Agent Id
In brief
The documentation clarifies that policies scoped through the Users assignment do not apply to agent user accounts, regardless of whether they target all users, selected users, groups, directory roles, or external users. To protect agents, select Agents under Users, agents, or workload identities.
What Entra admins need to know
Create or review a Conditional Access policy specifically targeting all or selected agent users.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
The following configurations aren't currently supported:
- Policies
targeting all usersscoped through the "Users" assignment don'tincludeapply to agent'suser accounts. This boundary applies whether the policy targets all users, selected users, groups, directory roles, or external users. To protect agent user accounts, create a policy that targets "Agent Users." - Scoping a Conditional Access policy to include or exclude agent's user account based on their group
membershipmembership. - A Conditional Access policy targeting agent identities won't apply to the agent's user account.
- A Conditional Access policy targeting agent identities using agent identity blueprint covers only the agent identity, not the agent's user account.
Instead, to scope policies to agent users, under Assignments > Users, agents, or workload identities, select Agents, and then target all agent users or specific agent users.
Related content
@@ -158,11 +158,13 @@ Conditional Access policies don't apply when: The following configurations aren't currently supported: -- Policies targeting all users don't include agent's user accounts.-- Scoping a Conditional Access policy to include or exclude agent's user account based on their group membership+- Policies scoped through the "Users" assignment don't apply to agent user accounts. This boundary applies whether the policy targets all users, selected users, groups, directory roles, or external users. To protect agent user accounts, create a policy that targets "Agent Users."+- Scoping a Conditional Access policy to include or exclude agent's user account based on their group membership. - A Conditional Access policy targeting agent identities won't apply to the agent's user account. - A Conditional Access policy targeting agent identities using agent identity blueprint covers only the agent identity, not the agent's user account. +Instead, to scope policies to agent users, under **Assignments** > **Users, agents, or workload identities**, select **Agents**, and then target all agent users or specific agent users.+ ## Related content - [Target agent identities in Conditional Access policies](howto-target-agent-identities.md) 