Microsoft Entra Agent ID
Authentication

Agent Token Claims

In brief

The Agent ID token claims documentation no longer includes one `tid` claim table row.

What Entra admins need to know

No product behavior change is indicated. Administrators should use the updated documentation when referencing token claims.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

| sub | Subject (the user, service principal, or agent identity being authenticated) | | oid | Object ID of the subject. User object ID for user delegation scenarios. Agent ID service principal OID for app-only scenarios. Agent's user account OID for user impersonation scenarios. | | idtyp | Type of entity the subject is. Values are user, app. | | tid | Tenant ID of the customer tenant where the agent identity is registered. | | xms_idrel | Relationship between the subject and the resource tenant. Learn more. | | aud | Audience (the API that the agent is trying to access) | | azp or appid | Authorized party / actor. The application ID of the agent identity. Enables proper client attribution in audit logs. |

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…