Master production-grade identity architecture for AI agents using Microsoft Entra Agent ID, Microsoft.Identity.Web and Microsoft Agent Framework.
Hereβs what youβll learn: π₯
π Classic vs. Agentic OBO Flow: Why traditional identity passthrough breaks in AI systems and how agentic OBO maintains secure user context.
π Framework Integration: How to combine Microsoft.Identity.Web and Microsoft Agent Framework to execute downstream requests on behalf of the user.
π Implementation Patterns: 4 distinct ways to execute Agent OBO flows using Microsoft.Identity.Web based libraries.
π Cloud Deployment Models: Running Agent OBO flows with Federated Credentials in Azure App Service and the problems with running OBO flow in Microsoft Foundry using Hosted Agents model.
π Sidecar vs. In-Process Auth: Key trade-offs between the Microsoft Entra ID Auth SDK sidecar pattern and in-process Microsoft.Identity.Web.
-----
0:00 Intro
1:42 A quick video walkthrough
4:11 Intro to On Behalf Of flow in Microsoft Entra
9:43 Classic vs Agentic On Behalf Of flow
13:40 Identity Passthrough limitations in the agentic solutions
18:32 On Behalf Of flow using Microsoft.Identity.Web and Microsoft Agent Framework
33:26 Demo of Behalf Of flow using Agent Identities and Microsoft Entra
45:28 4 ways to perform Agent On Behalf Of flow using Microsoft.Identity.Web
50:44 Microsoft.Identity.Web InMemoryTokenCaches
52:34 Agent OBO Flow with Microsoft Agent Framework and Hosted Agents in Microsoft Foundry
57:57 Agent OBO Flow with Federated Credential in Azure App Service
1:04:08 Microsoft Entra ID Auth SDK (sidecar) vs In-Process Microsoft.Identity.Web
1:06:43 Outro
-----
Follow me π
π Blog: https://deployedinazure.com
π» GitHub: https://github.com/deployed-in-azure
π LinkedIn: LinkedIn: deployed-in-azure
Master production-grade identity architecture for AI agents using Microsoft Entra Agent ID, Microsoft.Identity.Web and Microsoft Agent Framework.
Hereβs what youβll learn: π₯
π Classic vs. Agentic OBO Flow: Why traditional identity passthrough breaks in AI systems and how agentic OBO maintains secure user context.
π Framework Integration: How to combine Microsoft.Identity.Web and Microsoft Agent Framework to execute downstream requests on behalf of the user.
π Implementation Patterns: 4 distinct ways to execute Agent OBO flows using Microsoft.Identity.Web based libraries.
π Cloud Deployment Models: Running Agent OBO flows with Federated Credentials in Azure App Service and the problems with running OBO flow in Microsoft Foundry using Hosted Agents model.
π Sidecar vs. In-Process Auth: Key trade-offs between the Microsoft Entra ID Auth SDK sidecar pattern and in-process Microsoft.Identity.Web.
-----
0:00 Intro
1:42 A quick video walkthrough
4:11 Intro to On Behalf Of flow in Microsoft Entra
9:43 Classic vs Agentic On Behalf Of flow
13:40 Identity Passthrough limitations in the agentic solutions
18:32 On Behalf Of flow using Microsoft.Identity.Web and Microsoft Agent Framework
33:26 Demo of Behalf Of flow using Agent Identities and Microsoft Entra
45:28 4 ways to perform Agent On Behalf Of flow using Microsoft.Identity.Web
50:44 Microsoft.Identity.Web InMemoryTokenCaches
52:34 Agent OBO Flow with Microsoft Agent Framework and Hosted Agents in Microsoft Foundry
57:57 Agent OBO Flow with Federated Credential in Azure App Service
1:04:08 Microsoft Entra ID Auth SDK (sidecar) vs In-Process Microsoft.Identity.Web
1:06:43 Outro
-----
Follow me π
π Blog: https://deployedinazure.com
π» GitHub: https://github.com/deployed-in-azure
π LinkedIn: LinkedIn: deployed-in-azure
You could perhaps relate the topics covered in this video to a framework such as OWASP.
It would provide a more structured security perspective and help people understand where the topics discussed in this video fit within the overall AI agent security ecosystem.