# Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID > Amazon Bedrock AgentCore Identity and Microsoft Entra Agent ID score within a point of each other on agent readiness, 74.8 (BB) and 74.4 (BB). Microsoft Entra Agent ID leads on reliability and maintenance & community. Both do auth oauth. Category scores, facts, verdicts and… - Canonical: https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id - Markdown: https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.md (~2,850 tokens) - Slim: https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.min.md (~730 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 Amazon Bedrock AgentCore Identity and Microsoft Entra Agent ID score within a point of each other on agent readiness, 74.8 (BB) and 74.4 (BB). Microsoft Entra Agent ID leads on reliability and maintenance & community. Both do auth oauth. - Amazon Bedrock AgentCore Identity: grade BB, 74.8/100, rank #64 of 842. Markdown https://www.anchorterminal.com/tools/agentcore-identity.md · JSON https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json - Microsoft Entra Agent ID: grade BB, 74.4/100, rank #71 of 842. Markdown https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json ## Which one, for what ### Amazon Bedrock AgentCore Identity (BB) Good for: Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge. Ahead on: - Agent ergonomics, 76 against 71 - Payments & pricing, 30 against 20 Watch for: No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider. ### Microsoft Entra Agent ID (BB) Good for: Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs. Ahead on: - Reliability, 91 against 85 - Maintenance & community, 80 against 70 Watch for: Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing ## Score by category | Category | Weight | Amazon Bedrock AgentCore Identity | Microsoft Entra Agent ID | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 85 | 91 | Microsoft Entra Agent ID +6 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 88 | 87 | Amazon Bedrock AgentCore Identity +1 | | Agent ergonomics | 13% (16.2 this run) | 76 | 71 | Amazon Bedrock AgentCore Identity +5 | | Security & auth | 14% (17.5 this run) | 84 | 83 | Amazon Bedrock AgentCore Identity +1 | | Payments & pricing | 10% (12.5 this run) | 30 | 20 | Amazon Bedrock AgentCore Identity +10 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 70 | 80 | Microsoft Entra Agent ID +10 | | Transparency & trust | 7% (8.8 this run) | 75 | 74 | Amazon Bedrock AgentCore Identity +1 | | Negative events | ≤15 | 0 | 0 | | | **Total** | | **74.8 · BB** | **74.4 · BB** | | ## Facts side by side | Fact | Amazon Bedrock AgentCore Identity | Microsoft Entra Agent ID | | --- | --- | --- | | Kind | HTTP API | HTTP API | | Vendor | Amazon Web Services | Microsoft | | Hosted endpoint | `https://bedrock-agentcore.us-east-1.amazonaws.com` | `https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity` | | Transports | HTTP | HTTP | | Auth | OAuth or key | OAuth | | Pricing | Pay per use | Freemium | | Price for auth oauth | $0.01 per 1,000 requests | not published | | x402 | no | no | | Licence | Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0 | Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT | | Read-only variant documented | no | no | | llms.txt | yes | no | | Last release | 2026-09-01 | 2026-09-30 | | Terms last updated | 2026-10-01 | 2025-10-01 | | Privacy policy last updated | 2026-05-18 | 2026-09-01 | | Customer content may train models | yes, with an opt-out | yes | | Terms restrict automated access | yes | yes | | Terms restrict benchmarking | yes | yes | | Terms or service can change without notice | yes | yes | | Arbitration or class-action waiver | not found in the text | not found in the text | | Popularity | 335k npm/wk, 1.4M PyPI/wk | 787 stars | ## Verdicts **Amazon Bedrock AgentCore Identity.** The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference. **Microsoft Entra Agent ID.** Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence. ## Before you call either ### Amazon Bedrock AgentCore Identity 1. Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`. 2. When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent. 3. For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session. 4. Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian. 5. Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true. ### Microsoft Entra Agent ID 1. Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token 2. Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object 3. Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required 4. Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page 5. Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it ## Questions ### Which is better for AI agents, Amazon Bedrock AgentCore Identity or Microsoft Entra Agent ID? Amazon Bedrock AgentCore Identity and Microsoft Entra Agent ID score within a point of each other on agent readiness, 74.8 (BB) and 74.4 (BB). Microsoft Entra Agent ID leads on reliability and maintenance & community. ### Do Amazon Bedrock AgentCore Identity and Microsoft Entra Agent ID need an API key? Amazon Bedrock AgentCore Identity takes an API key or an OAuth sign-in. Microsoft Entra Agent ID uses an OAuth sign-in. ### Can an agent call Amazon Bedrock AgentCore Identity and Microsoft Entra Agent ID without installing anything? Yes. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com and Microsoft Entra Agent ID at https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity. ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.json, and with the fewest tokens: https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "agentcore-identity", "b": "microsoft-entra-agent-id"}`. From a terminal: `anchor compare agentcore-identity microsoft-entra-agent-id` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json and https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json ## Other comparisons with Amazon Bedrock AgentCore Identity or Microsoft Entra Agent ID - [Aembit vs Amazon Bedrock AgentCore Identity](https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.md) - [Aembit vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.md) - [Amazon Bedrock AgentCore Identity vs Arcade.dev](https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.md) - [Amazon Bedrock AgentCore Identity vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents.md) - [Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.md) - [Amazon Bedrock AgentCore Identity vs Keycard](https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.md) - [Amazon Bedrock AgentCore Identity vs Nango](https://www.anchorterminal.com/compare/agentcore-identity-vs-nango.md) - [Amazon Bedrock AgentCore Identity vs Scalekit AgentKit](https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.md) - [Amazon Bedrock AgentCore Identity vs Stytch Connected Apps](https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.md) - [Amazon Bedrock AgentCore Identity vs Vercel Connect](https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.md) - [Amazon Bedrock AgentCore Identity vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes.md) - [Arcade.dev vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.md) - [Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.md) - [Descope Agentic Identity Hub vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.md) - [Keycard vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.md) - [Microsoft Entra Agent ID vs Nango](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.md) - [Microsoft Entra Agent ID vs Scalekit AgentKit](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.md) - [Microsoft Entra Agent ID vs Stytch Connected Apps](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.md) - [Microsoft Entra Agent ID vs Vercel Connect](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-vercel-connect.md) - [Microsoft Entra Agent ID vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.md)