Microsoft Entra Agent ID
Authentication

Integrate third-party agents with Microsoft Entra Agent ID

In brief

The article now consistently refers to the sidecar integration as the Microsoft Entra ID Auth SDK instead of the Microsoft Entra Auth SDK. The integration guidance is otherwise unchanged.

What Entra admins need to know

Administrators following this guidance should recognize the updated SDK name; the article continues to advise keeping the SDK updated for security and compatibility.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Integrate third-party agents with Microsoft Entra Agent ID

Microsoft Entra Agent ID enables AI agents from third-party platforms to authenticate and access your APIs securely without handling credentials directly. This article covers two integration patterns - the Microsoft Entra ID Auth SDK (sidecar) and federation - for platforms such as Amazon Web Service (AWS) Bedrock and n8n.

Prerequisites

  • Remove the need for agents to handle credentials directly.
  • Use workload identity federation for agents running outside Azure.
  • Support multiple authentication patterns, including client credentials, federated identity, and on-behalf-of.
  • Integrate with third-party agent platforms by using the Microsoft Entra ID Auth SDK (sidecar).

Integration patterns for third-party agents

To integrate third-party agents with Microsoft Entra Agent ID, choose from the following patterns:

Use the Microsoft Entra ID Auth SDK (sidecar)

The sidecar pattern runs the Microsoft Entra ID Auth SDK (sidecar) as a companion container alongside your agent. The agent calls the sidecar to request tokens for API calls. The agent never handles credentials directly; instead, it delegates token acquisition to the sidecar.

Best for:

  • Validate token audience and issuer. Always verify that tokens come from your Microsoft Entra tenant.
  • Rotate credentials regularly. If you use client secrets, rotate them on a schedule. Consider federated credentials instead.
  • Monitor token usage. Use Microsoft Entra logs to track which agents access which APIs.
  • Keep the Microsoft Entra ID Auth SDK (sidecar) updated. Security and compatibility updates are released regularly.

Troubleshoot common issues

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…