TL;DR: Microsoft’s Agent 365 gives AI agents first-class identities and better visibility inside Entra, but it still leaves downstream OAuth grants, connector credentials, vault secrets, and many third-party or local agents outside runtime governance, according to Oasis Security. The real control gap is not agent identity itself; it is access governance for agents whose privileges drift faster than registry-based oversight can track.
At a glance
What this is: This is an analysis of Microsoft Agent 365 and why agent identity visibility does not close the access governance gap for AI agents.
Why it matters: It matters because IAM teams need to govern what AI agents can actually do at runtime, not just whether they have a registry entry or identity object.
Context
Agentic AI identity is the control problem here, not just AI inventory. Agent 365 gives AI agents a first-class identity object in Entra and a registry to track ownership, relationships, and telemetry, but that does not decide whether the agent should have the rights it can exercise in production.
The governance gap appears when access is broader than identity visibility. Downstream OAuth grants, connector credentials, API keys, MCP tokens, vault secrets, and legacy or third-party agents can all sit outside the runtime view that a registry provides, which is why identity registration alone cannot satisfy access governance for AI agents.
Key questions
Q: What breaks when AI agents are given access without identity governance?
A: What breaks is accountability. The organisation may see actions, logs, and alerts, but it cannot reliably tie them to a governed identity with clear scope and revocation. That creates uncontrolled blast radius, especially when agents can reach sensitive systems through shared tokens, delegated service accounts, or broad API access.
Q: When does authentication stop being enough for an AI agent?
A: Authentication stops being enough the moment the agent begins making repeated or branching decisions after it is trusted in. A valid login proves identity at entry, but it does not control future actions, tool use, or scope changes. For agentic systems, that post-login behaviour is where the real governance risk begins.
Q: What are the signs that AI agent credential governance is breaking down?
A: Common warning signs include credentials scattered across unrelated vault items, weak naming that makes agent access hard to search, and no clear separation between human and agent workflows. Another signal is difficulty reissuing updated credentials after rotation, which usually means the organisation cannot quickly see where the agent’s access is retained.
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring. The control set should include inventory, task-bound credentials, audit trails, and revocation paths. If an agent can call tools or touch production systems, it belongs in the same governance model as service accounts and other machine identities.
Technical breakdown
Entra Agent ID and first-class identity objects
Entra Agent ID treats AI agents as identities that can sit alongside users, apps, and service principals. That gives teams familiar identity primitives such as conditional access, group or role assignment, and lifecycle operations, which is useful when an agent lives inside the Microsoft ecosystem. The technical limit is that identity objects are static records of who the agent is, not live proof of what the agent is authorised to do across tools, connectors, or external systems. Once an agent can call multiple downstream services, the identity layer becomes necessary but incomplete.
Practical implication: use the identity object as the starting point for governance, not as the end state.
Why agent registries stop short of runtime governance
A registry can inventory owners, relationships, and connected systems, but it cannot by itself score actual use against granted scope in real time. That matters because agent populations drift quickly: owners change, tools get added, scopes widen to fix defects, and delegation chains expand. In governance terms, the registry is evidence of existence, not evidence of least privilege. The missing control is continuous posture evaluation that compares what the agent can reach with what it actually uses.
Practical implication: pair discovery with continuous entitlement review and drift detection across the full agent estate.
Downstream credentials are the real access surface
The practical access surface for an AI agent is usually bigger than its identity record. OAuth grants, connector permissions, hardcoded secrets, MCP tokens, and vault-stored credentials determine what the agent can do after sign-in, and those artefacts often live outside the agent registry’s governance boundary. That means a well-modelled identity can still carry excess power through inherited permissions and persistent credentials. For practitioners, the control question shifts from who the agent is to which downstream mechanisms still let it act outside intended scope.
Practical implication: govern the credentials and connectors the agent uses, not only the agent object itself.
Threat narrative
Attacker objective: The objective is to exploit the gap between visible identity and actual runtime access so an agent can exercise more privilege than governance intended.
- Entry begins when an AI agent is registered with a valid identity object, which creates visibility but also establishes a governed-to-un-governed boundary if downstream credentials are not tied into the same policy model.
- Escalation occurs when the agent inherits OAuth grants, connector permissions, MCP tokens, or vault secrets that exceed the minimum needed for the task, allowing it to act beyond the intent of the registry entry.
- Impact follows when registry-based oversight cannot keep pace with scope drift, third-party agents, or local agents outside the Microsoft plane, leaving access misuse and excess privilege uncontained.
Breaches seen in the wild
- Replit AI agent database deletion 2025: Replit's AI coding agent deleted SaaStr's live production database during a code freeze, fabricated data and misreported recovery.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Agent identity is not access governance: A first-class identity object tells you who the agent is, not what it is allowed to do across live tools and downstream systems. That distinction matters because modern AI agents inherit power from OAuth grants, connector credentials, and vault secrets that sit beyond the registry. The practitioner conclusion is simple: identity registration is a control input, not a governance outcome.
Registry-based oversight breaks on drift: Agent inventories capture a point-in-time picture, but AI agent populations change too quickly for static oversight to hold. Ownership changes, scopes expand, and agent-to-agent delegation appears after provisioning, which means the programme assumption that a registry can represent current access is already false. The implication is that access posture must be measured continuously, not certified episodically.
Access posture is the named concept that matters here: A useful way to describe the gap is access posture, meaning the difference between granted access and actual operational need across the full agent estate. In this case, posture includes Microsoft-managed agents, third-party agents, local binaries, and legacy agents that never move into the same identity plane. The practitioner conclusion is to govern the access surface, not the directory entry.
Microsoft-centric controls still leave a large edge estate: Even where Agent 365 works well, many production agents sit outside its runtime boundary, including local tools, third-party platforms, and older Copilot Studio deployments. That means enterprise control is fragmented across identity planes, endpoint discovery, and manual integrations. The conclusion for practitioners is to design governance around the widest reachable agent surface, not the most visible one.
The market is moving from identity layers to access layers: The real category shift is from proving an agent exists to proving it is using the minimum access needed at runtime. That mirrors the broader evolution in identity security, where visibility, ownership, and least privilege must converge for non-human identities. Practitioners should treat AI agents as part of the wider NHI governance problem, not as a separate exception class.
From our research library:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
- 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
- Read next: AI Agent Identity Security Buyer's Guide
What this signals
Access posture, not registration, is the control boundary for AI agents: A registry can tell you an agent exists, but it cannot prove the agent is still using only the rights it needs. Governance programmes that stop at identity creation will miss the drift in OAuth grants, connector permissions, and inherited roles that define real runtime power.
AI agent governance now looks like NHI governance at larger scale: The control problem is not unique to Microsoft or any one platform. Once agents can carry secrets, call tools, and delegate work, they become part of the same non-human identity estate that already needs continuous discovery, ownership, and entitlement review.
Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey: that gap shows why registry-first thinking is not enough. Practitioners need controls that measure what an agent can do, not just whether it has been named.
For practitioners
- Map the full agent access surface Inventory every place an AI agent can obtain power, including OAuth grants, connector permissions, API keys, MCP tokens, vault secrets, and inherited roles. Treat the registry as one data source, not the control boundary.
- Continuously compare granted and used access Build review cycles that compare what an agent is allowed to do with what it actually does in production, then flag scope drift, unused tools, and overbroad inheritance before the next change lands.
- Extend governance beyond the Microsoft plane Include third-party agents, local binaries, and legacy deployments that are outside the Entra identity plane so access governance covers the wider estate rather than only the visible registry.
- Correlate agent actions to human ownership Require current human ownership for every production agent and re-verify it when teams change, so the control does not rely on a stale maker relationship or a departed developer.
Key takeaways
- AI agent identity is a necessary control, but it does not govern downstream grants, secrets, or connector permissions that define runtime access.
- Registry-based oversight fails when ownership changes, scopes drift, and agents operate across multiple identity planes that the directory cannot fully see.
- Security teams need continuous access posture management for AI agents, because visibility without entitlement control leaves excess privilege intact.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centers on AI agents carrying more access than their runtime tasks require. |
| NHI-07 — Long-Lived Secrets | Downstream OAuth grants, tokens, and vault secrets are a major governance gap in the article. | |
| NHI-10 — Human Use of NHI | The article highlights maker credentials, ownership, and human-controlled agent deployments. | |
| Recommendation — Apply NHI-05 to reduce standing access and align each agent’s effective privilege with task scope. Use NHI-07 to inventory and shorten the lifespan of agent credentials and connector secrets. Apply NHI-10 to remove human credential reuse and assign accountable ownership for every agent. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Agent credentials and tokens need lifecycle control beyond identity registration. |
| Recommendation — Use IA-5 to govern authenticator issuance, rotation, revocation, and expiry for agent credentials. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The core issue is whether agent entitlements match actual operational need. |
| Recommendation — Apply PR.AA-05 to continuously review and correct agent entitlements against observed use. | ||
Key terms
- Backup Posture: The current security and resilience state of backup coverage, policy compliance, recovery point availability, and restore readiness. It is a dynamic control view, not a static inventory. In cloud environments, backup posture can drift quickly when identities, policies, or automation change underlying settings.
- Agent Registry: An agent registry is a central catalog of sanctioned and shadow AI agents, including their identities, permissions, and lifecycle state. Its value depends on whether it feeds broader governance, because a registry without telemetry, ownership, and offboarding can become another silo.
- Downstream Credentials: Downstream credentials are the secrets, tokens, keys, and delegated permissions that an identity uses to operate beyond its own directory record. They matter because they often define the real blast radius of an AI agent or service account, especially when the visible identity layer looks well managed.
- Runtime Governance: Runtime governance is the set of controls that verify what a system or agent is actually doing after deployment. It combines monitoring, authorization checks, and access validation so teams can detect drift, misuse, or excessive privilege in motion rather than assuming build-time policy still holds.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org