# Microsoft Entra Agent ID > Microsoft Entra Agent ID is an identity type for AI agents in Microsoft Entra ID. Agents get their own directory identity, request OAuth 2.0 tokens autonomously or on behalf of a user, and are managed through Microsoft Graph. - Canonical: https://www.anchorterminal.com/tools/microsoft-entra-agent-id - Markdown: https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md (~9,200 tokens) - Slim: https://www.anchorterminal.com/tools/microsoft-entra-agent-id.min.md (~1,980 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/microsoft-entra-agent-id.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade BB · 74.4/100 · rank #63 of 722 · #2 in Agent auth & delegated access · agent-ready · confidence medium** More from Microsoft, listed separately because each is its own product: [Microsoft Foundry fine-tuning (Azure OpenAI)](https://www.anchorterminal.com/tools/azure-foundry-fine-tuning.md) (Fine-tuning), [Azure AI Content Safety (Prompt Shields)](https://www.anchorterminal.com/tools/azure-ai-content-safety.md) (Guardrails & safety filters), [Azure AI Speech speech-to-text](https://www.anchorterminal.com/tools/azure-speech-to-text.md) (Speech-to-text), [Azure AI Speech text-to-speech](https://www.anchorterminal.com/tools/azure-text-to-speech.md) (Text-to-speech), [Microsoft Agent Framework](https://www.anchorterminal.com/tools/microsoft-agent-framework.md) (Agent frameworks & SDKs), [Microsoft Execution Containers](https://www.anchorterminal.com/tools/microsoft-execution-containers.md) (Code execution sandboxes), [Azure Key Vault](https://www.anchorterminal.com/tools/azure-key-vault.md) (Secrets & credential vaults), [Azure DevOps MCP Server](https://www.anchorterminal.com/tools/azure-devops-mcp.md) (Code & developer platforms), [Microsoft Learn MCP Server](https://www.anchorterminal.com/tools/microsoft-learn-mcp.md) (Code & developer platforms), [Playwright MCP](https://www.anchorterminal.com/tools/playwright-mcp.md) (Browser automation), [Azure MCP Server](https://www.anchorterminal.com/tools/azure-mcp.md) (Cloud & infrastructure), [Azure Maps](https://www.anchorterminal.com/tools/azure-maps.md) (Maps, geocoding & places), [Azure Translator](https://www.anchorterminal.com/tools/azure-translator.md) (Translation), [Microsoft Graph Calendar API](https://www.anchorterminal.com/tools/microsoft-graph-calendar.md) (Calendars & scheduling), [Microsoft Teams (Microsoft Graph)](https://www.anchorterminal.com/tools/microsoft-teams.md) (Work & productivity), [Microsoft Dynamics 365 Sales](https://www.anchorterminal.com/tools/dynamics-365-sales.md) (CRM & customer platforms), [Microsoft Power Automate](https://www.anchorterminal.com/tools/power-automate.md) (Workflow automation), [Microsoft Advertising API](https://www.anchorterminal.com/tools/microsoft-advertising-api.md) (Advertising & campaign operations), [Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/tools/microsoft-excel-graph.md) (Spreadsheets & operational tables), [Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/tools/outlook-mail-graph.md) (Mailbox access). ## Assessment Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence. ## Facts | Field | Value | | --- | --- | | Vendor | Microsoft (https://learn.microsoft.com/en-us/entra/agent-id/) | | Kind | HTTP API | | Category | Agent auth & delegated access (https://www.anchorterminal.com/categories/agent-auth) | | Transport | HTTP | | Endpoint | `https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity` | | Auth | OAuth · Access starts with a Microsoft Entra tenant and a person holding the Agent ID Developer or Agent ID Administrator role, who creates an agent identity blueprint. The blueprint authenticates to login.microsoftonline.com with a managed identity, a certificate or a client secret (Microsoft advises against secrets in production) and exchanges for a token as one of its agent identities. Agent identities hold no credentials. Three flows exist, which are app-only, on behalf of a signed-in user, and as the agent's own user account. Interactive `/authorize` and public clients aren't supported. Management calls on Microsoft Graph need AgentIdentity.Create.All or AgentIdentity.ReadWrite.All. | | Pricing | Freemium ($15 / seat-mo) · Microsoft's docs say Agent ID is available to all Microsoft Entra customers, and Entra ID Free comes with any Microsoft cloud subscription. No per-agent price is published. Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15.00 a user a month on yearly billing, or Microsoft 365 E7 at $99.00. Conditional Access for agents also needs Entra P1 or Microsoft 365 E3 alongside Agent 365. No sandbox was found in the Agent ID docs (https://www.microsoft.com/en-us/microsoft-agent-365, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the Agent ID docs, the Graph reference or the pricing pages (checked 2026-10-08). | | Licence | Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT | | Packages | nuget: `Microsoft.Identity.Web.AgentIdentities` | | Source | https://github.com/AzureAD/microsoft-identity-web | | Docs | https://learn.microsoft.com/en-us/entra/agent-id/ | | llms.txt | not found | | Last release | 2026-09-30 | | GitHub stars | 787 (as of 2026-10-08) | | Objects | Agent identity blueprint (a template, like an app registration), blueprint principal, agent identity (a service principal subtype) and an optional agent's user account paired one to one with an agent identity | | Token flows | Autonomous app-only (client_credentials), on behalf of a user (jwt-bearer), and the agent's own user account. Refresh tokens for background user-delegated work. No interactive `/authorize` flow and no public clients | | Credentials | Held by the blueprint only. Managed identity as a federated identity credential (preferred), client certificate, or client secret for local development | | Management API | Microsoft Graph v1.0 at /servicePrincipals/microsoft.graph.agentIdentity for list, create, get, update, delete, owners, sponsors and restore. Inherited permissions, attest and communication configuration are on /beta only | | Permissions | AgentIdentity.Create.All (least privileged), AgentIdentity.CreateAsManager, AgentIdentity.ReadWrite.All. Roles Agent ID Developer and Agent ID Administrator | | Blocked for agents | Global Administrator, Privileged Role Administrator, User Administrator and role-assignable groups. Graph permissions including Application.ReadWrite.All, RoleManagement.ReadWrite.All, User.ReadWrite.All and Directory.AccessAsUser.All | | Rate limits | Graph identity and access limits by token bucket. Per app and tenant, 3,500 to 8,000 resource units per 10 seconds by tenant size and 3,000 writes per 2 minutes 30 seconds. Per tenant, 18,000 writes per 5 minutes. 429 carries Retry-After | | Quotas | 250 agent identities per blueprint for outside platforms using app-only permissions, 250 owned objects per non-admin user, blueprints at most 95 per cent of tenant quota | | SDKs | Microsoft.Identity.Web.AgentIdentities 4.16.0 on NuGet (.NET), the Auth SDK sidecar container for other languages, Microsoft Graph SDKs and Entra PowerShell for management | | Logs | Audit and sign-in logs with agentType and blueprintId. Kept seven days on Entra ID Free and 30 days on P1 or P2, longer if routed to Azure storage | | Paid controls | Conditional Access, ID Protection, ID Governance and network controls for agents need Microsoft Agent 365 or Microsoft 365 E7 | | Third-party agents | Guides for Amazon Bedrock and n8n through the sidecar or workload identity federation | | Deprecation | Microsoft Graph gives at least 24 months' notice before retiring a generally available API or version. /beta can change without notice | | Capabilities | auth.oauth, auth.agent-identity, auth.consent, auth.audit | | Tags | hosted, enterprise, oauth, openapi, dotnet, sidecar, microsoft-graph, mcp, freemium, sla | | JSON | https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 91 | 18.2 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 87 | 14.1 | | Agent ergonomics | 13% | 16.2 | 71 | 11.5 | | Security & auth | 14% | 17.5 | 83 | 14.5 | | Payments & pricing | 10% | 12.5 | 20 | 2.5 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 80 | 7.0 | | Transparency & trust (editorial 63, provenance 85) | 7% | 8.8 | 74 | 6.5 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **74.4 → BB** | ### Why each score - Reliability 91: Microsoft's SLA page for Entra ID points to the Azure status history for incidents, and that page was readable with dated entries and reviews (20). The last 90 days show three Azure incidents, on 23 July, 29 September and 30 September 2026. None names Entra ID, the 23 July West US network fault lists Azure AD B2C, and Microsoft reports 99.999 per cent authentication availability for July, August and September. We scored between clean and minor because the page lists only wide incidents (25). Graph identity limits are published as numbers, such as 3,000 writes per 2 minutes 30 seconds per app and tenant (15). 429 carries Retry-After and the FAQ asks for exponential backoff, but there is no idempotency key and back-to-back creates can fail with 400 during replication (11). An SLA for Microsoft Entra ID is published and attainment is reported monthly. The SLA document itself didn't load for us (10). Agent ID has been generally available since April 2026 and the agentIdentity API is on Graph v1.0 (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 87: agentIdentity is in Microsoft's public Graph v1.0 OpenAPI file (25). learn.microsoft.com returns Markdown when asked with `Accept: text/markdown`, but learn.microsoft.com/llms.txt returned 404 (8). Concept, design-pattern and best-practice pages say when to use each flow and when to pick the sidecar over the .NET library (16). Graph resources are typed with required fields listed, though agentIdentity is an open type that inherits servicePrincipal properties that don't all apply (12). Request and response examples on each reference page and a list of 17 Agent ID error codes, without the HTTP status for each (11). v1.0 and beta versioning with a monthly dated Graph changelog and Entra release notes (15). - Agent ergonomics 71: List calls take `$select`, `$top`, `$filter`, `$search` and `$count`, with a default and maximum page of 100 (20). OData paging and filtering work on the main collection, but ownedObjects, deletedItems and owners can't filter by agent type and need client-side filtering (17). Named error codes such as `AgentIdentity_CredentialsNotSupported` say what to change (16). No idempotency key for creates, and sequential creates need retries. Token requests are safe to repeat (8). Creating an identity needs three fields, but getting a token is a two-step exchange that Microsoft's docs call complex and error-prone by hand, with an in-process library only for .NET and a sidecar container for everything else (10). - Security & auth 83: OAuth 2.0 with scoped Graph permissions. Agent identities can't hold credentials, the blueprint signs in with a managed identity or certificate, and client secrets are allowed but warned against (30). Entra refuses high-privilege roles and permissions such as Application.ReadWrite.All for agents, and an identity can be disabled. Conditional Access for agents needs an Agent 365 licence, and nothing asks a person to approve a destructive call (16). The service returns tokens and directory objects, not untrusted content (10). Audit and sign-in logs carry agentType and blueprintId, kept seven days on Free and 30 on P1 or P2, while the FAQ says Graph activity logs don't separate agents (12). MSRC disclosure policy and an identity bounty of $750 to $100,000, but microsoft.com's security.txt expired on 23 September 2026 and we didn't read certification reports (15). - Payments & pricing 20: No x402, MPP or L402 (0). Agent 365 is listed at $15 a user a month and Microsoft 365 E7 at $99, and the docs say Agent ID is available to all Entra customers, but no page gives a per-agent price or says plainly which parts are free (10). Entra ID Free comes with a Microsoft cloud subscription. We didn't establish whether a new tenant can be opened without a card, so this line gets half (10). A person creates the tenant, holds an Agent ID role and creates the blueprint before any agent can act (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 80: Microsoft.Identity.Web 4.16.0, which carries the agent identity package and the sidecar, was tagged on 30 September 2026, and the Agent ID FAQ was updated on 1 October (30). Eight tags from 4.13.0 on 9 July to 4.16.0, and Graph changelog entries for agent identities in August and September (20). A closed service with public release notes and a public SDK tracker showing 340 open issues. We didn't read reply times (10). The current in-process SDK is .NET only, with the sidecar container for other languages (12). Azure Pipelines and CodeQL are configured, and 4.14.x raised dependencies for four CVEs (8). - Transparency & trust 74: Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDK source (15). The privacy statement was updated in September 2026, Entra publishes a data residency page and log retention periods, and we didn't read the DPA (20). Microsoft Graph gives at least 24 months' notice before retiring a GA API or version, while several Agent ID operations are still on /beta, which can change without notice (18). Entra documents where tenant data is stored by geography. We didn't read the sub-processor list (10). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/microsoft-entra-agent-id.md (JSON https://www.anchorterminal.com/fixes/microsoft-entra-agent-id.json) ### What we couldn't check - unchecked: the SLA document for Microsoft Entra ID. The link redirected to a general SLA index and we didn't read the availability figure or which licences it covers. - unchecked: whether a new Entra tenant can be created without a payment card. - Whether creating and using agent identities on Entra ID Free carries any charge. The docs say Agent ID is available to all Entra customers and give no per-agent price. - unchecked: the Microsoft Products and Services DPA, the sub-processor list and the Product Terms for Entra and Agent 365. - unchecked: certification reports (SOC 2, ISO 27001) for Entra ID, and reply times on the microsoft-identity-web issue tracker. - unchecked: status.cloud.microsoft, which needs JavaScript. The incident record rests on the Azure status history and Microsoft's own monthly SLA table. - The Agent ID how-to page for creating identities still shows the /beta Graph endpoint while the reference documents the same call on v1.0. - The logs page says audit events carry agentType, while the FAQ says audit logs don't distinguish agent identities by default. We didn't test which is current. ### Sources - What is Microsoft Entra Agent ID: (seen 2026-10-08) - agent identities concept and licensing: (seen 2026-10-08) - what's new in Agent ID: (seen 2026-10-08) - FAQ, limits and known gaps: (seen 2026-10-08) - authentication protocols: (seen 2026-10-08) - autonomous app flow: (seen 2026-10-08) - authorisation and blocked roles: (seen 2026-10-08) - error codes: (seen 2026-10-08) - sign-in and audit logs for agents: (seen 2026-10-08) - create agent identities: (seen 2026-10-08) - MCP server guide: (seen 2026-10-08) - agentIdentity resource, Graph v1.0: (seen 2026-10-08) - Create agentIdentity, Graph v1.0: (seen 2026-10-08) - List agentIdentity query options: (seen 2026-10-08) - Graph OpenAPI v1.0: (seen 2026-10-08) - Graph throttling guidance: (seen 2026-10-08) - Graph throttling limits: (seen 2026-10-08) - Graph versioning and breaking change policy: (seen 2026-10-08) - Graph changelog: (seen 2026-10-08) - Entra release notes: (seen 2026-10-08) - Entra SLA performance: (seen 2026-10-08) - Azure status history: (seen 2026-10-08) - Entra log retention: (seen 2026-10-08) - Entra data residency: (seen 2026-10-08) - Conditional Access for agents, licensing: (seen 2026-10-08) - Agent 365 pricing: (seen 2026-10-08) - Entra pricing: (seen 2026-10-08) - Auth SDK sidecar overview: (seen 2026-10-08) - Auth SDK sidecar installation: (seen 2026-10-08) - microsoft-identity-web repository, tags and changelog: (seen 2026-10-08) - NuGet versions: (seen 2026-10-08) - Microsoft APIs terms of use: (seen 2026-10-08) - privacy statement: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - identity bounty: (seen 2026-10-08) - RDAP: (seen 2026-10-08) ## Who's behind it (provenance 85/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Microsoft Corporation | 20/20 | | Domain age | microsoft.com, registered 1991-05-02 (35 years) | 15/15 | | Endpoint on the vendor's domain | graph.microsoft.com | 15/15 | | Terms of service | read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points | 2.3/10 | | Privacy policy | read, states 8 of the 8 things a reader expects, and has 1 clause that costs points | 8/10 | | Status page | azure.status.microsoft/en-us/status/history | 10/10 | | Changelog | published | 10/10 | | security.txt | published but past its Expires date | 5/10 | www.microsoft.com/.well-known/security.txt carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08. The Microsoft APIs terms of use cover the Microsoft Graph API and other APIs that reach directory data, and were last updated in October 2025. Tenant use of Entra also falls under the customer's Microsoft licensing agreement and the Product Terms, which we didn't read. The Microsoft privacy statement was last updated in September 2026. Tokens come from login.microsoftonline.com and management calls go to graph.microsoft.com, both Microsoft domains. Entra's SLA page sends readers to the Azure status history for incidents that affect Entra ID. RDAP for microsoft.com gives a registration date of 1991-05-02. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use), read 2026-10-08, dated 2025-10-01, states 5 of the 7 things a reader expects. - To know. Restricts automated access (costs points). "Scrape, build databases or otherwise create copies of any data accessed or obtained using the Microsoft APIs, except as necessary to enable an intended usage scenario for your Application;" - To know. Restricts benchmarking or competitive use (costs points). "Use the Microsoft APIs, or any data obtained using the Microsoft APIs, to conduct performance testing of a Microsoft Offering unless expressly permitted by Microsoft" - To know. Says the terms or the service can change without notice (costs points). "WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU." - To know. Says access can be ended without notice or for any reason. "We may suspend or immediately terminate these API Terms, any rights granted herein, and/or your license to the Microsoft APIs, in our sole discretion at any time, for any reason." - Gives the date it was last updated. Last updated 2025-10-01. - Not found in the text. Names the governing law or courts. - Says how changes to the terms are announced. Says it gives notice of a change. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). Recoverable damages are limited to direct damages of up to 5 US dollars in total. "YOU AGREE THAT YOUR EXCLUSIVE REMEDY IS TO RECOVER, FROM MICROSOFT OR ANY AFFILIATES, RESELLERS, DISTRIBUTORS, SUPPLIERS (AND RESPECTIVE EMPLOYEES, SHAREHOLDERS, OR DIRECTORS) AND VENDORS, ONLY DIRECT DAMAGES UP TO USD $5.00 COLLECTIVELY." - Also in the text (2026-10-08). After a data breach involving the Microsoft APIs, the developer may make no public statement about it without Microsoft's prior written permission. "You agree to refrain from making public statements (e.g., press, blogs, social media, bulletin boards, etc.) without prior written and express permission from Microsoft in each instance as it relates to the Microsoft APIs." - Also in the text (2026-10-08). The developer must allow Microsoft reasonable access to its application so Microsoft can monitor compliance with the API terms. "You will permit Microsoft reasonable access to your Application for purposes of monitoring compliance with these API Terms." **Privacy policy** (https://www.microsoft.com/en-us/privacy/privacystatement), read 2026-10-08, dated 2026-09-01, states 8 of the 8 things a reader expects. - To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). "As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models." - To know. Says it sells personal data or shares it for advertising. "We also disclose personal data for digital advertising purposes." - Gives the date it was last updated. Last updated 2026-09-01. - Says how long data is kept. Names a period of 7 days. - Gives a privacy contact. Names a data protection officer. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict. "In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control." - Also in the text (2026-10-08). Prompts and related data sent to the consumer Microsoft Copilot are used to improve services and for relevant advertising. "Microsoft Copilot also uses prompts and related data to provide and improve services, including relevant advertising." - Also in the text (2026-10-08). Microsoft staff manually review some results of its automated systems, including AI, against the source data. "For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data." ## Live (updated 2026-10-08 20:21 UTC) - Right now: up, HTTP 401, 57 ms, checked 2026-10-08 20:21 UTC (get on `https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity`, asks for auth) - Uptime 24h 100.0% (32 probes) · 30 days 100.0% (32 probes) · p50 32 ms · p95 172 ms - Vendor status page: unknown, no machine-readable status found - Watching changelog - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/microsoft-entra-agent-id.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Microsoft Agent 365 | $15 | per seat per month | billed yearly, needed for Conditional Access, ID Protection and governance for agents | | Microsoft 365 E7 (includes Agent 365) | $99 | per seat per month | billed yearly | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Agent identities can't hold credentials. The blueprint authenticates with a managed identity, certificate or secret and exchanges for the agent's token - Global Administrator and similar roles, and Graph permissions such as Application.ReadWrite.All, are refused for agent identities - Create, list, update, delete and restore are on Microsoft Graph v1.0, with agentIdentity in the public OpenAPI file - Audit and sign-in logs carry an agentType and blueprintId for agent activity - Microsoft.Identity.Web 4.16.0 shipped on 30 September 2026, the eighth tagged release since 9 July ## Weaknesses - Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing - Microsoft's docs call hand-written token exchange complex and error-prone and steer developers to a .NET library or a sidecar container - Creating a blueprint, a principal and an identity in quick succession can fail with 400 until the directory replicates - Audit and sign-in logs are kept seven days on Entra ID Free and 30 days on P1 or P2 - microsoft.com's security.txt passed its Expires date on 23 September 2026 ## Before you call it (notes for agents) 1. Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token 2. Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object 3. Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required 4. Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page 5. Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it ## Connect Install: ```bash dotnet add package Microsoft.Identity.Web.AgentIdentities ``` First request: ```bash curl -X POST https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity \ -H "Authorization: Bearer $BLUEPRINT_TOKEN" -H "Content-Type: application/json" \ -d '{"displayName": "My Agent Identity", "agentIdentityBlueprintId": "", "sponsors@odata.bind": ["https://graph.microsoft.com/v1.0/users/"]}' ``` Through letme (picks today, calling later): https://letme.dev/microsoft-entra-agent-id. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Descope Agentic Identity Hub | A | 78.1 | 13 | auth.oauth, auth.consent, auth.agent-identity, auth.audit | no | https://www.anchorterminal.com/tools/descope-agentic-identity.md | | Aembit | BB | 70.5 | 134 | auth.oauth, auth.agent-identity, auth.consent, auth.audit | no | https://www.anchorterminal.com/tools/aembit.md | | WorkOS Pipes and Agents | C | 59.9 | 418 | auth.oauth, auth.consent, auth.agent-identity, auth.audit | no | https://www.anchorterminal.com/tools/workos-pipes.md | | Keycard | C | 56.2 | 492 | auth.oauth, auth.consent, auth.agent-identity, auth.audit | no | https://www.anchorterminal.com/tools/keycard.md | | Permit MCP Gateway | C | 54.1 | 534 | auth.oauth, auth.consent, auth.agent-identity, auth.audit | no | https://www.anchorterminal.com/tools/permit-mcp-gateway.md | | Scalekit AgentKit | BB | 71.9 | 100 | auth.oauth, auth.consent, auth.agent-identity | no | https://www.anchorterminal.com/tools/scalekit-agentkit.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Agent ID became generally available in April 2026 per the Entra release notes (source: ) - An agent identity blueprint can impersonate only its own child agent identities, and each agent identity is single-tenant (source: ) - Apps outside Microsoft's own platforms that use app-only permissions are capped at 250 agent identities per blueprint, and blueprints can take at most 95 per cent of the tenant's resource quota (source: ) - Deleted agent identities are soft-deleted for 30 days and can be restored through Microsoft Graph or PowerShell, not in the admin centre (source: ) - The Auth SDK sidecar is a container at mcr.microsoft.com/entra-sdk/auth-sidecar that returns an Authorization header over local HTTP, so agents in any language can use it (source: ) - Microsoft documents Entra ID as the authorisation server for an MCP server, with the client sending the RFC 8707 resource parameter (source: ) - The admin consent workflow doesn't work for permissions requested by agent identities, per the FAQ (source: ) ## Compare - [Aembit vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.md): BB 70.5 vs BB 74.4 - [Arcade.dev vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.md): B 66.9 vs BB 74.4 - [Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.md): BB 71.4 vs BB 74.4 - [Descope Agentic Identity Hub vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.md): A 78.1 vs BB 74.4 - [Keycard vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.md): C 56.2 vs BB 74.4 - [Microsoft Entra Agent ID vs Nango](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.md): BB 74.4 vs B 67.7 - [Microsoft Entra Agent ID vs Scalekit AgentKit](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.md): BB 74.4 vs BB 71.9 - [Microsoft Entra Agent ID vs Stytch Connected Apps](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.md): BB 74.4 vs C 60.8 - [Microsoft Entra Agent ID vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.md): BB 74.4 vs C 59.9 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on microsoft.com or one of its subdomains, or the README of github.com/AzureAD/microsoft-identity-web. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "microsoft-entra-agent-id", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Microsoft Entra Agent ID on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Microsoft Entra Agent ID on Anchor Terminal](https://www.anchorterminal.com/badges/microsoft-entra-agent-id.svg)](https://www.anchorterminal.com/tools/microsoft-entra-agent-id) ``` Plain link: ```html Microsoft Entra Agent ID on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Microsoft Entra Agent ID is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/microsoft-entra-agent-id-dark.png - Light: https://www.anchorterminal.com/assets/share/microsoft-entra-agent-id-light.png