Entra Agent ID + Agent 365 governance platform

The same capstone goals implemented natively on the Microsoft stack.

πŸ›  Capstone

Goal

Stand up a full Microsoft-native governance plane for a mixed fleet of agents (Copilot Studio + LangChain + AWS Bedrock + n8n) inside a single Entra tenant. Demonstrate to a hypothetical enterprise buyer (bank / telco / public-sector) that every agent β€” regardless of origin β€” is identified, permissioned, policy-controlled, risk-monitored, and governed under one control plane. Deliver a public repo (secrets scrubbed), demo video, and a 3-slide architecture pitch.

Complements Project 5 (which uses the vendor-neutral open-source stack). Read both if you're targeting enterprise architect / agent-security-engineer roles at M365-heavy customers.

Stack

  • Tenant: Microsoft Entra ID tenant + Microsoft Agent 365 licence (E7 trial is fine).
  • Identity foundation: Microsoft Entra Agent ID β€” 3 blueprints, ~15 agent identities, 2 agent user accounts.
  • Governance: Access packages, Lifecycle Workflows, custom security attributes, sponsors.
  • Policy: Conditional Access (blueprint-scoped + attribute-driven), ID Protection with auto-block.
  • Observability: Agent 365 SDK (Python + Node), OpenTelemetry β†’ Azure Monitor + Splunk.
  • Tool governance: Agent 365 SDK ToolCatalog + 2 MCP servers registered to the tenant.
  • Network: Global Secure Access for the Copilot Studio agent, allow-list of approved egress domains.
  • Multi-platform agents:
    • Copilot Studio agent β€” with auto Agent ID assignment.
    • LangChain agent in Azure Container Apps β€” sidecar pattern.
    • AWS Bedrock Claude agent in ECS Fargate β€” sidecar + FIC to AWS STS.
    • n8n workflow in a separate Container Apps env β€” community node.
  • Third-party federation: FIC to AWS STS for Bedrock; FIC to GitHub Actions OIDC for CI/CD.
  • Sponsors + owners: 3 sponsors (business owners), 2 owners (technical), all with manager populated.
  • CI/CD: GitHub Actions (OIDC federation to Entra, no static secrets); Bicep / Terraform for infra.

Reference architecture

                    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                    β”‚         M365 Admin Center            β”‚
                    β”‚  Agent Registry / At Risk / Shadow   β”‚
                    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                      β”‚
                                      β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                    Microsoft Agent 365 (control plane)           β”‚
β”‚  Access packages Β· Lifecycle workflows Β· Notifications Β· MCP     β”‚
β”‚  catalogue Β· OTel spans β†’ Azure Monitor β†’ Splunk                 β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
          β”‚                   β”‚                    β”‚
          β–Ό                   β–Ό                    β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  Microsoft      β”‚  β”‚  Microsoft        β”‚  β”‚  Microsoft Purview   β”‚
β”‚  Entra          β”‚  β”‚  Defender / GSA   β”‚  β”‚  DLP + audit         β”‚
β”‚  Agent ID       β”‚  β”‚  network + threat β”‚  β”‚  labels + evidence   β”‚
β”‚  (3 blueprints, β”‚  β”‚  policies         β”‚  β”‚                      β”‚
β”‚   15 identities,β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚   Conditional   β”‚
β”‚   Access,       β”‚
β”‚   ID Protection)β”‚
β””β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”˜
   β”‚ FIC      β”‚ FIC
   β”‚          β”‚
   β–Ό          β–Ό
Azure MI    AWS STS    GitHub OIDC    SPIRE (optional Part D)
   β”‚          β”‚            β”‚
   β–Ό          β–Ό            β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Copilot       β”‚  β”‚ LangChain agent  β”‚  β”‚ Bedrock Claude    β”‚  β”‚ n8n workflow β”‚
β”‚ Studio agent  β”‚  β”‚ ACA + sidecar    β”‚  β”‚ ECS + sidecar     β”‚  β”‚ ACA + node   β”‚
β”‚ (auto Agent IDβ”‚  β”‚                  β”‚  β”‚                   β”‚  β”‚              β”‚
β”‚  assignment)  β”‚  β”‚ ← MCP catalog β†’  β”‚  β”‚ ← MCP catalog β†’   β”‚  β”‚ ← MCP β†’ …   β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Every agent hits at least one MCP server + one Microsoft Graph endpoint. Every hop is instrumented.

Build plan (12 days)

Days 1-2 β€” Foundation

  1. Provision an Entra tenant with Agent 365 trial (E7 or E5 + Agent 365 + Entra Suite).
  2. Bicep / Terraform: two Azure Container Apps environments (aca-agents-dev, aca-agents-prod), a user-assigned managed identity per environment, an Azure Monitor workspace, a Log Analytics workspace, an Application Insights instance.
  3. GitHub repo with OIDC FIC into Entra (no AZURE_CLIENT_SECRET).

Days 3-4 β€” Blueprints + identities

  1. Create three blueprints via Agent 365 CLI: crm-helpdesk, momo-fraud-triage, onbill-billrun.
  2. Wire FIC on each blueprint β†’ the corresponding environment's managed identity.
  3. Create 3-5 agent identities per blueprint (dev / staging / prod Γ— business unit). Populate sponsors + owners + custom security attributes.
  4. Create an agent user account for the momo-fraud-triage prod identity; assign Teams Enterprise licence; wait for mailbox.

Days 5-6 β€” Policy + risk

  1. Custom security attribute set AgentGovernance with 5 keys (Env, BU, DataSensitivity, RiskTier, PurposeArea).
  2. CA policies: block high-risk agents (from template), require named-location for prod, MFA-exclude for agent user accounts.
  3. ID Protection: enable, deploy the CA "block high risk" template, forward RiskyAgents + AgentRiskDetection to Log Analytics β†’ Splunk.
  4. Trigger some synthetic risk (Lesson 10.6 lab) and verify SIEM alerts + auto-block work.

Days 7-8 β€” Third-party integration

  1. Deploy the LangChain agent to ACA-prod with the sidecar. Verify autonomous + OBO tokens.
  2. Deploy the Bedrock agent to ECS Fargate with sidecar; configure FIC to AWS STS (WIF pattern for Part D bonus).
  3. Deploy n8n to ACA-dev with the community node.
  4. Deploy the Copilot Studio agent; enable auto Agent ID assignment tenant-wide.

Days 9-10 β€” Governance + registry

  1. Access packages for the two most sensitive agents: momo-fraud-triage (financial data) and onbill-billrun (write to BSS).
  2. Lifecycle Workflows: sponsor auto-transfer to manager, 60/30/15 day notifications.
  3. Access review every 6 months for all agents.
  4. Register any third-party agents that don't auto-register in the M365 admin center registry.
  5. Run the "shadow agents" detection query; ensure none exist.

Days 11-12 β€” Observability, GSA, hardening

  1. Add Agent 365 SDK to LangChain and Bedrock agents (runtime + observability-core + framework extensions). Export OTel to Azure Monitor + Splunk.
  2. Register 2 MCP servers to the tenant catalogue (a mock Mail search + a mock ticket create). Wire via ToolCatalog.for_agent().
  3. Enable GSA traffic forwarding for the Copilot Studio environment. Allow-list approved domains; block social + consumer storage.
  4. Red-team exercise: try a prompt-injection asking the LangChain agent to hit an unregistered MCP server. Verify hard-refuse. Try to trigger earlyLifeMaliciousActivity.
  5. Threat model + agent cards for all agents. Governance report exported from admin registry.

Acceptance criteria

  • All 4 platform agents visible in the M365 admin center registry.
  • "Unmanaged agents" and "Agents without owners" both = 0.
  • Every agent identity has: sponsor with manager, owner, 5 custom attributes, an access package (where applicable).
  • CA policies enforce location + block-on-high-risk.
  • Triggering Confirm Compromise in ID Protection blocks the agent within 5 minutes end-to-end.
  • Splunk / Sentinel dashboard shows agent activity by identity, blueprint, risk state.
  • OTel spans reach Azure Monitor + Splunk with agent identity + blueprint attributes.
  • Attempted MCP call to unregistered server is refused by ToolCatalog.
  • GSA blocks Copilot Studio agent's egress to a disallowed domain.
  • Sponsor departure triggers auto-transfer + review workflow.
  • CI/CD deploys new agent identities without any static Azure secret in the repo.
  • Recorded 5-minute demo video walking through: create agent β†’ policy applied β†’ risk fired β†’ CA blocks β†’ remediation β†’ access package renewed β†’ agent decommissioned.

Stretch goals

  • SPIRE integration β€” enable SPIRE OIDC discovery, add an FIC on a blueprint trusting your SPIFFE trust domain; verify a SPIRE-issued JWT-SVID can be exchanged at Entra.
  • Second tenant + multitenant blueprint β€” publish crm-helpdesk as a multitenant blueprint; add it to a partner tenant; verify agent creation + policy inheritance works cross-tenant.
  • Purview DLP integration β€” apply a sensitivity label to a SharePoint site; verify the Copilot Studio agent's access is blocked when it violates a DLP rule; log the block into your SIEM.
  • Defender for Cloud Apps β€” configure a real-time policy that alerts on unusual agent-token usage patterns; wire to Sentinel.
  • Cost attribution β€” use OTel agent.identity_oid on every span to build a Grafana panel showing LLM cost by agent per week.
  • Kill-switch runbook β€” a single button (or POST /admin/kill-agent) that: confirms compromise in ID Protection, revokes all sessions, disables the identity, notifies sponsor + owner, opens a Sentinel incident.

Deliverables

  • Public GitHub repo: iam-for-agents-project-6-entra-agent365/ with the full Bicep / Terraform / SDK code (secrets scrubbed).
  • README.md, ARCHITECTURE.md, THREAT_MODEL.md, AGENT_CARDS/ (one per agent), RUNBOOK.md.
  • 5-minute demo video (YouTube / Loom).
  • Slide deck (3-5 slides) suitable for pitching to an enterprise architecture review board.
  • Interview talking points β€” how you designed the object model, why FIC over secrets, how CA + ID Protection interlock, how the sidecar keeps third-party agents governable, how you scale governance from 15 to 1500 agents.

Notes

  • License trials matter. Microsoft's Agent 365 trial has time limits. Plan the 12 days around it.
  • Diagnostic settings + Log Analytics workspace need to exist before you flip ID Protection on, or you'll lose the first days of detection data.
  • Copilot Studio auto Agent ID assignment is preview at time of writing β€” verify it's still on in your tenant.
  • Do not put real MTN / customer data in this lab. Use contoso.com-style test fixtures.
  • Sponsor discipline matters even in a lab. Assign a real (test) user with manager populated; the workflows only fire if the graph is populated correctly.