Most organizations can tell you exactly who owns every laptop, every mailbox and every application. Ask who owns a specific AI agent, and the answer is often a shrug.
An agent without a responsible human is what Microsoft calls an orphaned agent. It keeps its access, keeps running, and nobody notices when someone should have switched it off.
Microsoft Entra Agent ID and Microsoft Agent 365 now give every AI agent its own identity, separate from the humans and apps around it. That is a big step forward. But an identity on its own does not create accountability. These six questions do.
1. Do you know how many agents you actually have?
People create agents in Copilot Studio, in Microsoft Foundry, in Azure, and increasingly anywhere with the right license and five minutes to spare. Most organizations have never counted them.
Start here. If you cannot answer this question, none of the others matter yet.
2. Does each agent have its own identity, or are some sharing one?
Microsoft’s guidance is clear: give every agent instance its own identity rather than sharing one across several agents. A shared identity means you cannot disable one agent without affecting the others, and you lose the ability to tell which agent did what.
3. Does every agent have a named human sponsor?
A sponsor is the person accountable for an agent’s access and life-cycle. Not a team, not a mailbox, a named person. Without one, decisions about an agent’s access have nobody behind them.
4. Does its access expire, or does it last forever?
Access that never expires is access nobody has to justify again. Entra now supports access packages for agent identities, so agent access can carry an end date and go through review, the same as it can for people.
5. What happens to the agent when its sponsor leaves?
This is the moment most governance plans quietly fail. If a sponsor leaves the organization and nobody has configured what happens next, the agent keeps its access with nobody watching it. Entra can transfer sponsorship automatically to the sponsor’s manager, but only if you set that up in advance.
6. Are your agents covered by Conditional Access?
Human users get Conditional Access policies as standard. Agents can too, but someone has to deliberately apply it. Worth checking whether that has actually happened, or whether your team just assumed it.
Where this is going
These six questions are the start of a series on identity and governance for AI agents in Microsoft 365. Coming next: an honest count of how many agents are running in a real lab tenant, and how many of them turned out to have no sponsor at all.
If you want to follow along, you can read more about me and find me on LinkedIn as each post goes live.