AI agent identity visibility [What It Changes]
TL;DR
AI agent identity visibility is the ability to list every AI agent account in Microsoft Entra ID, see what it can access, and treat that account like a hire — with an owner, a permission review, and a kill switch.
On August 18, 2026, Netwrix shipped PingCastle and Threat Manager updates that inventory AI agent identities in Entra ID; agent-specific threat detection is promised later, not in this release.
A 10-person marketing agency, a solo clinic, or a two-truck HVAC shop on Microsoft 365 already has the same directory those agents live in, even if nobody on staff uses the word "Entra."
Inventory first. Do not wait for a dedicated security team. Map agents the same way you map employees in the admin center.
Key Takeaways
An AI agent in Microsoft 365 is not a feature toggle. It is an identity with permissions, as Microsoft Entra Agent ID now frames it.
Netwrix's August 18, 2026 release is one vendor's inventory layer on top of Entra ID, not a replacement for Microsoft's own agent-identity platform.
Non-human identity governance is still the gap: most organizations do not fully govern service accounts and agents.
CISA's small-business basics — MFA, logging, backups — still apply; an unlisted agent account bypasses all three if nobody knows it exists.
Teams already routing documents through US Tech Automations can add an "agent account?" check next to the human-user offboarding step.
What AI agent identity visibility is
AI agent identity visibility is the practice of seeing which AI agent accounts exist in Microsoft Entra ID, what permissions those accounts hold, and whether anyone owns them — the same checklist you would run for a new employee.
A 10-person marketing agency that turns on a content agent to draft client emails just created a login that can read mailboxes. A solo-run clinic that lets a scheduling agent book patients just created a login that can see calendars and names. A two-truck HVAC shop that asks Copilot to pull invoices from SharePoint just created a login that can open the file share. None of those shops has a security operations center. All of them already have Microsoft Entra ID if they pay for Microsoft 365.
The constraint that broke is simple: agents used to hide as "just another app." They now get their own identity objects. Until you can list those objects, you cannot review them, and you cannot shut them off.
As of August 18, 2026, Netwrix says its Threat Manager release is meant to close that listing gap inside Entra ID.
What Netwrix shipped on August 18, 2026
Yahoo Finance carried the paid PR Newswire item from Frisco, Texas: Netwrix PingCastle and Netwrix Threat Manager now extend identity security into the Microsoft cloud, including coverage of AI agents.
According to Security Info Watch, PingCastle now extends Microsoft Entra ID coverage to 102 risk checks, and Threat Manager adds an inventory of AI agent identities plus the access they hold.
The same Security Info Watch report says a Cloud Security Alliance survey cited by Netwrix found that more than 16% of organizations do not track when a new AI identity is created, and that fewer than a quarter have a formally adopted policy for creating or removing the identities their AI systems run on.
Jeff Warren, Netwrix's chief product officer, is quoted there: "Earlier this year, we gave organizations visibility into what AI agents can access. This release goes a layer deeper: which agents exist at all."
PingCastle 4.0 and Threat Manager 3.3 are listed as available now. Azure Files threat detection — ransomware, abnormal behavior, open-access creation — shipped in the same Threat Manager drop. Agent-specific threat detection is planned for a subsequent release. That last sentence is the honest limit: this is an inventory and posture release, not a finished agent-attack detector.
Netwrix PingCastle's product page still describes a hybrid Active Directory and Entra ID assessment tool, trusted by 45,000+ domains in 193 countries, detecting 170+ hybrid identity risks, mapped to MITRE and ANSSI controls. The August 18 Entra ID count of 102 risk checks is the cloud-plane expansion on top of that AD heritage.
Netwrix Threat Manager already watched service accounts and Entra ID application permission changes. This release extends that non-human coverage to AI agents. Netwrix's non-human identity defense page is the older service-account version of the same idea: discover the account, baseline it, contain it.
The PingCastle assessment engine also powers more than 200 checks inside Netwrix 1Secure, per the Security Info Watch write-up. That is a product-family note, not a reason to buy 1Secure for a 10-person shop.
Why the numbers on identity expansion matter
According to the Netwrix 2026 Data and Identity Security Report, organizations where AI expanded identities reported a 43% breach rate versus 11%.
The report surveyed 2,317 IT and security professionals representing 1,889 organizations across more than 60 industries. Netwrix CEO Grady Summers is quoted on that page: organizations where AI expanded access saw four times the breach rate, 43% versus 11%.
According to the same Netwrix report, 76% of organizations do not fully govern non-human identities, and 11% report full AI security readiness through continuous enforcement and monitoring.
The August 18 press item, via Yahoo Finance, also states that only 19% of organizations fully govern non-human identities such as service accounts and AI agents. That 19% figure and the report-page 76% "do not fully govern" line are both Netwrix's published wording; treat them as the vendor's own survey results, not as a government statistic.
| Metric | Figure |
|---|---|
| Survey respondents | 2,317 |
| Organizations represented | 1,889 |
| Breach rate where AI expanded identities | 43% |
| Breach rate where AI did not expand identities | 11% |
| Do not fully govern non-human identities | 76% |
| Full AI security readiness | 11% |
Source: Netwrix 2026 Data and Identity Security Report.
| Release item (as of August 18, 2026) | Figure |
|---|---|
| PingCastle Entra ID risk checks | 102 |
| PingCastle 1Secure engine checks | 200+ |
| PingCastle domains (product page) | 45,000+ |
| PingCastle countries (product page) | 193 |
| PingCastle hybrid identity risks (product page) | 170+ |
| PingCastle version | 4.0 |
| Threat Manager version | 3.3 |
Sources: Security Info Watch; Yahoo Finance / PR Newswire; Netwrix PingCastle.
USTA analysis: the 32-point gap
USTA analysis. Inputs are the two breach rates Netwrix published on the 2026 report page.
Input A: 43% breach rate where AI significantly expanded the number of identities needing access.
Input B: 11% breach rate where AI had not materially changed access patterns.
Difference: 43 − 11 = 32 percentage points.
Ratio: 43 ÷ 11 ≈ 3.91, which matches the report's own "nearly four times" wording.
This is not a claim that turning on an agent causes a breach. It is the arithmetic on Netwrix's two published rates, so a 10-person shop can see the size of the gap the vendor is using to sell inventory.
What Microsoft already put in the directory
Microsoft Entra is the identity family. Microsoft Entra ID is the cloud identity and access service that every Microsoft 365 tenant already is. Microsoft's own page says if you are a Microsoft 365, Azure, or Dynamics CRM Online subscriber, you are already using Entra ID.
According to Microsoft's Entra ID product page, more than 720,000 organizations use Microsoft Entra ID, and MFA reduces 99.22% of identity compromise risk.
That page also lists Microsoft Entra Agent ID Preview as the product to "secure access for AI agent identities." The Learn documentation is the deeper spec.
Microsoft Entra Agent ID is an identity and security framework that extends Entra capabilities to AI agents: authenticate, authorize, govern, and protect nonhuman identities. Agent identity blueprints act as templates. The platform supports OAuth 2.0, Model Context Protocol (MCP), and agent-to-agent (A2A). Third-party agents from platforms such as AWS Bedrock and n8n can be integrated. Microsoft says Agent ID is available for all Microsoft Entra customers; extending Entra security features to agents requires Microsoft Agent 365, which is included with Microsoft 365 E7 and sold as an add-on to E5/A5/Business Premium.
So a small Microsoft 365 tenant may already have agent identities in the directory even if it has not bought Agent 365 security extras. Visibility and paid protection are not the same SKU.
Microsoft Entra Workload ID is the older bucket: applications, service principals, and managed identities. Microsoft now calls AI agents a distinct category because they make dynamic decisions, unlike a script that always does the same thing.
Application objects and service principals are how Entra has long represented apps. A service principal is the local identity of an app in your tenant. If you never open Enterprise applications in the Entra admin center, you will not see those principals — or the new agent identities sitting next to them.
Managed identities remove secrets from Azure compute. They are still service principals. Microsoft documents a limit of 20 federated identity credentials when a managed identity is used as a credential on an Entra app.
Microsoft Graph is the API at https://graph.microsoft.com that reads Entra and Microsoft 365 data. Any agent that can call Graph with a token can read mail, files, and users at the scope you granted. That is why an unlisted agent account is not a toy.
Microsoft's Zero Trust overview restates three principles: verify explicitly, use least privilege, assume breach. An agent identity that nobody has listed fails all three.
The same Threat Manager release adds detection for Azure Files, Microsoft's managed SMB/NFS file shares. Open-access file shares plus an unlisted agent is a concrete SMB failure mode: the agent can read the share, and nobody is watching the identity.
| Identity type in Entra | What Microsoft calls it | Typical SMB example |
|---|---|---|
| Human user | User principal | Employee mailbox login |
| App in a tenant | Service principal | A SaaS app you consented |
| Azure compute | Managed identity | A VM that talks to storage |
| AI agent | Agent identity (Agent ID) | A Copilot or Copilot Studio agent |
Sources: Microsoft Entra overview; Workload identities; Entra Agent ID; Apps and service principals.
What a small shop should do this week
Open the Microsoft Entra admin center (or the Microsoft 365 admin center identity blade) and list Enterprise applications and any Agent ID objects. Write down owner, purpose, and last sign-in. If you cannot name an owner, disable the agent until you can.
Turn on MFA for humans. According to CISA's Secure Your Business guidance, the FBI reported over $2.7 billion in losses from business email compromise in 2024, and CISA's four essentials for small firms are phishing training, strong passwords, MFA, and software updates. An agent account with mailbox access is a BEC path that does not phish a person.
CISA's Secure Our World page is the consumer version of the same four habits. Logging is the "level up" step on the business page: if you do not log agent sign-ins, you will not notice a token abuse.
The NIST AI Risk Management Framework (AI RMF 1.0, NIST.AI.100-1) is voluntary. It organizes work into GOVERN, MAP, MEASURE, and MANAGE. For a 10-person shop, MAP means "list the agents"; GOVERN means "someone owns each one." NIST released AI RMF 1.0 on January 26, 2023, and a generative-AI profile (NIST.AI.600-1) on July 26, 2024.
According to OWASP, the GenAI LLM Top 10 2026 was published August 4, 2026. The archived 2023 list still names LLM08 Excessive Agency: granting LLMs unchecked autonomy to take action. That is the risk AI agent identity visibility is supposed to make reviewable.
The Cloud Security Alliance is the organization Netwrix cited for the "fewer than a quarter have a policy" survey. CSA also publishes an AI Controls Matrix aligned with NIST AI RMF. You do not need to join CSA to keep a spreadsheet of agent accounts.
If your shop already uses form-to-CRM automation, add a field for "which Entra identity does this agent use?" If executive-assistant automations book meetings or file invoices, those flows are exactly the ones that spawn agent accounts. Accounting and tax stacks — practice-management software, Drake vs ProConnect vs UltraTax, even Fathom vs Jirav reporting — sit on the same Microsoft 365 tenant as the agent. The small-business automation landscape is the backdrop: tools multiply faster than reviews.
Shops already routing intake and offboarding through US Tech Automations can put the Entra agent list on the same cadence as the human-user list: add on hire-like provisioning, remove on project end.
Do not confuse Netwrix inventory with Microsoft's Agent ID platform. You can use Microsoft's admin center alone. Netwrix is one independent assessment layer. Microsoft Graph is how a technical partner would export the list if the UI is not enough.
Signal vs Speculation
Demonstrated fact (sourced): As of August 18, 2026, Netwrix announced PingCastle 4.0 and Threat Manager 3.3 with AI agent identity inventory in Microsoft Entra ID, 102 Entra ID risk checks in PingCastle, Azure Files threat detection in Threat Manager, and agent-specific threat detection deferred to a later release.
Demonstrated fact (sourced): Netwrix's 2026 survey of 2,317 professionals / 1,889 organizations reports a 43% versus 11% breach-rate split tied to AI-driven identity expansion, 76% not fully governing non-human identities, and 11% claiming full AI security readiness.
Demonstrated fact (sourced): Microsoft documents Entra Agent ID as the identity framework for AI agents, Workload ID for apps/service principals/managed identities, and Entra ID as the directory every Microsoft 365 tenant already uses.
Our read: For a small Microsoft 365 tenant, the next 12 months are an inventory problem, not a product bake-off. The shops that list agent accounts in the same spreadsheet as employees will be able to turn one off when a contractor leaves. The shops that do not will discover the account during an incident.
Our read: If Microsoft keeps Agent 365 security features behind E7 or an E5 add-on, independent inventory tools will keep a role for Business Premium and smaller SKUs. That is a licensing forecast, not a price quote.
Our read: Over 12–36 months, "AI agent identity visibility" will stop being a vendor slogan and become an access-review checkbox next to joiner-mover-leaver. OWASP's excessive-agency item and NIST's MAP function already describe that checkbox. Netwrix is early product on that path, not the path itself.
This block is not a claim that Netwrix prevents breaches.
Glossary
AI agent identity visibility: Listing AI agent accounts in Entra ID, their permissions, and their owners.
Microsoft Entra ID: Microsoft's cloud identity service; every Microsoft 365 tenant is an Entra tenant.
Microsoft Entra Agent ID: Microsoft's identity framework for AI agents, including blueprints and (with Agent 365) extra security features.
Service principal: The local Entra identity of an application in your tenant.
Managed identity: An Entra identity assigned to Azure compute so the workload needs no stored secret.
Non-human identity (NHI): Service accounts, apps, and AI agents — anything that is not a person.
PingCastle: Netwrix's AD and Entra ID posture assessment tool; version 4.0 adds 102 Entra ID risk checks.
Threat Manager: Netwrix's identity and file-system detection product; version 3.3 adds AI agent inventory in Entra ID.
FAQs
What is AI agent identity visibility in one sentence?
It is the ability to see which AI agent accounts exist in Microsoft Entra ID and what those accounts can access, the same way you would audit a new employee's login.
Did Netwrix invent agent accounts in Entra ID?
No. Microsoft Entra Agent ID is Microsoft's own framework; Netwrix's August 18, 2026 release is an independent inventory and posture layer on that directory, as Security Info Watch reported.
Is agent-specific threat detection included today?
No. The Yahoo Finance / PR Newswire item and Security Info Watch both say agent-specific threat detection is planned for a subsequent release.
Do I need Netwrix if I already have Microsoft 365?
Not necessarily. You can list identities in the Entra admin center and in Microsoft Graph. Netwrix is one way to get a prioritized risk list across on-prem AD and Entra ID.
Why should a clinic or HVAC shop care?
If the shop uses Microsoft 365, it already has Entra ID. Any agent that reads mail, files, or calendars is an identity in that directory. CISA's small-business guidance starts with MFA and logging; an unlisted agent skips both.
What is the first workflow step?
Export or screenshot the Enterprise applications and Agent ID lists, assign an owner to each, and add that list to the same offboarding checklist you already use for people. Shops routing that checklist through US Tech Automations can add the agent row without rebuilding the hire/fire path.
AI agent identity visibility is a directory problem wearing a vendor announcement. As of August 18, 2026, Netwrix will sell you an inventory of Entra agent accounts; Microsoft will sell you Agent ID and Agent 365; NIST and OWASP already told you to map and limit agency. A 10-person Microsoft 365 tenant can start with a list.
If your team already runs intake and offboarding on US Tech Automations, put the Entra agent list on that same path, then use the agentic workflow builder to make "list agents, assign owners, revoke on project end" a repeatable step instead of a one-off admin-center hunt.
About the Author

Helping businesses leverage automation for operational efficiency.
Related Articles
See how AI agents fit your team
US Tech Automations builds and runs the AI agents that handle this work end to end, so your team doesn't have to.
View pricing & plans