
A dean at a mid-sized private university spun up an AI agent last Tuesday. She did it in a browser tab, between a search committee meeting and lunch. The agent has an identifier. It has a credential. It can read files, draft emails, and query a data source. It exists inside her institution's Microsoft tenant, and it will exist there tomorrow morning whether anyone in IT ever hears about it or not.
Nobody named an owner. Nobody set a retirement date. Nobody wrote down what data class the agent is allowed to touch. The load-bearing human, the one who has always translated between the humans and the machines on campus, just inherited a new job she does not know she has.
That is the story of this month. And the receipts landed in the same two weeks.
On July 5, Microsoft moved Entra Agent ID to general availability. At the same time, it shipped lifecycle-workflow support so tenants can sponsor, approve, rotate, and retire agent identities through the same entitlement-management interface used for people. Five days later, on July 10, Microsoft announced a public preview of Extended Conditional Access, which lets you apply multi-factor authentication, device compliance, and risk-based policies to any managed identity, service principal, or AI agent principal on your tenant.
Read that again. The controls you spent five years bolting onto human accounts, Microsoft can now apply to a piece of software your dean stood up between meetings.
This is exactly what I predicted on record: within twelve to eighteen months, agentic workflows would gain real capability inside major vendor solutions, and the *how-to-implement* would still be left for the institution to figure out. Capability without guidance. It is the load-bearing-human pattern, transplanted from the human identity layer to the agent layer, on a compressed timeline.
If you are running A3 or A5 education licensing, and most of you are, you now have an agent identity platform sitting inside your tenant. The question is not whether to adopt Entra Agent ID. The question is whether your identity policy has a section that names who can sponsor an agent, who approves it, who reviews it, and what triggers its retirement.
If that section does not exist, Microsoft's defaults are your policy now.
The Cloud Security Alliance published its 2026 Non-Human Identity Reality Report and put a number on the vacuum: 78 percent of organizations have no documented policy for creating or removing AI identities. Only 8 percent report comprehensive lifecycle policies. Service accounts already outnumber human users in most environments, and machines are scaling faster than manual governance can respond.
Your campus is almost certainly in the 92 percent that does not have a comprehensive lifecycle policy. I say that with confidence because higher ed did not solve this problem for humans. In 2025 alone, $180 million in federal student aid was disbursed to ineligible students, and $30 million of that went to deceased identities. The California Community College system reported a 26 percent fraud rate across 1.2 million applications. One college received 50 fake FAFSA submissions within two seconds.
If we cannot keep dead people out of the human identity system, the notion that we are going to spontaneously solve identity governance for a class of principal that can be instantiated by a faculty member in a browser tab is a fantasy.
The four states of legacy provisioning at QuickLaunch have always been Manual, Delayed, Forgotten, Orphaned. Those states now apply to agents. A forgotten agent with narrow scope is a nuisance. A forgotten agent with broad standing access to institutional data is a breach report waiting to be filed.
On June 16, the CISO Platform breach report documented agentjacking attacks against AI coding agents. The pattern: adversaries compromise or manipulate an autonomous agent to exfiltrate data, alter code, or perform actions the agent was never meant to perform. The mitigation checklist is exactly what you would expect. Remove broad standing access. Review low-privilege roles. Require phishing-resistant multi-factor authentication for management-plane users. Enable controls over file operations.
Strata's analysis of privilege drift in agentic environments reinforces the pattern. Agents accumulate entitlements beyond their intended scope through overly broad permissions, shared service accounts, and broken delegation chains. Sound familiar? It is every ghost-account problem you have ever had, except the ghost can now write to production.
I have predicted on record that two or more high-profile institutions would suffer AI-identity-driven harm within twelve to eighteen months. The developer-tools world has now named the attack. It is not a hypothetical. It is a documented pattern with a documented mitigation checklist. And the reason it will hit higher ed first is the same reason ransomware hit us first. We run more shadow integrations per capita than any other sector. Our sponsors are faculty who do not report to IT. Our incident response cycle is measured in academic semesters, not hours.
If you are not running a tabletop exercise on an agent-compromise scenario before fall term, you are betting your career on the hope that the first documented campus agentjacking happens to someone else.
While the vendors were shipping defaults and the researchers were naming attacks, the standards bodies were writing the rulebook. In the same two-week window, four Internet Engineering Task Force drafts advanced. The AI Agent Authentication and Authorization draft updated on July 6. The Workload Identity Practices draft updated on July 1 and leads with a first section stating that credentials should be scoped as narrowly as possible. A workload credentials draft updated on July 2. An ACME device attestation extension reached submission status on July 6. Separately, the National Institute of Standards and Technology's National Cybersecurity Center of Excellence published a concept paper on accelerating the adoption of software and AI agent identity and authorization.
You do not need to read these drafts. You need to know they exist, and you need to know they encode a specific opinion. Credentials should be scoped as narrowly as possible. Agents should carry cryptographically bound identifiers. Authorization decisions should leave signed evidence records.
That is a very different model from the annual access review your auditor asks about.
When your identity governance vendor's next release notes reference workload identifiers or device attestation, that is the vocabulary they will be speaking. The vendors who show up at your 2027 renewal will be using this language, and the ones who cannot will be shopping the same brochure they showed you in 2024.
I have to name a challenge to my own thesis, because it matters. EDUCAUSE Review ran a Shop Talk episode yesterday titled *Agentic AI and Change Management Lessons for Modernizing Systems*. The June piece *The Current State of Play: AI in Higher Education* declares that agentic AI has come for the back office. A January piece recounted an AI system that computed average aid per student by conflating loans, grants, and work-study. A semantic-scope error inside a properly credentialed agent, with real reporting consequences.
The sector's premier convening organization is running the right conversations at the wrong altitude. Change management is real work. I am not knocking the podcast. But change management is not enough when Microsoft ships an agent identity default on July 5 and the standards body publishes credential formats on July 2. The conversations about who should be at the table are important, and they are happening while the vendors and standards bodies decide what will be on the table.
The near-miss aid calculation in the January piece is the tell. It was not an access violation. The agent had proper credentials. It was a semantic-scope failure, and higher ed's governance discourse is not yet built to catch that failure mode. If EDUCAUSE does not publish a technical governance framework for AI agent identity in the next twelve months, that framework will be written for the sector by Microsoft, Saviynt, and SailPoint. It will be enterprise-native. And it will be higher-ed-taxed.
Here is what keeps me up.
Microsoft shipped Entra Agent ID general availability on July 5. The standards body pushed four non-human identity drafts in the same two weeks. The Cloud Security Alliance says 78 percent of organizations do not have a policy for creating an AI identity, and only 8 percent have a lifecycle policy. That is not a slow-moving story. That is the identity layer being rewritten under our feet.
I am not knocking the change management podcast. Change management is real work, and the people running those sessions are serious people. But if the sector waits for a working group white paper before it names an owner for each agent on campus, the platforms will have decided the answer. The answer will look exactly like every other corporate-IT default that landed on us with no lifecycle in mind. Ask anyone who ran a Microsoft Entra Connect deployment in 2020 how the 30-minute deprovisioning sync worked out for the student worker who got terminated on Friday afternoon.
Write the policy this month. One page. Name the owner. Name the data class. Name the trigger that kills the agent. If you cannot fill in those three fields for every agent on your campus, you do not have an AI strategy. You have an exposure.
The dean who spun up the agent last Tuesday did not do anything wrong. She used the tool the platform gave her. The wrong is upstream, in the governance layer that was supposed to name her sponsor role before the button existed. That layer is your job. The good news is it is a Tuesday afternoon job, not a two-year transformation.
Three fields. One page. Before fall term.
Primary: Download the CIO Guide for Managing AI Identities on Campus — the one-page policy template plus the sponsor/owner/trigger framework, ready for your governance committee.
Secondary: Subscribe to the QuickLaunch column and get the weekly practitioner read on identity, agentic AI, and the messy reality of higher-ed IT.
Raymond Todd Blackwood is the President of QuickLaunch and writes about identity, agentic AI, and the messy reality of higher-ed IT. #ItsExistential