Microsoft Entra Agent ID
General

Agent Access Packages

In brief

The documentation now states that agent identities need delegated OAuth permissions for target resources, such as Microsoft Graph or an application, to assist users with API access.

What Entra admins need to know

Ensure relevant agent identities have the required delegated permissions assigned.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  1. Agents are using Microsoft Entra Agent ID agent identities, or service principals, for authorization to access resources.
  2. The authorization is one of:
    • Agents need their identity to be assigned OAuth application permissions for a target resource, such as Microsoft Graph or an application, to be able to access a target resource's APIs.
    • Agents need their identity to be assigned OAuth delegated permissions for a target resource, such as Microsoft Graph or an application, to be able to assist a user in accessing when accessing a target resource's APIs.
    • Agents need their identity to be assigned as members of groups.
    • Agents need their identity to be assigned to directory roles. The allowable roles are listed in Microsoft Entra roles allowed for agents.
  3. You have or can create an entitlement management catalog suitable to hold those resources. The access package that you'll be creating, and any resources included in it, will be added to the catalog. For more information, see create a catalog.
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…