Conditional Access Optimization Agent
A Security Copilot agent in Microsoft Entra that continuously scans a tenant's Conditional Access configuration for coverage gaps, overlapping policies and exceptions, and produces policy suggestions. Where an administrator has enabled the corresponding setting, the agent creates new Conditional Access policies in report-only mode; it does not change existing policies or turn any policy on without explicit administrator approval.
Recorded characteristics
- Function
- Scans all Conditional Access policies in the tenant plus new users, applications and agent identities from the previous 24 hours, checks for coverage gaps and consolidation opportunities, reviews previous suggestions to avoid repeats, applies administrator custom instructions and knowledge-base guidance, and then either creates a new Conditional Access policy in report-only mode (only where the corresponding agent capability is enabled) or raises a suggestion to modify an existing policy. Documented suggestion scenarios include requiring multifactor authentication, enforcing device-based controls (device compliance, app protection policies, domain-joined devices), blocking legacy authentication, blocking device code flow, risky users, risky sign-ins, risky agents, agent-assisted flows (preview), policy consolidation, deep analysis including MFA gap analysis, and least-privileged access for agent identities (preview). The agent also creates policy review reports (preview) highlighting spikes or dips that may indicate misconfiguration, and can generate phased rollout plans for eligible report-only policies.
- Data access
- Conditional Access policies in the tenant (enabled and report-only); new users, applications and agent identities from the previous 24-hour window; groups, roles and group membership; users, licence assignment and custom security attribute assignment; audit logs; sign-in activity used for policy impact and phased rollout planning; Intune device compliance and application protection policy configuration; Global Secure Access (Microsoft Entra Internet Access and Private Access) network access configuration; Microsoft Defender threat insights, which provide threat context only and no remediation logic; Microsoft Graph permission usage on agent identities for the least-privileged access suggestions (preview); the administrator's custom instructions; an uploaded organisational knowledge-base document (single Word .docx or PDF); and the agent's own previous suggestions. The agent identity's assigned Microsoft Graph permissions are read-only apart from Policy.Create.ConditionalAccessRO.
- Actions
- Can take actions
- External actions
- Conditional
- Human confirmation
- Conditional
- Permission basis
- Dedicated agent identity
- Administrative control
- Activation requires the Security Administrator role for the first run; Conditional Access Administrator and Security Administrator can view and act on suggestions, while Security Reader and Global Reader can view only. Settings cover: the daily automatic run; activity-based runs (preview, enabled by default for new tenants, opt in for existing tenants, five-minute change detection with a documented cooldown); which Microsoft Entra objects to monitor (new users and applications by default); the agent capability that allows the agent to create report-only policies, which is off by default; phased rollout, on by default; Microsoft Teams notifications to up to ten recipients, one-way only; a knowledge base of a single uploaded Word or PDF document; custom instructions that include or exclude specific users, groups and roles, exclude objects from agent consideration and apply policy exceptions such as excluding break-glass accounts; the Intune and Global Secure Access built-in integrations; the ServiceNow plugin integration (preview); and the agent identity, created and managed by a Security Administrator with permissions assigned automatically. Per-suggestion controls include Review suggestion, Review policy changes with summary and JSON views, Policy impact visualisation, View agent's full activity, Turn on policy, Mark suggestion as reviewed, Snooze for 14 days, notes for other administrators, and edit, duplicate, download or delete of the suggested policy. Removing the agent deletes agent activity, suggestions and metrics, while policies created or updated from its suggestions remain intact.
- Default state
- Disabled
- Availability
- Generally available in the Microsoft Entra admin center as a Microsoft Security Copilot agent for Microsoft Entra; Microsoft does not label the core agent as preview. The following components are documented as preview: the ServiceNow integration, activity-based runs, policy review reports, agent-assisted flows suggestions, and least-privileged access suggestions for agent identities. Intune integration requires the agent to run as Global Administrator or Conditional Access Administrator together with Global Reader. Microsoft does not document cloud or geographic restrictions for this agent.
- Licensing
- Requires at least a Microsoft Entra ID P1 licence and available Security Compute Units; Microsoft states each agent run consumes less than one SCU on average, that Security Copilot requires at least one provisioned SCU billed monthly, and that turning the agent off does not stop that monthly billing. Risky users, risky sign-ins, risky agents and agent-assisted flows suggestions require Microsoft Entra ID P2. Device-based controls require Microsoft Intune licences. Using the agent also requires Security Copilot access, which Security Administrator has by default and which can be assigned to Conditional Access Administrators.
- External model or provider
- Not established
- Limitations and uncertainty
- The agent creates Conditional Access policy objects but does not enforce access with them: all new policies it creates are in report-only mode, and an administrator must review the impact and explicitly turn a policy on. Microsoft states the agent makes no changes to existing policies unless an administrator explicitly approves the suggestion. Policy creation authority is off by default; with it disabled the administrator receives the suggestion and details but must approve creation of the report-only policy. Phased rollout is administrator-executed: the administrator reviews, edits and accepts the plan and starts the rollout, after which a new policy is created and turned on for the first phase groups while the original report-only policy remains intact; a tenant needs at least five groups already used in Conditional Access for a plan to be generated. Documented run limits: scanning is limited to a 24-hour period, up to 300 users and 150 applications per run, 40 similar policy pairs per run for consolidation, two policies can be consolidated only if they differ by no more than two conditions or controls, and a run cannot be stopped or paused once started. Suggestions cannot be customised or overridden. MFA gap analysis evaluates MFA only and does not count report-only policies as coverage. The ServiceNow integration is preview: whether a state-changing action outside Microsoft occurs depends on the organisation configuring the ServiceNow plugin and enabling the integration, so external action capability is recorded as conditional rather than yes. Runtime identity: new installations default to a Microsoft Entra Agent ID agent identity and agents activated after 17 November 2025 no longer use the identity of the activating user; installations predating that can still run under the original user context until migrated, and the migration cannot be reversed. The agent identity's documented permission list includes only Policy.Create.ConditionalAccessRO as a write permission, so how approved modifications to existing policies are executed is not fully established. Microsoft does not identify the model or provider used by this agent.
Evidence
- Microsoft Entra Conditional Access Optimization Agent
Supports: Function · Data access · Actions · External actions · Human confirmation · Permission basis · Admin controls · Default state · Availability · Licensing · External model · Limitations · Primary source
"The agent can recommend new policies and update existing policies, based on best practices aligned with Zero Trust." Each run scans all Conditional Access policies, checks for policy gaps and consolidation opportunities, reviews previous suggestions, evaluates custom instructions, and then "creates a new policy in report-only mode or provides the suggestion to modify a policy". Documented scenarios: Require MFA, require device-based controls, block legacy authentication, block device code flow, risky users, risky sign-ins, risky agents, agent-assisted flows (preview), policy consolidation, deep analysis, deep analysis MFA gap analysis, and least-privileged access for agent identities (preview). It also creates policy review reports (preview).
Scans the tenant for new users, applications and agent identities from the last 24 hours and scans all Conditional Access policies; Intune integration monitors device compliance and application protection policies; Global Secure Access integration covers network locations and protected applications; Microsoft Defender supplies threat insights as context only, with no remediation logic.
"The agent creates a new policy in report-only mode or provides the suggestion to modify a policy." "The agent doesn't make any changes to existing policies unless an administrator explicitly approves the suggestion. All new policies that the agent suggests are created in report-only mode." When a suggestion is identified, the associated policy can be updated with one-click remediation by the administrator.
Documented built-in integrations (Intune, Global Secure Access, Microsoft Defender) supply signal to the agent; no state-changing action outside Microsoft is described on the capability overview page.
"The agent doesn't make any changes to existing policies unless an administrator explicitly approves the suggestion." All new policies the agent creates are in report-only mode.
A Conditional Access Optimization Agent activated after 17 November 2025 no longer uses the identity of the user who activated it; earlier installations that used a PIM-dependent account can fail and are resolved by migrating to Microsoft Entra Agent ID.
Configurable settings listed: automatic runs every 24 hours, activity-based runs (preview), objects to check for changes, allowing the agent to create report-only policies, Microsoft Teams notifications, phased rollout plans, ServiceNow integration, and knowledge sources. Removing the agent deletes agent activity, suggestions and metrics while previously created or updated policies remain intact.
A Security Administrator role is required to activate the agent the first time, and the administrator selects Start agent to begin the first run.
The ServiceNow integration and activity-based runs are currently in preview; policy review reports, agent-assisted flows suggestions and least-privileged access suggestions for agent identities are also marked preview. The core agent is documented in the Microsoft Entra admin center without a preview label. Intune suggestions require the agent to run as Global Administrator or Conditional Access Administrator and Global Reader.
At least Microsoft Entra ID P1; available security compute units, with each run consuming less than one SCU on average; Security Copilot requires at least one provisioned SCU billed monthly even if unused, and turning the agent off does not stop that billing; risk-based and agent-assisted flow suggestions require Microsoft Entra ID P2; device-based controls require Microsoft Intune licences.
No model or provider is identified for this agent in Microsoft's documentation.
Once started a run cannot be stopped or paused; policy consolidation evaluates 40 similar policy pairs per run and two policies can be consolidated only if they differ by no more than two conditions or controls; scanning is limited to a 24-hour period; suggestions cannot be customised or overridden; up to 300 users and 150 applications per run.
- Review and apply suggestions from the Conditional Access Optimization Agent
Supports: Function · Actions · Human confirmation · Admin controls · Availability · Limitations · Primary source
The agent might run and: not identify any unprotected users, create a new Conditional Access policy in report-only mode, suggest modifying an existing policy, suggest consolidating overlapping policies, or identify a spike or dip in activity related to an existing policy.
Administrator actions on a suggestion include Turn on policy for agent-created report-only policies, Review policy changes for existing-policy modifications, Mark suggestion as reviewed, Snooze for 14 days, add notes, and edit, duplicate, download or delete the suggested policy.
Administrators review suggestions, reasoning, policy impact and full agent activity, and choose whether to turn on a policy or apply a modification; Defender-linked recommendations are always reviewed and approved by an administrator before any policy change takes effect.
Role split: Security Reader and Global Reader can view the agent and suggestions but take no action; Conditional Access Administrator and Security Administrator can view and act; Security Administrator can view and act on Microsoft Defender alerts in the Defender portal. Per-suggestion review tooling includes JSON and summary policy change views, policy impact graphs, downloadable affected user and application lists, and full agent activity.
Prerequisites restated: Microsoft Entra ID P1 licence, available Security Compute Units, and appropriate Microsoft Entra roles; ServiceNow integration and least-privileged access suggestions for agent identities are in preview.
MFA gap analysis evaluates MFA only, does not count report-only policies as coverage, samples uncovered users above 100, and can duplicate standard suggestions; deep analysis suggestions may have significant environmental impact, so Microsoft recommends snoozing and annotating them.
- Conditional Access Optimization Agent Settings
Supports: Data access · Actions · External actions · Human confirmation · Permission basis · Admin controls · Default state · Limitations · Primary source
The agent identity is automatically assigned AuditLog.Read.All, CustomSecAttributeAssignment.Read.All, DeviceManagementApps.Read.All, DeviceManagementConfiguration.Read.All, GroupMember.Read.All, LicenseAssignment.Read.All, NetworkAccess.Read.All, Policy.Create.ConditionalAccessRO, Policy.Read.All, RoleManagement.Read.Directory and User.Read.All. Custom instructions can reference specific users, groups and roles by name or object ID.
By default the agent cannot create new policies even in report-only mode; with the setting enabled it creates report-only policies on the organisation's behalf and an administrator must still approve before the policy is turned on. With the setting disabled, the administrator receives the suggestion and details but must manually approve before the report-only policy is created. When the ServiceNow plugin is turned on, each new suggestion creates a ServiceNow change request and the agent monitors its state and can automatically implement the change once the change request is approved.
ServiceNow integration (preview): with the ServiceNow plugin for Security Copilot configured and the integration turned on, each new suggestion creates a ServiceNow change request (CHG only) containing the policy type, affected users or groups and rationale; the agent monitors the change request state and can automatically implement the change when it is approved. This external action is contingent on optional configuration, so external action capability is recorded as conditional.
With the report-only creation capability enabled, the agent creates the policy without per-policy approval but "an administrator must approve the new report-only policy before it's turned on"; with it disabled, the administrator must manually approve before any policy is created. Approval therefore varies by configuration and by action type.
"New installations of the agent default to use an agent identity." Existing installations can switch from user context to an agent identity at any time and cannot switch back; a Security Administrator creates the identity and the listed Microsoft Graph permissions are assigned automatically.
Settings are reached from Agents or from the Conditional Access policy summary card. They include scheduled and activity-based triggers with documented cooldowns and new-versus-existing tenant defaults, Microsoft Entra objects to monitor, the agent capability for report-only policy creation (off by default), phased rollout (on by default), Teams notifications limited to ten recipients and five objects with one-way communication, knowledge source files, custom instructions, the ServiceNow plugin, and agent identity and permission management. The least-privileged role needed to use the agent is Conditional Access Administrator.
"By default, the Conditional Access Optimization Agent can't create new policies, even in report-only mode." The administrator must change this setting for the agent to create report-only policies.
Activity-based runs (preview) are detected every five minutes with a documented cooldown between runs and do not replace the daily run; Teams notifications are one-way and capped; ServiceNow support is limited to change requests (CHG) and requires the ServiceNow plugin; migration from user context to agent identity is irreversible.
- Conditional Access Optimization Agent knowledge base
Supports: Data access · Admin controls · Primary source
A single Word (.docx) or PDF document describing organisational Conditional Access standards is parsed by the agent, which generates a natural-language summary of its understanding; the approved understanding applies to future recommendations and existing recommendations are not modified retroactively.
Administrators upload a single organisational standards document, may start from a downloadable template, and the agent's natural-language understanding of it is approved before being applied to future recommendations.
- Conditional Access Optimization Agent phased rollout
Supports: Actions · Human confirmation · Admin controls · Limitations · Primary source
When the first phase of an accepted rollout plan starts, a new policy is created and turned on for the groups in that phase, while the original report-only policy remains intact; the administrator starts, advances, pauses, rolls back or completes the rollout.
The phased rollout process is: agent identifies an eligible report-only policy, administrator reviews, edits and accepts the rollout plan, administrator executes the approved plan.
Conditional Access Administrator and Security Administrator can modify phased rollout settings; administrators can edit the groups in each phase, pause the rollout, roll back to a previous phase or mark the rollout complete at any time.
A phased rollout plan requires at least five groups already used in Conditional Access policies, and only report-only policies that apply to all users are eligible.