Field guide · AI agent security

AI agent identity:
who can act for your business?

AI agent identity proves which user, agent or system is requesting access. Inbound controls who can call your agent. Outbound controls how your agent reaches other systems.

five checkpoints, one question each: who is this, really?
1
You
Sign in
2
Entra ID
Checks who you are
3
Agent A
Borrows your access
4
Agent B
Hands off the task
5
Your systems
Checks the ID again
Direction of trust

What are inbound and outbound agent connections?

Direction tells you which side of the agent boundary needs protection. It's one flow through your agent, checked twice — once coming in, once going out.

Inbound

Who is allowed to call my agent?

Your agent checks the caller's token, issuer, intended audience, tenant and permissions before accepting the request.

Outbound

How does my agent access another system?

Your agent obtains a token for that destination, requests only the permissions it needs and identifies itself or the user it represents.

Source of authority

What are 2LO and 3LO?

They are informal OAuth shorthand, not traffic directions. Either an inbound or outbound request can use 2LO or 3LO. The difference is whether a person has delegated their authority.

2LO

Two-legged OAuth: the agent acts as itself

No user is present. The agent or service uses its own workload identity and application permissions, commonly through the OAuth client credentials flow.

AGENT SYSTEM
direct — no one to vouch for
3LO

Three-legged OAuth: the agent acts for a person

A user delegates specific permissions. The agent carries that user's identity and access limits forward, often through an authorization code and On-Behalf-Of flow.

USER AGENT SYSTEM
borrowed, never owned

How direction and authority fit together

2LOagent as itself
3LOagent for a person
Inboundinto your agent

Another trusted service or agent calls your agent as itself.

A caller invokes your agent with delegated user context.

Outboundfrom your agent

Your agent accesses a system using its own workload identity.

Your agent accesses a downstream system on a user's behalf.

Four trust relationships

How does AI agent identity work?

Each relationship checks who is acting, what they can access and whether the next system should accept the request.

Sign-in works the same way it does for any Microsoft 365 app — single sign-on, multi-factor authentication, and conditional access rules for device and location. Group membership then decides which agents actually appear in your catalogue: Finance sees the finance agents, HR sees the HR ones.
This is the 3LO path: the user delegates authority, and the agent doesn't simply wear their login. It trades the user's access token, plus its own credential, for a new token that says "this agent, acting for this person, with these permissions" — Microsoft calls this an On-Behalf-Of exchange. Agents that run with nobody watching use 2LO instead: their own standing identity, a named owner and automatically rotated credentials.
When agents collaborate, the calling agent makes an outbound request and the receiving agent handles it inbound. This is often 2LO because the caller acts as itself; when work is being done for a person, delegated 3LO context may also travel with the request. Under A2A, each agent publishes a "business card" listing what it does and what forms of ID it accepts. Insist on a cryptographically signed card for agents outside your tenant.
The last hop — an agent touching your CRM, files or inbox — is outbound. It uses 2LO when the agent acts as itself and 3LO when it acts for a signed-in user. The receiving system validates that the token was issued by a trusted identity provider, intended for that system and limited to the required permissions.
Invoice Approval Agent Signed
Skills
Reads invoices, checks PO match, flags exceptions
Accepted ID
Bearer token API key mTLS certificate
Agent-to-agent

What does an AI agent identity card contain?

Under A2A, an agent can publish a card like this one before anyone talks to it. The card describes the agent's inbound boundary: what it does, which authentication methods it accepts and how another agent should call it.

Outbound access is separate. The calling agent still needs a 2LO workload token or 3LO delegated token that the destination system will accept.

The protocol standardises the handshake — it doesn't force anyone to check the signature. That's the one gap worth knowing about.

Insist on the signed version for anything outside your own tenant.

Five controls

How do you secure AI agent identities?

Start with five controls: unique identities, delegated access, named owners, signed agent cards and complete activity logs.

  • Give every agent its own identity — never a shared account.
  • Let interactive agents borrow, never inherit, a person's access.
  • Give unattended agents a named owner and automatic credential rotation.
  • Require signed ID cards for any agent from outside your own tenant.
  • Log the agent and the person together — every single time.