Agent Id Governance Overview
In brief
The documentation now describes the linked guidance as covering delegated and application permissions for Microsoft Graph and applications.
What Entra admins need to know
Administrators can more easily identify the relevant permissions guidance.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
When created, agent identities have limited permissions, such as OAuth 2 delegated permission scopes inherited from their parent agent identity blueprint. In addition, agent identities can have resource access assigned to them directly via access packages. Agents can request an access package for own agent IDs, or have their owner or sponsor request one on their behalf. With access packages, you're able to assign agent identities access to the following resources:
- Security Group memberships
- OAuth API permissions,
includingdelegated and application permissions for Microsoft Graphapplication permissionsand applications - Microsoft Entra roles
To use access packages for agent identities, configure an access package with the required policy settings. When creating an access package assignment policy, in the Who can get access section, select For users, service principals, and agent identities in your directory, and then select the option of All agents.
@@ -47,7 +47,7 @@ The agent identity and the agent user allow AI agents to take on digital identit When created, agent identities have limited permissions, such as OAuth 2 delegated permission scopes [inherited from their parent agent identity blueprint](../agent-id/configure-inheritable-permissions-blueprints.md). In addition, agent identities can have resource access assigned to them directly via access packages. Agents can request an access package for own agent IDs, or have their owner or sponsor request one on their behalf. With access packages, you're able to assign agent identities access to the following resources: - Security Group memberships-- [Application OAuth API permissions](../identity/enterprise-apps/assign-agent-identities-to-applications.md), including Graph application permissions+- [OAuth API permissions](../identity/enterprise-apps/assign-agent-identities-to-applications.md), delegated and application permissions for Microsoft Graph and applications - [Microsoft Entra roles](../agent-id/authorization-agent-id.md#microsoft-entra-role-assignments-for-agent-identities) To use access packages for agent identities, configure an access package with the required policy settings. When creating an access package assignment policy, in the **Who can get access** section, select **For users, service principals, and agent identities in your directory**, and then select the option of **All agents**. 