# Microsoft Entra Agent ID (slim) > Microsoft Entra Agent ID is an identity type for AI agents in Microsoft Entra ID. Agents get their own directory identity, request OAuth 2.0 tokens autonomously or on behalf of a user, and are managed through Microsoft Graph. - Full: https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md (~9,200 tokens) · this version ~1,980 tokens · JSON https://www.anchorterminal.com/tools/microsoft-entra-agent-id.json · canonical https://www.anchorterminal.com/tools/microsoft-entra-agent-id - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 74.4/100 · rank #63 of 722 · #2 in Agent auth & delegated access · agent-ready · confidence medium** Assessment: Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence. ## Facts - Kind: HTTP API · vendor: Microsoft · category: Agent auth & delegated access · legal entity: Microsoft Corporation · provenance 85/100 - Endpoint: `https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity` (HTTP) - Auth: OAuth · pricing: Freemium · x402: no · licence: Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT - Probe metrics: not measured yet (probes haven't run) - Objects: Agent identity blueprint (a template, like an app registration), blueprint principal, agent identity (a service principal subtype) and an optional agent's user account paired one to one with an agent identity - Token flows: Autonomous app-only (client_credentials), on behalf of a user (jwt-bearer), and the agent's own user account. Refresh tokens for background user-delegated work. No interactive `/authorize` flow and no public clients - Credentials: Held by the blueprint only. Managed identity as a federated identity credential (preferred), client certificate, or client secret for local development - Management API: Microsoft Graph v1.0 at /servicePrincipals/microsoft.graph.agentIdentity for list, create, get, update, delete, owners, sponsors and restore. Inherited permissions, attest and communication configuration are on /beta only - Permissions: AgentIdentity.Create.All (least privileged), AgentIdentity.CreateAsManager, AgentIdentity.ReadWrite.All. Roles Agent ID Developer and Agent ID Administrator - Blocked for agents: Global Administrator, Privileged Role Administrator, User Administrator and role-assignable groups. Graph permissions including Application.ReadWrite.All, RoleManagement.ReadWrite.All, User.ReadWrite.All and Directory.AccessAsUser.All - Rate limits: Graph identity and access limits by token bucket. Per app and tenant, 3,500 to 8,000 resource units per 10 seconds by tenant size and 3,000 writes per 2 minutes 30 seconds. Per tenant, 18,000 writes per 5 minutes. 429 carries Retry-After - Quotas: 250 agent identities per blueprint for outside platforms using app-only permissions, 250 owned objects per non-admin user, blueprints at most 95 per cent of tenant quota - SDKs: Microsoft.Identity.Web.AgentIdentities 4.16.0 on NuGet (.NET), the Auth SDK sidecar container for other languages, Microsoft Graph SDKs and Entra PowerShell for management - Logs: Audit and sign-in logs with agentType and blueprintId. Kept seven days on Entra ID Free and 30 days on P1 or P2, longer if routed to Azure storage - Paid controls: Conditional Access, ID Protection, ID Governance and network controls for agents need Microsoft Agent 365 or Microsoft 365 E7 - Third-party agents: Guides for Amazon Bedrock and n8n through the sidecar or workload identity federation - Deprecation: Microsoft Graph gives at least 24 months' notice before retiring a generally available API or version. /beta can change without notice - Prices: Microsoft Agent 365 $15 per seat per month; Microsoft 365 E7 (includes Agent 365) $99 per seat per month - Scores: Reliability 91, Performance pending, Schema & documentation 87, Agent ergonomics 71, Security & auth 83, Payments & pricing 20, Task success pending, Maintenance & community 80, Transparency & trust 74 · total over the 7 assessed categories - Why: Reliability, Microsoft's SLA page for Entra ID points to the Azure status history for incidents, and that page was readable with dated entries and review… · Schema & documentation, agentIdentity is in Microsoft's public Graph v1.0 OpenAPI file (25). · Agent ergonomics, List calls take `$select`, `$top`, `$filter`, `$search` and `$count`, with a default and maximum page of 100 (20). · Security & auth, OAuth 2.0 with scoped Graph permissions. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Microsoft.Identity.Web 4.16.0, which carries the agent identity package and the sidecar, was tagged on 30 September 2026, and the Agent ID F… · Transparency & trust, Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDK source (15). - Sources: 36, open questions: 8, both in the full twin - Capabilities: auth.oauth, auth.agent-identity, auth.consent, auth.audit - JSON: https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/microsoft-entra-agent-id.svg` or a link to https://www.anchorterminal.com/tools/microsoft-entra-agent-id from a page on microsoft.com or one of its subdomains, or the README of github.com/AzureAD/microsoft-identity-web, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token 2. Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object 3. Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required 4. Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page 5. Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it ## Connect ```bash dotnet add package Microsoft.Identity.Web.AgentIdentities ``` ```bash curl -X POST https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity \ -H "Authorization: Bearer $BLUEPRINT_TOKEN" -H "Content-Type: application/json" \ -d '{"displayName": "My Agent Identity", "agentIdentityBlueprintId": "", "sponsors@odata.bind": ["https://graph.microsoft.com/v1.0/users/"]}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/microsoft-entra-agent-id ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Descope Agentic Identity Hub | A | 78.1 | auth.oauth, auth.consent, auth.agent-identity, auth.audit | https://www.anchorterminal.com/tools/descope-agentic-identity.min.md | | Aembit | BB | 70.5 | auth.oauth, auth.agent-identity, auth.consent, auth.audit | https://www.anchorterminal.com/tools/aembit.min.md | | WorkOS Pipes and Agents | C | 59.9 | auth.oauth, auth.consent, auth.agent-identity, auth.audit | https://www.anchorterminal.com/tools/workos-pipes.min.md | | Keycard | C | 56.2 | auth.oauth, auth.consent, auth.agent-identity, auth.audit | https://www.anchorterminal.com/tools/keycard.min.md | | Permit MCP Gateway | C | 54.1 | auth.oauth, auth.consent, auth.agent-identity, auth.audit | https://www.anchorterminal.com/tools/permit-mcp-gateway.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)