours. Add [email protected] to your safe recipients list to make sure that you're receiving all emails.
 
1. Look for an email from Microsoft that asks you to review access. Here's an example email to review your access to a group.