Skip to content
Setup Risk-Based Conditional Access for Entra Agents to Automatically Protect against Compromised Agents

Setup Risk-Based Conditional Access for Entra Agents to Automatically Protect against Compromised Agents

Written By Anoop C Nair
Last Updated July 7, 2026
Posted In Entra
SHARE

Let’s discuss Setup Risk-Based Conditional Access for Entra Agents to Automatically Protect against Compromised Agents. On the Ignite event 2025 Microsoft introduced Microsoft Entra Agent designed to interacts with enterprise resources.

Risk-Based Conditional Access for Entra Agents is one of the important concept that helps admins to Automatically Protect against Compromised Agents in environment. It leverage User Risk and Sign-in Risk signals from Entra ID Protection.

These policies automatically block or require remediation when an agent identity is flagged as high risk, ensuring compromised agents cannot access organizational resources. Risks signals are Probability that a specific authentication attempt is malicious.

Admins can easily understand Risk Signals in many ways. User Risk can be quickly Indicates the likelihood that an agent identity has been compromised (e.g., leaked credentials). Sign-in Risk are evaluates the probability that a specific authentication attempt is malicious (e.g., unusual location, impossible travel).

Patch My PC
Setup Risk-Based Conditional Access for Entra Agents to Automatically Protect against Compromised Agents - Fig.1
Setup Risk-Based Conditional Access for Entra Agents to Automatically Protect against Compromised Agents – Fig.1

Setup Risk-Based Conditional Access for Entra Agents to Automatically Protect against Compromised Agents

Protecting Entra Agents with risk-based Conditional Access means combining risk signals (User & Sign-in) with policy enforcement (block or remediate), supported by governance through Agent ID lifecycle management.

The purpose of Risk-Based Conditional Access for Entra Agents is Prevent Compromised Agents from Acting. If an agent identity shows signs of compromise (e.g., leaked credentials, unusual sign-in), the policy can block access immediately.

Purpose
By preventing Compromised Agents from Acting, admins can ensures malicious actors cannot use agent accounts to interact with your apps or data.
Instead of outright blocking, policies can require remediation actions like MFA,
Risk-based policies continuously evaluate user risk and sign-in risk.

How to Setup Risk Based Conditional Access Control Policy

To create Risk Based Access Conditional Control Policy, Sign in to the Microsoft Entra admin center as a Conditional Access Administrator. Navigate to Entra ID > Security > Conditional Access > Policies > Create New Policy.

Setup Risk-Based Conditional Access for Entra Agents to Automatically Protect against Compromised Agents - Fig.2 - Creds to MS
Setup Risk-Based Conditional Access for Entra Agents to Automatically Protect against Compromised Agents – Fig.2 – Creds to MS

Adding Name, Assignments, Conditions and Target Resources

On the New page you can add Name, Assignments, Conditions and Target Resources etc. Here added the name as Block Agents at risk, assignments as Users,agents, workloaded identities. Target Resources is All resources.

Here conditions is used Agent risk which is available on preview. The agent risk levels needed for policy to be enforced as High. Then click on the Next button.

Setup Risk-Based Conditional Access for Entra Agents to Automatically Protect against Compromised Agents - Fig.3 - Creds to MS
Setup Risk-Based Conditional Access for Entra Agents to Automatically Protect against Compromised Agents – Fig.3 – Creds to MS

Block Access

After that, you can choose Access Control. Here you can control access enforcement to block or grant access. Click on the Radio button near Block access and click on the Next button.

Setup Risk-Based Conditional Access for Entra Agents to Automatically Protect against Compromised Agents - Fig.4 - Creds to MS
Setup Risk-Based Conditional Access for Entra Agents to Automatically Protect against Compromised Agents – Fig.4 – Creds to MS

Enable Policy

After adding all the details above mentioned, you can Enable the Risk-based conditional access policy by enabling Report-only mode as “ON“. Then click on the Next button. Then the policy success notification will get on the portal.

With this policy, admins can ensure that, any agent that shows high risk of being compromised won’t be able to access resources in organization.

Setup Risk-Based Conditional Access for Entra Agents to Automatically Protect against Compromised Agents - Fig.5 - Creds to MS
Setup Risk-Based Conditional Access for Entra Agents to Automatically Protect against Compromised Agents – Fig.5 – Creds to MS

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,  Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Entra

Entra ID SSPR Improves Security with Registered Authentication Methods | Impact on Unregistered Users Starting September 2026

Key Takeaway Entra ID SSPR Improves Security with Registered Authentication Methods! Starting September 7, 2026, Microsoft Entra ID Self-Service Password Reset (SSPR) will require users to verify their identity using explicitly registered authentication methods. Directory-sourced contact information, such as mobile phone numbers, business phone numbers, and alternate email addresses, will no longer be accepted for […]

AC Anoop C Nair 4 min read
Entra

Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing

Key Takeaways Explicit Forward Proxy in Microsoft Entra Internet Access! This feature allows organizations to use secure web and AI gateway capabilities without deploying the Global Secure Access client, making it useful for browser-based and lightly managed environments. It works with browsers that support Proxy Auto-Configuration (PAC) files. Since this is a prerelease feature, Microsoft […]

AC Anoop C Nair 3 min read
Cloud

Microsoft Enables Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server

Key Takeaways: Let’s discuss about Microsoft Unlocks Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server. For customers with no remaining dependency on their last Exchange Server, a guide for decommissioning your last Exchange Server. Microsoft announced the Public Preview of Cloud-Managed Remote Mailboxes. Microsoft is excited to share these two new milestones […]

AC Anoop C Nair 3 min read