Service principal of a special kind representing an AI agent, holding no credentials itself. It can act on its own using app-only permissions or for a user using delegated ones; Conditional Access offers only block, not grant controls, for it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Agent identity in context, with comparison tables and the common traps.
Terms in this definition
- Service principal
The tenant-local instance of a managed identity or app registration, which users and Azure or directory roles are assigned to. Those from app registrations authenticate with a stored certificate or secret that needs rotating and can be copied, which suits code running outside Azure.
- AI agent
Software pairing a generative model with tools, enabling it to understand what is asked, converse and act to reach a goal.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Grant controls
The part of a Conditional Access policy that either blocks access or demands conditions such as MFA, a compliant device or an approved client app. Several can be combined, requiring all of them or just one.
Related terms
- Agent Application
Resource that Azure creates on publishing an agent version; it has a stable endpoint plus its own Microsoft Entra agent identity and blueprint. Role assignments held by the project identity do not carry over and need to be granted again.
- Agent's user account
Optional Microsoft Entra user object tied one-to-one to an agent identity, for services such as a mailbox, Teams or OneDrive that expect a user. No password or passkey exists for it, and privileged admin roles cannot be assigned to it.