Microsoft · Microsoft Entra

Conditional Access Optimization Agent

A Security Copilot agent in Microsoft Entra that continuously scans a tenant's Conditional Access configuration for coverage gaps, overlapping policies and exceptions, and produces policy suggestions. Where an administrator has enabled the corresponding setting, the agent creates new Conditional Access policies in report-only mode; it does not change existing policies or turn any policy on without explicit administrator approval.

Recorded characteristics

Function
Scans all Conditional Access policies in the tenant plus new users, applications and agent identities from the previous 24 hours, checks for coverage gaps and consolidation opportunities, reviews previous suggestions to avoid repeats, applies administrator custom instructions and knowledge-base guidance, and then either creates a new Conditional Access policy in report-only mode (only where the corresponding agent capability is enabled) or raises a suggestion to modify an existing policy. Documented suggestion scenarios include requiring multifactor authentication, enforcing device-based controls (device compliance, app protection policies, domain-joined devices), blocking legacy authentication, blocking device code flow, risky users, risky sign-ins, risky agents, agent-assisted flows (preview), policy consolidation, deep analysis including MFA gap analysis, and least-privileged access for agent identities (preview). The agent also creates policy review reports (preview) highlighting spikes or dips that may indicate misconfiguration, and can generate phased rollout plans for eligible report-only policies.
Data access
Conditional Access policies in the tenant (enabled and report-only); new users, applications and agent identities from the previous 24-hour window; groups, roles and group membership; users, licence assignment and custom security attribute assignment; audit logs; sign-in activity used for policy impact and phased rollout planning; Intune device compliance and application protection policy configuration; Global Secure Access (Microsoft Entra Internet Access and Private Access) network access configuration; Microsoft Defender threat insights, which provide threat context only and no remediation logic; Microsoft Graph permission usage on agent identities for the least-privileged access suggestions (preview); the administrator's custom instructions; an uploaded organisational knowledge-base document (single Word .docx or PDF); and the agent's own previous suggestions. The agent identity's assigned Microsoft Graph permissions are read-only apart from Policy.Create.ConditionalAccessRO.
Actions
Can take actions
External actions
Conditional
Human confirmation
Conditional
Permission basis
Dedicated agent identity
Administrative control
Activation requires the Security Administrator role for the first run; Conditional Access Administrator and Security Administrator can view and act on suggestions, while Security Reader and Global Reader can view only. Settings cover: the daily automatic run; activity-based runs (preview, enabled by default for new tenants, opt in for existing tenants, five-minute change detection with a documented cooldown); which Microsoft Entra objects to monitor (new users and applications by default); the agent capability that allows the agent to create report-only policies, which is off by default; phased rollout, on by default; Microsoft Teams notifications to up to ten recipients, one-way only; a knowledge base of a single uploaded Word or PDF document; custom instructions that include or exclude specific users, groups and roles, exclude objects from agent consideration and apply policy exceptions such as excluding break-glass accounts; the Intune and Global Secure Access built-in integrations; the ServiceNow plugin integration (preview); and the agent identity, created and managed by a Security Administrator with permissions assigned automatically. Per-suggestion controls include Review suggestion, Review policy changes with summary and JSON views, Policy impact visualisation, View agent's full activity, Turn on policy, Mark suggestion as reviewed, Snooze for 14 days, notes for other administrators, and edit, duplicate, download or delete of the suggested policy. Removing the agent deletes agent activity, suggestions and metrics, while policies created or updated from its suggestions remain intact.
Default state
Disabled
Availability
Generally available in the Microsoft Entra admin center as a Microsoft Security Copilot agent for Microsoft Entra; Microsoft does not label the core agent as preview. The following components are documented as preview: the ServiceNow integration, activity-based runs, policy review reports, agent-assisted flows suggestions, and least-privileged access suggestions for agent identities. Intune integration requires the agent to run as Global Administrator or Conditional Access Administrator together with Global Reader. Microsoft does not document cloud or geographic restrictions for this agent.
Licensing
Requires at least a Microsoft Entra ID P1 licence and available Security Compute Units; Microsoft states each agent run consumes less than one SCU on average, that Security Copilot requires at least one provisioned SCU billed monthly, and that turning the agent off does not stop that monthly billing. Risky users, risky sign-ins, risky agents and agent-assisted flows suggestions require Microsoft Entra ID P2. Device-based controls require Microsoft Intune licences. Using the agent also requires Security Copilot access, which Security Administrator has by default and which can be assigned to Conditional Access Administrators.
External model or provider
Not established
Limitations and uncertainty
The agent creates Conditional Access policy objects but does not enforce access with them: all new policies it creates are in report-only mode, and an administrator must review the impact and explicitly turn a policy on. Microsoft states the agent makes no changes to existing policies unless an administrator explicitly approves the suggestion. Policy creation authority is off by default; with it disabled the administrator receives the suggestion and details but must approve creation of the report-only policy. Phased rollout is administrator-executed: the administrator reviews, edits and accepts the plan and starts the rollout, after which a new policy is created and turned on for the first phase groups while the original report-only policy remains intact; a tenant needs at least five groups already used in Conditional Access for a plan to be generated. Documented run limits: scanning is limited to a 24-hour period, up to 300 users and 150 applications per run, 40 similar policy pairs per run for consolidation, two policies can be consolidated only if they differ by no more than two conditions or controls, and a run cannot be stopped or paused once started. Suggestions cannot be customised or overridden. MFA gap analysis evaluates MFA only and does not count report-only policies as coverage. The ServiceNow integration is preview: whether a state-changing action outside Microsoft occurs depends on the organisation configuring the ServiceNow plugin and enabling the integration, so external action capability is recorded as conditional rather than yes. Runtime identity: new installations default to a Microsoft Entra Agent ID agent identity and agents activated after 17 November 2025 no longer use the identity of the activating user; installations predating that can still run under the original user context until migrated, and the migration cannot be reversed. The agent identity's documented permission list includes only Policy.Create.ConditionalAccessRO as a write permission, so how approved modifications to existing policies are executed is not fully established. Microsoft does not identify the model or provider used by this agent.

Evidence