Microsoft Entra Agent ID
Conditional Access

Agent Id

In brief

The documentation now states that Conditional Access evaluates the signed-in user who is the token subject, including users targeted directly or through groups. Selecting an agent identity does not cover OBO traffic.

What Entra admins need to know

Administrators should use user-targeted policies when defining Conditional Access guardrails for resources accessed through OBO.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

In this flow, the agent can't reuse the user's original token because it was issued for a different audience. Instead, the agent uses the OBO flow to exchange tokens with Microsoft Entra ID, obtaining a new token scoped to the target resource. This token exchange is also evaluated by Conditional Access, letting admins enforce granular controls over which resources agents can access on behalf of the user.

Because the signed-in user is the token subject in this flow, Conditional Access evaluates policies targetassigned to that users and groupsuser, notwhether the user is targeted directly, through a group, or through another supported user-targeting mechanism. Selecting an agent identities. Policies that targetidentity as the policy subject doesn't cover agent identities don't apply to OBO traffic. Use user-targeted policies to providerequests made on behalf of the Conditional Access guardrails for resources the agent accesses on the user's behalf.user.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…