Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

Microsoft Foundry Agent Permission Governance: OBO, RBAC, and Approval Boundaries

The previous article, Microsoft Foundry Agent Identity Governance: Agent Identities, Blueprints, and Managed Identities mapped the relationships among User Identity, Agent Identity, Agent Identity Blueprint, and Project Managed Identity. This article turns that identity model into a permission ledger, a publish-time migration plan, and a set of negative tests. It uses one scenario to answer three…

This article explores Microsoft Foundry Agent permission governance, focusing on On-Behalf-Of (OBO) and Agent Identity. It uses a customer meeting preparation scenario to illustrate practical questions regarding when to use OBO versus Agent Identity, why an agent might suddenly return a 403 error after publication, and why high-risk tools still require approval even with RBAC in place.

The article introduces a permission ledger, a publish-time migration plan, and a set of negative tests. It outlines a scenario where a sales team wants an agent to help prepare for a meeting by reading the user's email, calendar events, and documents, generating a team summary, and sending it to attendees or updating a CRM record.

The article emphasizes the importance of defining permission boundaries before configuring tools, with six key fields: principal, resource, action, scope, approval, and audit. It highlights that not all tools support every authentication method, so it's crucial to check the tool documentation and connection authentication type during implementation.

Two paths are presented for handling the user boundary: preserving the user boundary when the user is present and using an independent agent identity for background work. The former involves OBO authentication, where the agent acts for the user, constrained by delegated scopes, user consent, and downstream authorization. The latter uses Agent Identity for background tasks, receiving only the necessary permissions for the task.

For OBO authentication, the article provides an example of how a salesperson should not gain access to another user's private email through the agent. For Agent Identity authentication, it explains how to set up a blueprint using a Project Managed Identity and Agent Identity token exchange, assigning the appropriate RBAC role to the Agent Identity.

The article concludes by emphasizing the need to record approval requirements and audit trails for every new action and to verify the authentication methods supported by each tool. By following these guidelines, organizations can create a more secure and manageable permission governance system using Microsoft Foundry Agents.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Donald Trump's Latin America allies open arms to Israel

While the ongoing military actions in Gaza and settler attacks on Palestinians in the West Bank have largely isolated Israel globally, Latin America's authoritarian right sees an opening for a…

  • Venezuela's Hugo Chavez expelled Israel's ambassador in 2009 over Gaza offensive
  • Colombia reversed expulsion after 2023 Gaza war, relocating embassy to Jerusalem
  • Latin America strengthening ties with Israel amid radical right rise and shared interests

More from Saturday 15 August →