TL;DR: Microsoft’s Agent 365 gives AI agents first-class identities and better visibility inside Entra, but it still leaves downstream OAuth grants, connector credentials, vault secrets, and many third-party or local agents outside runtime governance, according to Oasis Security. The real control gap is not agent identity itself; it is access governance for agents whose privileges drift faster than registry-based oversight can track.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “AI Agent Identity (Agent 365) Meets Access Governance”.
Key questions
Q: What breaks when AI agents are given access without identity governance?
A: What breaks is accountability.
Q: When does authentication stop being enough for an AI agent?
A: Authentication stops being enough the moment the agent begins making repeated or branching decisions after it is trusted in.
Q: What are the signs that AI agent credential governance is breaking down?
A: Common warning signs include credentials scattered across unrelated vault items, weak naming that makes agent access hard to search, and no clear separation between human and agent workflows.
Practitioner guidance
- Map the full agent access surface Inventory every place an AI agent can obtain power, including OAuth grants, connector permissions, API keys, MCP tokens, vault secrets, and inherited roles.
- Continuously compare granted and used access Build review cycles that compare what an agent is allowed to do with what it actually does in production, then flag scope drift, unused tools, and overbroad inheritance before the next change lands.
- Extend governance beyond the Microsoft plane Include third-party agents, local binaries, and legacy deployments that are outside the Entra identity plane so access governance covers the wider estate rather than only the visible registry.
Bottom line: AI agent identity is a necessary control, but it does not govern downstream grants, secrets, or connector permissions that define runtime access.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity visibility is not the same as access governance, and that gap is now the central NHI problem for AI agents. A directory can tell you an agent exists, but it cannot tell you whether the agent still needs its current scopes, connectors, or delegated credentials. That is why agent identity layers help with inventory while leaving the harder governance question unresolved. Practitioners should treat visibility as a prerequisite, not a control outcome.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, and 77% of those incidents resulted in tangible damage.
A question worth separating out:
Q: How do organisations compare agent identity platforms with access governance needs?
A: They should compare them on control scope, not branding. Identity platforms are useful when the problem is discovery, ownership, or sign-in policy. Access governance is required when the problem is runtime privilege, downstream credentials, or tool misuse across multiple environments.
👉 Read our full editorial: Agent 365 shows why identity is not access governance for AI agents
Identity visibility is not the same as access governance, and that gap is now the central NHI problem for AI agents. A directory can tell you an agent exists, but it cannot tell you whether the agent still needs its current scopes, connectors, or delegated credentials. That is why agent identity layers help with inventory while leaving the harder governance question unresolved. Practitioners should treat visibility as a prerequisite, not a control outcome.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, and 77% of those incidents resulted in tangible damage.
A question worth separating out:
Q: How do organisations compare agent identity platforms with access governance needs?
A: They should compare them on control scope, not branding. Identity platforms are useful when the problem is discovery, ownership, or sign-in policy. Access governance is required when the problem is runtime privilege, downstream credentials, or tool misuse across multiple environments.
👉 Read our full editorial: Agent 365 shows why identity is not access governance for AI agents
Agent identity is not access governance: A first-class identity object tells you who the agent is, not what it is allowed to do across live tools and downstream systems. That distinction matters because modern AI agents inherit power from OAuth grants, connector credentials, and vault secrets that sit beyond the registry. The practitioner conclusion is simple: identity registration is a control input, not a governance outcome.
A few things that frame the scale:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
- 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring. The control set should include inventory, task-bound credentials, audit trails, and revocation paths. If an agent can call tools or touch production systems, it belongs in the same governance model as service accounts and other machine identities.
👉 Read our full editorial: Agent 365 shows why identity is not access governance for AI agents