Protego field desk
Security Operations, Identity and Compliance / 25-30% of exam

L7.Identity, Access & Agent Identity Architecture

Course outlineLesson 7 of 18

Design modern access across workforce, external, workload, and agent identities using explicit trust, Conditional Access, continuous evaluation, and protected actions.

Treat identity as a control plane

Design Microsoft Entra ID for workforce, partner, application, hybrid, and multicloud access. Define authoritative identity sources, lifecycle events, authentication strength, recovery, and monitoring before assigning resource permissions.

Modernize authentication and authorization

Prefer phishing-resistant authentication for privileged and high-risk users. Conditional Access combines identity, device, location, application, and risk signals. Continuous access evaluation can react to critical events during a session. Protected actions add stronger policy to sensitive administrative operations.

Design external and decentralized identity

For B2B access, decide who can invite guests, which partner trust settings apply, how access is reviewed, and how it is removed. Decentralized identity can support verifiable claims, but resource authorization still belongs to the relying service.

Govern agent identities

Microsoft Entra Agent ID provides identities for agents. Separate an agent's identity from its human sponsor and from the identities of tools it invokes. Apply Conditional Access where supported, narrow permissions, short-lived credentials, owner accountability, and monitoring for unusual actions.

Harden legacy identity

Active Directory Domain Services still requires tiered administration, protected credentials, secure domain controllers, patching, monitoring, and recovery. Hybrid identity connects two control planes, so compromise paths must be evaluated in both directions.

Exam Focus Points
  • Design identity lifecycle before resource authorization
  • Conditional Access evaluates signals; continuous access evaluation reacts during sessions
  • B2B governance includes invitation, trust, review, and removal
  • Agent identities need separate ownership, narrow permissions, and behavioral monitoring
Knowledge Check

1. Why should an AI agent have its own managed identity instead of sharing its sponsor's account?