Policy Autonomous Agents
In brief
The documentation now specifies Microsoft Entra ID P1 or Microsoft 365 E3 for Conditional Access, and Microsoft Entra ID P2 or Microsoft 365 E5 when using agent risk-based Conditional Access with Microsoft Agent 365.
What Entra admins need to know
Administrators can use the clarified licensing requirements to assess eligibility for these Conditional Access scenarios.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
- One of the following license plans:
- Microsoft 365 E7, which includes Agent 365 and Microsoft Entra Suite, to protect access for both users and agents.
- Microsoft Agent
365 license365, pairedwith at leastwith:- Microsoft Entra ID P1 or Microsoft 365
E3.E3 for Conditional Access. - Microsoft Entra ID P2 or Microsoft 365 E5 when using agent risk-based Conditional Access.
- Microsoft Entra ID P1 or Microsoft 365
- At least the Conditional Access Administrator role.
- At least one agent identity registered in your tenant.
- The agent uses the autonomous app OAuth flow.
@@ -23,7 +23,9 @@ Before you start, review the licensing, role, and agent setup requirements. - One of the following license plans: - Microsoft 365 E7, which includes Agent 365 and Microsoft Entra Suite, to protect access for both users and agents.- - Microsoft Agent 365 license paired with at least Microsoft Entra P1 or Microsoft 365 E3.+ - Microsoft Agent 365, paired with:+ - Microsoft Entra ID P1 or Microsoft 365 E3 for Conditional Access.+ - Microsoft Entra ID P2 or Microsoft 365 E5 when using agent risk-based Conditional Access. - At least the [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator) role. - At least one agent identity registered in your tenant. - The agent uses the [autonomous app OAuth flow](../../agent-id/agent-autonomous-app-oauth-flow.md). 