Microsoft Entra ID
General

Policy Agent User

In brief

The documentation adds links and clarifies that relevant agents run on Intune-managed Windows 365 Cloud PCs, with Global Secure Access for compliant network policies. It also refines targeting, assignment, and risk-level guidance.

What Entra admins need to know

Administrators configuring Conditional Access for agent users should follow the clarified endpoint, targeting, and risk guidance. No required action is stated.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

- Microsoft Agent 365 license paired with at least Microsoft Entra P1 or Microsoft 365 E3.

A policy that targets an agent identity doesn't apply to the agent's user account. If the agent also uses its own agent identity, create a separate policy for that access pattern. For more information, see Secure autonomous agents with Conditional Access.

  • Apply agent risk conditions to block risky agents
  • Use the agent execution environments condition to scope policies to agents running on endpoints
  • Enforce device compliance for agents running on managed endpoints (Windows 365 Cloud PCs)
  • Enforce compliant network locations for agents running on managed endpoints (Windows 365 Cloud PCs) with a Global Secure Access client

To create a Conditional Access policy for agents operating with their own identity,agent users, use the following settings:

  • Assignments: In an agent access flow, the access token is issued to the agent identityusers (the token subject), so you assign the policy to agents or their agent identity blueprint.
  • Target resources: Select the resources the agent needs to access.
  • Conditions: Configure whether you want the policy to apply when the agent is at a particular risk level. For example, a restrictive policy for agents that are high-risk. For more information, see ID Protection for agents.
  • Access control: Because this agent accesses resources with its own identity, there's no remediation and the only available option is blocking access.

Require a compliant network

Use this policy to require agents running on endpoints to connect through a compliant network using Global Secure Access. The client provides the network location signal that Conditional Access evaluates. This applies to agents that run on a managed endpoint, such as a Windows 365 Cloud PC for Agents.

  1. Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator.
  2. Browse to Entra ID > Conditional Access > Policies.
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…