AI Agent & Non-Human Identity Governance
AI agents — Microsoft 365 Copilot Studio agents, Microsoft Foundry agents, custom-built ones, plus traditional service principals and managed identities — are now the fastest-growing identity population in most tenants. They authenticate, hold permissions, act on behalf of users (or themselves), and are usually under-governed.
This skill is the lifecycle governance layer for those identities: ownership, scoping, credential hygiene, reviews, decommissioning, and incident response.
When to use
Establishing or maturing governance for the agent / NHI population — Copilot Studio agents, Foundry agents, custom LLM agents, and the service principals that back them.
Do not use this skill for workload identity federation patterns alone (entra-workload-identity), human identity governance (entra-id-governance), or generic agent build guidance.
Agent identity inventory — know what you're governing
| Class |
Identity model |
Surface |
| Copilot Studio agent (M365) |
Tenant-scoped agent identity + per-user delegated permissions |
M365 admin center / Copilot Studio |
| Microsoft Foundry agent |
Service principal + managed identity + per-user OBO |
Azure portal / Foundry |
| Custom AI agent (your code) |
App registration + workload identity federation / managed identity |
Entra admin center |
| Plugin / connector |
Service principal + delegated/app Graph permissions |
Entra admin center |
| Legacy automation service principal |
App registration, often with secret |
Entra admin center |
Approach
- Inventory and tag. Pull every app registration, service principal, and Copilot
Studio / Foundry agent. Tag each with: - Owner (person + group). - Sponsor / business owner. - Purpose (one sentence). - Data scope (which tenants/sites/mailboxes/resources). - Lifecycle stage (pilot / production / sunset). - Criticality (tier 0 / 1 / 2). Orphaned identities → freeze them; require owner re-claim.
- Scope permissions tightly.
- Microsoft Graph: prefer Sites.Selected over Sites.Read.All, mailbox scoping via Application Access Policy over Mail.Send, custom security attributes over broad directory roles. - Azure: scope role assignments at RG or resource, never subscription Owner unless truly required. - Copilot Studio agent knowledge sources: explicit site/library lists, not "All SharePoint." - Foundry agent tools: only the tools needed; remove http plugin unless necessary.
- Credential hygiene. No client secrets in new builds — federated credentials
(GitHub Actions, Azure DevOps, AKS, external OIDC) or certificates with auto-rotation via Key Vault. Existing secrets: inventory, cap expiry at 180 days, rotate via automation, plan migration to federation.
- Conditional Access for workloads (Workload Identities Premium). Apply to
tier-0 agents and externally-callable agents: - Restrict source IP ranges. - Block legacy auth. - Require named locations. Don't try to apply to every SP in the tenant — focus on high-blast-radius identities.
- Access reviews for agents via Entra ID Governance. Owner reviews per quarter:
- Still needed? - Still the right scope? - Credential rotation up to date? - Owner / sponsor still in role? Auto-disable on owner non-response.
- Lifecycle workflows. Build automation for:
- Provisioning: owner-initiated request → approval → SP created with template permissions, tagged, owner assigned. - Modification: scope change requires re-approval. - Decommissioning: 30-day disable window, then delete; remove role assignments, federated credentials, knowledge-source attachments.
- Audit and monitoring.
- Stream ServicePrincipalSignInLogs and AuditLogs to Sentinel. - For Copilot Studio agents: interaction audit logs via Purview Audit. - Detections: - New high-privilege role assignment to an agent identity. - Agent sign-in from unexpected IP/country. - Sudden spike in Graph API calls per agent. - Sensitive data access by agent outside business hours. - New credential added to an agent by an identity other than its owner.
- Incident response when an agent is compromised.
1. Disable the identity (block sign-in on the app registration / SP). 2. Rotate credentials, revoke refresh tokens. 3. Hunt actions taken by the agent identity in the past 7–30 days (Graph audit, resource activity). 4. Notify data owners for the resources the agent had access to. 5. Root cause (leaked secret? OAuth consent phishing? supply chain?). 6. Restore with tightened scope or retire.
- Couple with usage signals. Purview AI Hub / DSPM for AI shows *what the agent
does* (sensitive data flowing through prompts). Pair with identity audit to get a complete view.
Guardrails
- Every agent identity has a named human owner. Empty owners list = orphan =
audit/security risk.
- No client secrets for new identities. Federation > certificate > secret.
- Sites.Selected (and similar) is mandatory where it exists. "Quick start with
.All and we'll scope later" never scopes later.
- Conditional Access for workloads is a separate license. Confirm SKU before
designing.
- OAuth consent for new agents must be admin-reviewed. End-user consent for high-
privilege scopes is the agent equivalent of a phishing onboarding.
- Decommissioned ≠ deleted in 1 day. 30-day disable window catches "wait, that was
in use somewhere."
- Agent credentials are not for human use. Don't share an agent's secret with the
team for "easier debugging."
- Tag agents with data scope and tier. Without it, IR and reviews are guesswork.
Common anti-patterns
- "Copilot Studio agent grounded on 'All SharePoint'" — same oversharing problem as
Copilot itself, scaled. Use site-scoped knowledge sources.
- "Agent SP granted Mail.Send Application permission tenant-wide" — can email as
anyone. Use app access policies to scope to specific mailboxes.
- "Owner field set to a leaver's account" — orphaned, no review, no rotation.
- "Long-lived client secret in agent code" — git history forever; leak detection
too late.
- "All agents in tier-0 because 'they're all important'" — review and IR effort
becomes uniform but is uniformly low quality. Real tiering.
- "Decommissioned by deleting the app reg, leaving role assignments behind" —
dangling principal IDs in RBAC; restore-with-same-id risk.
- "No audit on Copilot Studio agent interactions" — compromised agent acts
invisibly.
- "Treated agent identity governance as identical to human IGA" — different
lifecycle, different controls, different reviews.
Example prompts
- `Inventory all Copilot Studio agents, Foundry agents, and service principals in the
tenant and produce an owner + scope + tier report.`
Roll out access reviews for 600 agent identities via Entra ID Governance quarterly.
- `Scope a Copilot Studio agent for HR from "All SharePoint" to 4 specific knowledge
sites.`
- `Build a decommissioning workflow: 30-day disable, owner notification, full cleanup of
RBAC and federated credentials.`
- `Sentinel detections for agent identity compromise: new credential, anomalous sign-in,
spike in Graph calls.`
- `IR runbook: compromised Foundry agent that called Microsoft Graph for 48 hours —
containment, hunt, notification.`
- `Replace client secrets across 120 legacy automation SPs with workload identity
federation or Key Vault certificates.`
Apply Conditional Access for workload identities to all tier-0 agents.
Microsoft Learn