About this integration
Manage Entra agent identity blueprints, agent users, and federated credentials via Microsoft Graph. Connect it to any workflow without writing code.
You can choose from 3 triggers, 10 search modules and 21 actions. The connection type is oauth or oauth authentication.
How to connect
The credential form asks for Microsoft - Tenant, Microsoft - Client ID, Microsoft - Client Secret, and Microsoft - Tenant.
OAuth asks you to approve AgentIdentity.Read.All, AgentIdentity.ReadWrite.All, and AgentIdentity.EnableDisable.All before access is granted.
Sign in and approve access — your password is never shared with WEXTL®, and you can revoke access from the provider at any time.
You’ll be redirected to sign in and approve access — your password is never shared with WEXTL.
You’ll be redirected to sign in and approve access — your password is never shared with WEXTL.
Connecting Microsoft Entra Agent ID to WEXTL®
| Field | Type | Help |
|---|---|---|
Microsoft - TenantRequired | select | Go to |
Microsoft - Client IDRequired | text | Go to the Microsoft Entra admin center → Entra ID → App registrations and select New registration. → enter a description and expiration → Add, then immediately copy your Client ID |
Microsoft - Client SecretRequired | password | Copy you client Secret from the previously created app |
- AgentIdentity.Read.All
- AgentIdentity.ReadWrite.All
- AgentIdentity.EnableDisable.All
- AgentIdentity.DeleteRestore.All
- AgentIdentityBlueprint.Read.All
- AgentIdentityBlueprint.ReadWrite.All
- AgentIdentityBlueprint.Create
- AgentIdUser.ReadWrite.All
- AgentCard.Read.All
- AgentCard.ReadWrite.All
- AgentCardManifest.Read.All
- AgentCardManifest.ReadWrite.All
- AgentCollection.Read.All
- AgentCollection.ReadWrite.All
- AgentInstance.Read.All
- AgentInstance.ReadWrite.All
- AgentRegistration.Read.All
- AgentRegistration.ReadWrite.All
| Field | Type | Help |
|---|---|---|
Microsoft - TenantRequired | select | Go to |
Microsoft - Client IDRequired | text | Register your application in the Microsoft Entra admin center, then copy the Application (client) ID from the app's Overview page |
Microsoft - Client SecretRequired | password | In your app registration, go to Certificates & secrets → Client secrets, create a new client secret, and copy its value immediately after it's generated. |
- AgentIdentity.Read.All
- AgentIdentity.ReadWrite.All
- AgentIdentity.EnableDisable.All
- AgentIdentity.DeleteRestore.All
- AgentIdentityBlueprint.Read.All
- AgentIdentityBlueprint.ReadWrite.All
- AgentIdentityBlueprint.Create
- AgentIdUser.ReadWrite.All
- AgentCard.Read.All
- AgentCard.ReadWrite.All
- AgentCardManifest.Read.All
- AgentCardManifest.ReadWrite.All
- AgentCollection.Read.All
- AgentCollection.ReadWrite.All
- AgentInstance.Read.All
- AgentInstance.ReadWrite.All
- AgentRegistration.Read.All
- AgentRegistration.ReadWrite.All
Use it in workflow automation
Start with Watch Agent Blueprints, then add Add an Agent Blueprint Key.
The canvas below runs Watch Agent Blueprints into Add an Agent Blueprint Key — watch the video, then drop a node onto the canvas.
Select the Watch Agent Identity Blueprints Principal trigger and the workflow fires automatically when the event occurs — no polling required.
Then add Add an Agent Blueprint Key as the next node. Branch, filter, or hand off to other integrations from there.
The integration includes 24 ready-made modules for developer tools work — each run logs its inputs and outputs for debugging.
Microsoft Entra Agent ID workflow on the canvas: Watch Agent Identity Blueprints Principal then Add an Agent Blueprint Key
Triggers, searches and actions
Explore the fields available for each Microsoft Entra Agent ID trigger, search, and action — 3 triggers, 10 searchs, and 21 actions.
Triggers
Whenever something changes in the app, one of 3 available triggers can start a run immediately.
- Watch Agent Blueprints
- Watch Agent Identity Blueprints Principal
- Watch Agent User
Searches
10 search modules let you query the app mid-run and feed the results to the next step.
- List Agent Blueprints
- List Agent Identity Blueprints Principal
- List Agent User
- List App Role Assignment
- List App Roles Assigned
Actions
Use 21 action modules to write data back into the app from anywhere in a run.
- Add an Agent Blueprint Key
- Add an Agent Blueprint Password
- Add App Role Assignment
- Assign App Role
- Create a Federated Identity Credential
Explore the fields available for each Microsoft Entra Agent ID trigger, search, and action.
Triggers
| Field | Type |
|---|---|
@odata type | text |
ID | text |
App ID | text |
Identifier uris | array |
Created by app ID | text |
Created date time | date |
Description | text |
Disabled by microsoft status | text |
Display name | text |
Group membership claims | text |
Publisher domain | text |
Sign in audience | text |
Tags | array |
Token encryption key ID | text |
Unique name | text |
Service management reference | text |
Optional claims | text |
API | object |
Requested access token version | number |
Accept mapped claims | text |
Known client applications | array |
Oauth 2permission scopes | array |
Pre authorized applications | array |
Token encryption setting | object |
App roles | array |
Info | object |
Terms of service URL | url |
Support URL | url |
Privacy statement URL | url |
Marketing URL | url |
Logo URL | url |
| Field | Type |
|---|---|
@odata type | text |
ID | text |
App ID | text |
Created date time | date |
Created by app ID | text |
Account enabled | boolean |
App display name | text |
App owner organization ID | text |
App role assignment required | boolean |
App roles | array |
Disabled by microsoft status | text |
Info | object |
Terms of service URL | url |
Support URL | url |
Privacy statement URL | url |
Marketing URL | url |
Logo URL | url |
Oauth 2permission scopes | array |
Service principal type | text |
Tags | array |
Verified publisher | text |
| Field | Type |
|---|---|
@odata type | text |
ID | text |
App ID | text |
Created date time | date |
Created by app ID | text |
Account enabled | boolean |
App display name | text |
App owner organization ID | text |
App role assignment required | boolean |
App roles | array |
Disabled by microsoft status | text |
Info | object |
Terms of service URL | url |
Support URL | url |
Privacy statement URL | url |
Marketing URL | url |
Logo URL | url |
Oauth 2permission scopes | array |
Service principal type | text |
Tags | array |
Verified publisher | text |
Searches
| Field | Type |
|---|---|
Limit | number |
| Field | Type |
|---|---|
@odata type | text |
ID | text |
App ID | text |
Identifier uris | array |
Created by app ID | text |
Created date time | date |
Description | text |
Disabled by microsoft status | text |
Display name | text |
Group membership claims | text |
Publisher domain | text |
Sign in audience | text |
Tags | array |
Token encryption key ID | text |
Unique name | text |
Service management reference | text |
Optional claims | text |
API | object |
Requested access token version | number |
Accept mapped claims | text |
Known client applications | array |
Oauth 2permission scopes | array |
Pre authorized applications | array |
Token encryption setting | object |
App roles | array |
Info | object |
Terms of service URL | url |
Support URL | url |
Privacy statement URL | url |
Marketing URL | url |
Logo URL | url |
| Field | Type |
|---|---|
Limit | number |
| Field | Type |
|---|---|
@odata type | text |
ID | text |
App ID | text |
Created date time | date |
Created by app ID | text |
Account enabled | boolean |
App display name | text |
App owner organization ID | text |
App role assignment required | boolean |
App roles | array |
Disabled by microsoft status | text |
Info | object |
Terms of service URL | url |
Support URL | url |
Privacy statement URL | url |
Marketing URL | url |
Logo URL | url |
Oauth 2permission scopes | array |
Service principal type | text |
Tags | array |
Verified publisher | text |
| Field | Type |
|---|---|
Limit | number |
| Field | Type |
|---|---|
@odata type | text |
ID | text |
Deleted date time | date |
Sign in activity | object |
@odata type | text |
Cloud licensing | object |
@odata type | text |
Account enabled | text |
Age group | text |
Assigned licenses | array |
Assigned plans | array |
Authorization info | text |
Business phones | array |
City | text |
Cloud realtime communication info | object |
@odata type | text |
Company name | text |
Consent provided for minor | text |
Country | text |
Created date time | date |
Creation type | text |
Department | text |
Display name | text |
| Field | Type |
|---|---|
Application IDRequired | choice |
Limit | number |
| Field | Type |
|---|---|
ID | text |
Created date time | date |
App role ID | text |
Principal display name | text |
Principal ID | text |
Principal type | text |
Resource display name | text |
Resource ID | text |
| Field | Type |
|---|---|
Application IDRequired | choice |
Limit | number |
| Field | Type |
|---|---|
ID | text |
Deleted date time | text |
App role ID | text |
Created date time | date |
Principal display name | text |
Principal ID | text |
Principal type | text |
Resource display name | text |
Resource ID | text |
| Field | Type |
|---|---|
Application IDRequired | choice |
Limit | number |
| Field | Type |
|---|---|
@odata ID | text |
ID | text |
Name | text |
Issuer | text |
Subject | text |
Description | text |
Audiences | array |
| Field | Type |
|---|---|
Application IDRequired | choice |
Audiences | array |
Audience | text |
Issuer | url |
Name | text |
Subject | text |
| Field | Type |
|---|---|
@odata ID | text |
ID | text |
Name | text |
Issuer | text |
Subject | text |
Description | text |
Audiences | array |
| Field | Type |
|---|---|
Object IDRequired | choice |
| Field | Type |
|---|---|
@odata type | text |
ID | text |
App ID | text |
Identifier uris | array |
Created by app ID | text |
Created date time | date |
Description | text |
Disabled by microsoft status | text |
Display name | text |
Group membership claims | text |
Publisher domain | text |
Sign in audience | text |
Tags | array |
Token encryption key ID | text |
Unique name | text |
Service management reference | text |
Optional claims | text |
API | object |
Requested access token version | number |
Accept mapped claims | text |
Known client applications | array |
Oauth 2permission scopes | array |
Pre authorized applications | array |
Token encryption setting | object |
App roles | array |
Info | object |
Terms of service URL | url |
Support URL | url |
Privacy statement URL | url |
Marketing URL | url |
Logo URL | url |
| Field | Type |
|---|---|
Agent Identity Blueprint Principal IDRequired | choice |
| Field | Type |
|---|---|
@odata type | text |
ID | text |
App ID | text |
Created date time | date |
Created by app ID | text |
Account enabled | boolean |
App display name | text |
App owner organization ID | text |
App role assignment required | boolean |
App roles | array |
Disabled by microsoft status | text |
Info | object |
Terms of service URL | url |
Support URL | url |
Privacy statement URL | url |
Marketing URL | url |
Logo URL | url |
Oauth 2permission scopes | array |
Service principal type | text |
Tags | array |
Verified publisher | text |
| Field | Type |
|---|---|
Agent User IDRequired | choice |
| Field | Type |
|---|---|
@odata type | text |
ID | text |
Deleted date time | date |
Sign in activity | object |
@odata type | text |
Cloud licensing | object |
@odata type | text |
Account enabled | text |
Age group | text |
Assigned licenses | array |
Assigned plans | array |
Authorization info | text |
Business phones | array |
City | text |
Cloud realtime communication info | object |
@odata type | text |
Company name | text |
Consent provided for minor | text |
Country | text |
Created date time | date |
Creation type | text |
Department | text |
Display name | text |
Actions
| Field | Type |
|---|---|
Object IDRequired | choice |
Key CredentialRequired | object |
TypeRequired | choice |
UsageRequired | choice |
KeyRequired | text |
Password Credential | object |
Secret Text | secret |
Proof | text |
| Field | Type |
|---|---|
@odata type | text |
Custom key identifier | text |
Display name | text |
End date time | date |
Key | text |
Key ID | text |
Start date time | date |
Type | text |
Usage | text |
| Field | Type |
|---|---|
Object IDRequired | choice |
Display Name | text |
Start Date Time | date |
End Date Time | date |
| Field | Type |
|---|---|
Custom key identifier | text |
End date time | date |
Key ID | text |
Start date time | date |
Secret text | text |
Hint | text |
Display name | text |
| Field | Type |
|---|---|
Application IDRequired | choice |
Principal Display NameRequired | text |
App Role IDRequired | choice |
Principal IDRequired | choice |
Resource IDRequired | choice |
Resource Display Name | text |
| Field | Type |
|---|---|
@odata context | text |
ID | text |
Created date time | date |
App role ID | text |
Principal display name | text |
Principal ID | text |
Principal type | text |
Resource display name | text |
Resource ID | text |
| Field | Type |
|---|---|
Application IDRequired | choice |
Principal Display NameRequired | text |
App Role IDRequired | choice |
Principal IDRequired | choice |
Resource IDRequired | choice |
Resource Display Name | text |
| Field | Type |
|---|---|
App role ID | text |
Created date time | date |
Deleted date time | date |
ID | text |
Principal display name | text |
Principal ID | text |
Principal type | text |
Resource display name | text |
Resource ID | text |
| Field | Type |
|---|---|
Application IDRequired | choice |
AudiencesRequired | array |
Audience | text |
IssuerRequired | url |
NameRequired | text |
SubjectRequired | text |
| Field | Type |
|---|---|
@odata ID | text |
ID | text |
Name | text |
Issuer | text |
Subject | text |
Description | text |
Audiences | array |
| Field | Type |
|---|---|
Display NameRequired | text |
SponsorsRequired | choice |
Description | text |
Identifier URIs | array |
URI | url |
Tags | array |
Tag | text |
Sign-In Audience | choice |
| Field | Type |
|---|---|
@odata type | text |
ID | text |
App ID | text |
Identifier uris | array |
Created by app ID | text |
Created date time | date |
Description | text |
Disabled by microsoft status | text |
Display name | text |
Group membership claims | text |
Publisher domain | text |
Sign in audience | text |
Tags | array |
Token encryption key ID | text |
Unique name | text |
Service management reference | text |
Optional claims | text |
API | object |
Requested access token version | number |
Accept mapped claims | text |
Known client applications | array |
Oauth 2permission scopes | array |
Pre authorized applications | array |
Token encryption setting | object |
App roles | array |
Info | object |
Terms of service URL | url |
Support URL | url |
Privacy statement URL | url |
Marketing URL | url |
Logo URL | url |
| Field | Type |
|---|---|
Account EnabledRequired | boolean |
Display NameRequired | text |
App Display NameRequired | text |
App IDRequired | choice |
App Description | text |
App Owner Organization ID | text |
App Role Assignment Required | boolean |
App Roles | array |
Disabled By Microsoft Status | text |
Informational URL | object |
Published Permission Scopes | array |
Publisher Name | text |
Service Principal Names | array |
Service Principal Name | text |
Service Principal Type | text |
Tags | array |
Tag | text |
Verified Publisher | object |
| Field | Type |
|---|---|
@odata type | text |
ID | text |
App ID | text |
Created date time | date |
Created by app ID | text |
Account enabled | boolean |
App display name | text |
App owner organization ID | text |
App role assignment required | boolean |
App roles | array |
Disabled by microsoft status | text |
Info | object |
Terms of service URL | url |
Support URL | url |
Privacy statement URL | url |
Marketing URL | url |
Logo URL | url |
Oauth 2permission scopes | array |
Service principal type | text |
Tags | array |
Verified publisher | text |
| Field | Type |
|---|---|
Identity Parent IDRequired | choice |
Display NameRequired | text |
Account Enabled | boolean |
Mail Nickname | text |
User Principal Name | text |
| Field | Type |
|---|---|
@odata type | text |
ID | text |
Deleted date time | date |
Sign in activity | object |
@odata type | text |
Cloud licensing | object |
@odata type | text |
Account enabled | text |
Age group | text |
Assigned licenses | array |
Assigned plans | array |
Authorization info | text |
Business phones | array |
City | text |
Cloud realtime communication info | object |
@odata type | text |
Company name | text |
Consent provided for minor | text |
Country | text |
Created date time | date |
Creation type | text |
Department | text |
Display name | text |
| Field | Type |
|---|---|
Application IDRequired | choice |
Audiences | array |
Audience | text |
Issuer | url |
Name | text |
Subject | text |
| Field | Type |
|---|---|
Object IDRequired | choice |
| Field | Type |
|---|---|
Agent Identity Blueprint Principal IDRequired | choice |
| Field | Type |
|---|---|
Agent User IDRequired | choice |
| Field | Type |
|---|---|
Application IDRequired | choice |
| Field | Type |
|---|---|
Application IDRequired | choice |
| Field | Type |
|---|---|
URLRequired | text |
MethodRequired | choice |
Headers | array |
Header | object |
Query String | array |
Parameter | object |
Body | text |
| Field | Type |
|---|---|
Body | text |
Headers | object |
Status code | number |
| Field | Type |
|---|---|
Object IDRequired | choice |
| Field | Type |
|---|---|
Object IDRequired | choice |
| Field | Type |
|---|---|
Object IDRequired | choice |
Display Name | text |
Description | text |
Identifier URIs | array |
URI | url |
Tags | array |
Tag | text |
Sign-In Audience | choice |
Sponsors | choice |
| Field | Type |
|---|---|
Agent Identity Blueprint Principal IDRequired | choice |
Account Enabled | boolean |
Display Name | text |
App Display Name | text |
App ID | choice |
App Description | text |
App Owner Organization ID | text |
App Role Assignment Required | boolean |
App Roles | array |
Disabled By Microsoft Status | text |
Informational URL | object |
Published Permission Scopes | array |
Publisher Name | text |
Service Principal Names | array |
Service Principal Name | text |
Service Principal Type | text |
Tags | array |
Tag | text |
Verified Publisher | object |
| Field | Type |
|---|---|
Agent User IDRequired | choice |
Identity Parent ID | choice |
Display Name | text |
Account Enabled | boolean |
Mail Nickname | text |
User Principal Name | text |
| Field | Type |
|---|---|
Application IDRequired | choice |
Audiences | array |
Audience | text |
Issuer | url |
Name | text |
Subject | text |



