Microsoft Entra ID
General

Policy Autonomous Agents

In brief

The documentation now uses corrected step numbering and clearer instructions for excluding agent blueprints or identities and creating custom attributes and predefined values.

What Entra admins need to know

No administrator action is required; use the updated steps when following this guidance.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

The enhanced object picker replaces the previous flat list experience in both the assignment and target resources sections of policy configuration. The new experience is meant to simplify the selection of items you want to scope in the policy.

  1. Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator.
  2. Browse to Entra ID > Conditional Access > Policies.
  3. Select New policy.
  4. Give your policy a name. Create a meaningful standard for the names of your policies.
  5. Under Assignments, select Users, agents or workload identities.
    1. Under What does this policy apply to?, select Agents.
      1. Under Include, select All agent identities.
      2. Under Exclude:
        1. Select Select individual agent identities.
        2. Using the enhanced object picker, switch between the tabs All, Agent blueprint principals, and Agent identities tabs to select the individual agent blueprints and/blueprints, agent identities, or agent identities approved for use in your environment.both that you want to exclude.
        3. Select Select.
  6. Under Target resources:
    1. Under Include, select All resources (formerly 'All cloud apps').
  7. Under Access controls > Grant:
    1. Select Block.
    2. Select Select.
  8. Confirm your settingssettings, and set Enable policy to Report-only.
  9. Select Create to create your policy.

[!INCLUDE conditional-access-report-only-mode]

Create and assign custom attributes

  1. Create the custom security attributes:
    1. Create an Attribute set named AgentAttributes.
    2. Create a New attributesattribute named AgentApprovalStatus that has Allow multiple values to be assigned and Only allow predefined values to be assigned. selected.
      1. Add the following predefined values: New, In_Review, HR_Approved, Finance_Approved, and IT_Approved.
  2. Create another attribute set to group resources that your agents are allowed to access.access:
    1. Create an Attribute set named ResourceAttributes.
    2. Create a New attributesattribute named Department that has Allow multiple values to be assigned and Only allow predefined values to be assigned. selected.
      1. Add the following predefined values: Finance, HR, IT, Marketing, and Sales.
  3. Assign the appropriate value to resources that your agent is allowed to access. For example, you might want only agents that are HR_Approved to be able to access resources that are tagged HR.

Create Conditional Access policy

After you complete the previous steps, create a Conditional Access policy using custom security attributes to block all agents except those reviewed and approved by your organization.

After you complete the previous steps, create a Conditional Access policy using custom security attributes to block all agents except those reviewed and approved by your organization.

  1. Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator and Attribute Assignment Reader.
  2. Browse to Entra ID > Conditional Access > Policies.
  3. Select New policy.
  4. Give your policy a name. Create a meaningful standard for the names of your policies.
  5. Under Assignments, select Users, agents or workload identities.
    1. Under What does this policy apply to?, select Agents.
      1. Under Include, select All agent identities.
      2. Under Exclude:
        1. Select Select agent identities based on attributes.
        2. Set Configure to Yes.
        3. Select the Attribute weattribute you created earlier calledearlier, AgentApprovalStatus.
        4. Set Operator to Contains.
        5. Set Value to HR_Approved.
        6. Select Done.
  6. Under Target resources:
    1. Under Include, select All resources (formerly 'All cloud apps').
  7. Under Access controls > Grant:
    1. Select Block.
    2. Select Select.
  8. Confirm your settings and set Enable policy to Report-only.
  9. Select Create to create your policy.

[!INCLUDE conditional-access-report-only-mode]

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…