An agent is not a user with a longer session.
An autonomous agent acts on someone’s behalf, for a stated purpose, with a scope and a limit. Identity systems can now give that agent an identity. Something still has to enforce the purpose and the limit at the point the agent acts.
This capability is a Q4 2026 roadmap extension. The sections below describe the planned shape and evidence; production availability has not yet been declared. The status above is rendered from the Product Truth Registry.
1. What this enforces
The four things an agent identity alone does not carry into a method call: who sponsors the agent, the purpose it is acting for, the tools and data within its scope, and the transaction limits that bound it.
2. Where it enforces
In-process, per action. An agent that is permitted to read a record is not thereby permitted to move value from it, and the difference is only observable where the action executes.
3. What evidence it produces
The agent, its sponsor, the declared purpose, the scope in force and the limit consumed — on every decision. Purpose recorded after the fact is not purpose, it is narration.
4. Why you cannot assemble this from what you already own
Entra Agent ID establishes that the agent is who it claims to be and that a sponsor exists. It does not evaluate whether this action, on this record, for this purpose, is within the agent’s remit — and an agent’s remit is exactly the thing that needs to be narrow.
5. What Q4 2026 adds
Entra Agent ID Authorization
Agent identity, blueprint, sponsor, purpose, tools, datasets, transaction limits, approval thresholds and revocation.
Model agent sponsor, purpose, blueprint, tool, dataset, transaction threshold and human approval requirement.
6. Acceptance criteria
These are the conditions the capability must satisfy to be considered complete. They are quoted from the specification rather than paraphrased, because an acceptance criterion that has been reworded is no longer the criterion.
- Every agent action is attributable to an agent identity and sponsor. MF-014
- Policies can constrain purpose, tool, dataset, amount and required human approval. MF-014
- Agent revocation prevents subsequent protected actions within the defined SLO. MF-014
7. Dependencies
Beyond the platform baseline every extension depends on — the B5 security context, the evidence pipeline, configuration, the tenant model and the release registry — this capability also depends on:
- Microsoft Entra and Azure integration packages.
8. What is still open
The following are genuinely undecided rather than merely undocumented, and each one changes what the capability is:
- Whether purpose is a closed vocabulary or free text, and how it is validated.
- How transaction limits aggregate across an agent’s actions, and over what window.
- What happens when a sponsor’s own authority is revoked while the agent is mid-task — the in-flight question again.
Every Q4 2026 extension is also held to four platform-wide requirements, six test classes and four release gates. They are published once, on the Q4 2026 roadmap, rather than repeated on every page.