If you are an enterprise architect working on Microsoft Entra and AI agents, your first overdue job is not another policy wizard, another dashboard, or another governance steering committee. It is schema design.
Specifically, it is deciding how you classify non-human identities with custom security attributes in Microsoft Entra. Not eventually. Up front.
I keep seeing the same pattern across customers of every size: teams move quickly on agent experimentation, they onboard identities, they test controls, and then they realize they have no consistent attribute language for policy scope. At that point, every policy becomes a naming convention problem in disguise.
That is backwards.
The control plane starts with classification







