Skip to content
Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents

Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents

Written By Anoop C Nair
Last Updated June 30, 2026
Posted In Entra
SHARE

Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents! Microsoft Entra Identity Governance has introduced full support for Access Packages for Service Principals and Agent Identities.

It makes a significant expansion in how organizations can automate and manage access for non-human identities. This update, announced during the recent MSIgnite event, brings long-awaited capabilities to Entitlement Management, enabling secure and scalable governance for application and workload identities.

At Microsoft Ignite 2025, Microsoft introduced a major upgrade to its Entra Agentic AI. Instead of depending on older Copilot tools that only respond when someone types a prompt, the new Agentic AI can work independently. It can make decisions, take action, and complete tasks without needing constant direction from a user.

The new feature makes it easier for organisations to handle access requests, approvals, and reviews for API permissions. Earlier, these steps often needed manual work or complicated setups. By expanding Access Packages to include service principals and agent identities, not just users, Entra now gives a single, automated way to manage permissions for both human and non-human identities.

Patch My PC
Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents - Fig.1
Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents – Fig.1

Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents

The scope for requesting an access package can now include both Service Principals and Agent Identities. This means administrators, the owners of a Service Principal, and in some cases the Service Principal itself can request an access package. This greatly expands how access can be managed and automated for non-human identities.

  • Who can get Access
    • For users, service principals and agent identities in your directory
Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents - Fig.2 - Creds to MS
Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents – Fig.2 – Creds to MS

How Entra Access Packages Now Include Delegated and Application Permissions

All delegated and application permissions can now be added directly as resources inside an access package. This makes it easier for admins to manage API permissions in one place and give the right level of access to service principals, agent identities, and applications without manual setups.

Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents - Fig.3 - Creds to MS
Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents – Fig.3 – Creds to MS

Just-in-Time Access and Access Reviews for Service Principals

Expiration policies allow Service Principals to receive “just-in-time” or on-demand access, minimizing the risks associated with standing permissions. In addition, access reviews are supported to ensure that app role assignments do not remain stale or permanent without evaluation by the workload owner, thereby maintaining secure and up-to-date access control.

Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents - Fig.4 - Creds to MS
Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents – Fig.4 – Creds to MS

Access Requests for Service Principal Owners

Owners of a Service Principal object can request access directly. However, the system does not currently support sponsors or delegations at the object-level, limiting more granular or delegated access management.

FeatureSupportedDetails
Owner access requestsYesOwners can directly request access
Sponsor supportNoSponsors cannot request access on behalf
Object-level role delegationNoRole assignments cannot be delegated at object level
Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents – Table 1
Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents - Fig.5 - Creds to Thomas Naunheim
Non-Human Identities and Agent Identities Gain Access Package Support with Entra Identity Governance for AI Agents – Fig.4 – Creds to MS

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,  Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Entra

Entra ID SSPR Improves Security with Registered Authentication Methods | Impact on Unregistered Users Starting September 2026

Key Takeaway Entra ID SSPR Improves Security with Registered Authentication Methods! Starting September 7, 2026, Microsoft Entra ID Self-Service Password Reset (SSPR) will require users to verify their identity using explicitly registered authentication methods. Directory-sourced contact information, such as mobile phone numbers, business phone numbers, and alternate email addresses, will no longer be accepted for […]

AC Anoop C Nair 4 min read
Entra

Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing

Key Takeaways Explicit Forward Proxy in Microsoft Entra Internet Access! This feature allows organizations to use secure web and AI gateway capabilities without deploying the Global Secure Access client, making it useful for browser-based and lightly managed environments. It works with browsers that support Proxy Auto-Configuration (PAC) files. Since this is a prerelease feature, Microsoft […]

AC Anoop C Nair 3 min read
Cloud

Microsoft Enables Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server

Key Takeaways: Let’s discuss about Microsoft Unlocks Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server. For customers with no remaining dependency on their last Exchange Server, a guide for decommissioning your last Exchange Server. Microsoft announced the Public Preview of Cloud-Managed Remote Mailboxes. Microsoft is excited to share these two new milestones […]

AC Anoop C Nair 3 min read