Add Extra Protection to Your AI Agents with Conditional Access | Agent 365
AI agents now have their own identities in Microsoft Entra, and that means we can protect them the same way we protect people. In this video, I explain how Conditional Access works for AI agents and show how to apply it to an agent in Agent 365.
I start with the basics: what Conditional Access is and how it is part of Zero Trust. Then I explain the three ways agents access resources, which are on behalf of a signed-in user, with their own agent identity, and with their own agent user account. This is important because Conditional Access checks the identity that receives the token, so you need to know which identity your agent uses before you create a policy. I also cover target resources, the access controls that are available for agents, and why these controls are more limited than for users.
Along the way, I share some gotchas I found while preparing. An agent can have more than one identity, and each one needs its own policy. Policies that target "All users" do not include agent users. Device compliance rules can block cloud-hosted agents with no way to fix it. And the best way to start is to check the agent's sign-in logs, because they show you exactly which identity and which resources the agent uses.
In the demo, I use an external agent that is already registered in Agent 365. I check its sign-in logs, create a Conditional Access policy that blocks one specific resource, and confirm the block in the logs, while the agent keeps working with its other resources. At the end, I explain agent risk and how Conditional Access can block an agent automatically when Microsoft Entra ID Protection detects that it may be compromised.
This video focuses on external agents. Conditional Access works differently for Copilot Studio and Foundry agents because of how each platform handles agent identity, so I will cover them in separate videos.