AI engineering

Govern Copilot Studio Agents with Microsoft Entra Agent ID Identities

Find the Entra Agent ID behind each Copilot Studio agent, review its connector permissions, migrate legacy app registrations and apply Conditional Access.

16 min read
On this page

Copilot Studio now creates a Microsoft Entra Agent ID for every new agent, so each agent appears in the Microsoft Entra admin center under Entra ID > Agents > Agent identities as a child of the Microsoft-owned Microsoft Copilot Studio agent identity blueprint. To govern those agents, inventory them in both the Power Platform admin center and Entra, review the connector permissions Copilot Studio attaches to each identity at publish time, migrate older app-registration agents, and target the agent identities with Conditional Access and sponsor-based lifecycle controls.

Who this is for and what you will have at the end

This guide is for identity administrators, Power Platform administrators and Microsoft 365 administrators who share responsibility for Copilot Studio agents. Makers create agents in Copilot Studio, but since May 2026 every new agent also creates a directory object in your tenant. That object is where Entra-side governance happens: sign-in logs, permissions, sponsors, risk and Conditional Access.

At the end you will have:

  • A combined inventory that links each Copilot Studio agent to its Entra Agent ID or legacy app registration.
  • A review routine for the connector permissions attached to each agent identity.
  • A tested migration path for agents still on app registrations.
  • Report-only Conditional Access policies scoped to agent identities, plus a clear view of where those policies are and aren't enforced today.
  • A containment runbook for a misbehaving agent.

If you also need to control what data agents can reach, the SharePoint knowledge source guide covers the user-authenticated side of agent access.

How Copilot Studio agent identities work

Copilot Studio assigns every agent an identity so it can authenticate to channels such as Teams and Omnichannel, and to services. There are now two identity types in most tenants.

PropertyEntra Agent IDApp registration (legacy)
Applies toAgents created after the May 2026 rollout, and migrated agentsAgents created before May 2026 that haven't been migrated
Object typeService principal with an "Agent" subtypeClassic application and service principal
ParentMicrosoft Copilot Studio agent identity blueprintNone
CredentialsFederated identity credentials managed by a Microsoft-owned blueprint; no one in your tenant can mint tokensCredentials can be created by Global, Application or Cloud Application Administrators, or by owners
Connector permissions visible in EntraYes, attached at publish timeNo API scopes attached
Agent owner added asSponsorOwner of the app registration

A few points from the Copilot Studio documentation are worth stating plainly:

  • The authentication flow doesn't change. Agent IDs use the same OAuth-based flows as app registrations. The difference is governance visibility and lifecycle management.
  • You can't opt out. Environment-level opt-out existed before May 2026; it no longer does for new agents.
  • You can't bring your own identity. Copilot Studio requires automatic management.
  • Agent Builder agents have no identity. Agents built with Agent Builder in Microsoft Copilot don't use app registrations or Agent IDs.
  • The blueprint is created on first use. When the first agent identity is created, Copilot Studio adds the Microsoft Copilot Studio agent identity blueprint and its blueprint principal to your tenant. Copilot Studio documents the blueprint ID as 25664c89-cea5-4ab6-b924-a54fd8a19ae0, and all Copilot Studio agent identities are children of it.

Prerequisites

TaskRequirement
View agent identities in EntraAny Microsoft Entra user account; no admin role is needed
Manage or disable agent identitiesAgent ID Administrator or Cloud Application Administrator (owners can manage their own agents)
Create Conditional Access policiesConditional Access Administrator
Conditional Access for agents licensingMicrosoft 365 E7, or a Microsoft Agent 365 license paired with at least Microsoft Entra ID P1 or Microsoft 365 E3; agent risk-based policies need Microsoft Entra ID P2 or Microsoft 365 E5 alongside Agent 365
ID Protection risk reports for agentsSecurity Administrator, Security Operator or Security Reader; Microsoft states that ID Protection for agents will require a Microsoft Agent 365 license
Power Platform inventoryGlobal Administrator, Power Platform Administrator, Dynamics 365 Administrator, Global Reader, AI Administrator or AI Reader
Manual migration of legacy agentsPower Platform Administrator, Dynamics 365 Administrator or Global Administrator, with Power Platform inventory enabled

Microsoft Entra Agent ID itself is available to all Microsoft Entra customers. Extending Entra security features such as Conditional Access to agents is what requires Microsoft Agent 365, which is included in Microsoft 365 E7 and available as an add-on to Microsoft E5, A5 and Business Premium (or Microsoft Defender Suite plus Microsoft Purview Suite).

Also check directory capacity. Every Entra Agent ID that Copilot Studio creates is a directory object and counts against the tenant resource quota: 50,000 objects by default, or 300,000 if the tenant has a verified domain (tenants created through self-service signup stay at 50,000). The identity is provisioned when the agent is created, so a tenant at quota can't create new agents. The per-blueprint cap of 250 agent identities doesn't apply to Copilot Studio because its blueprint is Microsoft-owned.

Step 1: Build the inventory from both sides

Power Platform admin center

The Power Platform inventory lists every agent created in Copilot Studio or Agent Builder, including drafts, and refreshes within about 15 to 20 minutes of a change.

  1. Sign in to the Power Platform admin center.
  2. Go to Manage > Copilot Studio for agents, or Manage > Inventory for all resource types.
  3. Add columns with the Add or remove columns icon and filter by environment, owner or creation date.
  4. Select Download to export the full inventory to CSV.

For Copilot Studio agents, the inventory schema exposes identity fields that join the two worlds: entraAgentId and entraAgentBlueprintId for agents on the new model, and entraAppId for legacy agents. It also reports authentication, channels, sharedWithViewers (including whether the agent is shared with the entire tenant) and the Power Platform connectors each agent uses.

If a Conditional Access policy requires MFA for Azure Resource Manager, the inventory might not load. The documented fix is to include the Power Platform admin center application (00b46ad5-e4ae-43ac-a878-281fc03d0839) and the Microsoft Azure Management resource in that MFA policy.

Microsoft Entra admin center

  1. Sign in to the Microsoft Entra admin center.
  2. Browse to Entra ID > Agents > Agent blueprints and select Microsoft Copilot Studio agent identity blueprint.
  3. Use View linked agent identities to list every Copilot Studio agent identity in the tenant.
  4. For the full tenant list, browse to Entra ID > Agents > Agent identities. Select Choose columns and add Blueprint App ID, Owners and Sponsors and Uses agent identity.

The Uses agent identity column separates real agent identity objects from agents that use a classic service principal. Legacy Copilot Studio agents fall into the second group.

When a maker reports a problem with one agent, find its identity from the agent itself:

  1. In Copilot Studio, open the agent's Settings page and select Advanced.
  2. Expand Metadata. The GUID under Entra Agent ID identifies the agent identity. Legacy agents show the application ID in the same section.
  3. Search for that GUID in the Microsoft Entra admin center.

Step 2: Review the connector permissions on each identity

When a maker publishes an agent, Copilot Studio attaches API permissions to the agent's Entra Agent ID for every Power Platform connector the agent is configured to use. Each connector has its own service principal in your tenant, and that service principal grants one of these permissions:

PermissionWhen it's granted
Operations.Execute.AllThe connector is added at the agent (tool) level, so the agent can invoke any operation the connector exposes
Individual operation scopesThe maker added specific connector actions instead of the whole connector
Azure API Connections Runtime.AllGeneric fallback for connectors that don't define granular scopes

To review them, open the agent identity in the Microsoft Entra admin center and check API permissions, or use the View Access column in the agent identity list.

Keep these limits in mind when you read the list:

  • Scopes are evaluated and applied at publish time. Adding or removing a connector and republishing updates them.
  • The scopes describe connector access only, not raw resource permissions such as Mail.Read. The Power Platform connector runtime is the only component that honors them, and it revalidates every call against your advanced connector policies and data policies. Data policies still decide what an agent is allowed to do at run time.
  • Today this applies to first-party and certified connectors. Custom connectors, MCP servers and REST API tools don't add API permissions to the Entra Agent ID, so they won't show up here. Use the connector inventory in the Power Platform admin center for those.

A useful review pattern is to flag agents with Operations.Execute.All on a high-impact connector and ask the maker whether specific actions would be enough.

Step 3: Migrate legacy app-registration agents

Microsoft states that existing app-registration agents are being migrated automatically. Migration keeps the application (client) ID, so channel registrations and connectors keep resolving, and Microsoft describes it as zero downtime. You can migrate earlier, which is the only way to test Conditional Access against those agents on your schedule. The manual migration experience is in preview.

Migrate in the Power Platform admin center

  1. Sign in to the Power Platform admin center and select Actions > Recommendations.
  2. On the Active tab, open Migrate Copilot Studio agents to Microsoft Entra Agent ID for enhanced agent governance.
  3. Review Suggested migration order and Migration notes to choose a pilot batch of noncritical agents that still covers your channels, authentication modes and connectors.
  4. Select the agents, select Migrate, and confirm.
  5. Track Action, Action state and Action date, or open Action history.

Agree a validation window with the makers first. After each batch, confirm that every agent responds in each published channel, runs its connectors and flows, and authenticates as expected. Review the Entra sign-in logs before moving to the next batch. If an agent fails validation, stop and revert it.

Migrate or revert with the Power Platform API

For scripted batches, the Power Platform API exposes migrate and rollback operations per agent. You need the agent's BotId and EnvironmentId, which the inventory shows under Manage > Copilot Studio, and a token from an account with one of the admin roles listed earlier.

$token = (Get-AzAccessToken -ResourceUrl "https://api.powerplatform.com").Token
 
$environmentId = "<EnvironmentId>"
$botId = "<BotId>"
 
$uri = "https://api.powerplatform.com/copilotstudio/environments/$environmentId/bots/$botId/api/agentidentitymigration/migrate?api-version=2024-10-01"
Invoke-RestMethod -Method Post -Uri $uri -Headers @{ Authorization = "Bearer $token" }

A successful call returns a status of Migrated (or AlreadyMigrated) along with the new agentIdentityId. To revert, call the same path with rollback in place of migrate; the response status is RolledBack or NotMigrated.

Step 4: Target Copilot Studio agents with Conditional Access

Conditional Access policies for agent identities have three rules that differ from user policies:

  • The only grant control is Block access, because an agent signing in as itself can't complete interactive remediation.
  • The only condition is Agent risk (Preview).
  • Targeting a blueprint covers every agent identity created from it, including future ones.

For Copilot Studio there is a fourth rule that matters more than the others: runtime enforcement on the agent identity currently happens only when the agent runs in Microsoft Teams. Teams is the only channel that authenticates end to end with the Entra Agent ID token. In other channels you can see the scopes, but connector calls use the existing Power Platform connector authentication flow and Conditional Access on the agent identity isn't evaluated.

Start with a report-only baseline

A report-only policy that blocks all agent identities shows which agents would be affected without stopping anything.

  1. Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator and browse to Entra ID > Conditional Access > Policies.
  2. Select New policy and name it.
  3. Under Assignments, select Users, agents (Preview) or workload identities, set What does this policy apply to to Agents, and choose All agent identities.
  4. Under Target resources, include All resources (formerly 'All cloud apps').
  5. Under Access controls > Grant, select Block.
  6. Set Enable policy to Report-only and select Create.

The same policy through Microsoft Graph is a POST to https://graph.microsoft.com/beta/identity/conditionalAccess/policies with this body:

{
  "displayName": "Block all agent identities from accessing resources",
  "conditions": {
    "clientApplications": {
      "includeAgentIdServicePrincipals": ["All"],
      "excludeAgentIdServicePrincipals": [],
      "agentIdServicePrincipalFilter": null
    },
    "applications": {
      "includeApplications": ["All"],
      "excludeApplications": []
    }
  },
  "grantControls": {
    "operator": "AND",
    "builtInControls": ["block"]
  },
  "state": "enabledForReportingButNotEnforced"
}

Narrow it to approved agents

To turn the baseline into an allow-list, choose Select agent identities and exclude approved agents individually or by custom security attributes. Attributes scale better: once an approval value is on an agent, every policy that keys on it applies automatically. Add a second report-only policy that includes All agent identities, sets Agent risk (Preview) to High, and blocks.

Remember the user side

Most Copilot Studio knowledge and tool calls run on behalf of the signed-in user. In that on-behalf-of pattern the user is the token subject, so your user policies apply and a policy targeting the agent identity doesn't. The Zero Trust remote access architecture describes how those user-side controls fit together.

Step 5: Assign accountability and plan the lifecycle

Copilot Studio adds the agent owner as a sponsor of the Entra Agent ID. Sponsors have fewer permissions than owners and are accountable for the agent's purpose and lifecycle. Some older agents might not have sponsors yet, so check the Owners and Sponsors column in your inventory.

Entra handles sponsor continuity for you in two ways:

  • If a sponsor leaves the organization, sponsorship is automatically reassigned to the sponsor's manager.
  • Lifecycle Workflows provides mover and leaver tasks that email the manager or cosponsors about sponsorship changes.

Deleting an agent in Copilot Studio also deletes its Entra Agent ID or app registration, so orphaned identities from deleted agents shouldn't accumulate.

Step 6: Contain an agent that misbehaves

Choose the narrowest control that stops the problem.

ControlWhereEffect
Block a published agentPower Platform admin center inventory or Manage > Copilot StudioAgent can't be used in any channel; makers can still see and test it; reversible
Disable the agent identityEntra ID > Agents > Agent identitiesBlocks token issuance and sign-in; identity and metadata are kept; reversible
Confirm compromiseRisky Agents report in ID ProtectionSets risk to High and triggers any risk-based block policy
Conditional Access blockPolicy targeting the agent identityStops token issuance; enforced on the agent identity in Teams today

Don't disable the Copilot Studio blueprint to stop one agent. Disabling a blueprint blocks existing identities and prevents new ones, and every Copilot Studio agent identity in the tenant is a child of that single blueprint.

Verify the setup

  1. In the Microsoft Entra admin center, browse to Entra ID > Monitoring & health > Sign-in logs as at least a Reports Reader. Filter Is Agent to Yes, or Agent type to Agent Identity.
  2. Check the Report-only tab on agent sign-ins for your baseline policy. Approved agents should show the policy as not applied once your exclusions are in place.
  3. Query service principal sign-ins by agent identities through Microsoft Graph:
GET https://graph.microsoft.com/beta/auditLogs/signIns?$filter=signInEventTypes/any(t: t eq 'servicePrincipal') and agent/agentType eq 'AgentIdentity'
  1. In audit logs, remember that agent identity creation appears as a service principal event. A value other than notAgentic in the agentType property means an agent was involved.

Troubleshooting

SymptomLikely causeFix
Agent creation fails with a Microsoft Entra quota or limit errorTenant at its directory object quota, or tenant less than two days old (capped at 600 objects)Remove unused objects or raise the quota as described in the Entra service limits article
Conditional Access policy shows no effect on an agentAgent isn't running in Teams, or the call is on behalf of a userExpect enforcement only in Teams today; apply controls through user policies for delegated calls
Agent works in the test pane but doesn't reply in Teams after migrationA Conditional Access policy blocks the authentication Teams needsReview the agent's sign-in events and the policies applied
Agent missing from the Agent identities listLegacy app-registration agent, or an Agent Builder agentCheck Uses agent identity; migrate legacy agents; Agent Builder agents have no identity
A connector the agent uses isn't in API permissionsCustom connector, MCP server or REST tool, or the agent wasn't republishedUse the Power Platform connector inventory; republish after tool changes
Inventory or Advisor shows no agentsInventory not enabled, or missing admin roleEnable Power Platform inventory and sign in with a supported role
Migration skips an agentAgent already has an Entra Agent ID, or the BotId or EnvironmentId is wrongConfirm the identifiers in the inventory

Checklist

  • Inventory exported from the Power Platform admin center with entraAgentId, entraAppId, channels and sharing.
  • Copilot Studio blueprint located in Entra and its linked agent identities reviewed.
  • Connector permissions reviewed for broad Operations.Execute.All grants.
  • Legacy agents migrated in small validated batches, or scheduled for it.
  • Report-only Conditional Access baseline and high-risk policy created for agent identities, with Teams-only enforcement understood.
  • Sponsors present on every agent identity.
  • Containment runbook agreed: Block in Power Platform, Disable in Entra, never the shared blueprint.

For the wider design of AI workloads that read corporate data, see the production LLMOps and enterprise RAG architecture.

References

Questions people ask

Does Copilot Studio create a Microsoft Entra Agent ID for every agent?

Yes, for agents created after the May 2026 rollout. Copilot Studio automatically creates an Entra Agent ID for each new agent as a child of the Microsoft Copilot Studio agent identity blueprint, and you can no longer opt out. Agents created earlier keep their app registration until Microsoft migrates them or you migrate them yourself.

Can I bring my own app registration or agent identity to Copilot Studio?

No. Copilot Studio requires automatic management of the agent identity. A Microsoft-owned blueprint principal creates agent identities with federated identity credentials, and nobody in your tenant, including tenant administrators, can generate tokens with them.

Why doesn't my Conditional Access policy affect a Copilot Studio agent?

Conditional Access on the agent identity is currently evaluated only when the agent runs in Microsoft Teams, because Teams is the only channel that authenticates end to end with the Entra Agent ID token. In other channels the scopes are visible in Entra but connector calls still use the existing Power Platform connector authentication flow.

What happens to the Entra Agent ID when a Copilot Studio agent is deleted?

Copilot Studio deletes the associated Entra Agent ID (or the app registration for legacy agents) when you delete the agent. Use Block in the Power Platform admin center or Disable in the Microsoft Entra admin center when you need to stop an agent but keep its identity and metadata.

Copilot StudioMicrosoft Entra Agent IDConditional AccessMicrosoft Agent 365Power Platform
  1. Govern Copilot Studio Agents with Data Policies and an Environment Strategy

    Use Power Platform environments, environment routing and data policies to control which knowledge sources, connectors, HTTP calls and channels Copilot Studio agents can use and publish to.

    AI engineering11 min read
  2. Copilot Studio SharePoint Knowledge: Set It Up and Fix No-Answer Errors

    Add SharePoint sites and lists as Copilot Studio knowledge, choose the right authentication, and fix agents that answer "I'm not sure how to help with that."

    AI engineering12 min read
  3. Audit, Retain and Search Microsoft 365 Copilot Prompts with Purview

    Find Copilot interactions in the Purview audit log, keep or delete prompts and responses with a retention policy, and search or purge them with eDiscovery when something goes wrong.

    AI engineering11 min read