{
  "data": {
    "similar": [
      {
        "grade": "A",
        "json": "https://www.anchorterminal.com/tools/descope-agentic-identity.json",
        "name": "Descope Agentic Identity Hub",
        "score": 78.1,
        "shared": [
          "auth.oauth",
          "auth.consent",
          "auth.agent-identity",
          "auth.audit"
        ],
        "slug": "descope-agentic-identity"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/aembit.json",
        "name": "Aembit",
        "score": 70.5,
        "shared": [
          "auth.oauth",
          "auth.agent-identity",
          "auth.consent",
          "auth.audit"
        ],
        "slug": "aembit"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/workos-pipes.json",
        "name": "WorkOS Pipes and Agents",
        "score": 59.9,
        "shared": [
          "auth.oauth",
          "auth.consent",
          "auth.agent-identity",
          "auth.audit"
        ],
        "slug": "workos-pipes"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/keycard.json",
        "name": "Keycard",
        "score": 56.2,
        "shared": [
          "auth.oauth",
          "auth.consent",
          "auth.agent-identity",
          "auth.audit"
        ],
        "slug": "keycard"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/permit-mcp-gateway.json",
        "name": "Permit MCP Gateway",
        "score": 54.1,
        "shared": [
          "auth.oauth",
          "auth.consent",
          "auth.agent-identity",
          "auth.audit"
        ],
        "slug": "permit-mcp-gateway"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/scalekit-agentkit.json",
        "name": "Scalekit AgentKit",
        "score": 71.9,
        "shared": [
          "auth.oauth",
          "auth.consent",
          "auth.agent-identity"
        ],
        "slug": "scalekit-agentkit"
      }
    ],
    "tool": {
      "slug": "microsoft-entra-agent-id",
      "name": "Microsoft Entra Agent ID",
      "vendor": "Microsoft",
      "vendorUrl": "https://learn.microsoft.com/en-us/entra/agent-id/",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Microsoft Entra Agent ID is an identity type for AI agents in Microsoft Entra ID. Agents get their own directory identity, request OAuth 2.0 tokens autonomously or on behalf of a user, and are managed through Microsoft Graph.",
      "url": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json",
      "repo": "https://github.com/AzureAD/microsoft-identity-web",
      "license": "Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
      "packages": [
        {
          "registry": "nuget",
          "name": "Microsoft.Identity.Web.AgentIdentities"
        }
      ],
      "auth": "oauth",
      "authNotes": "Access starts with a Microsoft Entra tenant and a person holding the Agent ID Developer or Agent ID Administrator role, who creates an agent identity blueprint. The blueprint authenticates to login.microsoftonline.com with a managed identity, a certificate or a client secret (Microsoft advises against secrets in production) and exchanges for a token as one of its agent identities. Agent identities hold no credentials. Three flows exist, which are app-only, on behalf of a signed-in user, and as the agent's own user account. Interactive `/authorize` and public clients aren't supported. Management calls on Microsoft Graph need AgentIdentity.Create.All or AgentIdentity.ReadWrite.All.",
      "pricing": "freemium",
      "pricingNotes": "Microsoft's docs say Agent ID is available to all Microsoft Entra customers, and Entra ID Free comes with any Microsoft cloud subscription. No per-agent price is published. Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15.00 a user a month on yearly billing, or Microsoft 365 E7 at $99.00. Conditional Access for agents also needs Entra P1 or Microsoft 365 E3 alongside Agent 365. No sandbox was found in the Agent ID docs (https://www.microsoft.com/en-us/microsoft-agent-365, checked 2026-10-08).",
      "priceSummary": "$15 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Agent ID docs, the Graph reference or the pricing pages (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 787,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/entra/agent-id/",
      "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.agent-identity",
        "auth.consent",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "oauth",
        "openapi",
        "dotnet",
        "sidecar",
        "microsoft-graph",
        "mcp",
        "freemium",
        "sla"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 74.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 63,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 80,
          "payments": 20,
          "reliability": 91,
          "schema": 87,
          "security": 83,
          "transparency": 74
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 91,
            "points": 18.2,
            "reason": "Microsoft's SLA page for Entra ID points to the Azure status history for incidents, and that page was readable with dated entries and reviews (20). The last 90 days show three Azure incidents, on 23 July, 29 September and 30 September 2026. None names Entra ID, the 23 July West US network fault lists Azure AD B2C, and Microsoft reports 99.999 per cent authentication availability for July, August and September. We scored between clean and minor because the page lists only wide incidents (25). Graph identity limits are published as numbers, such as 3,000 writes per 2 minutes 30 seconds per app and tenant (15). 429 carries Retry-After and the FAQ asks for exponential backoff, but there is no idempotency key and back-to-back creates can fail with 400 during replication (11). An SLA for Microsoft Entra ID is published and attainment is reported monthly. The SLA document itself didn't load for us (10). Agent ID has been generally available since April 2026 and the agentIdentity API is on Graph v1.0 (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 87,
            "points": 14.14,
            "reason": "agentIdentity is in Microsoft's public Graph v1.0 OpenAPI file (25). learn.microsoft.com returns Markdown when asked with `Accept: text/markdown`, but learn.microsoft.com/llms.txt returned 404 (8). Concept, design-pattern and best-practice pages say when to use each flow and when to pick the sidecar over the .NET library (16). Graph resources are typed with required fields listed, though agentIdentity is an open type that inherits servicePrincipal properties that don't all apply (12). Request and response examples on each reference page and a list of 17 Agent ID error codes, without the HTTP status for each (11). v1.0 and beta versioning with a monthly dated Graph changelog and Entra release notes (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 71,
            "points": 11.54,
            "reason": "List calls take `$select`, `$top`, `$filter`, `$search` and `$count`, with a default and maximum page of 100 (20). OData paging and filtering work on the main collection, but ownedObjects, deletedItems and owners can't filter by agent type and need client-side filtering (17). Named error codes such as `AgentIdentity_CredentialsNotSupported` say what to change (16). No idempotency key for creates, and sequential creates need retries. Token requests are safe to repeat (8). Creating an identity needs three fields, but getting a token is a two-step exchange that Microsoft's docs call complex and error-prone by hand, with an in-process library only for .NET and a sidecar container for everything else (10)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 83,
            "points": 14.53,
            "reason": "OAuth 2.0 with scoped Graph permissions. Agent identities can't hold credentials, the blueprint signs in with a managed identity or certificate, and client secrets are allowed but warned against (30). Entra refuses high-privilege roles and permissions such as Application.ReadWrite.All for agents, and an identity can be disabled. Conditional Access for agents needs an Agent 365 licence, and nothing asks a person to approve a destructive call (16). The service returns tokens and directory objects, not untrusted content (10). Audit and sign-in logs carry agentType and blueprintId, kept seven days on Free and 30 on P1 or P2, while the FAQ says Graph activity logs don't separate agents (12). MSRC disclosure policy and an identity bounty of $750 to $100,000, but microsoft.com's security.txt expired on 23 September 2026 and we didn't read certification reports (15)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 20,
            "points": 2.5,
            "reason": "No x402, MPP or L402 (0). Agent 365 is listed at $15 a user a month and Microsoft 365 E7 at $99, and the docs say Agent ID is available to all Entra customers, but no page gives a per-agent price or says plainly which parts are free (10). Entra ID Free comes with a Microsoft cloud subscription. We didn't establish whether a new tenant can be opened without a card, so this line gets half (10). A person creates the tenant, holds an Agent ID role and creates the blueprint before any agent can act (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 80,
            "points": 7,
            "reason": "Microsoft.Identity.Web 4.16.0, which carries the agent identity package and the sidecar, was tagged on 30 September 2026, and the Agent ID FAQ was updated on 1 October (30). Eight tags from 4.13.0 on 9 July to 4.16.0, and Graph changelog entries for agent identities in August and September (20). A closed service with public release notes and a public SDK tracker showing 340 open issues. We didn't read reply times (10). The current in-process SDK is .NET only, with the sidecar container for other languages (12). Azure Pipelines and CodeQL are configured, and 4.14.x raised dependencies for four CVEs (8)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 74,
            "points": 6.48,
            "note": "editorial 63, provenance 85",
            "reason": "Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDK source (15). The privacy statement was updated in September 2026, Entra publishes a data residency page and log retention periods, and we didn't read the DPA (20). Microsoft Graph gives at least 24 months' notice before retiring a GA API or version, while several Agent ID operations are still on /beta, which can change without notice (18). Entra documents where tenant data is stored by geography. We didn't read the sub-processor list (10)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "List calls take `$select`, `$top`, `$filter`, `$search` and `$count`, with a default and maximum page of 100 (20). OData paging and filtering work on the main collection, but ownedObjects, deletedItems and owners can't filter by agent type and need client-side filtering (17). Named error codes such as `AgentIdentity_CredentialsNotSupported` say what to change (16). No idempotency key for creates, and sequential creates need retries. Token requests are safe to repeat (8). Creating an identity needs three fields, but getting a token is a two-step exchange that Microsoft's docs call complex and error-prone by hand, with an in-process library only for .NET and a sidecar container for everything else (10).",
            "maintenance": "Microsoft.Identity.Web 4.16.0, which carries the agent identity package and the sidecar, was tagged on 30 September 2026, and the Agent ID FAQ was updated on 1 October (30). Eight tags from 4.13.0 on 9 July to 4.16.0, and Graph changelog entries for agent identities in August and September (20). A closed service with public release notes and a public SDK tracker showing 340 open issues. We didn't read reply times (10). The current in-process SDK is .NET only, with the sidecar container for other languages (12). Azure Pipelines and CodeQL are configured, and 4.14.x raised dependencies for four CVEs (8).",
            "payments": "No x402, MPP or L402 (0). Agent 365 is listed at $15 a user a month and Microsoft 365 E7 at $99, and the docs say Agent ID is available to all Entra customers, but no page gives a per-agent price or says plainly which parts are free (10). Entra ID Free comes with a Microsoft cloud subscription. We didn't establish whether a new tenant can be opened without a card, so this line gets half (10). A person creates the tenant, holds an Agent ID role and creates the blueprint before any agent can act (0).",
            "reliability": "Microsoft's SLA page for Entra ID points to the Azure status history for incidents, and that page was readable with dated entries and reviews (20). The last 90 days show three Azure incidents, on 23 July, 29 September and 30 September 2026. None names Entra ID, the 23 July West US network fault lists Azure AD B2C, and Microsoft reports 99.999 per cent authentication availability for July, August and September. We scored between clean and minor because the page lists only wide incidents (25). Graph identity limits are published as numbers, such as 3,000 writes per 2 minutes 30 seconds per app and tenant (15). 429 carries Retry-After and the FAQ asks for exponential backoff, but there is no idempotency key and back-to-back creates can fail with 400 during replication (11). An SLA for Microsoft Entra ID is published and attainment is reported monthly. The SLA document itself didn't load for us (10). Agent ID has been generally available since April 2026 and the agentIdentity API is on Graph v1.0 (10).",
            "schema": "agentIdentity is in Microsoft's public Graph v1.0 OpenAPI file (25). learn.microsoft.com returns Markdown when asked with `Accept: text/markdown`, but learn.microsoft.com/llms.txt returned 404 (8). Concept, design-pattern and best-practice pages say when to use each flow and when to pick the sidecar over the .NET library (16). Graph resources are typed with required fields listed, though agentIdentity is an open type that inherits servicePrincipal properties that don't all apply (12). Request and response examples on each reference page and a list of 17 Agent ID error codes, without the HTTP status for each (11). v1.0 and beta versioning with a monthly dated Graph changelog and Entra release notes (15).",
            "security": "OAuth 2.0 with scoped Graph permissions. Agent identities can't hold credentials, the blueprint signs in with a managed identity or certificate, and client secrets are allowed but warned against (30). Entra refuses high-privilege roles and permissions such as Application.ReadWrite.All for agents, and an identity can be disabled. Conditional Access for agents needs an Agent 365 licence, and nothing asks a person to approve a destructive call (16). The service returns tokens and directory objects, not untrusted content (10). Audit and sign-in logs carry agentType and blueprintId, kept seven days on Free and 30 on P1 or P2, while the FAQ says Graph activity logs don't separate agents (12). MSRC disclosure policy and an identity bounty of $750 to $100,000, but microsoft.com's security.txt expired on 23 September 2026 and we didn't read certification reports (15).",
            "transparency": "Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDK source (15). The privacy statement was updated in September 2026, Entra publishes a data residency page and log retention periods, and we didn't read the DPA (20). Microsoft Graph gives at least 24 months' notice before retiring a GA API or version, while several Agent ID operations are still on /beta, which can change without notice (18). Entra documents where tenant data is stored by geography. We didn't read the sub-processor list (10)."
          },
          "sources": [
            {
              "what": "What is Microsoft Entra Agent ID",
              "url": "https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id",
              "seen": "2026-10-08"
            },
            {
              "what": "agent identities concept and licensing",
              "url": "https://learn.microsoft.com/en-us/entra/agent-id/what-are-agent-identities",
              "seen": "2026-10-08"
            },
            {
              "what": "what's new in Agent ID",
              "url": "https://learn.microsoft.com/en-us/entra/agent-id/whats-new-agent-id",
              "seen": "2026-10-08"
            },
            {
              "what": "FAQ, limits and known gaps",
              "url": "https://learn.microsoft.com/en-us/entra/agent-id/faq",
              "seen": "2026-10-08"
            },
            {
              "what": "authentication protocols",
              "url": "https://learn.microsoft.com/en-us/entra/agent-id/agent-oauth-protocols",
              "seen": "2026-10-08"
            },
            {
              "what": "autonomous app flow",
              "url": "https://learn.microsoft.com/en-us/entra/agent-id/agent-autonomous-app-oauth-flow",
              "seen": "2026-10-08"
            },
            {
              "what": "authorisation and blocked roles",
              "url": "https://learn.microsoft.com/en-us/entra/agent-id/authorization-agent-id",
              "seen": "2026-10-08"
            },
            {
              "what": "error codes",
              "url": "https://learn.microsoft.com/en-us/entra/agent-id/error-codes",
              "seen": "2026-10-08"
            },
            {
              "what": "sign-in and audit logs for agents",
              "url": "https://learn.microsoft.com/en-us/entra/agent-id/sign-in-audit-logs-agents",
              "seen": "2026-10-08"
            },
            {
              "what": "create agent identities",
              "url": "https://learn.microsoft.com/en-us/entra/agent-id/create-delete-agent-identities",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server guide",
              "url": "https://learn.microsoft.com/en-us/entra/agent-id/secure-mcp-server-with-entra-id",
              "seen": "2026-10-08"
            },
            {
              "what": "agentIdentity resource, Graph v1.0",
              "url": "https://learn.microsoft.com/en-us/graph/api/resources/agentidentity?view=graph-rest-1.0",
              "seen": "2026-10-08"
            },
            {
              "what": "Create agentIdentity, Graph v1.0",
              "url": "https://learn.microsoft.com/en-us/graph/api/agentidentity-post?view=graph-rest-1.0",
              "seen": "2026-10-08"
            },
            {
              "what": "List agentIdentity query options",
              "url": "https://learn.microsoft.com/en-us/graph/api/agentidentity-list?view=graph-rest-1.0",
              "seen": "2026-10-08"
            },
            {
              "what": "Graph OpenAPI v1.0",
              "url": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
              "seen": "2026-10-08"
            },
            {
              "what": "Graph throttling guidance",
              "url": "https://learn.microsoft.com/en-us/graph/throttling",
              "seen": "2026-10-08"
            },
            {
              "what": "Graph throttling limits",
              "url": "https://learn.microsoft.com/en-us/graph/throttling-limits",
              "seen": "2026-10-08"
            },
            {
              "what": "Graph versioning and breaking change policy",
              "url": "https://learn.microsoft.com/en-us/graph/versioning-and-support",
              "seen": "2026-10-08"
            },
            {
              "what": "Graph changelog",
              "url": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
              "seen": "2026-10-08"
            },
            {
              "what": "Entra release notes",
              "url": "https://learn.microsoft.com/en-us/entra/fundamentals/whats-new",
              "seen": "2026-10-08"
            },
            {
              "what": "Entra SLA performance",
              "url": "https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-sla-performance",
              "seen": "2026-10-08"
            },
            {
              "what": "Azure status history",
              "url": "https://azure.status.microsoft/en-us/status/history/",
              "seen": "2026-10-08"
            },
            {
              "what": "Entra log retention",
              "url": "https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-reports-data-retention",
              "seen": "2026-10-08"
            },
            {
              "what": "Entra data residency",
              "url": "https://learn.microsoft.com/en-us/entra/fundamentals/data-residency",
              "seen": "2026-10-08"
            },
            {
              "what": "Conditional Access for agents, licensing",
              "url": "https://learn.microsoft.com/en-us/entra/identity/conditional-access/agent-id",
              "seen": "2026-10-08"
            },
            {
              "what": "Agent 365 pricing",
              "url": "https://www.microsoft.com/en-us/microsoft-agent-365",
              "seen": "2026-10-08"
            },
            {
              "what": "Entra pricing",
              "url": "https://www.microsoft.com/en-us/security/business/microsoft-entra-pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "Auth SDK sidecar overview",
              "url": "https://learn.microsoft.com/en-us/entra/msidweb/agent-id-sdk/overview",
              "seen": "2026-10-08"
            },
            {
              "what": "Auth SDK sidecar installation",
              "url": "https://learn.microsoft.com/en-us/entra/msidweb/agent-id-sdk/installation",
              "seen": "2026-10-08"
            },
            {
              "what": "microsoft-identity-web repository, tags and changelog",
              "url": "https://github.com/AzureAD/microsoft-identity-web",
              "seen": "2026-10-08"
            },
            {
              "what": "NuGet versions",
              "url": "https://api.nuget.org/v3-flatcontainer/microsoft.identity.web.agentidentities/index.json",
              "seen": "2026-10-08"
            },
            {
              "what": "Microsoft APIs terms of use",
              "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy statement",
              "url": "https://www.microsoft.com/en-us/privacy/privacystatement",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://www.microsoft.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "identity bounty",
              "url": "https://www.microsoft.com/en-us/msrc/bounty-microsoft-identity",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP",
              "url": "https://rdap.verisign.com/com/v1/domain/microsoft.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the SLA document for Microsoft Entra ID. The link redirected to a general SLA index and we didn't read the availability figure or which licences it covers.",
            "unchecked: whether a new Entra tenant can be created without a payment card.",
            "Whether creating and using agent identities on Entra ID Free carries any charge. The docs say Agent ID is available to all Entra customers and give no per-agent price.",
            "unchecked: the Microsoft Products and Services DPA, the sub-processor list and the Product Terms for Entra and Agent 365.",
            "unchecked: certification reports (SOC 2, ISO 27001) for Entra ID, and reply times on the microsoft-identity-web issue tracker.",
            "unchecked: status.cloud.microsoft, which needs JavaScript. The incident record rests on the Azure status history and Microsoft's own monthly SLA table.",
            "The Agent ID how-to page for creating identities still shows the /beta Graph endpoint while the reference documents the same call on v1.0.",
            "The logs page says audit events carry agentType, while the FAQ says audit logs don't distinguish agent identities by default. We didn't test which is current."
          ]
        },
        "negative": 0,
        "verdict": "Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.",
        "bestFor": "Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.",
        "strengths": [
          "Agent identities can't hold credentials. The blueprint authenticates with a managed identity, certificate or secret and exchanges for the agent's token",
          "Global Administrator and similar roles, and Graph permissions such as Application.ReadWrite.All, are refused for agent identities",
          "Create, list, update, delete and restore are on Microsoft Graph v1.0, with agentIdentity in the public OpenAPI file",
          "Audit and sign-in logs carry an agentType and blueprintId for agent activity",
          "Microsoft.Identity.Web 4.16.0 shipped on 30 September 2026, the eighth tagged release since 9 July"
        ],
        "weaknesses": [
          "Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing",
          "Microsoft's docs call hand-written token exchange complex and error-prone and steer developers to a .NET library or a sidecar container",
          "Creating a blueprint, a principal and an identity in quick succession can fail with 400 until the directory replicates",
          "Audit and sign-in logs are kept seven days on Entra ID Free and 30 days on P1 or P2",
          "microsoft.com's security.txt passed its Expires date on 23 September 2026"
        ],
        "agentNotes": [
          "Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token",
          "Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object",
          "Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required",
          "Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page",
          "Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 74.4
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 80,
          "payments": 20,
          "reliability": 91,
          "schema": 87,
          "security": 83,
          "transparency": 63
        },
        "provenanceScore": 85
      },
      "connect": {
        "install": "dotnet add package Microsoft.Identity.Web.AgentIdentities",
        "http": "curl -X POST https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity \\\n  -H \"Authorization: Bearer $BLUEPRINT_TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"displayName\": \"My Agent Identity\", \"agentIdentityBlueprintId\": \"\u003cblueprint-app-id\u003e\", \"sponsors@odata.bind\": [\"https://graph.microsoft.com/v1.0/users/\u003cid\u003e\"]}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/microsoft-entra-agent-id"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "azure-key-vault",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "notable": [
        "Agent ID became generally available in April 2026 per the Entra release notes (https://learn.microsoft.com/en-us/entra/fundamentals/whats-new)",
        "An agent identity blueprint can impersonate only its own child agent identities, and each agent identity is single-tenant (https://learn.microsoft.com/en-us/entra/agent-id/agent-autonomous-app-oauth-flow)",
        "Apps outside Microsoft's own platforms that use app-only permissions are capped at 250 agent identities per blueprint, and blueprints can take at most 95 per cent of the tenant's resource quota (https://learn.microsoft.com/en-us/entra/agent-id/faq)",
        "Deleted agent identities are soft-deleted for 30 days and can be restored through Microsoft Graph or PowerShell, not in the admin centre (https://learn.microsoft.com/en-us/entra/agent-id/faq)",
        "The Auth SDK sidecar is a container at mcr.microsoft.com/entra-sdk/auth-sidecar that returns an Authorization header over local HTTP, so agents in any language can use it (https://learn.microsoft.com/en-us/entra/msidweb/agent-id-sdk/overview)",
        "Microsoft documents Entra ID as the authorisation server for an MCP server, with the client sending the RFC 8707 resource parameter (https://learn.microsoft.com/en-us/entra/agent-id/secure-mcp-server-with-entra-id)",
        "The admin consent workflow doesn't work for permissions requested by agent identities, per the FAQ (https://learn.microsoft.com/en-us/entra/agent-id/faq)"
      ],
      "area": "agent-runtime",
      "details": [
        {
          "label": "Objects",
          "value": "Agent identity blueprint (a template, like an app registration), blueprint principal, agent identity (a service principal subtype) and an optional agent's user account paired one to one with an agent identity"
        },
        {
          "label": "Token flows",
          "value": "Autonomous app-only (client_credentials), on behalf of a user (jwt-bearer), and the agent's own user account. Refresh tokens for background user-delegated work. No interactive `/authorize` flow and no public clients"
        },
        {
          "label": "Credentials",
          "value": "Held by the blueprint only. Managed identity as a federated identity credential (preferred), client certificate, or client secret for local development"
        },
        {
          "label": "Management API",
          "value": "Microsoft Graph v1.0 at /servicePrincipals/microsoft.graph.agentIdentity for list, create, get, update, delete, owners, sponsors and restore. Inherited permissions, attest and communication configuration are on /beta only"
        },
        {
          "label": "Permissions",
          "value": "AgentIdentity.Create.All (least privileged), AgentIdentity.CreateAsManager, AgentIdentity.ReadWrite.All. Roles Agent ID Developer and Agent ID Administrator"
        },
        {
          "label": "Blocked for agents",
          "value": "Global Administrator, Privileged Role Administrator, User Administrator and role-assignable groups. Graph permissions including Application.ReadWrite.All, RoleManagement.ReadWrite.All, User.ReadWrite.All and Directory.AccessAsUser.All"
        },
        {
          "label": "Rate limits",
          "value": "Graph identity and access limits by token bucket. Per app and tenant, 3,500 to 8,000 resource units per 10 seconds by tenant size and 3,000 writes per 2 minutes 30 seconds. Per tenant, 18,000 writes per 5 minutes. 429 carries Retry-After"
        },
        {
          "label": "Quotas",
          "value": "250 agent identities per blueprint for outside platforms using app-only permissions, 250 owned objects per non-admin user, blueprints at most 95 per cent of tenant quota"
        },
        {
          "label": "SDKs",
          "value": "Microsoft.Identity.Web.AgentIdentities 4.16.0 on NuGet (.NET), the Auth SDK sidecar container for other languages, Microsoft Graph SDKs and Entra PowerShell for management"
        },
        {
          "label": "Logs",
          "value": "Audit and sign-in logs with agentType and blueprintId. Kept seven days on Entra ID Free and 30 days on P1 or P2, longer if routed to Azure storage"
        },
        {
          "label": "Paid controls",
          "value": "Conditional Access, ID Protection, ID Governance and network controls for agents need Microsoft Agent 365 or Microsoft 365 E7"
        },
        {
          "label": "Third-party agents",
          "value": "Guides for Amazon Bedrock and n8n through the sidecar or workload identity federation"
        },
        {
          "label": "Deprecation",
          "value": "Microsoft Graph gives at least 24 months' notice before retiring a generally available API or version. /beta can change without notice"
        }
      ],
      "unitPrices": [
        {
          "item": "Microsoft Agent 365",
          "unit": "seat-month",
          "usd": 15,
          "note": "billed yearly, needed for Conditional Access, ID Protection and governance for agents"
        },
        {
          "item": "Microsoft 365 E7 (includes Agent 365)",
          "unit": "seat-month",
          "usd": 99,
          "note": "billed yearly"
        }
      ],
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": true,
        "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
        "privacy": "https://www.microsoft.com/en-us/privacy/privacystatement",
        "statusPage": "https://azure.status.microsoft/en-us/status/history/",
        "changelog": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "www.microsoft.com/.well-known/security.txt carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08.",
          "The Microsoft APIs terms of use cover the Microsoft Graph API and other APIs that reach directory data, and were last updated in October 2025. Tenant use of Entra also falls under the customer's Microsoft licensing agreement and the Product Terms, which we didn't read.",
          "The Microsoft privacy statement was last updated in September 2026.",
          "Tokens come from login.microsoftonline.com and management calls go to graph.microsoft.com, both Microsoft domains.",
          "Entra's SLA page sends readers to the Azure status history for incidents that affect Entra ID.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02."
        ],
        "score": 85,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Microsoft Corporation",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "microsoft.com, registered 1991-05-02 (35 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "graph.microsoft.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points",
            "points": 2.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects, and has 1 clause that costs points",
            "points": 8,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "azure.status.microsoft/en-us/status/history",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "published but past its Expires date",
            "points": 5,
            "max": 10,
            "state": "part"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-10-01",
            "words": 4555,
            "points": 2.3,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: October 2025 What's new?",
                "says": "Last updated 2025-10-01"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": false
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "WE MAKE NO WARRANTIES, EXPRESS OR IMPLIED, GUARANTEES OR CONDITIONS WITH RESPECT TO YOUR USE OF THE MICROSOFT APIs."
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "We may change, amend or terminate these API Terms at any time."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Unless you have use permissions expressly and specifically granted by Customers in connection with using your Application, you may not use Microsoft email protocols and APIs for any purpose other than:"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "Scrape, build databases or otherwise create copies of any data accessed or obtained using the Microsoft APIs, except as necessary to enable an intended usage scenario for your Application;",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "Use the Microsoft APIs, or any data obtained using the Microsoft APIs, to conduct performance testing of a Microsoft Offering unless expressly permitted by Microsoft",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "We may suspend or immediately terminate these API Terms, any rights granted herein, and/or your license to the Microsoft APIs, in our sole discretion at any time, for any reason."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Recoverable damages are limited to direct damages of up to 5 US dollars in total.",
                "quote": "YOU AGREE THAT YOUR EXCLUSIVE REMEDY IS TO RECOVER, FROM MICROSOFT OR ANY AFFILIATES, RESELLERS, DISTRIBUTORS, SUPPLIERS (AND RESPECTIVE EMPLOYEES, SHAREHOLDERS, OR DIRECTORS) AND VENDORS, ONLY DIRECT DAMAGES UP TO USD $5.00 COLLECTIVELY."
              },
              {
                "date": "2026-10-08",
                "text": "After a data breach involving the Microsoft APIs, the developer may make no public statement about it without Microsoft's prior written permission.",
                "quote": "You agree to refrain from making public statements (e.g., press, blogs, social media, bulletin boards, etc.) without prior written and express permission from Microsoft in each instance as it relates to the Microsoft APIs."
              },
              {
                "date": "2026-10-08",
                "text": "The developer must allow Microsoft reasonable access to its application so Microsoft can monitor compliance with the API terms.",
                "quote": "You will permit Microsoft reasonable access to your Application for purposes of monitoring compliance with these API Terms."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.microsoft.com/en-us/privacy/privacystatement",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-09-01",
            "words": 33580,
            "points": 8,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: September 2026",
                "says": "Last updated 2026-09-01"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "The data we collect depends on the context of your interactions with Microsoft and the choices you make, including your privacy settings and the products and features you use."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "When you delete an email or item from a mailbox in Outlook.com, the item generally goes into your Deleted Items folder where it remains for approximately 7 days unless you move it back to your inbox, you empty the folder, or the service empties the folder automatically, whichever comes first.",
                "says": "Names a period of 7 days"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Service providers that help us determine your device’s location."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "not use or share student personal data for advertising or similar commercial purposes, such as providing personalized advertising to students;"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "State Data Privacy Notice (including notice at collection details) and the Consumer Health Data Privacy Policy for additional information about your rights and the processing of your personal data."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have a privacy concern, complaint, or question for the Microsoft privacy team or Data Protection Officer, please visit our privacy support and requests page and click on “Contact the Microsoft privacy team or the Microsoft Data Protection Officer” menu.",
                "says": "Names a data protection officer"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "In such cases, we implement legal safeguards-such as standard contractual clauses approved by the European Commission – to help protect your rights and ensure your data remains protected.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "training",
                "label": "Says it may use customer content to train or improve models, and no opt-out was found",
                "found": true,
                "quote": "As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models.",
                "costsPoints": true
              },
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "We also disclose personal data for digital advertising purposes."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict.",
                "quote": "In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control."
              },
              {
                "date": "2026-10-08",
                "text": "Prompts and related data sent to the consumer Microsoft Copilot are used to improve services and for relevant advertising.",
                "quote": "Microsoft Copilot also uses prompts and related data to provide and improve services, including relevant advertising."
              },
              {
                "date": "2026-10-08",
                "text": "Microsoft staff manually review some results of its automated systems, including AI, against the source data.",
                "quote": "For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.json",
      "live": {
        "slug": "microsoft-entra-agent-id",
        "probe": {
          "target": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
          "method": "get",
          "lastAt": "2026-10-08T20:21:20.147544694Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 57,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 32,
          "p95ms24h": 172,
          "samples24h": 32,
          "samples30d": 32,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 32,
              "ok": 32
            }
          ]
        },
        "vendorStatus": {
          "page": "https://azure.status.microsoft/en-us/status/history",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:47.070808325Z"
        },
        "pages": [
          {
            "url": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:21:36.290153566Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "bca4f93493d4"
          },
          {
            "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:21:38.182590643Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1a1ee1c20d9a"
          }
        ],
        "updatedAt": "2026-10-08T20:21:20.147544694Z"
      }
    },
    "verify": {
      "accepts": "a page on microsoft.com or one of its subdomains, or the README of github.com/AzureAD/microsoft-identity-web",
      "badgeUrl": "https://www.anchorterminal.com/badges/microsoft-entra-agent-id.svg",
      "body": {
        "slug": "microsoft-entra-agent-id",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/microsoft-entra-agent-id\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/microsoft-entra-agent-id.svg\" alt=\"Microsoft Entra Agent ID on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Microsoft Entra Agent ID on Anchor Terminal](https://www.anchorterminal.com/badges/microsoft-entra-agent-id.svg)](https://www.anchorterminal.com/tools/microsoft-entra-agent-id)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/microsoft-entra-agent-id\"\u003eMicrosoft Entra Agent ID on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id",
    "json": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md",
    "slim": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.min.md"
  },
  "markdown": "## Overview\n\n**Grade BB · 74.4/100 · rank #63 of 722 · #2 in Agent auth \u0026 delegated access · agent-ready · confidence medium**\n\n\nMore from Microsoft, listed separately because each is its own product: [Microsoft Foundry fine-tuning (Azure OpenAI)](https://www.anchorterminal.com/tools/azure-foundry-fine-tuning.md) (Fine-tuning), [Azure AI Content Safety (Prompt Shields)](https://www.anchorterminal.com/tools/azure-ai-content-safety.md) (Guardrails \u0026 safety filters), [Azure AI Speech speech-to-text](https://www.anchorterminal.com/tools/azure-speech-to-text.md) (Speech-to-text), [Azure AI Speech text-to-speech](https://www.anchorterminal.com/tools/azure-text-to-speech.md) (Text-to-speech), [Microsoft Agent Framework](https://www.anchorterminal.com/tools/microsoft-agent-framework.md) (Agent frameworks \u0026 SDKs), [Microsoft Execution Containers](https://www.anchorterminal.com/tools/microsoft-execution-containers.md) (Code execution sandboxes), [Azure Key Vault](https://www.anchorterminal.com/tools/azure-key-vault.md) (Secrets \u0026 credential vaults), [Azure DevOps MCP Server](https://www.anchorterminal.com/tools/azure-devops-mcp.md) (Code \u0026 developer platforms), [Microsoft Learn MCP Server](https://www.anchorterminal.com/tools/microsoft-learn-mcp.md) (Code \u0026 developer platforms), [Playwright MCP](https://www.anchorterminal.com/tools/playwright-mcp.md) (Browser automation), [Azure MCP Server](https://www.anchorterminal.com/tools/azure-mcp.md) (Cloud \u0026 infrastructure), [Azure Maps](https://www.anchorterminal.com/tools/azure-maps.md) (Maps, geocoding \u0026 places), [Azure Translator](https://www.anchorterminal.com/tools/azure-translator.md) (Translation), [Microsoft Graph Calendar API](https://www.anchorterminal.com/tools/microsoft-graph-calendar.md) (Calendars \u0026 scheduling), [Microsoft Teams (Microsoft Graph)](https://www.anchorterminal.com/tools/microsoft-teams.md) (Work \u0026 productivity), [Microsoft Dynamics 365 Sales](https://www.anchorterminal.com/tools/dynamics-365-sales.md) (CRM \u0026 customer platforms), [Microsoft Power Automate](https://www.anchorterminal.com/tools/power-automate.md) (Workflow automation), [Microsoft Advertising API](https://www.anchorterminal.com/tools/microsoft-advertising-api.md) (Advertising \u0026 campaign operations), [Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/tools/microsoft-excel-graph.md) (Spreadsheets \u0026 operational tables), [Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/tools/outlook-mail-graph.md) (Mailbox access).\n\n## Assessment\n\nAgent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Microsoft (https://learn.microsoft.com/en-us/entra/agent-id/) |\n| Kind | HTTP API |\n| Category | Agent auth \u0026 delegated access (https://www.anchorterminal.com/categories/agent-auth) |\n| Transport | HTTP |\n| Endpoint | `https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity` |\n| Auth | OAuth · Access starts with a Microsoft Entra tenant and a person holding the Agent ID Developer or Agent ID Administrator role, who creates an agent identity blueprint. The blueprint authenticates to login.microsoftonline.com with a managed identity, a certificate or a client secret (Microsoft advises against secrets in production) and exchanges for a token as one of its agent identities. Agent identities hold no credentials. Three flows exist, which are app-only, on behalf of a signed-in user, and as the agent's own user account. Interactive `/authorize` and public clients aren't supported. Management calls on Microsoft Graph need AgentIdentity.Create.All or AgentIdentity.ReadWrite.All. |\n| Pricing | Freemium ($15 / seat-mo) · Microsoft's docs say Agent ID is available to all Microsoft Entra customers, and Entra ID Free comes with any Microsoft cloud subscription. No per-agent price is published. Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15.00 a user a month on yearly billing, or Microsoft 365 E7 at $99.00. Conditional Access for agents also needs Entra P1 or Microsoft 365 E3 alongside Agent 365. No sandbox was found in the Agent ID docs (https://www.microsoft.com/en-us/microsoft-agent-365, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the Agent ID docs, the Graph reference or the pricing pages (checked 2026-10-08). |\n| Licence | Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT |\n| Packages | nuget: `Microsoft.Identity.Web.AgentIdentities` |\n| Source | https://github.com/AzureAD/microsoft-identity-web |\n| Docs | https://learn.microsoft.com/en-us/entra/agent-id/ |\n| llms.txt | not found |\n| Last release | 2026-09-30 |\n| GitHub stars | 787 (as of 2026-10-08) |\n| Objects | Agent identity blueprint (a template, like an app registration), blueprint principal, agent identity (a service principal subtype) and an optional agent's user account paired one to one with an agent identity |\n| Token flows | Autonomous app-only (client_credentials), on behalf of a user (jwt-bearer), and the agent's own user account. Refresh tokens for background user-delegated work. No interactive `/authorize` flow and no public clients |\n| Credentials | Held by the blueprint only. Managed identity as a federated identity credential (preferred), client certificate, or client secret for local development |\n| Management API | Microsoft Graph v1.0 at /servicePrincipals/microsoft.graph.agentIdentity for list, create, get, update, delete, owners, sponsors and restore. Inherited permissions, attest and communication configuration are on /beta only |\n| Permissions | AgentIdentity.Create.All (least privileged), AgentIdentity.CreateAsManager, AgentIdentity.ReadWrite.All. Roles Agent ID Developer and Agent ID Administrator |\n| Blocked for agents | Global Administrator, Privileged Role Administrator, User Administrator and role-assignable groups. Graph permissions including Application.ReadWrite.All, RoleManagement.ReadWrite.All, User.ReadWrite.All and Directory.AccessAsUser.All |\n| Rate limits | Graph identity and access limits by token bucket. Per app and tenant, 3,500 to 8,000 resource units per 10 seconds by tenant size and 3,000 writes per 2 minutes 30 seconds. Per tenant, 18,000 writes per 5 minutes. 429 carries Retry-After |\n| Quotas | 250 agent identities per blueprint for outside platforms using app-only permissions, 250 owned objects per non-admin user, blueprints at most 95 per cent of tenant quota |\n| SDKs | Microsoft.Identity.Web.AgentIdentities 4.16.0 on NuGet (.NET), the Auth SDK sidecar container for other languages, Microsoft Graph SDKs and Entra PowerShell for management |\n| Logs | Audit and sign-in logs with agentType and blueprintId. Kept seven days on Entra ID Free and 30 days on P1 or P2, longer if routed to Azure storage |\n| Paid controls | Conditional Access, ID Protection, ID Governance and network controls for agents need Microsoft Agent 365 or Microsoft 365 E7 |\n| Third-party agents | Guides for Amazon Bedrock and n8n through the sidecar or workload identity federation |\n| Deprecation | Microsoft Graph gives at least 24 months' notice before retiring a generally available API or version. /beta can change without notice |\n| Capabilities | auth.oauth, auth.agent-identity, auth.consent, auth.audit |\n| Tags | hosted, enterprise, oauth, openapi, dotnet, sidecar, microsoft-graph, mcp, freemium, sla |\n| JSON | https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 91 | 18.2 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 87 | 14.1 |\n| Agent ergonomics | 13% | 16.2 | 71 | 11.5 |\n| Security \u0026 auth | 14% | 17.5 | 83 | 14.5 |\n| Payments \u0026 pricing | 10% | 12.5 | 20 | 2.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 80 | 7.0 |\n| Transparency \u0026 trust (editorial 63, provenance 85) | 7% | 8.8 | 74 | 6.5 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **74.4 → BB** |\n\n### Why each score\n\n- Reliability 91: Microsoft's SLA page for Entra ID points to the Azure status history for incidents, and that page was readable with dated entries and reviews (20). The last 90 days show three Azure incidents, on 23 July, 29 September and 30 September 2026. None names Entra ID, the 23 July West US network fault lists Azure AD B2C, and Microsoft reports 99.999 per cent authentication availability for July, August and September. We scored between clean and minor because the page lists only wide incidents (25). Graph identity limits are published as numbers, such as 3,000 writes per 2 minutes 30 seconds per app and tenant (15). 429 carries Retry-After and the FAQ asks for exponential backoff, but there is no idempotency key and back-to-back creates can fail with 400 during replication (11). An SLA for Microsoft Entra ID is published and attainment is reported monthly. The SLA document itself didn't load for us (10). Agent ID has been generally available since April 2026 and the agentIdentity API is on Graph v1.0 (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 87: agentIdentity is in Microsoft's public Graph v1.0 OpenAPI file (25). learn.microsoft.com returns Markdown when asked with `Accept: text/markdown`, but learn.microsoft.com/llms.txt returned 404 (8). Concept, design-pattern and best-practice pages say when to use each flow and when to pick the sidecar over the .NET library (16). Graph resources are typed with required fields listed, though agentIdentity is an open type that inherits servicePrincipal properties that don't all apply (12). Request and response examples on each reference page and a list of 17 Agent ID error codes, without the HTTP status for each (11). v1.0 and beta versioning with a monthly dated Graph changelog and Entra release notes (15).\n- Agent ergonomics 71: List calls take `$select`, `$top`, `$filter`, `$search` and `$count`, with a default and maximum page of 100 (20). OData paging and filtering work on the main collection, but ownedObjects, deletedItems and owners can't filter by agent type and need client-side filtering (17). Named error codes such as `AgentIdentity_CredentialsNotSupported` say what to change (16). No idempotency key for creates, and sequential creates need retries. Token requests are safe to repeat (8). Creating an identity needs three fields, but getting a token is a two-step exchange that Microsoft's docs call complex and error-prone by hand, with an in-process library only for .NET and a sidecar container for everything else (10).\n- Security \u0026 auth 83: OAuth 2.0 with scoped Graph permissions. Agent identities can't hold credentials, the blueprint signs in with a managed identity or certificate, and client secrets are allowed but warned against (30). Entra refuses high-privilege roles and permissions such as Application.ReadWrite.All for agents, and an identity can be disabled. Conditional Access for agents needs an Agent 365 licence, and nothing asks a person to approve a destructive call (16). The service returns tokens and directory objects, not untrusted content (10). Audit and sign-in logs carry agentType and blueprintId, kept seven days on Free and 30 on P1 or P2, while the FAQ says Graph activity logs don't separate agents (12). MSRC disclosure policy and an identity bounty of $750 to $100,000, but microsoft.com's security.txt expired on 23 September 2026 and we didn't read certification reports (15).\n- Payments \u0026 pricing 20: No x402, MPP or L402 (0). Agent 365 is listed at $15 a user a month and Microsoft 365 E7 at $99, and the docs say Agent ID is available to all Entra customers, but no page gives a per-agent price or says plainly which parts are free (10). Entra ID Free comes with a Microsoft cloud subscription. We didn't establish whether a new tenant can be opened without a card, so this line gets half (10). A person creates the tenant, holds an Agent ID role and creates the blueprint before any agent can act (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 80: Microsoft.Identity.Web 4.16.0, which carries the agent identity package and the sidecar, was tagged on 30 September 2026, and the Agent ID FAQ was updated on 1 October (30). Eight tags from 4.13.0 on 9 July to 4.16.0, and Graph changelog entries for agent identities in August and September (20). A closed service with public release notes and a public SDK tracker showing 340 open issues. We didn't read reply times (10). The current in-process SDK is .NET only, with the sidecar container for other languages (12). Azure Pipelines and CodeQL are configured, and 4.14.x raised dependencies for four CVEs (8).\n- Transparency \u0026 trust 74: Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDK source (15). The privacy statement was updated in September 2026, Entra publishes a data residency page and log retention periods, and we didn't read the DPA (20). Microsoft Graph gives at least 24 months' notice before retiring a GA API or version, while several Agent ID operations are still on /beta, which can change without notice (18). Entra documents where tenant data is stored by geography. We didn't read the sub-processor list (10).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/microsoft-entra-agent-id.md (JSON https://www.anchorterminal.com/fixes/microsoft-entra-agent-id.json)\n\n### What we couldn't check\n\n- unchecked: the SLA document for Microsoft Entra ID. The link redirected to a general SLA index and we didn't read the availability figure or which licences it covers.\n- unchecked: whether a new Entra tenant can be created without a payment card.\n- Whether creating and using agent identities on Entra ID Free carries any charge. The docs say Agent ID is available to all Entra customers and give no per-agent price.\n- unchecked: the Microsoft Products and Services DPA, the sub-processor list and the Product Terms for Entra and Agent 365.\n- unchecked: certification reports (SOC 2, ISO 27001) for Entra ID, and reply times on the microsoft-identity-web issue tracker.\n- unchecked: status.cloud.microsoft, which needs JavaScript. The incident record rests on the Azure status history and Microsoft's own monthly SLA table.\n- The Agent ID how-to page for creating identities still shows the /beta Graph endpoint while the reference documents the same call on v1.0.\n- The logs page says audit events carry agentType, while the FAQ says audit logs don't distinguish agent identities by default. We didn't test which is current.\n\n### Sources\n\n- What is Microsoft Entra Agent ID: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id\u003e (seen 2026-10-08)\n- agent identities concept and licensing: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/what-are-agent-identities\u003e (seen 2026-10-08)\n- what's new in Agent ID: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/whats-new-agent-id\u003e (seen 2026-10-08)\n- FAQ, limits and known gaps: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/faq\u003e (seen 2026-10-08)\n- authentication protocols: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/agent-oauth-protocols\u003e (seen 2026-10-08)\n- autonomous app flow: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/agent-autonomous-app-oauth-flow\u003e (seen 2026-10-08)\n- authorisation and blocked roles: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/authorization-agent-id\u003e (seen 2026-10-08)\n- error codes: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/error-codes\u003e (seen 2026-10-08)\n- sign-in and audit logs for agents: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/sign-in-audit-logs-agents\u003e (seen 2026-10-08)\n- create agent identities: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/create-delete-agent-identities\u003e (seen 2026-10-08)\n- MCP server guide: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/secure-mcp-server-with-entra-id\u003e (seen 2026-10-08)\n- agentIdentity resource, Graph v1.0: \u003chttps://learn.microsoft.com/en-us/graph/api/resources/agentidentity?view=graph-rest-1.0\u003e (seen 2026-10-08)\n- Create agentIdentity, Graph v1.0: \u003chttps://learn.microsoft.com/en-us/graph/api/agentidentity-post?view=graph-rest-1.0\u003e (seen 2026-10-08)\n- List agentIdentity query options: \u003chttps://learn.microsoft.com/en-us/graph/api/agentidentity-list?view=graph-rest-1.0\u003e (seen 2026-10-08)\n- Graph OpenAPI v1.0: \u003chttps://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml\u003e (seen 2026-10-08)\n- Graph throttling guidance: \u003chttps://learn.microsoft.com/en-us/graph/throttling\u003e (seen 2026-10-08)\n- Graph throttling limits: \u003chttps://learn.microsoft.com/en-us/graph/throttling-limits\u003e (seen 2026-10-08)\n- Graph versioning and breaking change policy: \u003chttps://learn.microsoft.com/en-us/graph/versioning-and-support\u003e (seen 2026-10-08)\n- Graph changelog: \u003chttps://learn.microsoft.com/en-us/graph/whats-new-overview\u003e (seen 2026-10-08)\n- Entra release notes: \u003chttps://learn.microsoft.com/en-us/entra/fundamentals/whats-new\u003e (seen 2026-10-08)\n- Entra SLA performance: \u003chttps://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-sla-performance\u003e (seen 2026-10-08)\n- Azure status history: \u003chttps://azure.status.microsoft/en-us/status/history/\u003e (seen 2026-10-08)\n- Entra log retention: \u003chttps://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-reports-data-retention\u003e (seen 2026-10-08)\n- Entra data residency: \u003chttps://learn.microsoft.com/en-us/entra/fundamentals/data-residency\u003e (seen 2026-10-08)\n- Conditional Access for agents, licensing: \u003chttps://learn.microsoft.com/en-us/entra/identity/conditional-access/agent-id\u003e (seen 2026-10-08)\n- Agent 365 pricing: \u003chttps://www.microsoft.com/en-us/microsoft-agent-365\u003e (seen 2026-10-08)\n- Entra pricing: \u003chttps://www.microsoft.com/en-us/security/business/microsoft-entra-pricing\u003e (seen 2026-10-08)\n- Auth SDK sidecar overview: \u003chttps://learn.microsoft.com/en-us/entra/msidweb/agent-id-sdk/overview\u003e (seen 2026-10-08)\n- Auth SDK sidecar installation: \u003chttps://learn.microsoft.com/en-us/entra/msidweb/agent-id-sdk/installation\u003e (seen 2026-10-08)\n- microsoft-identity-web repository, tags and changelog: \u003chttps://github.com/AzureAD/microsoft-identity-web\u003e (seen 2026-10-08)\n- NuGet versions: \u003chttps://api.nuget.org/v3-flatcontainer/microsoft.identity.web.agentidentities/index.json\u003e (seen 2026-10-08)\n- Microsoft APIs terms of use: \u003chttps://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use\u003e (seen 2026-10-08)\n- privacy statement: \u003chttps://www.microsoft.com/en-us/privacy/privacystatement\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://www.microsoft.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- identity bounty: \u003chttps://www.microsoft.com/en-us/msrc/bounty-microsoft-identity\u003e (seen 2026-10-08)\n- RDAP: \u003chttps://rdap.verisign.com/com/v1/domain/microsoft.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 85/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Microsoft Corporation | 20/20 |\n| Domain age | microsoft.com, registered 1991-05-02 (35 years) | 15/15 |\n| Endpoint on the vendor's domain | graph.microsoft.com | 15/15 |\n| Terms of service | read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points | 2.3/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects, and has 1 clause that costs points | 8/10 |\n| Status page | azure.status.microsoft/en-us/status/history | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | published but past its Expires date | 5/10 |\n\nwww.microsoft.com/.well-known/security.txt carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08.\n\nThe Microsoft APIs terms of use cover the Microsoft Graph API and other APIs that reach directory data, and were last updated in October 2025. Tenant use of Entra also falls under the customer's Microsoft licensing agreement and the Product Terms, which we didn't read.\n\nThe Microsoft privacy statement was last updated in September 2026.\n\nTokens come from login.microsoftonline.com and management calls go to graph.microsoft.com, both Microsoft domains.\n\nEntra's SLA page sends readers to the Azure status history for incidents that affect Entra ID.\n\nRDAP for microsoft.com gives a registration date of 1991-05-02.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use), read 2026-10-08, dated 2025-10-01, states 5 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"Scrape, build databases or otherwise create copies of any data accessed or obtained using the Microsoft APIs, except as necessary to enable an intended usage scenario for your Application;\"\n- To know. Restricts benchmarking or competitive use (costs points). \"Use the Microsoft APIs, or any data obtained using the Microsoft APIs, to conduct performance testing of a Microsoft Offering unless expressly permitted by Microsoft\"\n- To know. Says the terms or the service can change without notice (costs points). \"WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.\"\n- To know. Says access can be ended without notice or for any reason. \"We may suspend or immediately terminate these API Terms, any rights granted herein, and/or your license to the Microsoft APIs, in our sole discretion at any time, for any reason.\"\n- Gives the date it was last updated. Last updated 2025-10-01.\n- Not found in the text. Names the governing law or courts.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Recoverable damages are limited to direct damages of up to 5 US dollars in total. \"YOU AGREE THAT YOUR EXCLUSIVE REMEDY IS TO RECOVER, FROM MICROSOFT OR ANY AFFILIATES, RESELLERS, DISTRIBUTORS, SUPPLIERS (AND RESPECTIVE EMPLOYEES, SHAREHOLDERS, OR DIRECTORS) AND VENDORS, ONLY DIRECT DAMAGES UP TO USD $5.00 COLLECTIVELY.\"\n- Also in the text (2026-10-08). After a data breach involving the Microsoft APIs, the developer may make no public statement about it without Microsoft's prior written permission. \"You agree to refrain from making public statements (e.g., press, blogs, social media, bulletin boards, etc.) without prior written and express permission from Microsoft in each instance as it relates to the Microsoft APIs.\"\n- Also in the text (2026-10-08). The developer must allow Microsoft reasonable access to its application so Microsoft can monitor compliance with the API terms. \"You will permit Microsoft reasonable access to your Application for purposes of monitoring compliance with these API Terms.\"\n\n**Privacy policy** (https://www.microsoft.com/en-us/privacy/privacystatement), read 2026-10-08, dated 2026-09-01, states 8 of the 8 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). \"As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models.\"\n- To know. Says it sells personal data or shares it for advertising. \"We also disclose personal data for digital advertising purposes.\"\n- Gives the date it was last updated. Last updated 2026-09-01.\n- Says how long data is kept. Names a period of 7 days.\n- Gives a privacy contact. Names a data protection officer.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict. \"In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control.\"\n- Also in the text (2026-10-08). Prompts and related data sent to the consumer Microsoft Copilot are used to improve services and for relevant advertising. \"Microsoft Copilot also uses prompts and related data to provide and improve services, including relevant advertising.\"\n- Also in the text (2026-10-08). Microsoft staff manually review some results of its automated systems, including AI, against the source data. \"For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data.\"\n\n## Live (updated 2026-10-08 20:21 UTC)\n\n- Right now: up, HTTP 401, 57 ms, checked 2026-10-08 20:21 UTC (get on `https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity`, asks for auth)\n- Uptime 24h 100.0% (32 probes) · 30 days 100.0% (32 probes) · p50 32 ms · p95 172 ms\n- Vendor status page: unknown, no machine-readable status found\n- Watching changelog \u003chttps://learn.microsoft.com/en-us/graph/whats-new-overview\u003e\n- Watching terms \u003chttps://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/microsoft-entra-agent-id.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Microsoft Agent 365 | $15 | per seat per month | billed yearly, needed for Conditional Access, ID Protection and governance for agents |\n| Microsoft 365 E7 (includes Agent 365) | $99 | per seat per month | billed yearly |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Agent identities can't hold credentials. The blueprint authenticates with a managed identity, certificate or secret and exchanges for the agent's token\n- Global Administrator and similar roles, and Graph permissions such as Application.ReadWrite.All, are refused for agent identities\n- Create, list, update, delete and restore are on Microsoft Graph v1.0, with agentIdentity in the public OpenAPI file\n- Audit and sign-in logs carry an agentType and blueprintId for agent activity\n- Microsoft.Identity.Web 4.16.0 shipped on 30 September 2026, the eighth tagged release since 9 July\n\n## Weaknesses\n\n- Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing\n- Microsoft's docs call hand-written token exchange complex and error-prone and steer developers to a .NET library or a sidecar container\n- Creating a blueprint, a principal and an identity in quick succession can fail with 400 until the directory replicates\n- Audit and sign-in logs are kept seven days on Entra ID Free and 30 days on P1 or P2\n- microsoft.com's security.txt passed its Expires date on 23 September 2026\n\n## Before you call it (notes for agents)\n\n1. Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token\n2. Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object\n3. Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required\n4. Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page\n5. Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it\n\n## Connect\n\nInstall:\n\n```bash\ndotnet add package Microsoft.Identity.Web.AgentIdentities\n```\n\nFirst request:\n\n```bash\ncurl -X POST https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity \\\n  -H \"Authorization: Bearer $BLUEPRINT_TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"displayName\": \"My Agent Identity\", \"agentIdentityBlueprintId\": \"\u003cblueprint-app-id\u003e\", \"sponsors@odata.bind\": [\"https://graph.microsoft.com/v1.0/users/\u003cid\u003e\"]}'\n```\n\nThrough letme (picks today, calling later): https://letme.dev/microsoft-entra-agent-id. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Descope Agentic Identity Hub | A | 78.1 | 13 | auth.oauth, auth.consent, auth.agent-identity, auth.audit | no | https://www.anchorterminal.com/tools/descope-agentic-identity.md |\n| Aembit | BB | 70.5 | 134 | auth.oauth, auth.agent-identity, auth.consent, auth.audit | no | https://www.anchorterminal.com/tools/aembit.md |\n| WorkOS Pipes and Agents | C | 59.9 | 418 | auth.oauth, auth.consent, auth.agent-identity, auth.audit | no | https://www.anchorterminal.com/tools/workos-pipes.md |\n| Keycard | C | 56.2 | 492 | auth.oauth, auth.consent, auth.agent-identity, auth.audit | no | https://www.anchorterminal.com/tools/keycard.md |\n| Permit MCP Gateway | C | 54.1 | 534 | auth.oauth, auth.consent, auth.agent-identity, auth.audit | no | https://www.anchorterminal.com/tools/permit-mcp-gateway.md |\n| Scalekit AgentKit | BB | 71.9 | 100 | auth.oauth, auth.consent, auth.agent-identity | no | https://www.anchorterminal.com/tools/scalekit-agentkit.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Agent ID became generally available in April 2026 per the Entra release notes (source: \u003chttps://learn.microsoft.com/en-us/entra/fundamentals/whats-new\u003e)\n- An agent identity blueprint can impersonate only its own child agent identities, and each agent identity is single-tenant (source: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/agent-autonomous-app-oauth-flow\u003e)\n- Apps outside Microsoft's own platforms that use app-only permissions are capped at 250 agent identities per blueprint, and blueprints can take at most 95 per cent of the tenant's resource quota (source: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/faq\u003e)\n- Deleted agent identities are soft-deleted for 30 days and can be restored through Microsoft Graph or PowerShell, not in the admin centre (source: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/faq\u003e)\n- The Auth SDK sidecar is a container at mcr.microsoft.com/entra-sdk/auth-sidecar that returns an Authorization header over local HTTP, so agents in any language can use it (source: \u003chttps://learn.microsoft.com/en-us/entra/msidweb/agent-id-sdk/overview\u003e)\n- Microsoft documents Entra ID as the authorisation server for an MCP server, with the client sending the RFC 8707 resource parameter (source: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/secure-mcp-server-with-entra-id\u003e)\n- The admin consent workflow doesn't work for permissions requested by agent identities, per the FAQ (source: \u003chttps://learn.microsoft.com/en-us/entra/agent-id/faq\u003e)\n\n## Compare\n\n- [Aembit vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.md): BB 70.5 vs BB 74.4\n- [Arcade.dev vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.md): B 66.9 vs BB 74.4\n- [Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.md): BB 71.4 vs BB 74.4\n- [Descope Agentic Identity Hub vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.md): A 78.1 vs BB 74.4\n- [Keycard vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.md): C 56.2 vs BB 74.4\n- [Microsoft Entra Agent ID vs Nango](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.md): BB 74.4 vs B 67.7\n- [Microsoft Entra Agent ID vs Scalekit AgentKit](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.md): BB 74.4 vs BB 71.9\n- [Microsoft Entra Agent ID vs Stytch Connected Apps](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.md): BB 74.4 vs C 60.8\n- [Microsoft Entra Agent ID vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.md): BB 74.4 vs C 59.9\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on microsoft.com or one of its subdomains, or the README of github.com/AzureAD/microsoft-identity-web. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"microsoft-entra-agent-id\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/microsoft-entra-agent-id\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/microsoft-entra-agent-id.svg\" alt=\"Microsoft Entra Agent ID on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Microsoft Entra Agent ID on Anchor Terminal](https://www.anchorterminal.com/badges/microsoft-entra-agent-id.svg)](https://www.anchorterminal.com/tools/microsoft-entra-agent-id)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/microsoft-entra-agent-id\"\u003eMicrosoft Entra Agent ID on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Microsoft Entra Agent ID is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/microsoft-entra-agent-id-dark.png\n- Light: https://www.anchorterminal.com/assets/share/microsoft-entra-agent-id-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Agent auth \u0026 delegated access",
        "url": "https://www.anchorterminal.com/categories/agent-auth"
      },
      {
        "name": "Microsoft Entra Agent ID",
        "url": ""
      }
    ],
    "description": "Microsoft Entra Agent ID is an identity type for AI agents in Microsoft Entra ID. Agents get their own directory identity, request OAuth 2.0 tokens autonomously or on behalf of a user, and are managed through Microsoft Graph.",
    "facts": [
      "rank #63 of 722",
      "OAuth auth",
      "0 desk reviews"
    ],
    "h1": "Microsoft Entra Agent ID",
    "image": "https://www.anchorterminal.com/assets/og/tools-microsoft-entra-agent-id.png",
    "path": "/tools/microsoft-entra-agent-id",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Microsoft Entra Agent ID review for AI agents, grade BB (74.4/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id"
  },
  "tokens": {
    "markdown": 9200,
    "slim": 1980
  },
  "version": 1
}
