Microsoft Entra Agent ID
General

Agent Id

In brief

The documentation clarifies that policies scoped through the Users assignment do not apply to agent user accounts, regardless of whether they target all users, selected users, groups, directory roles, or external users. To protect agents, select Agents under Users, agents, or workload identities.

What Entra admins need to know

Create or review a Conditional Access policy specifically targeting all or selected agent users.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

The following configurations aren't currently supported:

  • Policies targeting all usersscoped through the "Users" assignment don't includeapply to agent's user accounts. This boundary applies whether the policy targets all users, selected users, groups, directory roles, or external users. To protect agent user accounts, create a policy that targets "Agent Users."
  • Scoping a Conditional Access policy to include or exclude agent's user account based on their group membershipmembership.
  • A Conditional Access policy targeting agent identities won't apply to the agent's user account.
  • A Conditional Access policy targeting agent identities using agent identity blueprint covers only the agent identity, not the agent's user account.

Instead, to scope policies to agent users, under Assignments > Users, agents, or workload identities, select Agents, and then target all agent users or specific agent users.

Related content

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…