ID Posture
Non-Human Identity

Your AI agents have identities too. Who's watching them?

Every AI agent built on Azure AI Foundry or Microsoft Security Copilot gets a real identity in Microsoft Entra ID, with its own permissions, its own owner, and (usually) nobody looking after it. ID Posture checks it the same way it checks every other identity in your tenant.

What we check

3 checks, sourced from a real Microsoft object model

AI agent identity governance inside the existing Non-Human Identity pillar -- no separate connection or tool required.

app.idposture.io/app/findings/pillar/non_human_identity
AI agent identity has no sponsor assigned
Medium
AI agent blueprint owned by another machine identity, not a person
Medium
AI agent blueprint granted excessive Microsoft Graph permissions
High

Why it matters

Microsoft auto-assigns an owner when an AI agent identity is created, but never a sponsor, so a real person accountable for that agent's behaviour is often missing entirely. And "owner" doesn't always mean a person either, it can resolve to another machine identity one step removed, which isn't the same thing as someone who can actually be held accountable. Then there's the permissions question: an agent's underlying blueprint can be granted broad Microsoft Graph access that every agent minted from it inherits automatically, a much wider blast radius than a single over-permissioned app. None of this shows up in the Entra admin center's day-to-day view. It's a new object type, created by a platform your security team may not have configured directly, and it behaves like every other unmanaged non-human identity that's come before it, just faster and with less oversight. ID Posture checks it the same way it already checks application registrations, service principals, and managed identities: on every scan, no separate tool required.

Why now

This isn't speculative. AI agent platforms are shipping features faster than most security teams can build governance around them, and identity is where that gap shows up first, the same pattern that played out with service accounts, then with cloud service principals, now with AI agents. ID Posture's approach here isn't a new "AI security" product bolted on, it's the same identity-governance discipline the rest of the platform already applies, extended to cover the newest kind of non-human identity in your tenant.

Part of ID Posture’s broader Azure resource coverage. See the full product overview, or explore Tenant Health and SQL Security.

See what's really in your tenant

Ask your ID Posture contact to enable AI agent identity checks for your tenant.

Book a demo