Agent Id
In brief
The documentation clarifies that Conditional Access policies targeting agent identities do not apply to on-behalf-of (OBO) traffic, because the user is the subject of that flow.
What Entra admins need to know
Use policies targeting users and groups to provide Conditional Access guardrails for resources accessed by the agent.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
In this flow, the agent can't reuse the user's original token because it was issued for a different audience. Instead, the agent uses the OBO flow to exchange tokens with Microsoft Entra ID, obtaining a new token scoped to the target resource. This token exchange is also evaluated by Conditional Access, letting admins enforce granular controls over which resources agents can access on behalf of the user.
Because the user is the subject in this flow, Conditional Access policies target users and groups, not agent identities. Policies that target agent identities don't apply to OBO traffic. Use user-targeted policies to provide the Conditional Access guardrails for resources the agent accesses on the user's behalf.
@@ -92,7 +92,7 @@ The most common access pattern is the on-behalf-of (OBO) flow. In the OBO flow, In this flow, the agent can't reuse the user's original token because it was issued for a different audience. Instead, the agent uses the OBO flow to exchange tokens with Microsoft Entra ID, obtaining a new token scoped to the target resource. This token exchange is also evaluated by Conditional Access, letting admins enforce granular controls over which resources agents can access on behalf of the user. -Because the user is the subject in this flow, Conditional Access policies target **users and groups**, not agent identities. +Because the user is the subject in this flow, Conditional Access policies target **users and groups**, not agent identities. Policies that target agent identities don't apply to OBO traffic. Use user-targeted policies to provide the Conditional Access guardrails for resources the agent accesses on the user's behalf. <a name='agents-acting-as-an-application'></a> 