
AI agents are quickly moving beyond simple chat interfaces. They’re reading files, querying databases, updating customer records, creating support tickets and initiating workflows. To accomplish those tasks, each agent needs permission to access business systems and data.
That makes every AI agent an identity – and potentially a privileged one.
For MSPs, this creates both a security challenge and a recurring-revenue opportunity. Most clients haven’t developed the policies, inventories or monitoring processes required to govern AI agents. MSPs can close that gap by extending their existing identity and access management practices to this new population of non-human users.
Why AI agents require identity governance
An AI agent may be software, but the security questions surrounding it are familiar: What can it access? Who approved that access? Who’s responsible for it? Is it still being used? What happens when its purpose or owner changes?
Unlike a traditional application that may remain relatively stable for years, agents can be created dynamically and exist for only a few minutes or hours. Others may become permanent parts of customer service, finance, sales or IT operations.
Microsoft explains that an agent might be created and destroyed thousands of times per day. Its Microsoft Entra Agent ID documentation also notes that autonomous agents can receive Microsoft Graph permissions, Azure role-based access control roles, directory roles and other powerful access rights.
Without governance, clients can quickly develop “agent sprawl”: a growing collection of poorly documented agents with excessive permissions, unclear ownership and no defined retirement process.
Research from the Cloud Security Alliance illustrates the scale of the problem. Its report on non-human identity and agentic AI governance found that 78% of organizations have no documented policy for creating or removing AI identities, and more than 16% don’t track the creation of these identities at all.
A timely warning for Microsoft environments
A recent announcement from Netwrix provides one example of how security vendors are responding. On Aug. 18, the company expanded its Microsoft identity-security capabilities to provide greater visibility into AI agent identities and the permissions they hold in Microsoft Entra ID.
The announcement also cited Netwrix research showing that only 19% of organizations fully govern non-human identities such as service accounts and AI agents. Organizations in which AI significantly expanded the identity population reported a 43% breach rate, compared with 11% among organizations where it hadn’t.
That breach gap is especially relevant to MSPs’ core market: the same Netwrix report found a 40.3% breach rate among organizations with 500 to 999 employees – the highest of any size band, and squarely the range many MSPs serve.
Netwrix is only one vendor addressing this issue, and MSPs shouldn’t build their service around a single product. The broader takeaway is that identity inventories, access reviews and lifecycle controls must expand beyond employees, contractors and service accounts – and beyond Microsoft alone, since MSPs’ clients are also deploying agents in Google Workspace, Salesforce, ServiceNow and other SaaS and cloud platforms that need the same discipline.
Microsoft is making the same architectural shift. Microsoft Entra Agent ID is designed to help organizations manage, govern and protect agent identities. Its capabilities include agent registration, ownership and sponsorship, lifecycle governance, Conditional Access and centralized activity monitoring.
Licensing determines how much of that governance a client can actually use. Base Agent ID capabilities – creating and managing agent identities – are included for all Microsoft Entra customers at no extra cost. Conditional Access, Identity Protection and full lifecycle governance for agents require Microsoft Agent 365, which is licensed per user and comes bundled with Microsoft 365 E7 or sold as an add-on to E5, A5 or Business Premium. Confirming which tier a client already owns – and whether an upgrade is worthwhile – is a natural extension of the initial assessment.
The technology is emerging, but the underlying service opportunity exists now.
Build an AI identity governance service
An MSP can begin with an AI agent discovery and risk assessment. The objective is to identify agents across the client’s environment, document what each one does and determine which applications, data and workflows it can access.
The initial assessment should answer five questions:
- Which agents exist?
- Who owns or sponsors each agent?
- What permissions does each agent have?
- When was each agent last used?
- What process will disable or remove it?
From there, the MSP can establish an agent identity register that records the agent’s purpose, business owner, technical owner, data access, authentication method, risk classification and expected retirement date.
Every agent should have an accountable human sponsor. Microsoft’s agent identity governance guidance emphasizes this requirement and describes processes for transferring sponsorship when an employee leaves the organization. That prevents an agent from becoming an orphaned identity with nobody responsible for reviewing its access.
MSPs should also apply least privilege. An agent that summarizes documents doesn’t necessarily need permission to modify or delete them. An accounts-receivable agent shouldn’t have unrestricted access to every finance system merely because broad permissions make deployment easier.
Finally, access should be time-bound and reviewed regularly. Microsoft’s Agent ID best practices recommend periodic access reviews, consistent naming conventions and quarterly checks for agents with missing sponsors, outdated information or no recent activity.
Turn governance into recurring revenue
The initial discovery project can lead naturally to a managed AI identity service. A monthly or quarterly offering could include:
- Continuous discovery of new agents and non-human identities
- Permission and configuration monitoring
- Scheduled access and ownership reviews
- Detection of inactive or orphaned agents
- Policy and naming-standard enforcement
- Audit-ready reporting
- Agent onboarding and decommissioning
- Incident-response support for compromised agents
The service can also complement vCISO, compliance, Microsoft 365 management and managed detection and response offerings. Instead of selling another isolated tool, the MSP is providing an ongoing governance outcome: every AI agent is known, owned, appropriately authorized and monitored throughout its lifecycle.
Pricing could be based on the number of agents, identities, tenants or applications under management, with an initial assessment fee followed by recurring monitoring and governance charges.
Don’t wait for agent sprawl
Many clients are adopting AI agents the way they once adopted cloud applications: one department and one experiment at a time. That can produce business value quickly, but it can also create a fragmented environment before IT recognizes the extent of the risk.
MSPs have an opportunity to intervene early. They already understand identity management, access control, Microsoft environments, security monitoring and compliance. Extending those disciplines to AI agents is a logical next step.
Every agent should be treated as an identity from the moment it’s created until the moment its access is revoked. MSPs that help clients establish that discipline won’t merely reduce risk. They’ll create a valuable managed service for the agentic era.











