{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "microsoft-entra-agent-id",
    "name": "Microsoft Entra Agent ID",
    "vendor": "Microsoft",
    "vendorUrl": "https://learn.microsoft.com/en-us/entra/agent-id/",
    "kind": "http-api",
    "category": "agent-auth",
    "summary": "Microsoft Entra Agent ID is an identity type for AI agents in Microsoft Entra ID. Agents get their own directory identity, request OAuth 2.0 tokens autonomously or on behalf of a user, and are managed through Microsoft Graph.",
    "url": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id",
    "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json",
    "repo": "https://github.com/AzureAD/microsoft-identity-web",
    "license": "Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
    "packages": [
      {
        "registry": "nuget",
        "name": "Microsoft.Identity.Web.AgentIdentities"
      }
    ],
    "auth": "oauth",
    "authNotes": "Access starts with a Microsoft Entra tenant and a person holding the Agent ID Developer or Agent ID Administrator role, who creates an agent identity blueprint. The blueprint authenticates to login.microsoftonline.com with a managed identity, a certificate or a client secret (Microsoft advises against secrets in production) and exchanges for a token as one of its agent identities. Agent identities hold no credentials. Three flows exist, which are app-only, on behalf of a signed-in user, and as the agent's own user account. Interactive `/authorize` and public clients aren't supported. Management calls on Microsoft Graph need AgentIdentity.Create.All or AgentIdentity.ReadWrite.All.",
    "pricing": "freemium",
    "pricingNotes": "Microsoft's docs say Agent ID is available to all Microsoft Entra customers, and Entra ID Free comes with any Microsoft cloud subscription. No per-agent price is published. Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15.00 a user a month on yearly billing, or Microsoft 365 E7 at $99.00. Conditional Access for agents also needs Entra P1 or Microsoft 365 E3 alongside Agent 365. No sandbox was found in the Agent ID docs (https://www.microsoft.com/en-us/microsoft-agent-365, checked 2026-10-08).",
    "priceSummary": "$15 / seat-mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the Agent ID docs, the Graph reference or the pricing pages (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 787,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://learn.microsoft.com/en-us/entra/agent-id/",
    "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
    "capabilities": [
      "auth.oauth",
      "auth.agent-identity",
      "auth.consent",
      "auth.audit"
    ],
    "tags": [
      "hosted",
      "enterprise",
      "oauth",
      "openapi",
      "dotnet",
      "sidecar",
      "microsoft-graph",
      "mcp",
      "freemium",
      "sla"
    ],
    "lastRelease": "2026-09-30",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 74.4,
      "grade": "BB",
      "agentReady": true,
      "rank": 63,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 2,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 71,
        "maintenance": 80,
        "payments": 20,
        "reliability": 91,
        "schema": 87,
        "security": 83,
        "transparency": 74
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 91,
          "points": 18.2,
          "reason": "Microsoft's SLA page for Entra ID points to the Azure status history for incidents, and that page was readable with dated entries and reviews (20). The last 90 days show three Azure incidents, on 23 July, 29 September and 30 September 2026. None names Entra ID, the 23 July West US network fault lists Azure AD B2C, and Microsoft reports 99.999 per cent authentication availability for July, August and September. We scored between clean and minor because the page lists only wide incidents (25). Graph identity limits are published as numbers, such as 3,000 writes per 2 minutes 30 seconds per app and tenant (15). 429 carries Retry-After and the FAQ asks for exponential backoff, but there is no idempotency key and back-to-back creates can fail with 400 during replication (11). An SLA for Microsoft Entra ID is published and attainment is reported monthly. The SLA document itself didn't load for us (10). Agent ID has been generally available since April 2026 and the agentIdentity API is on Graph v1.0 (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 87,
          "points": 14.14,
          "reason": "agentIdentity is in Microsoft's public Graph v1.0 OpenAPI file (25). learn.microsoft.com returns Markdown when asked with `Accept: text/markdown`, but learn.microsoft.com/llms.txt returned 404 (8). Concept, design-pattern and best-practice pages say when to use each flow and when to pick the sidecar over the .NET library (16). Graph resources are typed with required fields listed, though agentIdentity is an open type that inherits servicePrincipal properties that don't all apply (12). Request and response examples on each reference page and a list of 17 Agent ID error codes, without the HTTP status for each (11). v1.0 and beta versioning with a monthly dated Graph changelog and Entra release notes (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 71,
          "points": 11.54,
          "reason": "List calls take `$select`, `$top`, `$filter`, `$search` and `$count`, with a default and maximum page of 100 (20). OData paging and filtering work on the main collection, but ownedObjects, deletedItems and owners can't filter by agent type and need client-side filtering (17). Named error codes such as `AgentIdentity_CredentialsNotSupported` say what to change (16). No idempotency key for creates, and sequential creates need retries. Token requests are safe to repeat (8). Creating an identity needs three fields, but getting a token is a two-step exchange that Microsoft's docs call complex and error-prone by hand, with an in-process library only for .NET and a sidecar container for everything else (10)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 83,
          "points": 14.53,
          "reason": "OAuth 2.0 with scoped Graph permissions. Agent identities can't hold credentials, the blueprint signs in with a managed identity or certificate, and client secrets are allowed but warned against (30). Entra refuses high-privilege roles and permissions such as Application.ReadWrite.All for agents, and an identity can be disabled. Conditional Access for agents needs an Agent 365 licence, and nothing asks a person to approve a destructive call (16). The service returns tokens and directory objects, not untrusted content (10). Audit and sign-in logs carry agentType and blueprintId, kept seven days on Free and 30 on P1 or P2, while the FAQ says Graph activity logs don't separate agents (12). MSRC disclosure policy and an identity bounty of $750 to $100,000, but microsoft.com's security.txt expired on 23 September 2026 and we didn't read certification reports (15)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 20,
          "points": 2.5,
          "reason": "No x402, MPP or L402 (0). Agent 365 is listed at $15 a user a month and Microsoft 365 E7 at $99, and the docs say Agent ID is available to all Entra customers, but no page gives a per-agent price or says plainly which parts are free (10). Entra ID Free comes with a Microsoft cloud subscription. We didn't establish whether a new tenant can be opened without a card, so this line gets half (10). A person creates the tenant, holds an Agent ID role and creates the blueprint before any agent can act (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 80,
          "points": 7,
          "reason": "Microsoft.Identity.Web 4.16.0, which carries the agent identity package and the sidecar, was tagged on 30 September 2026, and the Agent ID FAQ was updated on 1 October (30). Eight tags from 4.13.0 on 9 July to 4.16.0, and Graph changelog entries for agent identities in August and September (20). A closed service with public release notes and a public SDK tracker showing 340 open issues. We didn't read reply times (10). The current in-process SDK is .NET only, with the sidecar container for other languages (12). Azure Pipelines and CodeQL are configured, and 4.14.x raised dependencies for four CVEs (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 74,
          "points": 6.48,
          "note": "editorial 63, provenance 85",
          "reason": "Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDK source (15). The privacy statement was updated in September 2026, Entra publishes a data residency page and log retention periods, and we didn't read the DPA (20). Microsoft Graph gives at least 24 months' notice before retiring a GA API or version, while several Agent ID operations are still on /beta, which can change without notice (18). Entra documents where tenant data is stored by geography. We didn't read the sub-processor list (10)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "List calls take `$select`, `$top`, `$filter`, `$search` and `$count`, with a default and maximum page of 100 (20). OData paging and filtering work on the main collection, but ownedObjects, deletedItems and owners can't filter by agent type and need client-side filtering (17). Named error codes such as `AgentIdentity_CredentialsNotSupported` say what to change (16). No idempotency key for creates, and sequential creates need retries. Token requests are safe to repeat (8). Creating an identity needs three fields, but getting a token is a two-step exchange that Microsoft's docs call complex and error-prone by hand, with an in-process library only for .NET and a sidecar container for everything else (10).",
          "maintenance": "Microsoft.Identity.Web 4.16.0, which carries the agent identity package and the sidecar, was tagged on 30 September 2026, and the Agent ID FAQ was updated on 1 October (30). Eight tags from 4.13.0 on 9 July to 4.16.0, and Graph changelog entries for agent identities in August and September (20). A closed service with public release notes and a public SDK tracker showing 340 open issues. We didn't read reply times (10). The current in-process SDK is .NET only, with the sidecar container for other languages (12). Azure Pipelines and CodeQL are configured, and 4.14.x raised dependencies for four CVEs (8).",
          "payments": "No x402, MPP or L402 (0). Agent 365 is listed at $15 a user a month and Microsoft 365 E7 at $99, and the docs say Agent ID is available to all Entra customers, but no page gives a per-agent price or says plainly which parts are free (10). Entra ID Free comes with a Microsoft cloud subscription. We didn't establish whether a new tenant can be opened without a card, so this line gets half (10). A person creates the tenant, holds an Agent ID role and creates the blueprint before any agent can act (0).",
          "reliability": "Microsoft's SLA page for Entra ID points to the Azure status history for incidents, and that page was readable with dated entries and reviews (20). The last 90 days show three Azure incidents, on 23 July, 29 September and 30 September 2026. None names Entra ID, the 23 July West US network fault lists Azure AD B2C, and Microsoft reports 99.999 per cent authentication availability for July, August and September. We scored between clean and minor because the page lists only wide incidents (25). Graph identity limits are published as numbers, such as 3,000 writes per 2 minutes 30 seconds per app and tenant (15). 429 carries Retry-After and the FAQ asks for exponential backoff, but there is no idempotency key and back-to-back creates can fail with 400 during replication (11). An SLA for Microsoft Entra ID is published and attainment is reported monthly. The SLA document itself didn't load for us (10). Agent ID has been generally available since April 2026 and the agentIdentity API is on Graph v1.0 (10).",
          "schema": "agentIdentity is in Microsoft's public Graph v1.0 OpenAPI file (25). learn.microsoft.com returns Markdown when asked with `Accept: text/markdown`, but learn.microsoft.com/llms.txt returned 404 (8). Concept, design-pattern and best-practice pages say when to use each flow and when to pick the sidecar over the .NET library (16). Graph resources are typed with required fields listed, though agentIdentity is an open type that inherits servicePrincipal properties that don't all apply (12). Request and response examples on each reference page and a list of 17 Agent ID error codes, without the HTTP status for each (11). v1.0 and beta versioning with a monthly dated Graph changelog and Entra release notes (15).",
          "security": "OAuth 2.0 with scoped Graph permissions. Agent identities can't hold credentials, the blueprint signs in with a managed identity or certificate, and client secrets are allowed but warned against (30). Entra refuses high-privilege roles and permissions such as Application.ReadWrite.All for agents, and an identity can be disabled. Conditional Access for agents needs an Agent 365 licence, and nothing asks a person to approve a destructive call (16). The service returns tokens and directory objects, not untrusted content (10). Audit and sign-in logs carry agentType and blueprintId, kept seven days on Free and 30 on P1 or P2, while the FAQ says Graph activity logs don't separate agents (12). MSRC disclosure policy and an identity bounty of $750 to $100,000, but microsoft.com's security.txt expired on 23 September 2026 and we didn't read certification reports (15).",
          "transparency": "Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDK source (15). The privacy statement was updated in September 2026, Entra publishes a data residency page and log retention periods, and we didn't read the DPA (20). Microsoft Graph gives at least 24 months' notice before retiring a GA API or version, while several Agent ID operations are still on /beta, which can change without notice (18). Entra documents where tenant data is stored by geography. We didn't read the sub-processor list (10)."
        },
        "sources": [
          {
            "what": "What is Microsoft Entra Agent ID",
            "url": "https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id",
            "seen": "2026-10-08"
          },
          {
            "what": "agent identities concept and licensing",
            "url": "https://learn.microsoft.com/en-us/entra/agent-id/what-are-agent-identities",
            "seen": "2026-10-08"
          },
          {
            "what": "what's new in Agent ID",
            "url": "https://learn.microsoft.com/en-us/entra/agent-id/whats-new-agent-id",
            "seen": "2026-10-08"
          },
          {
            "what": "FAQ, limits and known gaps",
            "url": "https://learn.microsoft.com/en-us/entra/agent-id/faq",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication protocols",
            "url": "https://learn.microsoft.com/en-us/entra/agent-id/agent-oauth-protocols",
            "seen": "2026-10-08"
          },
          {
            "what": "autonomous app flow",
            "url": "https://learn.microsoft.com/en-us/entra/agent-id/agent-autonomous-app-oauth-flow",
            "seen": "2026-10-08"
          },
          {
            "what": "authorisation and blocked roles",
            "url": "https://learn.microsoft.com/en-us/entra/agent-id/authorization-agent-id",
            "seen": "2026-10-08"
          },
          {
            "what": "error codes",
            "url": "https://learn.microsoft.com/en-us/entra/agent-id/error-codes",
            "seen": "2026-10-08"
          },
          {
            "what": "sign-in and audit logs for agents",
            "url": "https://learn.microsoft.com/en-us/entra/agent-id/sign-in-audit-logs-agents",
            "seen": "2026-10-08"
          },
          {
            "what": "create agent identities",
            "url": "https://learn.microsoft.com/en-us/entra/agent-id/create-delete-agent-identities",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server guide",
            "url": "https://learn.microsoft.com/en-us/entra/agent-id/secure-mcp-server-with-entra-id",
            "seen": "2026-10-08"
          },
          {
            "what": "agentIdentity resource, Graph v1.0",
            "url": "https://learn.microsoft.com/en-us/graph/api/resources/agentidentity?view=graph-rest-1.0",
            "seen": "2026-10-08"
          },
          {
            "what": "Create agentIdentity, Graph v1.0",
            "url": "https://learn.microsoft.com/en-us/graph/api/agentidentity-post?view=graph-rest-1.0",
            "seen": "2026-10-08"
          },
          {
            "what": "List agentIdentity query options",
            "url": "https://learn.microsoft.com/en-us/graph/api/agentidentity-list?view=graph-rest-1.0",
            "seen": "2026-10-08"
          },
          {
            "what": "Graph OpenAPI v1.0",
            "url": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
            "seen": "2026-10-08"
          },
          {
            "what": "Graph throttling guidance",
            "url": "https://learn.microsoft.com/en-us/graph/throttling",
            "seen": "2026-10-08"
          },
          {
            "what": "Graph throttling limits",
            "url": "https://learn.microsoft.com/en-us/graph/throttling-limits",
            "seen": "2026-10-08"
          },
          {
            "what": "Graph versioning and breaking change policy",
            "url": "https://learn.microsoft.com/en-us/graph/versioning-and-support",
            "seen": "2026-10-08"
          },
          {
            "what": "Graph changelog",
            "url": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
            "seen": "2026-10-08"
          },
          {
            "what": "Entra release notes",
            "url": "https://learn.microsoft.com/en-us/entra/fundamentals/whats-new",
            "seen": "2026-10-08"
          },
          {
            "what": "Entra SLA performance",
            "url": "https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-sla-performance",
            "seen": "2026-10-08"
          },
          {
            "what": "Azure status history",
            "url": "https://azure.status.microsoft/en-us/status/history/",
            "seen": "2026-10-08"
          },
          {
            "what": "Entra log retention",
            "url": "https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-reports-data-retention",
            "seen": "2026-10-08"
          },
          {
            "what": "Entra data residency",
            "url": "https://learn.microsoft.com/en-us/entra/fundamentals/data-residency",
            "seen": "2026-10-08"
          },
          {
            "what": "Conditional Access for agents, licensing",
            "url": "https://learn.microsoft.com/en-us/entra/identity/conditional-access/agent-id",
            "seen": "2026-10-08"
          },
          {
            "what": "Agent 365 pricing",
            "url": "https://www.microsoft.com/en-us/microsoft-agent-365",
            "seen": "2026-10-08"
          },
          {
            "what": "Entra pricing",
            "url": "https://www.microsoft.com/en-us/security/business/microsoft-entra-pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "Auth SDK sidecar overview",
            "url": "https://learn.microsoft.com/en-us/entra/msidweb/agent-id-sdk/overview",
            "seen": "2026-10-08"
          },
          {
            "what": "Auth SDK sidecar installation",
            "url": "https://learn.microsoft.com/en-us/entra/msidweb/agent-id-sdk/installation",
            "seen": "2026-10-08"
          },
          {
            "what": "microsoft-identity-web repository, tags and changelog",
            "url": "https://github.com/AzureAD/microsoft-identity-web",
            "seen": "2026-10-08"
          },
          {
            "what": "NuGet versions",
            "url": "https://api.nuget.org/v3-flatcontainer/microsoft.identity.web.agentidentities/index.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Microsoft APIs terms of use",
            "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy statement",
            "url": "https://www.microsoft.com/en-us/privacy/privacystatement",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.microsoft.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "identity bounty",
            "url": "https://www.microsoft.com/en-us/msrc/bounty-microsoft-identity",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP",
            "url": "https://rdap.verisign.com/com/v1/domain/microsoft.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the SLA document for Microsoft Entra ID. The link redirected to a general SLA index and we didn't read the availability figure or which licences it covers.",
          "unchecked: whether a new Entra tenant can be created without a payment card.",
          "Whether creating and using agent identities on Entra ID Free carries any charge. The docs say Agent ID is available to all Entra customers and give no per-agent price.",
          "unchecked: the Microsoft Products and Services DPA, the sub-processor list and the Product Terms for Entra and Agent 365.",
          "unchecked: certification reports (SOC 2, ISO 27001) for Entra ID, and reply times on the microsoft-identity-web issue tracker.",
          "unchecked: status.cloud.microsoft, which needs JavaScript. The incident record rests on the Azure status history and Microsoft's own monthly SLA table.",
          "The Agent ID how-to page for creating identities still shows the /beta Graph endpoint while the reference documents the same call on v1.0.",
          "The logs page says audit events carry agentType, while the FAQ says audit logs don't distinguish agent identities by default. We didn't test which is current."
        ]
      },
      "negative": 0,
      "verdict": "Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.",
      "bestFor": "Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.",
      "strengths": [
        "Agent identities can't hold credentials. The blueprint authenticates with a managed identity, certificate or secret and exchanges for the agent's token",
        "Global Administrator and similar roles, and Graph permissions such as Application.ReadWrite.All, are refused for agent identities",
        "Create, list, update, delete and restore are on Microsoft Graph v1.0, with agentIdentity in the public OpenAPI file",
        "Audit and sign-in logs carry an agentType and blueprintId for agent activity",
        "Microsoft.Identity.Web 4.16.0 shipped on 30 September 2026, the eighth tagged release since 9 July"
      ],
      "weaknesses": [
        "Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing",
        "Microsoft's docs call hand-written token exchange complex and error-prone and steer developers to a .NET library or a sidecar container",
        "Creating a blueprint, a principal and an identity in quick succession can fail with 400 until the directory replicates",
        "Audit and sign-in logs are kept seven days on Entra ID Free and 30 days on P1 or P2",
        "microsoft.com's security.txt passed its Expires date on 23 September 2026"
      ],
      "agentNotes": [
        "Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token",
        "Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object",
        "Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required",
        "Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page",
        "Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "BB",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 74.4
        }
      ],
      "editorialScores": {
        "ergonomics": 71,
        "maintenance": 80,
        "payments": 20,
        "reliability": 91,
        "schema": 87,
        "security": 83,
        "transparency": 63
      },
      "provenanceScore": 85
    },
    "connect": {
      "install": "dotnet add package Microsoft.Identity.Web.AgentIdentities",
      "http": "curl -X POST https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity \\\n  -H \"Authorization: Bearer $BLUEPRINT_TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"displayName\": \"My Agent Identity\", \"agentIdentityBlueprintId\": \"\u003cblueprint-app-id\u003e\", \"sponsors@odata.bind\": [\"https://graph.microsoft.com/v1.0/users/\u003cid\u003e\"]}'"
    },
    "letme": {
      "capability": "https://letme.dev/auth.oauth",
      "tool": "https://letme.dev/microsoft-entra-agent-id"
    },
    "sameCompany": [
      "azure-foundry-fine-tuning",
      "azure-ai-content-safety",
      "azure-speech-to-text",
      "azure-text-to-speech",
      "microsoft-agent-framework",
      "microsoft-execution-containers",
      "azure-key-vault",
      "azure-devops-mcp",
      "microsoft-learn-mcp",
      "playwright-mcp",
      "azure-mcp",
      "azure-maps",
      "azure-translator",
      "microsoft-graph-calendar",
      "microsoft-teams",
      "dynamics-365-sales",
      "power-automate",
      "microsoft-advertising-api",
      "microsoft-excel-graph",
      "outlook-mail-graph"
    ],
    "notable": [
      "Agent ID became generally available in April 2026 per the Entra release notes (https://learn.microsoft.com/en-us/entra/fundamentals/whats-new)",
      "An agent identity blueprint can impersonate only its own child agent identities, and each agent identity is single-tenant (https://learn.microsoft.com/en-us/entra/agent-id/agent-autonomous-app-oauth-flow)",
      "Apps outside Microsoft's own platforms that use app-only permissions are capped at 250 agent identities per blueprint, and blueprints can take at most 95 per cent of the tenant's resource quota (https://learn.microsoft.com/en-us/entra/agent-id/faq)",
      "Deleted agent identities are soft-deleted for 30 days and can be restored through Microsoft Graph or PowerShell, not in the admin centre (https://learn.microsoft.com/en-us/entra/agent-id/faq)",
      "The Auth SDK sidecar is a container at mcr.microsoft.com/entra-sdk/auth-sidecar that returns an Authorization header over local HTTP, so agents in any language can use it (https://learn.microsoft.com/en-us/entra/msidweb/agent-id-sdk/overview)",
      "Microsoft documents Entra ID as the authorisation server for an MCP server, with the client sending the RFC 8707 resource parameter (https://learn.microsoft.com/en-us/entra/agent-id/secure-mcp-server-with-entra-id)",
      "The admin consent workflow doesn't work for permissions requested by agent identities, per the FAQ (https://learn.microsoft.com/en-us/entra/agent-id/faq)"
    ],
    "area": "agent-runtime",
    "details": [
      {
        "label": "Objects",
        "value": "Agent identity blueprint (a template, like an app registration), blueprint principal, agent identity (a service principal subtype) and an optional agent's user account paired one to one with an agent identity"
      },
      {
        "label": "Token flows",
        "value": "Autonomous app-only (client_credentials), on behalf of a user (jwt-bearer), and the agent's own user account. Refresh tokens for background user-delegated work. No interactive `/authorize` flow and no public clients"
      },
      {
        "label": "Credentials",
        "value": "Held by the blueprint only. Managed identity as a federated identity credential (preferred), client certificate, or client secret for local development"
      },
      {
        "label": "Management API",
        "value": "Microsoft Graph v1.0 at /servicePrincipals/microsoft.graph.agentIdentity for list, create, get, update, delete, owners, sponsors and restore. Inherited permissions, attest and communication configuration are on /beta only"
      },
      {
        "label": "Permissions",
        "value": "AgentIdentity.Create.All (least privileged), AgentIdentity.CreateAsManager, AgentIdentity.ReadWrite.All. Roles Agent ID Developer and Agent ID Administrator"
      },
      {
        "label": "Blocked for agents",
        "value": "Global Administrator, Privileged Role Administrator, User Administrator and role-assignable groups. Graph permissions including Application.ReadWrite.All, RoleManagement.ReadWrite.All, User.ReadWrite.All and Directory.AccessAsUser.All"
      },
      {
        "label": "Rate limits",
        "value": "Graph identity and access limits by token bucket. Per app and tenant, 3,500 to 8,000 resource units per 10 seconds by tenant size and 3,000 writes per 2 minutes 30 seconds. Per tenant, 18,000 writes per 5 minutes. 429 carries Retry-After"
      },
      {
        "label": "Quotas",
        "value": "250 agent identities per blueprint for outside platforms using app-only permissions, 250 owned objects per non-admin user, blueprints at most 95 per cent of tenant quota"
      },
      {
        "label": "SDKs",
        "value": "Microsoft.Identity.Web.AgentIdentities 4.16.0 on NuGet (.NET), the Auth SDK sidecar container for other languages, Microsoft Graph SDKs and Entra PowerShell for management"
      },
      {
        "label": "Logs",
        "value": "Audit and sign-in logs with agentType and blueprintId. Kept seven days on Entra ID Free and 30 days on P1 or P2, longer if routed to Azure storage"
      },
      {
        "label": "Paid controls",
        "value": "Conditional Access, ID Protection, ID Governance and network controls for agents need Microsoft Agent 365 or Microsoft 365 E7"
      },
      {
        "label": "Third-party agents",
        "value": "Guides for Amazon Bedrock and n8n through the sidecar or workload identity federation"
      },
      {
        "label": "Deprecation",
        "value": "Microsoft Graph gives at least 24 months' notice before retiring a generally available API or version. /beta can change without notice"
      }
    ],
    "unitPrices": [
      {
        "item": "Microsoft Agent 365",
        "unit": "seat-month",
        "usd": 15,
        "note": "billed yearly, needed for Conditional Access, ID Protection and governance for agents"
      },
      {
        "item": "Microsoft 365 E7 (includes Agent 365)",
        "unit": "seat-month",
        "usd": 99,
        "note": "billed yearly"
      }
    ],
    "provenance": {
      "legalEntity": "Microsoft Corporation",
      "domain": "microsoft.com",
      "domainRegistered": "1991-05-02",
      "endpointOnVendorDomain": true,
      "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
      "privacy": "https://www.microsoft.com/en-us/privacy/privacystatement",
      "statusPage": "https://azure.status.microsoft/en-us/status/history/",
      "changelog": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
      "securityTxt": "expired",
      "checked": "2026-10-08",
      "notes": [
        "www.microsoft.com/.well-known/security.txt carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08.",
        "The Microsoft APIs terms of use cover the Microsoft Graph API and other APIs that reach directory data, and were last updated in October 2025. Tenant use of Entra also falls under the customer's Microsoft licensing agreement and the Product Terms, which we didn't read.",
        "The Microsoft privacy statement was last updated in September 2026.",
        "Tokens come from login.microsoftonline.com and management calls go to graph.microsoft.com, both Microsoft domains.",
        "Entra's SLA page sends readers to the Azure status history for incidents that affect Entra ID.",
        "RDAP for microsoft.com gives a registration date of 1991-05-02."
      ],
      "score": 85,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Microsoft Corporation",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "microsoft.com, registered 1991-05-02 (35 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "graph.microsoft.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points",
          "points": 2.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects, and has 1 clause that costs points",
          "points": 8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "azure.status.microsoft/en-us/status/history",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "published but past its Expires date",
          "points": 5,
          "max": 10,
          "state": "part"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-10-01",
          "words": 4555,
          "points": 2.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: October 2025 What's new?",
              "says": "Last updated 2025-10-01"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "WE MAKE NO WARRANTIES, EXPRESS OR IMPLIED, GUARANTEES OR CONDITIONS WITH RESPECT TO YOUR USE OF THE MICROSOFT APIs."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "We may change, amend or terminate these API Terms at any time."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Unless you have use permissions expressly and specifically granted by Customers in connection with using your Application, you may not use Microsoft email protocols and APIs for any purpose other than:"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "Scrape, build databases or otherwise create copies of any data accessed or obtained using the Microsoft APIs, except as necessary to enable an intended usage scenario for your Application;",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "Use the Microsoft APIs, or any data obtained using the Microsoft APIs, to conduct performance testing of a Microsoft Offering unless expressly permitted by Microsoft",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We may suspend or immediately terminate these API Terms, any rights granted herein, and/or your license to the Microsoft APIs, in our sole discretion at any time, for any reason."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Recoverable damages are limited to direct damages of up to 5 US dollars in total.",
              "quote": "YOU AGREE THAT YOUR EXCLUSIVE REMEDY IS TO RECOVER, FROM MICROSOFT OR ANY AFFILIATES, RESELLERS, DISTRIBUTORS, SUPPLIERS (AND RESPECTIVE EMPLOYEES, SHAREHOLDERS, OR DIRECTORS) AND VENDORS, ONLY DIRECT DAMAGES UP TO USD $5.00 COLLECTIVELY."
            },
            {
              "date": "2026-10-08",
              "text": "After a data breach involving the Microsoft APIs, the developer may make no public statement about it without Microsoft's prior written permission.",
              "quote": "You agree to refrain from making public statements (e.g., press, blogs, social media, bulletin boards, etc.) without prior written and express permission from Microsoft in each instance as it relates to the Microsoft APIs."
            },
            {
              "date": "2026-10-08",
              "text": "The developer must allow Microsoft reasonable access to its application so Microsoft can monitor compliance with the API terms.",
              "quote": "You will permit Microsoft reasonable access to your Application for purposes of monitoring compliance with these API Terms."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-01",
          "words": 33580,
          "points": 8,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: September 2026",
              "says": "Last updated 2026-09-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "The data we collect depends on the context of your interactions with Microsoft and the choices you make, including your privacy settings and the products and features you use."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "When you delete an email or item from a mailbox in Outlook.com, the item generally goes into your Deleted Items folder where it remains for approximately 7 days unless you move it back to your inbox, you empty the folder, or the service empties the folder automatically, whichever comes first.",
              "says": "Names a period of 7 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Service providers that help us determine your device’s location."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "not use or share student personal data for advertising or similar commercial purposes, such as providing personalized advertising to students;"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "State Data Privacy Notice (including notice at collection details) and the Consumer Health Data Privacy Policy for additional information about your rights and the processing of your personal data."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have a privacy concern, complaint, or question for the Microsoft privacy team or Data Protection Officer, please visit our privacy support and requests page and click on “Contact the Microsoft privacy team or the Microsoft Data Protection Officer” menu.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "In such cases, we implement legal safeguards-such as standard contractual clauses approved by the European Commission – to help protect your rights and ensure your data remains protected.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "training",
              "label": "Says it may use customer content to train or improve models, and no opt-out was found",
              "found": true,
              "quote": "As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models.",
              "costsPoints": true
            },
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "We also disclose personal data for digital advertising purposes."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict.",
              "quote": "In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control."
            },
            {
              "date": "2026-10-08",
              "text": "Prompts and related data sent to the consumer Microsoft Copilot are used to improve services and for relevant advertising.",
              "quote": "Microsoft Copilot also uses prompts and related data to provide and improve services, including relevant advertising."
            },
            {
              "date": "2026-10-08",
              "text": "Microsoft staff manually review some results of its automated systems, including AI, against the source data.",
              "quote": "For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.json",
    "live": {
      "slug": "microsoft-entra-agent-id",
      "probe": {
        "target": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
        "method": "get",
        "lastAt": "2026-10-08T19:52:56.035923923Z",
        "lastOk": true,
        "lastStatus": 401,
        "lastMs": 30,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 32,
        "p95ms24h": 97,
        "samples24h": 27,
        "samples30d": 27,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 27,
            "ok": 27
          }
        ]
      },
      "vendorStatus": {
        "page": "https://azure.status.microsoft/en-us/status/history",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T19:38:47.070808325Z"
      },
      "pages": [
        {
          "url": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:21:36.290153566Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "bca4f93493d4"
        },
        {
          "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
          "kind": "terms",
          "status": 304,
          "checkedAt": "2026-10-08T18:21:38.182590643Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "1a1ee1c20d9a"
        }
      ],
      "updatedAt": "2026-10-08T19:52:56.035923923Z"
    }
  }
}
