All skills
microsoft avatar

/entra-agent-id

@b3c238e
by microsoftmicrosoft/skills3.1k stars
351

Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmi_path, OBO, cross-tenant) including the Microsoft Entra SDK for AgentID sidecar. USE FOR: Agent Identity Blueprint, BlueprintPrincipal, agent OAuth, fmi_path token exchange, agent OBO, Workload Identity Federation for agents, polyglot agent auth, Microsoft.Identity.Web.AgentIdentities. DO NOT USE FOR: standard Entra app registration (use entra-app-registration), Microsoft Foundry agent authoring (use microsoft-foundry).

Use this Skill: https://skilld.dev/gh/microsoft/skills/entra-agent-id

This session only. Nothing lands on disk.

referencesknown-limitations.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Known Limitations

Source: Microsoft Entra Agent ID — known issues and gaps

API & Object Model

  1. Sponsors must be Users at Blueprint creation — ServicePrincipals and Groups are not accepted as Blueprint sponsors. (Agent Identity sponsors may be Users or Groups.)
  2. BlueprintPrincipal not auto-created — requires explicit POST /servicePrincipals/microsoft.graph.agentIdentityBlueprintPrincipal after Blueprint creation.
  3. Agent Identities cannot have password credentials — credentials belong on the Blueprint only (PropertyNotCompatibleWithAgentIdentity).
  4. Agent Identities have no backing application object — they are service-principal-only entities.
  5. Blueprint needs explicit identifierUris — not set by default; required for OAuth2 scope resolution (api://{app-id}/.default).
  6. No Graph relationship filtering for Agent IDs — /ownedObjects, /deletedItems, /owners return all types; filter client-side by odata.type.
  7. Orphaned agent users after deletion — deleting a Blueprint or identity does NOT auto-delete its agent users; clean up manually via admin center or Graph API.

Roles & Permissions

  1. Directory.AccessAsUser.All hard rejection — if present on the client, all other Agent ID delegated permissions are ignored → 403 Forbidden.
  2. No viable delegated permission for creating Agent Identities — use application permissions.
  3. No quick-start permission bundle — discover and grant 18+ individual Agent Identity permissions.
  4. Permission propagation delay — 30–120+ seconds after admin consent before tokens include new claims; prefer delegated permissions and add exponential backoff retry.
  5. Global Reader cannot list Agent Identities — GET /servicePrincipals/microsoft.graph.agentIdentity returns 403; use GET /servicePrincipals and filter instead.
  6. Custom roles cannot include Agent ID actions — use built-in roles (Agent ID Administrator, Agent ID Developer).
  7. Administrative units not supported — cannot add Agent Identities, Blueprints, or BlueprintPrincipals to admin units; use owners instead.
  8. Agent ID Admin cannot update agent-user photos — use User Administrator.

Admin Center & Management

  1. No Blueprint management in Entra admin center — use Microsoft Graph / PowerShell.
  2. /me endpoint unavailable in client_credentials flow — use az ad signed-in-user show or Graph delegated permissions for user context.

Authentication & Consent

  1. No SSO to web apps — Agent IDs can't sign in via Entra ID sign-in pages (no OpenID Connect or SAML); use web APIs instead.
  2. Admin consent workflow (ACW) broken for permissions requested by Agent IDs — contact tenant admin directly.
  3. Cannot grant app permissions to BlueprintPrincipals — grant to individual Agent Identities.
  4. Cannot assign app roles where target resource is an Agent Identity — use the BlueprintPrincipal as target resource.
  5. Risk-based step-up blocks consent silently — no "risky" indication in the UX.

Groups, Logs & Monitoring

  1. No dynamic group membership — Agent Identities and agent users cannot be added to dynamic groups; use security groups with fixed membership.
  2. Audit logs do not distinguish Agent IDs — operations on Blueprints/identities logged as ApplicationManagement, agent users as User Management; cross-reference object IDs via Graph to determine entity type.
  3. Graph activity logs do not distinguish Agent IDs — agent-identity requests logged as applications, agent-user requests as users; join with sign-in logs.

Performance & Scale

  1. Sequential creation requests may fail — Blueprint → Principal → Identity in quick succession can return 400 Bad Request: Object with id {id} not found, especially with application permissions. Prefer delegated permissions; add exponential backoff.

Product Integrations

  1. Copilot Studio — only custom engine agents are supported; Agent IDs are used for channel auth only (not connectors or tools).
  2. MSAL complexity — Agent ID scenarios require managing Federated Identity Credentials manually. For .NET use Microsoft.Identity.Web.AgentIdentities. For other languages use the Microsoft Entra SDK for AgentID.

Reporting Issues

Report unlisted issues via aka.ms/agentidfeedback.

Source: SKILL.md on GitHub

1 warning17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill facilitates the management of Microsoft Entra Agent IDs using official Microsoft tools and APIs. It includes important considerations for handling Azure credentials and provides guidance on transitioning from local development secrets to production-grade authentication methods.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer6mo

    4/4 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at b3c238e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "author": "Microsoft",
  "version": "1.1.1"
}

README badge

README badge for microsoft/skills/entra-agent-id