Microsoft Entra Agent ID
Developer

Authorization Agent Id

In brief

The documentation now describes blocked highly privileged directory roles for agent identities without the obsolete custom-role restriction wording.

What Entra admins need to know

Administrators should use the updated guidance when assigning Microsoft Entra roles to agents.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

From an authorization standpoint, an agent identity behaves somewhat like an application or a user with extra safeguards. Each agent identity has a service principal or a user in Microsoft Entra ID, and it can be assigned certain Microsoft Entra roles.

For example, an agent's identity can be assigned a Microsoft Entra role to give it administrator privileges, but many highly privileged directory roles are blocked for agents. Roles such as Global Administrator, Privileged Role Administrator, or User Administrator can't be assigned to agent identities. Only lower privileged roles (such as a reader role) can be assigned to an agent. You can't assign any custom roles to agent identities. Also, agentAgent identities can't be members of role-assignable groups.

Microsoft has created the Agent ID Administrator and Agent ID Developer roles for managing and creating agents themselves.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…