Your AI Agents Are Identities — Treat Them Like Users With Badges
September 21, 2026
Most businesses are experimenting with AI the way they once adopted cloud apps: one team, one use case, one “let’s try this” at a time. Chat assistants draft email. Copilot sits inside Microsoft 365. A workflow bot updates a CRM. A website agent answers after-hours questions. Each of those helpers needs permission to read, write, or trigger something — which means each one is an identity in your environment, whether anyone wrote it down that way or not.
That is the shift mid-market IT is still catching up to. The security questions are familiar (what can it access, who approved it, who owns it, how do we turn it off), but the population is new: non-human, sometimes short-lived, often created outside a formal IT request. Microsoft’s Entra Agent ID documentation describes agents that can receive Graph permissions, Azure roles, and other powerful rights — and notes that some agents may be created and destroyed thousands of times a day.
If you only inventory employees and a few service accounts, you are missing the new crowd.
Why “it is just a bot” is the wrong frame
An AI agent is software, but it behaves like a user with a job description and a badge. It may touch SharePoint libraries, mailboxes, ticket systems, finance tools, or customer data. Without clear ownership, those permissions tend to start wide (because broad access makes demos easy) and stay wide (because nobody schedules a review).
Industry research on non-human and agentic identity keeps pointing at the same gap: many organizations have no documented process for creating or retiring AI identities, and a meaningful share do not track them at all. Vendors are racing to surface agent identities inside Microsoft Entra and similar directories. The tooling helps. It does not replace a register, a sponsor, and a kill switch.
What Microsoft is building into the directory
Microsoft Entra Agent ID is Microsoft’s identity framework for AI agents: dedicated agent identities (not just reused app registrations), blueprints for consistent policy, sponsorship and ownership, lifecycle controls, and the ability to apply Conditional Access, Identity Protection, and audit logging to agent activity.
Base Agent ID create-and-manage capability is available to Entra customers. Extending the fuller Entra security stack to agents — Conditional Access, Identity Protection, deeper lifecycle governance — ties to Microsoft Agent 365 licensing (included with Microsoft 365 E7, or as an add-on to E5 / A5 / Business Premium paths). Copilot Studio has also moved toward creating Entra Agent IDs for new agents automatically, so the directory becomes the place admins can see what an agent is allowed to call.
You do not need to buy every SKU tomorrow to start governing. You do need to stop treating agents as anonymous features of an app.
A practical starting checklist for a mid-sized business
Before the next department spins up another assistant:
- Inventory what already exists. Copilot Studio agents, Microsoft 365 Copilot extensions, website chatbots wired into CRM or email, Zapier/Make-style AI steps, vendor “AI features” that hold OAuth grants to your tenant. Name, purpose, and where it lives.
- Assign a human sponsor for each agent. Someone accountable when the builder leaves or the experiment ends. Orphaned agents with standing permissions are the quiet version of orphaned service accounts.
- Write down least privilege in one sentence. “This agent may read X and create Y; it may not delete, pay, or export Z.” If you cannot say that sentence, the agent is not ready for production data.
- Put a kill switch on paper. Who disables the agent, rotates its credentials, and revokes OAuth grants — and how fast.
- Review on a calendar, not a vibe. Quarterly is a sane default: missing sponsor, unused agent, permissions that grew since last review.
- Ask your Microsoft partner which Entra / Agent 365 tier you already own before you assume governance features are “included.”
Where this meets managed IT
Identity, access reviews, Microsoft 365 hygiene, and monitoring are already core MSP work. Extending that discipline to AI agents is not a separate science project — it is the same craft applied to a new principal type. The businesses that wait until “agent sprawl” is obvious will invent governance under pressure. The ones that start with a simple register and ownership model will adopt AI faster because IT can say yes with controls.
For organizations without a dedicated identity team, that is exactly the gap a managed IT and practical AI partner is supposed to close: not banning agents, and not rubber-stamping them — making sure every agent that can touch your business is known, owned, narrowly authorized, and easy to shut off.