Exercise 2: Secure onboarding & identity governance
Scenario: A department submits a request to deploy an internal HR agent. The admin reviews the agent approval workflow, applies the Entra access packages and permission scopes, and configures lifecycle and expiration policies. The admin publishes the agent, and ensures it runs within approved runtime boundaries-without modifying how the agent was built.
In this exercise, you will apply an access package to a secuirty template for your organiztion's agent.
This exercise should take approximately 20 minutes to perform.
Task 1: Create an access package for agent identities
First, you need to ...
-
[] in a new browser tab, go to
https://entra.microsoft.com. -
[] If prompted, sign in with the admin credentials provided.
Option Value Username @lab.CloudCredential(WWLWWLM365withCopilotA365HydratedStakeholderSteveM).AdministrativeUsernamePassword @lab.CloudCredential(WWLWWLM365withCopilotA365HydratedStakeholderSteveM).AdministrativePassword[!Alert] You will have to setup your login with the Authenticator app. Please follow the prompts on screen to do so.
-
[] Navigate to Entra ID in the navigation menu on the left side on the screen.
-
[] Select Groups -> New Group.
-
[] In the New Group page, fill out the following fields:
- [] Group Type: Security
- [] Group Name:
agent 365-test group - [] Group description:
test group for labs
-
[] Select Create.
-
[] On the left hand side of the navigation menu, select ID Governance (you may need to scroll down)
-
[] Select Entitlement Management.
-
[] On the center menu, under Catalogs, select Catalogs.
-
[] Select the Agent 365 Governance catalog.
-
[] Select Resources.
-
[] Select + Add Resources
-
[] Select + Groups and Teams.
-
[] Search for and then select
agent365-test groupthat was created in step 4 -
[] Select Select, and then select Add.
-
[] On the left menu under ID Governance, select Access Reviews.
-
[] In the center menu under Entitlement management, select Access Packages.
-
[] Select + New access package.
-
[] Under the Basics tab fill out the following fields:
- [] Name:
Agent 365 New Access Package. - [] Description:
Access package for lab. - [] Catalog: Select Agent 365 Governance (the Catalog we modified in above) .
- [] Name:
-
[] Select Next: Resource roles >.
-
[] Under the Resource roles tab, select + Groups and Teams.
!IMAGEky37bpe0.png
-
[] In the pop window ,select the checkbox See all Group and Team(s) not in the 'Agent 365 Governance' catalog. You must have the correct permissions to add them in this access package.
-
[] Select the agent-365-test-group, and then select Select.
-
[] Select + SharePoint sites.
!IMAGEqhamjmnp.png
-
[] In the pop window ,select the checkbox See SharePoint Site(s) not in the 'Agent 365 Governance' catalog. You must have the correct permissions to add them in this access package.
-
[] Search for and then select
Operations Departmentsite, and then select Select. -
[] Back under the Resource roles tab, you should see Resource agent-365-test-group in the main grid. In the grid, select the drop down for the field Role. Select Member.
-
[] Back under the Resource roles tab, you should see resource 'Operations Department' in the main grid. In the grid, select the drop down for the field Role. Select Operations Department Members.
-
[] Select Next: Requests >.
-
[] Under the field Who can get access select For users, service, principals, and agent identities in your directory.
-
[] In the field Select specific scope select All agents.
-
[] Under Who can request access leave the default Admin as selected.
-
[] Scroll down to Approval and set Require approval to No.
-
[] Select Next: Requester Information >.
-
[] Under the Requester information tab, leave all default values and then select Next: Lifecycle.
-
[] Under Lifecycle tab, ensure that the checkbox for Require access reviews under Access Reviews is NOT selected.
-
[] Select Next: Rules >.
-
[] Under the Custom extensions tab, leave all default values and then select, and then select Next: Review + create >.
-
[] Under the Review and Create tab, select the Create.
Outcome: You have created an access package.
Task 2: Configure Conditional Access Policies
-
[] In the left menu under Entra ID, select Conditional Access.
-
[] In the center menu select Policies.
!IMAGE4ey5j9nr.png
-
[] Under Policy name, select the CA: Block High-Risk Agent Identities.
-
[] Under Users or agents (Preview), select the link 0 users or agents (Preview) selected.
-
[] In the dropdown for What does this policy apply to?, select Agents (Preview).
-
[] Under Include, select All agent identities (Preview).
-
[] Under Conditions, select the link 0 conditions selected.
-
[] Under Agent risk (Preview), select Not configured.
-
[] In the Agent risk (Preview) flyout, set Configure to Yes, and select the checkbox for High.
-
[] Select Done, and then select Save.
-
[] Under Policy name, select the CA: Block Unapproved Agent Identities.
-
[] Under Users or agents (Preview), select the link 0 users or agents (Preview) selected.
-
[] In the dropdown for What does this policy apply to?, select Agents (Preview).
-
[] Under Include, select All agent identities (Preview).
-
[] Under Conditions, select the link 0 conditions selected.
-
[] Under Agent risk (Preview), select Not configured.
-
[] In the Agent risk (Preview) flyout, set Configure to Yes, and select the checkbox for High.
-
[] Select Done, and then select Save.
Outcome: You have configured conditional access policies.
Task 3: Configure Custom security attributes
-
[] In the left menu under Entra ID, select Users, and then select All Users
-
[] Search for and then select
MOD Administrator -
[] Select the number next to Assigned roles.
!IMAGE07jrn6v9.png
-
[] Select + Add assignments
-
[] In the dropdown for Select role, search for and then select the role
Attribute Assignment Administrator -
[] Select Next.
-
[] Under assignment type, select Active
-
[] Under Enter justification, enter
to access custom security attributes. -
[] Select Assign.
-
[] Select + Add assignments
-
[] In the dropdown for Select role, search for and then select the role
Attribute Assignment Reader -
[] Select Next.
-
[] Under assignment type, select Active
-
[] Under Enter justification, enter
to access custom security attributes. -
[] Select Assign.
-
[] Select + Add assignments
-
[] In the dropdown for Select role, search for and then select the role
Attribute Definition Administrator -
[] Select Next.
-
[] Under assignment type, select Active
-
[] Under Enter justification, enter
to access custom security attributes. -
[] Select Assign.
-
[] Select + Add assignments
-
[] In the dropdown for Select role, search for and then select the role
Attribute Definition Reader -
[] Select Next.
-
[] Under assignment type, select Active
-
[] Under Enter justification, enter
to access custom security attributes. -
[] Select Assign.
-
[] Select Refresh to confirm the assignments were added.
-
[] In the left menu under Entra ID, select Custom security attributes.
-
[] Select the AgentGovernance security attribute.
-
[] Select Department
-
[] Select the ellipses … on the right and then select Edit attribute.
-
[] Ensure Compliance is listed under Predefined values.
-
[] Select the x at the top right of the window.
Outcome: You have configured a custom security attirbute.
Task 4: Create a new security template for Agents
-
[] Return to the Microsoft 365 admin center browser tab.
-
[] Select Agents, and then select Settings.
-
[] Select Templates.
-
[] Select + Add a new template.
-
[] For Template name, enter
HR Helper agent template. -
[] For Template description, enter
Test template for labs. -
[] Select Next.
-
[] Under the Security policies and protections page, select the following checkboxes:
- [] Conditional Access: ensure the CA: Block High-Risk Agent Identities, and CA: Block Unapproved Agent Identities are selected and grayed out.
- [] Access Packages: set the drop down to Agent 365 New Access Package, which you created in Task 1 of this exercise.
- [] Custom Security Attribute: set the drop down fields to Department and Compliance.
-
[] Select Next.
-
[] Select Save template.
-
[] Select Finish.
Outcome: You have configured a custom security attirbute.
Task 5: Assign an agent identity to the access package
-
[] Select Agents, and then select All agents.
-
[] Select Requests.
!IMAGE3zgrhcby.png
-
[] Select the HR Helper Agent.
-
[] Select Publish to store.
!IMAGEn6v4thek.png
-
[] In the Publish agent to selected users page select the following options:
- [] Under Select users or groups who can install the agent, select All users.
- [] Under Select users or groups who will have the agent pre-installed (optional), select All users.
-
[] Select Next.
-
[] In the Template dropdown, select HR Helper agent template
-
[] Review all the policies in the Default section to learn more about which policies can be managed in different platforms, and then select Next.
-
[] Select Next.
-
[] Select Publish.
-
[] Select Done.
Outcome: You have applied the agent identity to the access package.
Optional Task 6: Test your agent's access
-
[] In a new browser tab connect to
https://m365.cloud.microsoft/chat. -
[] On the left navigation pane, select …All agents.
-
[] In the search box search for and then select the HR Helper Agent,
-
[] Type the following prompt and select enter:
What can you do for me?wait for the agent to respond and then type in any other prompt. For example,What can you tell me about Contoso Ltd.'s open positions?
Outcome: Your agent should respond with tasks it can do for you.