Securing Non-Human Identities with Microsoft Entra
Solution overview
Non-human identities, service principals, managed identities, and now AI agents, outnumber human users in most Microsoft Entra tenants, and most of them run without anyone actively watching. This lab series follows a single real non-human identity, the Conditional Access Optimization Agent that Microsoft Entra provisions for you, from the moment it is registered through governing it over time and finally responding to a security incident involving it.
The three labs are meant to be done in order, in the same tenant, against the same agent identity. What you register and govern in Lab 1 is what drifts and gets remediated in Lab 2, and what gets attacked and defended in Lab 3. That continuity is the point: real non-human identity security is not a one-time setup, it is something you maintain and defend across the whole life of the identity.