← Previous day

Day in brief

Agent Conditional Access guidance now separates agent identities, user accounts, and OBO traffic

Agent Conditional Access is the clear center of the 7 October update: a new Entra ID guide covers agents operating through their own user accounts, while Agent ID guidance separates agent identities, agent user accounts, and delegated or on-behalf-of access. The guidance directs administrators to match policy targeting to the token subject and check the stated licensing, role, device, network, registration, and OAuth prerequisites. A separate authentication update refreshes FIDO2 attestation data.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

29 updates

7

Policy Autonomous Agents

Feature update

The documentation now specifies Microsoft Entra ID P1 or Microsoft 365 E3 for Conditional Access, and Microsoft Entra ID P2 or Microsoft 365 E5 when using agent risk-based Conditional Access with Microsoft Agent 365.

Policy Agent User

Doc update

The documentation adds links and clarifies that relevant agents run on Intune-managed Windows 365 Cloud PCs, with Global Secure Access for compliant network policies. It also refines targeting, assignment, and risk-level guidance.

Policy Autonomous Agents

Doc update

The documentation now uses corrected step numbering and clearer instructions for excluding agent blueprints or identities and creating custom attributes and predefined values.

Policy Agent User

Feature update

The documentation now lists Microsoft 365 E7, or Microsoft Agent 365 paired with Microsoft Entra P1 or Microsoft 365 E3, instead of a general Entra ID P1 or P2 requirement.

Policy Autonomous Agents

Feature updateAction required

The documentation now lists two licensing options: Microsoft 365 E7, or Agent 365 paired with Microsoft Entra P1 or Microsoft 365 E3. It also states that Agent 365 will soon be required.

Policy Agent User

Doc update

The guidance now links to the Windows 365 Cloud PC for Agents introduction and the Entra Global Secure Access overview.

Policy Autonomous Agents

Doc update

The documentation now says Microsoft 365 E7 protects access for both users and agents, replacing wording about governance of user and agent identities.

1
1

Secure agent users with Microsoft Entra Conditional Access

New feature

A new guide explains how to apply Conditional Access to agents using their own user accounts, including policies for agent risk, compliant devices, and compliant networks. It also documents agent-specific targeting and prerequisites.

1

Sla Performance

Doc update

The September row now includes an additional 99.999% value in the performance reference table.

15

Secure agents that act as users with Conditional Access

Doc update

The page now covers agent identities and additional policy options, including custom security attributes, agent execution environments, device compliance, network locations, and agent risk. It also updates policy creation steps and links.

Conditional Access for agents

Doc update

The documentation now refers to real-time risk information, rather than session risk information, among the signals used to determine access.

Policy Autonomous Agents

Doc update

The autonomous agents policy documentation now includes a section for custom security attributes in policies.

Agent Id

Doc update

The Agent ID documentation now uses the correct anchor for the “Allow approved agents by using custom security attributes” policy example.

Agent Id

Doc update

The policy example link now points to the `use-custom-security-attributes` section.

Secure autonomous agents with Conditional Access

Feature update

The article now documents the enhanced object picker for selecting agent identities and blueprints, updates policy-creation steps, and notes that an Agent 365 license will soon be required.

Conditional Access for Agents in Microsoft Entra

Doc update

The overview now explains policy decisions, evaluation timing, token subjects and audiences, and supported agent access patterns. It also adds links to related identity-management and policy guidance.

Microsoft Entra Conditional Access for agents overview

Doc update

The overview now explains how Conditional Access evaluates the token subject and resource, and distinguishes delegated, agent-identity, and agent-user-account scenarios. Licensing and network-control requirements remain documented.

Agent Id

Doc update

The documentation now states that Microsoft Entra ID Conditional Access for agents requires an eligible license plan, including Microsoft 365 E7 with Agent 365 and Microsoft Entra Suite. The explanatory governance phrase was removed.

Agent Id

Doc update

The documentation now states that Conditional Access evaluates the signed-in user who is the token subject, including users targeted directly or through groups. Selecting an agent identity does not cover OBO traffic.

Agent Id

Doc update

The documentation clarifies that Conditional Access policies targeting agent identities do not apply to on-behalf-of (OBO) traffic, because the user is the subject of that flow.

Agent Id

Feature update

The licensing requirements now list Microsoft 365 E7, or Microsoft Agent 365 paired with at least Microsoft Entra P1 or Microsoft 365 E3.

Agent Id

Doc update

The Microsoft Agent 365 licensing prerequisite bullet was reformatted for consistency.

4

Agent Id

Doc update

The Conditional Access Agent ID page now links to Microsoft Agent 365 plans and pricing instead of the Agent ID getting-started information.

Howto Target Agent Identities

Doc update

The agent identity targeting documentation now links to the relevant section on Conditional Access policies and agent identity blueprints.

Agent Id

Doc updateAction required

The documentation clarifies that policies scoped through the Users assignment do not apply to agent user accounts, regardless of whether they target all users, selected users, groups, directory roles, or external users. To protect agents, select Agents under Users, agents, or workload identities.

Agent Id

Doc update

The documentation now identifies the agent identity, rather than the application or autonomous agent, as the subject in application-only access.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…