Microsoft Entra ID delivered two significant updates this week: eye-opening findings from Identiverse 2026 about AI agent sprawl in enterprise environments, and a deepened integration with SAP identity systems that positions Entra ID Governance as the strategic successor to SAP Identity Management. Both announcements carry significant implications for IT administrators managing identity in the AI era.

AI Agents Are Everywhere: Identiverse 2026 Roundtable Insights

At Identiverse 2026, Microsoft Security hosted a Power Breakfast bringing together 150 identity professionals across 10 simultaneous roundtable discussions. Participants came from financial services, healthcare, government, and energy sectors, representing every stage of AI adoption. The findings paint a stark picture of the current state of AI agent governance.

Agent Sprawl Is a Present Reality

Nine in ten roundtables described unmanaged agent sprawl not as a future risk, but as a present reality. What started as dozens of agents became tens of thousands in months or even weeks. One participant reported discovering 44,000 agents in their corporate tenant by accident during a demo. No single audit could capture the full picture, and practitioners described finding far more agents than they expected when they finally looked.

Shadow AI and Ownerless Agents

Eight in ten roundtables said shadow AI is already present in their organizations, running across platforms that no single governance layer currently covers. These agents are tracked only through network logs, if tracked at all. Nine in ten raised the ownerless-agent problem: agents get built, tied to their creator’s identity, and keep running long after that person has changed roles or left the organization — unreviewed, over-permissioned, and undetected.

Agent-to-Agent Chains: The Hardest Challenge

Eight in ten roundtables identified agent-to-agent chains as the most difficult security challenge they had encountered. Multiple teams rolled back agent-to-agent deployments after finding they could not maintain consistent governance across the chain. As one participant noted: “I can control point A to point B, but point B needs to talk to point C, and that’s where context was lost.”

Three Actionable Starting Points

Microsoft outlined three practical steps for organizations grappling with agent sprawl:

1. Build your inventory before you do anything else. Start in the Microsoft Entra admin center at Entra ID > Agents > Agents overview to see the total number of agents with identities, how many were recently created, how many are active, and how many are unmanaged. For agents running outside the Microsoft ecosystem, register them using the Agent 365 CLI and SDK or federated identity credentials. You do not need to migrate them — you need to get them into the registry so they are visible and can be governed.

2. Assign an owner and a sponsor to every agent. Every agent identity in Microsoft Entra Agent ID requires a sponsor (the person accountable for what the agent does) and an owner (the person responsible for its technical management). Assign both at creation time, at the blueprint layer. When someone leaves your organization, Microsoft Entra lifecycle workflows can automatically trigger an ownership review for every agent associated with that person.

3. Scope permissions tightly and apply Conditional Access at the blueprint level. Use enumerated scopes on every blueprint: only the specific delegated permissions the agent needs, nothing more. For agents acting on behalf of a user, use the on-behalf-of flow so that user-level access policies apply. For autonomous agents, use the client credentials flow, scoped narrowly. Apply Conditional Access policies at the blueprint level — not agent by agent — so every agent instance created from that blueprint inherits the policy automatically.

Licensing Considerations

Starting in July 2026, agent security capabilities including agent-specific Conditional Access and Identity Protection require Microsoft 365 Agent or M365 E7 licenses. Organizations should confirm their tenant has Agent 365-eligible licenses and that required administrators have them assigned. The Security for AI Agents toggle in Microsoft Defender should be enabled, and SOC teams should update Advanced Hunting queries from the legacy AIAgentInfo table to the new AgentInfo table.

Modernize SAP Identity Management with Microsoft Entra

On July 23, Microsoft published detailed guidance on modernizing SAP identity management with Microsoft Entra, targeting organizations transitioning away from SAP Identity Management (SAP IDM) toward a cloud-native identity platform.

Deepened Integration Capabilities

Over the past two years, Microsoft Entra and SAP have continued to deepen interoperability. The key updates include:

  • More flexible provisioning patterns between Microsoft Entra and SAP Cloud Identity Services, supporting a wider range of deployment models
  • Custom extension attributes on Microsoft Entra users for SAP-specific scenarios, making it easier to align identity data with the needs of SAP applications
  • Account discovery to identify accounts in SAP Cloud Identity Services that are not yet correlated with users in Microsoft Entra, reducing manual investigation and strengthening governance
  • OAuth 2.0 client credentials support to secure service-to-service communication between Microsoft Entra and SAP Cloud Identity Services, replacing older and less secure authentication methods
  • Integration between Entra ID Governance and SAP Identity Access Governance (IAG), allowing organizations to request and govern SAP business roles alongside other access rights through Entra access packages

How the SAP IAG Integration Works

When a user requests assignment to an access package with an SAP business role through Microsoft Entra, the request is sent automatically to SAP Identity Access Governance. SAP IAG then enforces approvals and additional checks within its own governance process. This approach connects enterprise-wide access packages in Entra with the business role and risk context available in SAP IAG, creating a unified governance experience across SAP and non-SAP applications.

This integration matters because access governance often spans applications: employees, contractors, and partners may need coordinated access across SAP and non-SAP resources. Organizations can use the integration to manage those requests consistently.

Customer Success: Cenibra

Cenibra, a cellulose company, used Microsoft Entra ID Governance to modernize identity management across more than 80 systems, including SAP as a core platform. The approach helped reduce manual work, improve audit readiness, and create a more scalable foundation for managing access — demonstrating the practical value of the Entra-SAP integration for complex enterprise environments.

Broader Microsoft Security Context for SAP

Identity establishes the foundation for securing SAP in your security environment. Microsoft delivers additional SAP-aware capabilities aligned with the NIST Cybersecurity Framework:

  • Identify: Microsoft Purview discovers and classifies sensitive SAP data, including data mirrored into Microsoft Fabric through SAP Datasphere
  • Protect: Microsoft Defender safeguards endpoints, servers, and cloud resources surrounding SAP applications
  • Detect: Microsoft Sentinel connects SAP signals to detect incidents with built-in analytics rules in an SAP-certified solution
  • Respond: Microsoft Security Copilot accelerates investigation and guides response for SAP incidents

For organizations evaluating their SAP identity strategy, Microsoft recommends a phased approach:

  1. Perform a SAP identity landscape assessment — Inventory which SAP systems are in scope, what SAP IDM currently manages, and identify authoritative sources feeding SAP IDM
  2. Design your Entra-SAP integration model — Map SAP identity attributes to Entra extension attributes, plan account discovery and reconciliation, and configure OAuth 2.0 client credentials
  3. Integrate Entra ID Governance with SAP IAG — Establish access request workflows in Entra that trigger SAP IAG role assignments, and define the division of responsibilities between the platforms
  4. Plan SAP IDM migration and retirement — Start with coexistence (Entra orchestrates while SAP IDM executes), move to progressive cutover (new provisioning solely through Entra + SAP IAG), and finish with decommissioning
  5. Align with broader Entra and AI security initiatives — Apply Zero Trust principles to SAP access, govern SAP integration service accounts as workload identities, and treat SAP users as part of the same identity perimeter as AI agents and SaaS apps

What This Means for Your Organization

These two announcements reflect Microsoft’s broader strategy of making every identity — whether human, AI agent, or SAP service account — a first-class, governable entity within the Entra identity fabric. For IT administrators, the message is clear: the tools to manage AI agent sprawl and modernize legacy IAM systems like SAP IDM are available now, and the cost of inaction grows with each passing month.

If your organization is deploying AI agents without governance, start with an inventory in the Entra admin center today. If you are running SAP IDM, begin planning your migration path to Entra ID Governance before SAP’s November 2026 basic authentication deprecation for SuccessFactors APIs creates additional pressure.

Follow the conversation on X at https://x.com/kkaminsk for ongoing coverage of Microsoft Entra ID updates and identity security insights.