Agent Access Packages
In brief
The documentation now states more clearly that an agent needs assigned OAuth delegated permissions to assist a user when accessing a target resource’s APIs.
What Entra admins need to know
No administrator action is required.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
- Agents are using Microsoft Entra Agent ID agent identities, or service principals, for authorization to access resources.
- The authorization is one of:
- Agents need their identity to be assigned OAuth application permissions for a target resource, such as Microsoft Graph or an application, to be able to access a target resource's APIs.
- Agents need their identity to be assigned OAuth delegated permissions for a target resource, such as Microsoft Graph or an application, to be able to assist a user
in accessingwhen accessing a target resource's APIs. - Agents need their identity to be assigned as members of groups.
- Agents need their identity to be assigned to directory roles. The allowable roles are listed in Microsoft Entra roles allowed for agents.
- You have or can create an entitlement management catalog suitable to hold those resources. The access package that you'll be creating, and any resources included in it, will be added to the catalog. For more information, see create a catalog.
@@ -20,7 +20,7 @@ Before creating an access package, confirm the following prerequisites are met i 1. Agents are using Microsoft Entra Agent ID agent identities, or service principals, for authorization to access resources. 1. The authorization is one of: - Agents need their identity to be assigned OAuth *application permissions* for a target resource, such as Microsoft Graph or an application, to be able to access a target resource's APIs.- - Agents need their identity to be assigned OAuth *delegated permissions* for a target resource, such as Microsoft Graph or an application, to be able to assist a user in accessing when accessing a target resource's APIs.+ - Agents need their identity to be assigned OAuth *delegated permissions* for a target resource, such as Microsoft Graph or an application, to be able to assist a user when accessing a target resource's APIs. - Agents need their identity to be assigned as members of groups. - Agents need their identity to be assigned to directory roles. The allowable roles are listed in [Microsoft Entra roles allowed for agents](authorization-agent-id.md#microsoft-entra-roles-allowed-for-agents). 2. You have or can create an entitlement management catalog suitable to hold those resources. The access package that you'll be creating, and any resources included in it, will be added to the catalog. For more information, see [create a catalog](/entra/id-governance/entitlement-management-catalog-create). 