The rise of agentic AI—autonomous software agents that can act, make decisions, and interact with systems—is fundamentally changing the landscape of digital identity.
As enterprises integrate these “digital teammates” into their workflows, the traditional models of identity and access management (IAM), designed primarily for human users, are no longer sufficient. This shift has prompted a critical re-evaluation of how we govern, secure, and manage non-human identities, pushing the identity industry into a bold new era.
The Challenge of AI Agent Identity
The core challenge lies in the nature of AI agents themselves. Unlike human users who operate within predictable patterns, organisations can spin up agents on demand. These agents operate at machine speed and execute actions across multiple systems in unpredictable ways. This rapid proliferation, or “agent sprawl,” creates significant security risks if not properly managed.
The traditional approach of using static API keys or hard-coded credentials for agents is highly vulnerable. It lacks accountability, making it impossible to trace actions back to a source, and violates the principles of modern security. The solution is to treat AI agents as first-class identities. They are entities with their own verifiable identity, subject to the same rigorous security policies as human employees.
Microsoft’s Approach to AI Agent Identity
In response to these challenges, Microsoft is at the forefront of defining a new security paradigm for AI. Their initiatives highlight a strategic move to extend existing identity and security frameworks to the agentic workforce:
Microsoft Entra Agent ID
Entra Agent ID is a new service that provides every AI agent with a unique, manageable identity. This resembles a car’s VIN number, a unique identifier that allows organisations to track, govern, and secure an agent. By embedding a unique ID into every agent created with Microsoft tools, organisations can gain visibility. They can manage the agent lifecycle, and apply granular security policies through Conditional Access. This aims to be the new standard for agent identity, providing a foundation for secure, large-scale AI adoption.
The Evolution of OAuth for AI Agents
As AI agents need to authenticate and authorise their actions, the industry-standard OAuth protocol must adapt. Identity leaders like Alex Simons are advocating for a new chapter in identity standards that can secure agents and their actions. This requires organisations to rethink how they grant permissions for specific tasks rather than broad, long-lasting sessions, ensuring that agents operate with the principle of least privilege.
Zero Trust for the Agentic Workforce
Microsoft is expanding its Zero Trust principles—which assume no user or device can be trusted by default—to protect AI agents. This means every agent, regardless of its origin, must be verified before being granted access to resources. This approach provides a robust defence against emerging threats like “shadow AI” and manipulated agents.
Governance and The Future of Identity
The conversation is not just about technology; it’s about governance. The identity community, as seen at events like Identiverse 2025, is actively debating the most urgent questions: Who is accountable for an agent’s actions? How do we audit their behaviour? And what regulatory standards do we need to ensure responsible AI development? These discussions are shaping the future of governance. Organizations must log every agent action, make it auditable, and tie it back to a human or a policy-level decision.
The journey to a secure agentic workforce is just beginning, and the developments from Microsoft and the wider identity community show a clear path forward. It’s an exciting time to be involved in identity, where we are redefining the foundational principles of security for a new generation of digital colleagues.
Secure AI, Sustainable Value: Your CISO’s Guide to AI Risk Management

Get your free Whitepaper if you want to:
- Learn to identify and manage unique AI security challenges
- Implement Devoteam’s AI Cyber Trust Cube – our framework for trusted and secure AI deployments
- Align AI with your organisation’s sustainability goals
- Gain insights from Devoteam’s leading AI security experts.
