← All insights

News analysisLens: United States4 min read

Agents make weak IAM fail faster. Microsoft's 2026 Digital Defense Report puts agent identity beside passwords

Microsoft's new threat report says identity is still where attacks start, and the control plane now includes applications and agents. For AI programs, identity hygiene is the first security project.

Listen to this article · 7 min

AI-generated narration of the full article.

A row of metro turnstiles in a bright station, in La Madre duotone, beside the words Identity hygiene first
Photo: rawpixel (CC0)

Every year Microsoft’s Digital Defense Report tells security teams where attacks begin. The 2026 edition, published October 1, gives the familiar answer, identity, and adds something AI program leads should read closely: the identity control plane now spans human and non-human identities, including applications and agents.

That sentence turns an AI rollout into an identity project, whether or not the AI team planned one.

What the report says

The numbers Microsoft highlights are about ordinary attacks done at scale:

  • 52.2% of intrusions using valid accounts involved follow-on credential theft.
  • Exposed cloud workloads were attacked on average 5.3 hours after exposure.
  • More than 145 million QR-code phishing attacks were detected between July 2025 and June 2026, and more than 46 million business email impersonation attacks over the past 12 months.

On AI, the report is measured. Threat actors use it in reconnaissance, social engineering, malware and exploit development and post-compromise activity, mostly to speed up parts of existing workflows rather than to invent new ones. Defenders use it to bring information together and automate repeatable tasks. On agents, the report lists the questions security teams now own: agent identity, appropriate access, authentication between agents, attribution and the ability to revoke access, alongside prompt injection, memory, models and data.

The recommendations would fit any year: phishing-resistant MFA and passkeys, disciplined identity hygiene, tiered administration, strong privileged-access enforcement, and less oversharing of data in AI environments. Microsoft also asks organizations to govern agent identity before AI systems outnumber the people they work for.

The authors are careful not to turn general cyber statistics into agent statistics, and we will not either. The numbers above describe attacks on identities in general. The link to agents is structural: every agent adds identities and credentials to the same plane attackers already work.

Why agents amplify weak identity

Agents multiply credentials. Each agent needs a way to call tools, read data and sometimes act. Teams under pressure create a service principal, give it broad rights “for the pilot” and store a secret that never expires. That is exactly the kind of access the report says attackers exploit.

Agents act at machine speed. A stolen human password is used by a person, one session at a time. A compromised agent credential is used by software, or the agent itself acts on a poisoned instruction, across every system its rights reach.

Agents blur attribution. If an agent acts with a shared identity, or with a user’s full delegated rights, the logs cannot say who decided what. The report’s own list includes attribution and revocation for a reason.

The containment lessons from this year’s lab incidents point the same way: the agents in those cases used leaked credentials and open paths that ordinary hygiene would have closed.

An agent's identity, from request to revocationCREATECONSTRAINOPERATE01Namedhumansponsor02Ownidentityperagent03Short-lived,scopedcredentials04Conditionalaccessand datalimits05Activitymonitoredin theSIEM06Periodicaccessreview07RevocationonchangeorincidentAccountabilityLeast privilege
  1. Named human sponsor
  2. Own identity per agent
  3. Short-lived, scoped credentials
  4. Conditional access and data limits
  5. Activity monitored in the SIEM
  6. Periodic access review
  7. Revocation on change or incident
  • Create: Named human sponsor · Own identity per agent
  • Constrain: Short-lived, scoped credentials · Conditional access and data limits
  • Operate: Activity monitored in the SIEM · Periodic access review · Revocation on change or incident

AccountabilityLeast privilege

The same lifecycle a privileged employee account gets, applied to every agent before it reaches production.

What this means in a Microsoft environment

Most enterprises reading this report run Entra ID, so the controls are already on the shelf. The work is applying them to agents with the same discipline as to admins:

  • Give agents their own identities. Entra Agent ID registers agents as identities with sponsors, instead of hiding them behind app registrations with shared secrets.
  • Apply Conditional Access to workload identities, so an agent’s credential used from an unexpected location or network is blocked, not just logged.
  • Prefer managed identities and certificates over client secrets, and set short lifetimes where secrets are unavoidable.
  • Limit what agents can read. Sensitivity labels and oversharing reviews in Purview matter more when an agent can summarize everything a user can open.
  • Route agent activity to Sentinel with the agent identity as a first-class entity, so an investigation can follow one agent across systems.

None of this is AI-specific technology. That is the report’s point. We argued in our analysis of the control layer forming around the agent that every production agent needs a file with an identity, a sponsor, an allowed route, a budget and a record of actions. Microsoft’s report reads like the security case for that file.

For U.S. public companies there is also a disclosure angle. Under the SEC’s cybersecurity rules, a material incident must be reported on Form 8-K within four business days of determining materiality. An incident that runs through an over-privileged agent will be hard to assess quickly if nobody can say what the agent could reach.

What to do now

  1. Inventory every non-human identity used by AI: app registrations, service principals, API keys, MCP server credentials. Name an owner for each.
  2. Remove standing broad access. Replace “pilot” rights with scoped permissions per agent and per task.
  3. Rotate or replace long-lived secrets with managed identities, certificates or short-lived tokens.
  4. Turn on Conditional Access for workload identities and alert on agent sign-ins outside expected patterns.
  5. Add agents to access reviews on the same cycle as privileged human accounts.
  6. Rehearse revocation: how fast can you disable one agent everywhere it has access?

The bottom line

Microsoft’s report does not say AI changed the attacker’s playbook. It says the playbook still starts with identity, and that agents are now part of the identity estate. The fastest way to make agents safer is to make IAM boring and complete again, before the number of agents makes that impossible.

Have an AI use case stuck between prototype and production?

Tell us what you’re trying to ship. We’ll reply with honest next steps.

Discuss a use case