Microsoft starts putting Copilot Studio agents on company identity accounts

Microsoft has begun moving Copilot Studio agents onto Microsoft Entra Agent IDs, the same kind of company identity used for people and apps. Self-service migration started on 24 August 2026 in Power Platform Advisor. Automatic migration of agents that still lacked an Entra Agent ID began in September 2026. Agents created before May 2026 may still sit on older app-registration identities until they are moved. After each batch, Microsoft says channels, authentication, actions, connectors, and related flows should be checked, with a revert if that check fails. The Message Center item (MC1478488) is labelled awareness and says no action is required, while still telling admins to find remaining agents. Once on Entra, connector access can show up as API permissions on the agent identity, which Conditional Access and Entra audit logs can target.
Until now, a Copilot Studio agent often lived as a Power Platform object. Its permissions sat in a different admin world from Microsoft 365, so people could treat it as a clever workflow rather than an account that can read files, call connectors, and leave a trail. That split is closing. An agent that reaches SharePoint or other company data can now look, to IT, like a service account with logs, lifecycle, and access rules. Building a small agent is no longer a private experiment in one app. It is closer to requesting a new identity that security teams can see without opening the Power Platform admin centre.
Analysis
Treat this as a trap to avoid, not a reason to start Copilot Studio. Before anyone in your team publishes an agent, ask your Microsoft 365 or Entra admin whether remaining Copilot Studio agents, especially those created before May 2026, still use a legacy identity.
Source note
Pulse published by Collab365 Spaces, reviewed by Helen Jones on . Cite as "Microsoft starts putting Copilot Studio agents on company identity accounts", Collab365 Spaces. 1 source referenced.