Pro User
Timespan
explore our new search
​
Agent 365: Conditional Access for AI
Microsoft Entra
Oct 4, 2026 5:48 PM

Agent 365: Conditional Access for AI

by HubSite 365 about Rafsan Huseynov

IT Program Manager @ Caterpillar Inc. | Power Platform Solution Architect | Microsoft Copilot | Project Manager for Power Platform CoE | PMI Citizen Developer Business Architect | Adjunct Professor

Secure AI agents with Microsoft Entra Conditional Access, agent identities, sign-in logs and Zero Trust

Key insights

  • Conditional Access for agents: The video explains that Conditional Access evaluates an agent’s identity, context, and risk before issuing tokens or allowing access to resources.
    It treats AI agents as first-class identities so teams can govern them like users and workloads.
  • Agent 365 and Microsoft Entra Agent ID: Agent 365 is presented as the control plane for agent identities and protections.
    Microsoft Entra Agent ID gives each agent its own identity so Zero Trust rules can apply consistently.
  • Why agents need protection: The video shows organizations must control when agents get tokens, which resources they can reach, and whether a risky agent should be blocked.
    That reduces the chance a compromised agent can access email or other sensitive services.
  • Live demo highlights: The presenter creates a Conditional Access policy that blocks an agent’s email access and then verifies the effect in the agent’s sign-in logs.
    It also covers the “one agent, two identities” scenario where an agent can use multiple identity types.
  • How to build policies in practice: Go to Entra ID > Conditional Access, select Users, agents or workload identities, target All agent identities or a subset, and choose Grant: Block or allowed controls.
    Microsoft recommends starting in Report-only mode and using agent risk signals for gradual rollout.
  • Scale and governance: Use custom security attributes and blueprint-level controls to apply rules across many agents and enforce consistent behavior.
    The guidance notes templates for high-risk agents and signals that an Agent 365 license will be required for some features.

Conditional Access for AI Agents — Overview

Overview of the video and context

Rafsan Huseynov’s YouTube video, titled Add Extra Protection to Your AI Agents with Conditional Access | Agent 365, explains how organizations can extend identity and access controls from people to AI agents. He frames the update as part of Microsoft’s broader move to treat agents as first-class identities inside Microsoft Entra, which lets security teams apply familiar controls to automated actors. Consequently, the presentation connects familiar Zero Trust concepts to a new class of identities that increasingly interact with sensitive resources. The video is practical and aimed at administrators who must balance protection and continuity for agent-driven workflows.

In addition, Huseynov structures the content with clear chapters that cover what Conditional Access is, why agents need it, how it works, and a live demo that proves policy effects in real sign-in logs. He also highlights emerging features such as agent-specific risk signals and the administrative model in the Agent 365 control plane. Therefore, viewers leave with both conceptual understanding and hands-on examples. The sectioned format helps teams adopt these controls without guessing how they apply to agents.

How Conditional Access for agents works

At its core, the approach evaluates an agent’s identity, context, and risk before issuing tokens or allowing access to protected resources. Huseynov describes how Conditional Access policies can now target “Users, agents or workload identities” so that autonomous agents fall into the same policy canvas as human users. As a result, organizations can create rules that allow, block, or require additional checks based on agent attributes and behaviors. This alignment preserves consistency between human and agent governance while offering agent-specific options.

Moreover, the video explains that Agent 365 serves as the control plane for these agent identities, enabling centralized policy application and monitoring. Huseynov emphasizes that teams can scope policies to all agent identities or limit them to specific blueprints or security attributes, which helps scale protections across many agent instances. In practice, this makes it easier to enforce standard controls while permitting vetted exceptions. Thus, the model supports both broad protection and controlled flexibility.

Finally, Huseynov outlines how agent-focused Conditional Access can use risk signals—known as agent risk—to block compromised agents automatically. Since these signals come from Entra ID Protection, policies can act when unusual behavior appears, and this can happen without manual intervention. Consequently, organizations gain a faster response to compromised automated actors. Yet, as he notes, the feature is evolving and administrators should validate behavior before full enforcement.

Live demo: identity, logs, and blocking

Huseynov walks viewers through a live demo in which an agent is assigned its own user account to show real-world effects of a Conditional Access policy. First, he checks the agent’s sign-in logs to establish a baseline, then creates a policy that blocks only access to email while leaving other tokens intact. After enabling the policy, he returns to the logs and demonstrates that the email access attempt is blocked and recorded, proving the policy’s granularity. The demo underscores that Conditional Access can target specific resources without disabling all agent functions.

Additionally, the demonstration shows practical troubleshooting steps, such as using report-only mode before full enforcement so teams can observe impact without causing outages. Huseynov explains that this staging reduces the risk of accidental service disruption and helps identify false positives ahead of time. As a result, administrators can refine assignments and exclusions before turning a policy into a hard block. This methodical approach balances security gains with operational continuity.

He also discusses the concept of agents with “two identities,” meaning an agent can have both an agent-specific identity and a related service or user identity depending on how it acts. This complexity matters because policies must account for all identities to avoid gaps or unintended blocks. Therefore, teams should inventory agent identities and map their resource flows before applying broad policies. In turn, this reduces surprises during enforcement.

Tradeoffs and technical challenges

Applying Conditional Access to agents offers clear security benefits, but it also introduces tradeoffs that organizations must manage carefully. For example, tighter controls reduce risk exposure yet increase the chance of false positives that may interrupt critical automation. Consequently, administrators must balance strictness with operational needs and use staged rollouts to catch problems early. This tradeoff reflects a broader tension between security and availability for automated systems.

Another challenge lies in policy scope and manageability: while targeting all agents simplifies coverage, it can be heavy-handed, and carving exceptions quickly becomes hard to track. Therefore, Huseynov recommends using custom security attributes and blueprint-level controls to scale policies sensibly. However, this adds administrative overhead and requires reliable governance processes to keep attribute mappings accurate. Thus, teams face a tradeoff between central control and the effort needed to maintain it.

Licensing and preview features also complicate adoption because some agent capabilities will require a future Agent 365 license and other parts remain in preview. As a result, organizations must plan for potential cost changes and limited feature maturity while testing new controls. Additionally, distinguishing agents from human users in complex environments can be technically tricky and may require updates to identity inventories. Ultimately, careful planning and phased adoption reduce operational risk during the transition.

Practical recommendations for teams

To get started, Huseynov advises administrators to begin with report-only mode so they can observe policy impact without immediate enforcement. Next, teams should map agent identities and their resource access patterns to scope policies cleanly and avoid accidental service disruption. In addition, using blueprint and custom attribute strategies helps scale governance across many agents while preserving exceptions for trusted instances. These steps create a predictable path to stronger protection.

Furthermore, monitoring sign-in logs and refining policies based on real behavior remains essential, especially when enabling risk-based blocks that act automatically. Thus, organizations should build alerting and review processes so security teams can react to both true positives and false alarms. Finally, because the space is evolving, teams should plan for licensing updates and continue testing as Microsoft refines agent risk and Agent 365 capabilities. By combining staged enforcement, monitoring, and governance, teams can protect agents while keeping automation reliable.

Microsoft Entra - Agent 365: Conditional Access for AI

Keywords

AI agent security, Conditional Access for AI, Agent 365 conditional access, Protect AI agents, Azure AD conditional access AI, AI agent access controls, Enterprise AI security, Zero Trust AI agents