Microsoft Copilot Studio: Persistent identity for Copilot Studio Agents

🚨 The Signal: Copilot Studio agents can now have their own Entra ID accounts, complete with mailboxes and Teams presence. This creates new managed identities requiring governance and security controls, impacting identity and access management.

The Impact

Admins and security teams are affected by the introduction of new agent identities, creating a risk of unmanaged access if not properly governed.

  • Admins: Must manage new agent identities, increasing administrative overhead.
  • Security Teams: Need to secure and monitor agent identities to prevent unauthorized access.
  • Makers: Can deploy more integrated agents, potentially creating new attack surfaces if not configured securely.

The Action

  1. Review existing identity and access management policies for agent identities.
  2. Define a lifecycle management process for Copilot Studio agent accounts.
  3. Implement conditional access policies for agent identities.
  4. Monitor audit logs for activities performed by agent identities.
  5. Educate Copilot Studio makers on secure agent configuration practices.

Domain: Agentic-AI · Impact: high · Workload: Entra ID · Essential Eight: Restrict Administrative Privileges, Multi-Factor Authentication · ISM: ISM-0109, ISM-0123, ISM-0140, ISM-0445, ISM-0974, ISM-1173, ISM-1175, ISM-1228, ISM-1380, ISM-1401, ISM-1504, ISM-1505, ISM-1507, ISM-1508, ISM-1509, ISM-1647, ISM-1648, ISM-1650, ISM-1679, ISM-1680, ISM-1681, ISM-1682, ISM-1683, ISM-1686, ISM-1688, ISM-1689, ISM-1815, ISM-1819, ISM-1872, ISM-1873, ISM-1874, ISM-1883, ISM-1892, ISM-1893, ISM-1894, ISM-1897, ISM-1898, ISM-1906, ISM-1907