Microsoft Entra Agent ID
Conditional Access

Target agents in Microsoft Entra Conditional Access policies

In brief

The article now uses a scenario-based structure, explains that conditions and controls depend on the token subject, and links separately to guidance for agent identities and agent user accounts. Terminology, metadata, and related links were also updated.

What Entra admins need to know

Administrators can identify the token subject first, then follow the applicable policy guidance for autonomous agents or agents acting as users.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#customer intent: As an identity administrator, I want to target agents in Conditional Access policies so that each policy applies to the correct agent identity or agent user account.

Target agent identities in Microsoft Entra Conditional Access policies

Use this article to select agent identities or agent user accounts in a Conditional Access policies for agent identities let you control how AI agentspolicy, choose target resources, configure supported conditions, and select access corporate resources. As your organization deploys more agents, you need policies that targetcontrols.

The available conditions and controls depend on the token subject. To choose the right agents, evaluatesubject before you build the right signals, and enforce the right controls. To learn more about how Conditional Access policies for agents work for different scenarios,policy, see Conditional Access for agents overview.

This article walks through each section of the Conditional Access policy builder for agents:

  • Selecting which agents the policy applies to
  • Choosing target resources
  • Configuring conditions
  • Setting access controls.

Each section builds on the previous one to form a complete policy.

Prerequisites

Create a Conditional Access policy for agent identities

Policies that target agent identities introduce uniqueor agent user accounts have assignment options, conditions, and control limitationscontrols that differ from user-targeted policies.

To create a new Conditional Access policy for agent identities:

  • Policies targeting all users don't include agent's user accounts.
  • The agent users option targets agents' user accounts. This option is currently in Preview.
  • Agent-based policies apply when agents access resources using their own identity, not on behalf of a user.
  • Targeting a blueprint automatically covers all agent identities derived from it, including ones added in the future. For more information about targeting agent identity blueprints,information, see Agent identity blueprints.

Target resources

  • Block access: Deny the agent user account access to resources.
  • Grant access with:
    • Require device to be marked as compliant: Requires agents to run on Intune-managed compliant devices, such as Windows 365 Cloud PCs for Agents. For more information, seeWhat is Windows 365 for Agents?. :::image type="content" source="media/howto-target-agent-identities/agent-policy-grant-device-compliant.png" alt-text="Screenshot of the Conditional Access policy builder showing the grant option for device compliance." lightbox="media/howto-target-agent-identities/agent-policy-grant-device-compliant.png":::

Related content

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…