Copilot Studio provisions a Microsoft Entra Agent ID for every new agent when a maker creates it, before publication and before anyone reviews it. That moves the governance decision earlier than most approval processes assume.
Maker access, environment scope, and what your directory does at creation now all precede the approval conversation.
Copilot Studio creates the Entra Agent ID at build time
Giving software an identity in your directory used to mean a conversation with whoever runs identity. An admin provisioned each service principal deliberately, and somebody signed off.
Microsoft’s Copilot Studio documentation now says the platform creates a Microsoft Entra Agent ID for each new agent. Provisioning happens at creation and before publication, so a draft nobody shipped already holds a directory record.
Entra Agent IDs began appearing in May 2026. From July 2026, every new agent must have one, and no environment-level opt-out remains. Agents built earlier can keep legacy app registrations, and Microsoft 365 Copilot’s Agent Builder does not use Agent IDs. Your estate will stay mixed for a while.
Automatic provisioning also has a hard limit. Every Entra Agent ID counts as a directory object, against the same tenant quota as your users and devices. The default is 50,000 objects, or 300,000 with a verified domain.
The directory can occupy no more than 95% of that. When the tenant hits that limit, Copilot Studio cannot create the Agent ID, and the agent fails with it.
How the quota ceiling hits a mid-market tenant
In a 1,200-person company, that number sits unwatched because in a normal year nothing moves it. Then Copilot Studio licenses go to two departments, and makers build several drafts each.
An abandoned draft holds its identity until somebody deletes the agent. The first signal is a maker filing a ticket because agent creation failed for no reason visible inside the product.
Check whether your tenant has a verified domain. A self-service signup tenant stays at 50,000 even after someone verifies one later. Then pull your object count against whichever ceiling applies. The harder question is who deletes abandoned agents, because deletion in Copilot Studio releases the identity and no role owns that job by default.
Stay updated with Simform’s weekly insights.
Entra Agent ID sponsorship defaults to the creator
Each of those identities carries a named human, which improves on the shared service accounts they replace. The question is whose name.
Microsoft separates two roles on a Microsoft Entra Agent ID. Owners handle technical administration and are optional. Sponsors are the business representatives accountable for an agent’s purpose and lifecycle decisions, and they are mandatory. Entra’s documentation names the creator as the agent identity’s sponsor. Copilot Studio’s own page names the agent owner. For a newly built agent, those describe the same person, the maker.
You can change the default afterward, and the generic Agent ID API accepts an explicit sponsor at creation. What Microsoft documents nowhere is a Copilot Studio setting that nominates a different organization-wide default sponsor before provisioning runs.
Accountability therefore lands wherever creation happens, which raises a lifecycle question. What becomes of that name when the person leaves?
Sponsorship transfers only through a Lifecycle Workflows task
Less than the high-level documentation suggests. Microsoft’s identity governance overview says sponsorship automatically transfers to the manager when a sponsor leaves.
The operational documentation describes something narrower. Transferring agent identity sponsorships is a Lifecycle Workflows task an administrator adds to a mover or leaver workflow; it requires a populated manager attribute on the departing user, and Microsoft documents no fallback for a user without one.
How this plays out when a finance manager resigns
Follow that through a resignation. A finance manager builds a reconciliation agent in March and leaves in September. HR runs offboarding and disables her account. Suppose nobody built the leaver workflow, or her manager attribute sat blank after her department head left in June.
The agent keeps running under an accountable name that belongs to a former employee. Entra doesn’t evaluate a disabled sponsor account on its own.
What to check before you rely on it
Pull the users holding Copilot Studio licenses and see which ones have a populated manager attribute. Then confirm whether a mover or leaver workflow carrying the transfer task exists in your tenant at all. The capability in Entra and the workflow in your configuration are separate facts, and only the second protects you.
Free inventory, but Conditional Access requires Agent 365
Whether you can act on what you find depends on licensing. The line falls in a less obvious place than budget conversations assume.
Microsoft Entra Agent ID is available to all Microsoft Entra customers. Any ordinary user account can view the centralized inventory; no admin role required. It shows status, owners, sponsors, permissions, and sign-in information.
An Agent ID Administrator can disable a single identity or an entire blueprint. Visibility and object-level control cost nothing extra.
What sits behind an entitlement is cross-tenant enforcement. Conditional Access for agents requires Entra ID P1 or P2 plus a Microsoft Agent 365 license for every user.
Agent risk detection through ID Protection requires P2 during preview. Agent 365 lists at $15 per user per month. Since June 1, 2026, a new purchase requires Microsoft 365 E5, A5, Business Premium, or a Defender and Purview bundle.
Buying it does not finish the job. Copilot Studio’s identity documentation says scope visibility applies to agents on every channel. Runtime enforcement of Conditional Access on the agent identity applies only when the agent runs in Microsoft Teams, the one channel performing end-to-end authentication with the Agent ID token. Everywhere else, Advanced Connector Policies and DLP govern.
How the channel gap plays out after an Agent 365 purchase
Picture a company licensing Agent 365 across 600 users. It writes a policy requiring device compliance before an agent identity can obtain a token. The policy holds for agents published to Teams.
The customer-facing agent on the website and the one in Omnichannel keep calling connectors on the older Power Platform path. The policy never reaches them.
What to confirm before the Agent 365 line item renews
Ask which channels your published agents run on before you treat Conditional Access as tenant-wide coverage. Then confirm somebody owns the connector policies outside Teams. The pricing base deserves a look too. Agent 365 charges per user across your workforce, while what you govern is a count of agents.
Maker access decides your Copilot Studio agent count
All of which points back to the one control operating before any of it. Standard Copilot Studio creation requires a tenant entitlement and a user-level license an administrator assigns.
Organizations can also disable self-service trial signup, restrict environment access through role-based controls, and route makers into governed environments. Data policies can block publication, though Microsoft notes plainly that they do not block creation.
The blunt version has a documented side effect. Conditional Access can block all agent identities tenant-wide, and Microsoft’s own guidance warns this can push teams toward less transparent application or service principal identities.
Copilot Studio keeps creating the identity objects anyway. The license is where you suppress creation, and where the decision sits. In most mid-market tenants, whoever processes license requests makes it.
Agent registration is outpacing mid-market adoption
Timing is the argument for settling this now. Two months after launch, Agent 365 held nearly 40 million registered agents across tens of thousands of companies.
Microsoft disclosed the figure on its FY2026 fourth quarter earnings call, and it spans a wider estate than Copilot Studio alone. McKinsey’s 2026 State of AI survey puts 22% of organizations below $1 billion in revenue at scaling agents in at least one function, against 40% above that line.
The platform is provisioning faster than the mid-market is adopting, and that gap is the entire opportunity. Deciding who gets maker access is a short conversation while your agent count is in the dozens. It becomes a migration project once it reaches the thousands.
Simform helps mid-market teams build agent programs on Azure that settle identity, access, and lifecycle before the first agent ships.
