Entra ID

Agentic Identity Standards: Microsoft Entra’s View

3 min read

Summary

Microsoft has outlined how identity standards are evolving to support AI agents and other non-human identities in enterprise environments. The company highlights key standards work around trust bootstrapping, delegation, and reducing shared-secret use, signaling important changes for Entra administrators planning secure AI agent access.

Need help with Entra ID?Talk to an Expert

Introduction

AI agents are rapidly moving from pilot projects into real enterprise workflows, and identity systems now need to support them securely. In a new Microsoft Entra blog, Pamela Dingle explains how the standards landscape is shifting to accommodate agentic identities, with major implications for authentication, authorization, and governance.

What’s changing in agentic identity standards?

Microsoft says the biggest shift is conceptual: identity standards are no longer treating non-human identities as narrowly scoped actors with rigid boundaries. As AI agents gain reasoning capability and make decisions, the industry is rethinking how software identities establish trust and act across systems.

1. Bootstrapping trust for non-human identities

A core challenge is how AI agents, workloads, and service principals securely announce themselves and request access. Microsoft points to growing standards activity in this area, including:

  • OAuth ClientID Metadata Document (CIMD)
  • OAuth 2.0 Protected Resource Metadata (RFC 9728)
  • IETF WIMSE work connecting SPIFFE and OAuth
  • Broader automation for non-human onboarding across environments

This matters because manual federation-style onboarding does not scale well for large numbers of agents.

2. Delegation models are being reworked

Delegation is another major debate. Existing concepts such as token exchange, on-behalf-of (OBO), identity chaining, and token upscoping/downscoping are being revisited as agents begin acting with more autonomy.

Microsoft notes this area is still unsettled, so admins should expect continued standards discussions before best practices fully stabilize.

3. Shared secrets are becoming a bigger risk

The post also warns about growing reliance on API keys and other shared secrets in agent scenarios. Microsoft expects stronger focus on eliminating these patterns in favor of more secure, standards-based trust mechanisms.

Why this matters for Entra administrators

For IT and identity teams, this is an early signal that AI agent governance will increasingly depend on open identity standards. Entra admins should expect future capabilities and integrations to align more closely with industry efforts such as MCP, IETF, OpenID Foundation, FIDO Alliance, and AAIF.

In practice, this means administrators will need to think beyond traditional user and app identity models when planning access controls, trust relationships, and lifecycle management for AI-driven services.

Next steps

  • Review current use of API keys and shared secrets in AI or automation projects
  • Track standards communities influencing agentic identity, especially MCP and IETF
  • Follow Microsoft Entra Agent ID updates for future implementation guidance
  • Prepare for more dynamic onboarding and delegation models for non-human identities

Microsoft’s message is clear: agentic identity is becoming a foundational architectural layer, and standards will play a central role in making AI agents manageable and secure at enterprise scale.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Entra IDagentic identityAI agentsOAuthidentity standards

Related Posts

Entra ID

Microsoft Entra ID Branded Sign-In CSS Changes 2026

Microsoft Entra ID is tightening the security of branded sign-in pages by retiring support for custom CSS positioning properties starting October 26, 2026. Organizations that use these properties in company branding should review and remove them now to avoid layout changes and maintain a trusted sign-in experience.

Entra ID

Microsoft Entra Zero Trust Updates for AI and Apps

Microsoft has announced new Microsoft Entra Internet Access and Private Access capabilities to secure AI, web, and private app traffic with Zero Trust controls. The update adds public preview features for network DLP, AI agent controls, and agentic scenarios, while generally available features expand secure access for BYOD, kiosk devices, and MCP traffic visibility.

Entra ID

Azure AD B2C Migration Policy Analyzer Now GA

Microsoft has made the Migration Policy Analyzer generally available to help organizations assess Azure AD B2C custom policies before moving to Microsoft Entra External ID. The tool generates a structured migration assessment, helping IT teams understand current implementations, identify gaps, and prioritize migration work faster.

Entra ID

Microsoft Entra Agent ID: Secure AI Agent Access

Microsoft is urging organizations to treat AI agent governance as an immediate identity and access problem, not a future concern. Based on feedback from identity professionals at Identiverse 2026, the company highlights unmanaged agent sprawl, orphaned agents, and weak agent-to-agent controls, while positioning Microsoft Entra Agent ID and Agent 365 as the foundation for inventory, ownership, and policy enforcement.

Entra ID

Microsoft Entra Agent ID Adds AI Agent Governance

Microsoft has announced general availability of agent identity governance capabilities in Microsoft Entra as part of Microsoft Agent 365. The update helps organizations govern AI agents with dedicated identities, named sponsors, access packages, and lifecycle workflows to reduce overprivileged access and improve accountability.

Entra ID

Microsoft Purview and Entra Add Real-Time AI DLP

Microsoft has announced a public preview that extends data protection to the network layer using Microsoft Purview and Microsoft Entra. The integration helps organizations detect and block sensitive data moving to unmanaged SaaS, personal cloud storage, and generative AI apps in real time, reducing data leakage risk before exposure occurs.