Independent preview planner · Source checked August 12, 2026

Is the Dataverse agent identity pilot bounded enough?

Prepare a non-production evaluation without connecting to Microsoft. This checklist does not provision identity, authorize data access, inspect audit events, or override public-preview restrictions.

Preview readiness checks

Planning result

Complete the checks

Select only controls backed by current configuration and test evidence.

  • Start with one non-production environment and one bounded business process.
  • Create the narrow Dataverse role before granting the agent access.
  • Prove denied operations, attribution, revocation, and retirement.
  • Recheck preview, region, licensing, and terms before every adoption decision.

Quick answer

Identity is the start, not the authorization decision

The Entra agent identity identifies and governs the nonhuman actor. The Dataverse agent user supplies a security principal inside one environment. A purpose-built role determines the data and operations it may use.

The optional agent's user account solves a different need: access to systems that require a user identity. It remains restricted and is not a normal employee or privileged administrator account.

Successful access is insufficient evidence. The preview evaluation must prove denied tables, fields, operations, environments, and actions after disablement, while preserving traceable audit records.

A hard-stop result means production depends on preview, role scope is broad, or identity provisioning is overstated. Correct the plan before adding the agent to Dataverse.

Dataverse agent identity questions

No. It runs locally and does not connect to a tenant or environment, create an agent identity or user, assign a role, issue a token, inspect audit logs, or validate preview eligibility.
Microsoft labels it public preview and states that preview features are not meant for production and may have restricted functionality. Recheck current status, region, licensing, documentation, and terms.
No. It is a restricted nonhuman user linked one-to-one to a parent agent identity, with no password or passkey and no privileged administrator roles. Provisioning paths and licenses determine supported capabilities.

Official references: Microsoft preview announcement, Dataverse agent-user documentation, and Entra agent-user documentation.