Agent 365 Identity Backfill
Provision Entra agent identities and Agent 365 registry cards for agents that existed before Agent 365 was enabled, or whose automatic identity provisioning did not complete.
Overview
When Agent 365 is enabled for your tenant, new agents receive their Entra identity automatically at creation time. Agents created before enablement, or whose lazy provisioning was interrupted, are listed here so you can provision them manually.
Each provisioned agent receives:
- A Microsoft Entra agent identity using the tenant's approved blueprint for that agent type.
- An Agent 365 registry card that registers it as a first-class Agent 365 identity in your tenant.
Prerequisites
- The Agent 365 enablement ceremony must be completed before you can backfill identities. If you see an Agent 365 is not enabled notice, go to Settings - Microsoft 365 and enable Agent 365 governance there first (see Agent 365 Enablement).
- You must be signed in as an Outermind system administrator.
Reaching the Page
Navigate to Governance > Configuration > Microsoft Entra Agents in the admin console sidebar.
Provisioning Identities
Provision all agents at once
- The page loads and lists every agent that lacks an active identity.
- Click Create identities for all N to open a confirmation dialog.
- Review the confirmation and click Create identities to begin.
- A spinner appears on the button while provisioning runs. When complete, the agent list refreshes and successfully provisioned agents drop off.
Provision a single agent
Each agent row has a Provision button. Click it to provision only that agent without affecting the others.
Reading the results
After provisioning, each agent row shows a status pill:
| Status | Meaning |
|---|---|
| Active | Identity is fully provisioned and ready. |
| Identity created | The Entra identity was created; registry-card registration is in progress. |
| Error | Provisioning failed - an error message appears below the agent name. |
| Not provisioned | No identity exists yet. |
If any agents show an error, address the cause and use the per-agent Provision button to retry those agents.
"No consented blueprint" warning
An agent may show: No consented blueprint for this agent type yet - complete enablement for its type first.
This means the Agent 365 enablement ceremony has not been completed for that agent's type. Return to Agent 365 Enablement and complete the ceremony for the affected agent type, then retry provisioning.
All Agents Already Provisioned
If every agent in your tenant already has an active identity, the page shows an All agents are provisioned notice. No action is required - new agents created going forward are provisioned automatically at creation time.
FAQ
Do I need to run this page regularly?
No. It is a one-time or rare-use page. Once all existing agents are backfilled, new agents receive identities automatically. You would return here only after recovering from a provisioning failure, or after re-enabling Agent 365 on a tenant that had it disabled.
Can I provision agents one at a time instead of all at once?
Yes. Use the per-agent Provision button in each row. The bulk and per-agent actions are mutually exclusive - while one is running, all other buttons are disabled to prevent concurrent provisioning.
What happens if I close the browser while provisioning is running?
Provisioning runs server-side. The operation completes even if you navigate away. Return to this page and click Refresh to see the latest status.
Will provisioning affect agents that are currently handling email?
No. Adding an Agent 365 identity to an existing agent does not interrupt any in-flight tasks or change existing mail routing. The new identity is used for subsequent mail operations once it is fully active.