AgentStack
SKILL verified MIT Self-run

Agent Identity Governance

skill-vinayaklatthe-microsoft-security-skills-agent-identity-governance · by vinayaklatthe

Guidance for governing the identities of AI agents and non-human identities (NHIs) — Microsoft 365 Copilot Studio agents, Microsoft Foundry agents, custom AI agents, and traditional service principals/managed identities — through their full lifecycle. Covers ownership and tagging, scoped permissions and consent (delegated vs application; Sites.Selected; mailbox-scoped Graph), credential hygiene (…

No reviews yet
0 installs
14 views
0.0% view→install

Install

$ agentstack add skill-vinayaklatthe-microsoft-security-skills-agent-identity-governance

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Agent Identity Governance? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

AI Agent & Non-Human Identity Governance

AI agents — Microsoft 365 Copilot Studio agents, Microsoft Foundry agents, custom-built ones, plus traditional service principals and managed identities — are now the fastest-growing identity population in most tenants. They authenticate, hold permissions, act on behalf of users (or themselves), and are usually under-governed.

This skill is the lifecycle governance layer for those identities: ownership, scoping, credential hygiene, reviews, decommissioning, and incident response.

When to use

Establishing or maturing governance for the agent / NHI population — Copilot Studio agents, Foundry agents, custom LLM agents, and the service principals that back them.

Do not use this skill for workload identity federation patterns alone (entra-workload-identity), human identity governance (entra-id-governance), or generic agent build guidance.

Agent identity inventory — know what you're governing

| Class | Identity model | Surface | |---|---|---| | Copilot Studio agent (M365) | Tenant-scoped agent identity + per-user delegated permissions | M365 admin center / Copilot Studio | | Microsoft Foundry agent | Service principal + managed identity + per-user OBO | Azure portal / Foundry | | Custom AI agent (your code) | App registration + workload identity federation / managed identity | Entra admin center | | Plugin / connector | Service principal + delegated/app Graph permissions | Entra admin center | | Legacy automation service principal | App registration, often with secret | Entra admin center |

Approach

  1. Inventory and tag. Pull every app registration, service principal, and Copilot

Studio / Foundry agent. Tag each with:

  • Owner (person + group).
  • Sponsor / business owner.
  • Purpose (one sentence).
  • Data scope (which tenants/sites/mailboxes/resources).
  • Lifecycle stage (pilot / production / sunset).
  • Criticality (tier 0 / 1 / 2).

Orphaned identities → freeze them; require owner re-claim.

  1. Scope permissions tightly.
  • Microsoft Graph: prefer Sites.Selected over Sites.Read.All, **mailbox

scoping via Application Access Policy** over Mail.Send, custom security attributes over broad directory roles.

  • Azure: scope role assignments at RG or resource, never subscription Owner unless

truly required.

  • Copilot Studio agent knowledge sources: explicit site/library lists, not "All

SharePoint."

  • Foundry agent tools: only the tools needed; remove http plugin unless

necessary.

  1. Credential hygiene. No client secrets in new builds — federated credentials

(GitHub Actions, Azure DevOps, AKS, external OIDC) or certificates with auto-rotation via Key Vault. Existing secrets: inventory, cap expiry at 180 days, rotate via automation, plan migration to federation.

  1. Conditional Access for workloads (Workload Identities Premium). Apply to

tier-0 agents and externally-callable agents:

  • Restrict source IP ranges.
  • Block legacy auth.
  • Require named locations.

Don't try to apply to every SP in the tenant — focus on high-blast-radius identities.

  1. Access reviews for agents via Entra ID Governance. Owner reviews per quarter:
  • Still needed?
  • Still the right scope?
  • Credential rotation up to date?
  • Owner / sponsor still in role?

Auto-disable on owner non-response.

  1. Lifecycle workflows. Build automation for:
  • Provisioning: owner-initiated request → approval → SP created with template

permissions, tagged, owner assigned.

  • Modification: scope change requires re-approval.
  • Decommissioning: 30-day disable window, then delete; remove role

assignments, federated credentials, knowledge-source attachments.

  1. Audit and monitoring.
  • Stream ServicePrincipalSignInLogs and AuditLogs to Sentinel.
  • For Copilot Studio agents: interaction audit logs via Purview Audit.
  • Detections:
  • New high-privilege role assignment to an agent identity.
  • Agent sign-in from unexpected IP/country.
  • Sudden spike in Graph API calls per agent.
  • Sensitive data access by agent outside business hours.
  • New credential added to an agent by an identity other than its owner.
  1. Incident response when an agent is compromised.
  2. Disable the identity (block sign-in on the app registration / SP).
  3. Rotate credentials, revoke refresh tokens.
  4. Hunt actions taken by the agent identity in the past 7–30 days

(Graph audit, resource activity).

  1. Notify data owners for the resources the agent had access to.
  2. Root cause (leaked secret? OAuth consent phishing? supply chain?).
  3. Restore with tightened scope or retire.
  1. Couple with usage signals. Purview AI Hub / DSPM for AI shows *what the agent

does* (sensitive data flowing through prompts). Pair with identity audit to get a complete view.

Guardrails

  • Every agent identity has a named human owner. Empty owners list = orphan =

audit/security risk.

  • No client secrets for new identities. Federation > certificate > secret.
  • Sites.Selected (and similar) is mandatory where it exists. "Quick start with

.All and we'll scope later" never scopes later.

  • Conditional Access for workloads is a separate license. Confirm SKU before

designing.

  • OAuth consent for new agents must be admin-reviewed. End-user consent for high-

privilege scopes is the agent equivalent of a phishing onboarding.

  • Decommissioned ≠ deleted in 1 day. 30-day disable window catches "wait, that was

in use somewhere."

  • Agent credentials are not for human use. Don't share an agent's secret with the

team for "easier debugging."

  • Tag agents with data scope and tier. Without it, IR and reviews are guesswork.

Common anti-patterns

  • "Copilot Studio agent grounded on 'All SharePoint'" — same oversharing problem as

Copilot itself, scaled. Use site-scoped knowledge sources.

  • "Agent SP granted Mail.Send Application permission tenant-wide" — can email as

anyone. Use app access policies to scope to specific mailboxes.

  • "Owner field set to a leaver's account" — orphaned, no review, no rotation.
  • "Long-lived client secret in agent code" — git history forever; leak detection

too late.

  • "All agents in tier-0 because 'they're all important'" — review and IR effort

becomes uniform but is uniformly low quality. Real tiering.

  • "Decommissioned by deleting the app reg, leaving role assignments behind"

dangling principal IDs in RBAC; restore-with-same-id risk.

  • "No audit on Copilot Studio agent interactions" — compromised agent acts

invisibly.

  • "Treated agent identity governance as identical to human IGA" — different

lifecycle, different controls, different reviews.

Example prompts

  • `Inventory all Copilot Studio agents, Foundry agents, and service principals in the

tenant and produce an owner + scope + tier report.`

  • Roll out access reviews for 600 agent identities via Entra ID Governance quarterly.
  • `Scope a Copilot Studio agent for HR from "All SharePoint" to 4 specific knowledge

sites.`

  • `Build a decommissioning workflow: 30-day disable, owner notification, full cleanup of

RBAC and federated credentials.`

  • `Sentinel detections for agent identity compromise: new credential, anomalous sign-in,

spike in Graph calls.`

  • `IR runbook: compromised Foundry agent that called Microsoft Graph for 48 hours —

containment, hunt, notification.`

  • `Replace client secrets across 120 legacy automation SPs with workload identity

federation or Key Vault certificates.`

  • Apply Conditional Access for workload identities to all tier-0 agents.

Microsoft Learn

  • Workload identities overview: https://learn.microsoft.com/entra/workload-id/workload-identities-overview
  • Entra ID Governance overview: https://learn.microsoft.com/entra/id-governance/identity-governance-overview
  • Access reviews for service principals: https://learn.microsoft.com/entra/id-governance/create-access-review
  • Conditional Access for workload identities: https://learn.microsoft.com/entra/identity/conditional-access/workload-identity
  • Application access policies (Graph mailbox scoping): https://learn.microsoft.com/graph/auth-limit-mailbox-access
  • Sites.Selected: https://learn.microsoft.com/sharepoint/dev/solution-guidance/security-apponly-azuread
  • Copilot Studio security and governance: https://learn.microsoft.com/microsoft-copilot-studio/security-and-governance
  • Microsoft Foundry agent security: https://learn.microsoft.com/azure/ai-foundry/concepts/ai-resources
  • Audit (unified) for Copilot: https://learn.microsoft.com/purview/audit-copilot
  • Workload identity federation: https://learn.microsoft.com/entra/workload-id/workload-identity-federation

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.