Known Limitations
Source: Microsoft Entra Agent ID — known issues and gaps
API & Object Model
- Sponsors must be Users at Blueprint creation — ServicePrincipals and Groups are not accepted as Blueprint sponsors. (Agent Identity sponsors may be Users or Groups.)
- BlueprintPrincipal not auto-created — requires explicit
POST /servicePrincipals/microsoft.graph.agentIdentityBlueprintPrincipalafter Blueprint creation. - Agent Identities cannot have password credentials — credentials belong on the Blueprint only (
PropertyNotCompatibleWithAgentIdentity). - Agent Identities have no backing application object — they are service-principal-only entities.
- Blueprint needs explicit
identifierUris— not set by default; required for OAuth2 scope resolution (api://{app-id}/.default). - No Graph relationship filtering for Agent IDs —
/ownedObjects,/deletedItems,/ownersreturn all types; filter client-side byodata.type. - Orphaned agent users after deletion — deleting a Blueprint or identity does NOT auto-delete its agent users; clean up manually via admin center or Graph API.
Roles & Permissions
Directory.AccessAsUser.Allhard rejection — if present on the client, all other Agent ID delegated permissions are ignored → 403 Forbidden.- No viable delegated permission for creating Agent Identities — use application permissions.
- No quick-start permission bundle — discover and grant 18+ individual Agent Identity permissions.
- Permission propagation delay — 30–120+ seconds after admin consent before tokens include new claims; prefer delegated permissions and add exponential backoff retry.
- Global Reader cannot list Agent Identities —
GET /servicePrincipals/microsoft.graph.agentIdentityreturns 403; useGET /servicePrincipalsand filter instead. - Custom roles cannot include Agent ID actions — use built-in roles (Agent ID Administrator, Agent ID Developer).
- Administrative units not supported — cannot add Agent Identities, Blueprints, or BlueprintPrincipals to admin units; use
ownersinstead. - Agent ID Admin cannot update agent-user photos — use User Administrator.
Admin Center & Management
- No Blueprint management in Entra admin center — use Microsoft Graph / PowerShell.
/meendpoint unavailable inclient_credentialsflow — useaz ad signed-in-user showor Graph delegated permissions for user context.
Authentication & Consent
- No SSO to web apps — Agent IDs can't sign in via Entra ID sign-in pages (no OpenID Connect or SAML); use web APIs instead.
- Admin consent workflow (ACW) broken for permissions requested by Agent IDs — contact tenant admin directly.
- Cannot grant app permissions to BlueprintPrincipals — grant to individual Agent Identities.
- Cannot assign app roles where target resource is an Agent Identity — use the BlueprintPrincipal as target resource.
- Risk-based step-up blocks consent silently — no "risky" indication in the UX.
Groups, Logs & Monitoring
- No dynamic group membership — Agent Identities and agent users cannot be added to dynamic groups; use security groups with fixed membership.
- Audit logs do not distinguish Agent IDs — operations on Blueprints/identities logged as
ApplicationManagement, agent users asUser Management; cross-reference object IDs via Graph to determine entity type. - Graph activity logs do not distinguish Agent IDs — agent-identity requests logged as applications, agent-user requests as users; join with sign-in logs.
Performance & Scale
- Sequential creation requests may fail — Blueprint → Principal → Identity in quick succession can return
400 Bad Request: Object with id {id} not found, especially with application permissions. Prefer delegated permissions; add exponential backoff.
Product Integrations
- Copilot Studio — only custom engine agents are supported; Agent IDs are used for channel auth only (not connectors or tools).
- MSAL complexity — Agent ID scenarios require managing Federated Identity Credentials manually. For .NET use Microsoft.Identity.Web.AgentIdentities. For other languages use the Microsoft Entra SDK for AgentID.
Reporting Issues
Report unlisted issues via aka.ms/agentidfeedback.