MC1478488 - Migrate Copilot Studio agents to Microsoft Entra Agent ID
Microsoft 365 Message Center announcement MC1478488.
MS Message Center's Summary
Microsoft is rolling out migrations for Copilot Studio agents to use Microsoft Entra Agent IDs to improve governance and security capabilities. This change introduces audit logging integration, lifecycle management support, and Conditional Access policy targeting for agent identities. Administrators should review tenant inventories using the Power Platform admin center, plan pilot migrations for eligible agents, and coordinate validation with agent owners before proceeding with full scale deployment across the environment.
- Administrator impact
- Administrators should use the Power Platform admin center to identify eligible agents and coordinate migration validation with agent owners.
- End user impact
- End users may experience temporary disruption if agent validation fails and configurations require review.
- Importance
- 4/10: This is an important administrative update requiring proactive identification and migration planning for legacy agent identities.
- Message Center ID
- MC1478488
- Category
- stay Informed
- Severity
- normal
- Services
- Microsoft Copilot (Power Platform)
- Tags
- Admin impact
- Published
- 2026-09-24
- Last updated
- 2026-09-24
- Expires
- 2026-11-24
On August 24, 2026, we initiated the gradual roll out of self-service migrations to Microsoft Entra Agent IDs for Copilot Studio agents in Power Platform Advisor. Beginning on September 2026, automatic migrations of agents without Entra Agent ID to Microsoft Entra Agent ID were also initiated. Copilot Studio agents created before May 2026 may still use legacy app-registration identities. We recommend migrating any of your remaining agents to Microsoft Entra Agent ID. How does this affect me? Migrating your agents to Microsoft Entra Agent ID helps your organization build, discover, govern, and protect agent identities across services by using a unified platform. Key benefits include: Audit logging in Microsoft Entra ID. Agent lifecycle management. Integration with Entra ID Governance . Visibility of connector permissions as API permissions on the agent identity, so Entra and Microsoft 365 admins can see what an agent can do without opening Power Platform admin center. Ability to target those connector permissions with Microsoft Entra Conditional Access policies (for example, network location, device compliance, or risk conditions). To find out if your agent has been migrated already been migrated or if there are any agents that remain to be migrated in your tenant, you can use the Advisor recommendation. What action do I need to take? We recommend identifying and migrating your eligible agents to Microsoft Entra Agent ID. To perform this mitigation, please follow the steps listed below: Confirm that Power Platform inventory is enabled for your tenant. In the Power Platform admin center, go to Actions > Recommendations > Active, and open Migrate Copilot Studio agents to Microsoft Entra Agent ID for enhanced agent governance. In the recommendation pane, expand Why is this important?, and review the migration guidance. Review the eligible agents. Use Suggested migration order and Migration notes to choose an initial pilot or the next migration batch. The table also provides information such as environment, environment type, owner, recent activity, and authentication method. Select the checkbox next to each agent you want to migrate. You can select one agent or multiple eligible agents. The Migrate button becomes available and the action bar shows the number of agents selected. Select Migrate, review the confirmation, and confirm the migration. Start with a small batch of noncritical agents. Review the Action, Action state, and Action date columns for each selected agent. To review actions across recommendations, select the Action history tab. Coordinate a validation window with the makers who own the agents. After migration, validate each agent's channels, authentication, actions, connectors, flows, and integrations before migrating another batch. Review Microsoft Entra sign-in logs and applicable Conditional Access results. If an agent does not pass validation, revert it before continuing. This message is for awareness, and no action is required. For more information, please visit Migrate Copilot Studio agents to Microsoft Entra Agent ID .