Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Provisions Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configures OAuth 2.0 token exchange.
Skill: entra-agent-id | Source code
Important
Preview API — All Agent Identity endpoints are under Microsoft Graph /beta only. They are not available in /v1.0. Verify API parameters match current preview behavior before production use.
What it provides
This skill provides GitHub Copilot with specialized knowledge for creating and managing OAuth 2.0-capable identities for AI agents using Microsoft Graph. Every agent instance gets a distinct identity, audit trail, and independently scoped permission grants. The skill covers the Agent Identity object model (Blueprint → BlueprintPrincipal → Agent Identity), runtime token exchange flows, and the Microsoft Entra SDK for AgentID sidecar.
For the latest Agent ID documentation, use the microsoft-docs skill which queries the Microsoft Learn MCP Server (learn.microsoft.com/api/mcp) for current API parameters and behavior.
Prerequisites
- Azure subscription: Create a free account if you don't have one.
- AI assistant with Azure Skills: GitHub Copilot for Azure, Visual Studio Code with Azure MCP extension, Claude Code, or another compatible MCP client.
- Microsoft Entra role: Agent Identity Developer, Agent Identity Administrator, or Application Administrator.
- Microsoft Graph access: PowerShell (
Microsoft.Graph.Applications) or Python (azure-identity,requests). - OData-Version header: Include
OData-Version: 4.0on every Graph request to Agent Identity endpoints.
When to use this skill
Use this skill when you need to:
- Provision a new Agent Identity Blueprint and BlueprintPrincipal.
- Create per-instance Agent Identities under a Blueprint.
- Configure credentials (Federated Identity Credential, Managed Identity, or client secret) on the Blueprint.
- Implement the two-step
fmi_pathruntime token exchange (autonomous or OBO). - Set up cross-tenant agent token flows.
- Deploy the Microsoft Entra SDK for AgentID sidecar for polyglot agents (Python, Node, Go, Java).
- Grant per-Agent-Identity application or delegated permissions.
- Diagnose Agent ID errors such as
AADSTS82001,AADSTS700211, orPropertyNotCompatibleWithAgentIdentity.
When not to use this skill
- Standard Entra app registration — use entra-app-registration.
- Microsoft Foundry agent authoring — use microsoft-foundry.
Suggested workflow
The skill follows a core provisioning workflow:
- Create Agent Identity Blueprint: Define the agent type/class as an application object.
- Create BlueprintPrincipal: Explicitly create the service principal. This step is mandatory — creating a Blueprint does NOT auto-create its service principal. Without this step, Agent Identity creation fails with
400: The Agent Blueprint Principal for the Agent Blueprint does not exist. - Create Agent Identities: Provision per-instance identities under the Blueprint. Sponsors are required and must be User objects — ServicePrincipals and Groups are rejected.
- Configure credentials: Set up authentication on the Blueprint (Workload Identity Federation for production, client secret for dev).
- Grant permissions: Assign application or delegated permissions per Agent Identity.
- Configure runtime exchange: Implement the two-step
fmi_pathtoken exchange for autonomous or OBO flows.
Important
DefaultAzureCredential is not supported for Agent Identity APIs. Azure CLI tokens carry Directory.AccessAsUser.All, which Agent Identity APIs reject with 403. You MUST use a dedicated app registration with client_credentials flow, or connect via Connect-MgGraph with explicit delegated scopes.
Required permissions
Agent Identity APIs use 18 specific Microsoft Graph application permissions. Discover them with:
az ad sp show --id 00000003-0000-0000-c000-000000000000 \
--query "appRoles[?contains(value, 'AgentIdentity')].{id:id, value:value}" -o json
Key permissions include:
| Permission | Purpose |
|---|---|
Application.ReadWrite.All |
Blueprint CRUD (application objects) |
AgentIdentityBlueprint.Create |
Create new Blueprints |
AgentIdentityBlueprint.ReadWrite.All |
Manage Blueprint lifecycle |
AgentIdentity.Create.All |
Create per-instance identities |
AgentIdentity.ReadWrite.All |
Manage Agent Identity lifecycle |
Example prompts
Try these prompts to activate this skill:
- "Set up an Agent Identity Blueprint for my AI agent"
- "Create a BlueprintPrincipal for my agent"
- "Provision agent identities for my AI agents"
- "Configure OAuth for agent identity"
- "Set up fmi_path token exchange for my agent"
- "Configure agent OBO flow"
- "Set up Workload Identity Federation for agents"
- "Deploy the Microsoft Entra SDK for AgentID sidecar"
- "Configure polyglot agent authentication"
Related content
- Microsoft Entra Agent ID AI-guided setup
- Microsoft Entra SDK for AgentID
- Azure Model Context Protocol (MCP) Server overview
- Skill source code
Note
The skill source is an AI instruction file that tells GitHub Copilot when and how to use this capability. For official developer documentation, see the Microsoft Entra Agent ID AI-guided setup.