---
name: Entra Agent ID Audit
description: Inventories every Microsoft Entra Agent ID, flags agents with no accountable sponsor, and reports Conditional Access coverage per agent.
lastReviewed: 2026-09-30
---

# Entra Agent ID Audit

> **TL;DR:** This skill lists every agent identity in your Microsoft Entra tenant, flags agents with no accountable sponsor, and shows which Conditional Access policies target each one, so an administrator can close governance gaps. It is read-only.

## What does the Entra Agent ID audit inventory?

This skill inventories Microsoft Entra agent identities, the identities Entra assigns to AI agents such as those built in Copilot Studio, then flags agents without an active sponsor, lists their granted permissions, and reports which Conditional Access policies target them, so an Entra administrator can close governance gaps. As Agentic AI grows, these non-human identities need governing like any other privileged account. The audit ranks agents so those combining no accountable sponsor, broad permissions and no Conditional Access coverage rise to the top.

## When should you run this skill?

Run this skill when you need to know which AI agents exist in your Microsoft Entra tenant, who is accountable for them, and whether Conditional Access covers them, for example before rolling out Microsoft 365 Copilot agents or during a periodic access review of non-human identities. Example prompts:

- "Audit Entra Agent IDs"
- "Review AI agents in Entra"
- "Inventory autonomous agents in our tenant"
- "Which agents have no Conditional Access policy applied?"

## How this skill works, step by step

1. List every agent identity in the tenant (Microsoft Entra admin center: Entra ID > Agents > Agent identities, or Microsoft Graph).
2. For each agent capture: name, created-on date, status, blueprint app ID, owners, sponsors and granted permissions.
3. Add last activity from the agent sign-in logs (filter by agent type).
4. Flag agents with no sponsor, or whose sponsor account is disabled or deleted. Sponsors are required on creation, so a missing one signals drift.
5. Flag agents that no Conditional Access policy targets, directly, through their agent identity blueprint, or through custom security attributes.
6. Flag agents holding broad permissions, such as write access to the directory or to mail and files.
7. Rank by composite risk: no active sponsor plus broad permissions plus no Conditional Access policy is High. This ranking is the skill's own heuristic, not a Microsoft-defined rating.
8. Produce the register table below.

## Output format

| Agent Name | Agent ID | Owners | Sponsors | Last Sign-in | Blueprint App ID | Permissions | CA Coverage | Risk |
| --- | --- | --- | --- | --- | --- | --- | --- | --- |

Followed by a summary:

- Total agents: N
- No active sponsor: N
- No Conditional Access coverage: N
- High risk: N (requires immediate review)

## Scope and safety

Read-only by default; the skill never disables or modifies agents. This skill does NOT:

- Disable or modify agents (read-only).
- Create Conditional Access policies (see Conditional Access for agents).
- Audit agent prompt content or runtime decisions.
- Cover access that bypasses Microsoft Entra, such as an API key. Conditional Access does not apply to it.

## Licensing and permissions

### Licences

- Microsoft Entra Agent ID is available to all Microsoft Entra customers.
- Extending Microsoft Entra security features, including Conditional Access, to agents requires Microsoft Agent 365 (a licence for each user) with Microsoft Entra ID P1 or P2.
- Learn notes that enforcement of Agent 365 licensing is coming soon. Check current terms before relying on this.
- Agent 365 is included in Microsoft 365 E7 and available as an add-on to Microsoft E5/A5/Business Premium.

### Least-privilege access

- Viewing agent identities in the admin center needs no admin role.
- Agent ID Administrator is the least-privileged built-in role for non-owners calling the Graph agent identity APIs with delegated access.
- Reports Reader (at least) is needed to view agent sign-in logs.
- Microsoft Graph application or delegated permission `AgentIdentity.Read.All` reads agent identities.

## Related skills

- [Agent 365 Registry and Shadow AI Discovery](/cowork/agent365-registry-shadow-ai-discovery): run before to compare registered agents with unmanaged agents found on endpoints
- [Entra Agent Identity Sponsorship Lifecycle](/cowork/entra-agent-sponsorship): run after to audit the sponsorship model and sponsor-departure handling
- [Conditional Access for Agents](/cowork/conditional-access-for-agents): run after to draft a Conditional Access policy specification for an agent
- [Workload Identity Risk Audit](/purview/workload-identity-risk-audit): run alongside to review service principals and managed identities for risk signals
- [Governing AI Agents in Microsoft 365](/cowork/agent-governance-guide): the pillar guide to governing agents by finding them first

## Notes

- Learn's What's new page states Microsoft Entra Agent ID is generally available, but marks individual features as preview, such as the Agent execution environments Conditional Access condition and ID Protection for agents. Confirm feature status for your tenant.
- The Conditional Access page lists Microsoft Entra Internet Access for network controls, and marks the Agent execution environments condition as preview.
- Microsoft Entra ID Protection risk reports for agents are outside this skill.

## Sources

Reviewed 2026-09-30 against the pages below.

- [Conditional Access for agents](https://learn.microsoft.com/en-us/entra/identity/conditional-access/agent-id)
- [What is Microsoft Entra Agent ID?](https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id)
- [What is the Microsoft agent identity platform (licensing)](https://learn.microsoft.com/en-us/entra/agent-id/what-is-agent-id-platform)
- [What are agent identities](https://learn.microsoft.com/en-us/entra/agent-id/what-are-agent-identities)
- [What's new in Microsoft Entra Agent ID](https://learn.microsoft.com/en-us/entra/agent-id/whats-new-agent-id)
- [Administrative relationships: owners, sponsors and managers](https://learn.microsoft.com/en-us/entra/agent-id/agent-owners-sponsors-managers)
- [Manage agent identities in your organization](https://learn.microsoft.com/en-us/entra/agent-id/manage-agent-identities-admin)
- [View and filter agent identities in your tenant](https://learn.microsoft.com/en-us/entra/agent-id/agent-lists)
- [Microsoft Entra Agent ID logs](https://learn.microsoft.com/en-us/entra/agent-id/sign-in-audit-logs-agents)
- [List agentIdentity objects (Microsoft Graph)](https://learn.microsoft.com/en-us/graph/api/agentidentity-list?view=graph-rest-1.0)
