AI Literacy Isn't a Training Problem. It's an Identity Problem
EU AI Act, Article 4, Won't Be Solved with More AI Training
For the last year, the EU AI Act conversation has been dominated by models, data, suppliers and risk frameworks. Organisations have been busy writing AI policies, forming governance boards and building inventories of AI systems. But Gartner’s recent analysis of Article 4 puts the spotlight somewhere much more uncomfortable: people.
That matters because Article 4 moves AI literacy out of the learning and development box and into the world of business risk, assurance and market access. Gartner’s interpretation is clear: organisations need to show that the people using AI systems understand how to use them appropriately in the context of their role. A sales user, HR decision-maker and software engineer do not need the same generic AI awareness course. They need different guidance, different oversight and different evidence.
Reading Gartner’s paper, I kept coming back to one thought: the industry may be looking at this through the wrong lens.
Most organisations will interpret Article 4 as a training problem. I believe it is actually an identity governance problem.
The issue is not whether someone sat through an AI course. It is whether the right guidance reached the right person, at the right moment, for the right AI-enabled activity, and whether the organisation can evidence that when challenged by regulators, customers, insurers or investors.
AI literacy is not about teaching everyone to “use AI.” It is about ensuring specific people have the specific understanding they need to make safe, accountable decisions in AI-influenced business processes.
That is where the IAM and IGA lens becomes powerful.
Identity Has Never Been About Technology
There is a persistent misconception that Identity and Access Management is primarily about technology. It is not. Technology is usually the smaller part of the problem.
Access decisions are rarely technical decisions. They are business decisions, shaped by people, process, accountability, risk and desired outcomes.
When an organisation asks who should approve a payment, access customer records, onboard a supplier, make a hiring decision or access privileged systems, the answer is not found in technology first. It is found by understanding the business process, the risks involved and the outcome the organisation is trying to achieve.
In my experience, 80% of a successful IAM or Identity Governance programme is understanding the organisation: how people work, how decisions are made, where accountability sits and what outcome the business is trying to protect. The technology only becomes useful once that is clear. The same is now true for AI. Article 4 is not simply asking whether people have completed training. It is asking whether the organisation understands which business processes are being influenced by AI, who is using AI within those processes, what outcomes they affect and what support they need to make good decisions.
What Article 4 Looks Like in Real Business Decisions
Example 1: Recruitment and Hiring
Traditionally the IAM discussion is:
Should a recruiter have access to the recruitment platform?
But with AI:
The recruiter uses AI to shortlist candidates, generate interview questions and recommend hiring decisions.
Article 4 now raises additional questions:
- Does the recruiter understand how the AI reaches those recommendations?
- Does the recruiter understand potential bias or limitations?
- Does the recruiter know when to challenge the output?
- Does the recruiter know when escalation is required?
The governance challenge is no longer simply whether access was granted.
It becomes: have we identified that this role uses AI, provided role-specific guidance and captured evidence that the individual received it?
Those are governance questions, not training questions.
Example 2: Finance Approvals
Historically, the question was simple:
Should a Finance Manager approve payments over £100,000?
Now the question is harder:
Finance Manager uses AI-generated spend analysis and risk recommendations before approving payments.
The risk is no longer just whether the person can access the system.
The risk becomes:
- Does the approver understand where the AI recommendation came from?
- Do they know what data influenced the recommendation?
- Do they understand when the output may be unreliable?
- Are they aware that they remain accountable for the final decision?
Article 4 asks whether that individual is equipped to exercise meaningful human oversight, not just whether they were authorised to click approve.
Example 3: HR Performance and Employee Decisions
Consider an HR professional using AI to:
- recommend internal candidates
- identify flight risk
- suggest performance actions
- generate redundancy scenarios
The IAM question is:
Should this person have access to the HR system?
The Article 4 question is:
Does this individual understand the limitations, risks and escalation requirements associated with the AI-driven recommendations they are receiving?
Access permission and literacy obligation start to become connected.
Just because someone can access an AI-enabled system does not mean they are competent to use it safely in the context of their role.
Example 4: Customer Service
The desired outcome is to resolve customer enquiries accurately and consistently.
The IAM question is whether the advisor should have access to the customer service platform or other systems within the organisation.
The AI governance question is whether they understand when to trust the AI response, when to override it and when to escalate.
Across these examples, Article 4 introduces a new governance relationship:
Identity – Access – AI capability – Literacy requirement – Business outcome
AI changes the IAM equation. Access alone is no longer enough. Organisations must understand how AI is influencing business processes, which roles are interacting with AI, what decisions those roles shape and whether those individuals have the right knowledge to provide effective oversight.
These are questions identity and access management (IAM) and identity governance and administration (IGA) have been solving for years.
We already know how to answer:
- Who has access?
- Why do they have access?
- Who approved it?
- Is it still appropriate?
- Can we prove it?
Article 4 introduces a parallel set of questions:
- Who is using AI?
- What decisions are they influencing?
- What guidance applies to them?
- Who owns the risk?
- Can we prove appropriate oversight exists?
The underlying governance challenge is strikingly familiar.
This is the opportunity for the identity profession: to become central to enterprise AI governance, not adjacent to it.
Organisations need more than visibility of the AI tools they deploy. They need visibility of the people, roles, responsibilities, approvals, ownership, attestations and evidence that sit around those tools. That is identity governance territory.
The next dimension is not only AI tooling and agents. It is the deeper integration of AI into the organisation itself.
The real power of AI will come when systems can draw on richer organisational context: business data, identity signals, collaboration patterns, operational workflows, customer records, risk indicators and process history. That integration will make AI outputs more relevant and more valuable. But it also raises the stakes.
The governance question is no longer only whether someone is trained to use an AI tool. It is whether the organisation understands what information the AI can access, which signals shape its recommendations, what decisions it supports and who remains accountable for the outcome.
Some are beginning to describe this as intelligence governance. But intelligence governance will depend on identity governance. Without clear control over people, roles, permissions, responsibilities, approvals and evidence, organisations will struggle to unlock the benefits of AI transformation safely.
AI systems are no longer only assisting users. Increasingly, they are acting on behalf of users: accessing systems, retrieving information, making recommendations and initiating action. So when Gartner refers to providers, deployers, employees, contractors, partners and service providers operating AI on behalf of an organisation, it raises the next obvious question: how will organisations govern AI agents alongside human identities?
For me, this is where Article 4 becomes particularly interesting.
The next generation of AI governance will not simply be about models and policies. It will be about proving which humans and which AI agents participated in a business decision, what permissions they had, what guidance was provided, who owned the outcome and whether meaningful oversight existed.
That is not a training conversation.
That is an identity conversation.
Organisations that recognise this early will be better positioned to demonstrate AI trustworthiness, accelerate customer assurance and reduce governance risk. Those that treat Article 4 as a compliance training exercise may find themselves with completed courses, but very little evidence that operational controls exist.
For years, IAM and IGA have helped organisations prove who can participate in a business process and under what conditions. Article 4 extends that challenge into AI. The question is no longer just who has access. It is who is using AI, what outcome they influence, what guidance they received and whether the organisation can prove appropriate oversight. That is why Article 4 is far more than an AI literacy requirement. It is the point where AI governance and identity governance begin to converge.
And if Gartner is right, the organisations that can demonstrate this convincingly will not simply reduce risk. They will create competitive advantage.
Let's talk.
Start your journey with a free briefing
Sense-check your identity approach, discuss challenges, and get practical guidance on governance, security, and modern identity, with a dedicated Condatis specialist.
The Controlled Path to Modern Enterprise Identity
The Controlled Path to Modern Enterprise Identity
Planning an IAM migration?
In this fireside conversation, Condatis experts Stacey Quintana and Alasdair Murray discuss how organisations can move beyond legacy identity platforms without disrupting the business. Learn how to build stakeholder confidence, manage coexistence, mitigate risk and create the identity foundations needed to support AI, innovation and future growth.
Business Outcomes Before Platforms
Have we been solving the wrong IAM problems as an industry?
For more than a decade, identity programmes have largely been framed as technology initiatives. The conversation typically centres on replacing legacy tooling, deploying Identity Governance and Administration (IGA), implementing Access Management, modernising authentication or reducing technical debt.
These activities are important. However, they are not the primary reason most organisations struggle to achieve value from identity investments.
Recent Gartner research found that only 20% of IAM leaders successfully improve business agility while simultaneously minimising loss and disruption. More than half of organisations report increases in identity-related incidents, despite years of investment in IAM technology.
The problem is not a lack of tools. The problem is that IAM programmes are too often measured by technical delivery milestones rather than business outcomes.
Organisations celebrate:
- Platform deployments
- Application onboarding
- Certification campaigns
- MFA adoption rates
- Provisioning automation
Yet boards are increasingly concerned with entirely different questions:
- How quickly can we integrate acquisitions?
- How quickly can we onboard talent?
- Can we safely enable AI agents?
- Can we demonstrate regulatory compliance continuously?
- Can we prove accountability for access decisions?
These are not technology questions. They are business capability questions.
Identity is no longer simply concerned with workforce access. Modern organisations increasingly rely on identities to enable customers, partners, applications, services, workloads and AI agents. As the number and diversity of identities increase, so does the consequence of making poor decisions about governance, ownership and accountability. Organisations that continue to treat identity as a technology project will struggle to scale securely, whereas those that treat it as a business capability are better positioned to support digital transformation, operational resilience and AI adoption.
Gartner now describes IAM as both a business enabler and a cybersecurity imperative, elevating identity from a supporting technical function to a business-first mechanism central to digital transformation, resilience and security.
This shift fundamentally changes how identity programmes should be designed, measured and governed.
Why Identity Programmes Keep Creating More Technology and Less Value
One of the most revealing findings from Gartner’s IAM Leadership Survey is not the technology data.
It is the operating model data.
Nearly 60% of IAM leaders report regularly delaying strategic activities to address short-term business demands. Only 33% consistently consider user-centric measures such as adoption and satisfaction when making strategic decisions. Just 27% provide standardised IAM capabilities across their organisation.
Viewed another way, the majority of IAM functions are operating reactively. They are trapped in delivery cycles. Every urgent onboarding requirement. Every emergency access request. Every audit finding. Every exception process. Every application integration. Gradually pulls the programme further away from its intended strategic outcomes.
The result is an environment where IAM teams become exceptionally busy whilst struggling to demonstrate measurable business impact.
At Condatis, we increasingly see identity programmes suffering from a failure to convert evidence into accountable action.
The organisation often possesses abundant signals that underlying problems already exist:
- Access ownership is unclear.
- Critical applications have no accountable owner.
- Manual approvals create delays.
- Excessive permissions accumulate over time.
- Exception processes become permanent.
Yet because these conditions have existed for years, they become accepted as normal. Technology is then introduced to address symptoms rather than causes.
The platform changes. The operating model does not.
This is why many organisations mistakenly believe they have a technology problem when they actually have an accountability problem. New platforms improve visibility, automation and policy enforcement, but they cannot answer fundamental questions that the organisation itself has failed to address:
- Who owns identity data?
- Who owns access decisions?
- Who owns exceptions?
- Who is accountable for governance outcomes?
Gartner’s research consistently highlights that successful IAM programmes align capabilities to measurable business outcomes and business priorities, rather than focusing solely on technical implementation. Organisations that do not establish those foundations often find themselves continuously deploying new tooling while achieving very little meaningful improvement.
Identity Data is the Constraint Nobody Wants to Talk About
Many identity programmes assume technology is the primary inhibitor to progress. In practice, identity data is often the largest constraint. Most organisations already operate multiple sources of identity information:
- HR systems
- Active Directory
- Cloud directories
- Line-of-business applications
- Service management platforms
- Partner directories
Over time these sources drift apart. Ownership becomes unclear. Accountability becomes fragmented. Data quality deteriorates. Yet modern identity platforms are entirely dependent on the integrity of the data they consume. Automating poor-quality identity data simply allows organisations to distribute poor decisions more quickly and at greater scale.
This becomes even more significant as organisations move towards:
- automated provisioning
- delegated access models
- machine identities
- AI agents
If the organisation cannot explain who owns a digital identity today, it will struggle even more to explain who owns the actions performed by an autonomous identity tomorrow. Technology can automate governance. It cannot create accurate identity data where none exists.
Technology Modernisation Is Not Transformation
One of the most common mistakes we see in identity programmes is the assumption that replacing a platform automatically improves the identity function. It rarely does. Identity migrations frequently preserve existing; access models, approval processes, ownership gaps, service accounts, governance exceptions and technical debt.
The organisation successfully migrates. The operating model remains unchanged. The result is often a modern platform operating with legacy assumptions. This is particularly visible in large-scale migration programmes where the pressure to deliver encourages teams to replicate current-state processes rather than challenge them.
A useful question for leadership teams is:
“What are we changing apart from the technology?”
If the answer is unclear, the programme may be delivering platform modernisation rather than genuine transformation. As Gartner notes, IAM programmes create the most value when strategies, governance structures, processes and business outcomes are clearly defined before technology implementation begins.
AI Is Not Creating A New Identity Problem, It Is Exposing Existing Ones
Much of the market conversation surrounding AI governance focuses on controlling AI agents.
Condatis believes this framing is incomplete. AI agents are not introducing fundamentally new identity challenges. They are exposing weaknesses that already exist.
Gartner’s 2025 Machine Identity survey found that 94% of organisations are experiencing growth in machine identities, driven largely by AI agents, automation and expanding workload ecosystems. Gartner now identifies AI Agent Identity, Workload Identity Management, Identity Security Posture Management and Workload Access Management as emerging strategic disciplines within modern identity programmes.
The significance of this shift should not be underestimated. For many organisations, machine identities already outnumber human identities. AI accelerates this challenge further. The consequence is that decisions about ownership, lifecycle management, delegated authority, least privilege and accountability become more important than ever. These are governance questions first and technology questions second.
Many organisations are already struggling to answer basic governance questions such as:
- Who owns this account?
- Why does this access exist?
- Who approved it?
- What evidence supports it?
- When should it be removed?
If those questions cannot be answered for human identities, they become almost impossible to answer for autonomous AI actors operating at machine speed. The challenge is not simply controlling AI. The challenge is controlling delegated authority. Every AI agent ultimately receives authority from a human decision, business policy, access model and governance process.
An unmanaged AI agent is therefore rarely an AI problem, it’s usually a governance problem operating at a larger scale. This is why organisations pursuing AI initiatives without first understanding identity maturity often find themselves attempting to govern automation using processes that are already struggling to govern people.
Identity Is Becoming an Executive Accountability Function
Historically, IAM has frequently sat several layers below executive leadership. It was often viewed as a technical service concerned with accounts, passwords and directory administration. That model is rapidly becoming outdated. Boards routinely review financial, regulatory, operational and cyber risks. Yet many organisations cannot answer a surprisingly simple question:
"Who is accountable for the identities that operate across our organisation?"
This applies not only to employees but also to service accounts, applications, workloads, automation platforms and increasingly AI agents. As identity becomes the control plane for modern business operations, accountability for identity becomes an executive concern, not simply a technical one. Gartner describes identity-first security as a shift that places identity controls at the centre of enterprise security architecture and digital business. This fundamentally changes the role identity should play in governance discussions.
Modern IAM increasingly influences:
- Cybersecurity effectiveness
- Operational resilience
- Regulatory compliance
- Workforce productivity
- Third-party access
- Digital transformation
- AI adoption
Gartner’s broader identity research now consistently positions IAM as the primary control plane for modern security and digital business. Identity-first security places identity controls at the centre of enterprise security architecture rather than treating them as supporting infrastructure.
This creates an important challenge for boards. Most boards already receive reporting on financial, operational, cyber and regulatory risk. Few receive reporting on identity risk despite identity increasingly underpinning them all.
The question for executive leadership is therefore no longer:
“Is our IAM platform modern?”
The question is:
“Can we demonstrate control, accountability and evidence for every digital identity operating inside our organisation?”
That includes people, machines and, that includes AI.
Conclusion
The identity industry has spent years discussing platforms, tooling and migrations. Those discussions remain important, but they are no longer sufficient. Identity has become a business capability, a security control, a governance function and increasingly a prerequisite for AI adoption.
Organisations that continue to approach identity as a technology project will likely continue measuring success through implementation milestones. Organisations that approach identity as an operating model will measure success through business outcomes.
Technology still matters, but technology is no longer the most important decision.
- Governance is.
- Accountability is.
- Evidence is.
- Outcomes are.
Let's talk.
Start your journey with a free briefing
Sense-check your identity approach, discuss challenges, and get practical guidance on governance, security, and modern identity, with a dedicated Condatis specialist.
Identity Governance in the Age of Agentic AI
Access the full white paper
The Agentic System of Work: Auditing, Governance, and Compliance in the Microsoft 365 E7 Era
As organisations accelerate the adoption of AI agents and autonomous digital workers, a new challenge is emerging: how do you maintain visibility, control and accountability when non-human identities begin taking actions across your business?
This white paper explores why identity has become the critical control plane for the AI era. As regulatory requirements such as the EU AI Act, DORA and GDPR place increasing emphasis on governance and accountability, organisations must ensure every AI agent operates within clearly defined ownership, access and compliance boundaries.
The paper examines how Microsoft 365 E7 combines productivity, security, identity governance and AI management into a unified platform, helping organisations establish a secure foundation for agentic AI. It highlights how Microsoft Entra ID Governance and Agent 365 can link every AI agent to a responsible employee, automate lifecycle management, and provide continuous oversight of both human and non-human identities.
Gain insight into:
- The governance and security risks introduced by autonomous AI agents
- Why traditional access controls are no longer sufficient in an always-on AI landscape
- How Continuous Access Evaluation helps mitigate threats in real time
- Approaches for tackling fragmented and legacy identity environments
- Practical steps organisations can take today to prepare for AI at scale
- A strategic framework for executive leaders to govern AI confidently while supporting innovation
For business and technology leaders, the message is clear: successful AI adoption depends not just on deploying agents, but on governing them effectively. Organisations that establish strong identity foundations today will be better positioned to unlock AI-driven productivity, satisfy regulatory requirements, strengthen resilience, and reduce operational risk.
Read the full white paper to discover how Microsoft 365 E7 can help you build an accountable, secure and scalable foundation for agentic AI.

Alasdair Murray
Chief Technology and Product Officer
Closing the AI Execution Gap: Why Identity is the Control Plane We're Missing
Access the full white paper
In a recent blog, Alasdair Murray, CTPO explored how organisations are racing ahead with AI adoption, yet struggling to translate that momentum into sustained, secure business value. That tension between ambition and execution is now playing out very visibly in identity and security.
Across enterprises, we’re seeing a consistent pattern:
- AI adoption is outpacing control
- Usage is accelerating faster than visibility
- Identity architectures designed for humans are being stretched by machines, agents and models
This is the AI execution gap and in the context of Identity and Access Management (IAM), Identity Governance (IGA) and Identity Threat Detection and Response (ITDR), it is becoming one of the most material risks facing organisations today.

Stacey Quintana, Head of Strategic Architecture
AI Powered Threats Concern
82%
of organisations worry about AI augmented cyber attacks
AI in Security Adoption
43%
of organisations are currently using AI in cyber security operations
Governance Gap for AI Agents
86%
of enterprises lack adequate controls to manage AI agents and non-human identities
AI adoption across enterprises is accelerating faster than the controls designed to govern it. Organisations are deploying copilots, assistants and autonomous agents at scale, yet many acknowledge that the guardrails around those systems remain immature. The result is a growing execution gap: AI is delivering productivity and innovation, but often without the visibility, accountability and assurance required to operate it safely.
At the centre of this gap sits identity. As attackers increasingly target credentials and privileged access, human and non‑human alike, identity systems have become the de facto frontline of cybersecurity. At the same time, AI introduces a new class of actors: agents, bots and service accounts that act continuously, across systems, and often with broad access. Many organisations are struggling to govern these identities coherently, with fragmented tools, limited integration and a shortage of AI‑specific security skills compounding the problem.
The market response is already taking shape. Large platform providers are embedding AI governance and agent controls directly into identity and access management suites, while a new generation of vendors is emerging around AI trust, risk and security management, including behavioural controls and so‑called “guardian” agents. The direction of travel is clear: away from siloed point solutions and towards unified, context‑driven platforms that can manage identity, risk and response together.
For organisations that close the execution gap, the upside is material. Strong identity governance combined with effective identity threat detection enables AI to be deployed faster, with greater confidence and fewer operational surprises. Where identity and access tools are consolidated and integrated into detection and response workflows, teams report improved efficiency and faster containment of incidents. Where the gap is ignored, the risk profile worsens and not because AI is inherently unsafe, but because it is insufficiently governed.
Over the next two to three years, AI governance will move firmly onto the board agenda. Operating models will evolve to span security, identity, architecture and the business, and success will increasingly be measured by outcomes rather than activity: how well identity controls support AI‑driven growth while limiting exposure. The organisations that lead in this phase will be those that treat identity and AI governance not as constraints on innovation, but as strategic enablers of it.
White Paper: Defining the Benchmark for Modern Identity
Access the full white paper
A benchmark grounded in reality
This paper defines a clear target state for “good” identity, while recognising the environments most organisations operate in:
- Complex legacy estates
- Multi-vendor dependencies
- Bespoke line-of-business applications
- Limited tolerance for disruption
Rather than rip-and-replace, the approach is practical: building modern identity capabilities alongside what exists today, enabling phased change while reducing operational and security risk.
Identity as the control plane
From our perspective at Condatis, identity underpins modern security and operations. It determines what people, devices, workloads, and increasingly AI-enabled agents, can access, under what conditions, and with what level of assurance.
When identity is inconsistent, every other control has to compensate. The result is increased complexity, reduced visibility, and a model that is harder to govern and defend.
From benchmark to roadmap
The paper also outlines how to turn this target state into an evidence-led plan:
- Assess current maturity
- Prioritise early risk reduction
- Improve assurance over time
- Measure progress in operational confidence and control effectiveness
What “good” looks like in practice
The benchmark is defined through measurable outcomes, including:
- Authoritative identity foundations
- Strong, phishing-resistant authentication
- Policy-driven access decisions
- Privileged access control
- Lifecycle governance and visibility
- Readiness for non-human identities and agents
Co-authored by Condatis’ Chief Technology & Product Officer, Alasdair Murray and Head of Strategy Architecture, Stacey Quintana, this paper reflects real-world experience delivering identity programmes in government and high-stakes enterprise environments.
Agent 365 GA: Identity as the Agentic Control Plane
Spotlight
Alasdair Murray, Chief Technology & Product Officer
Microsoft Agent 365 integrates agents into the existing identity and governance framework of Microsoft Entra, marking an important architectural advance. This approach shifts organisational focus from technology to outcomes like scale, risk, and compliance.
Microsoft Agent 365 is now generally available, but the significance is not the launch itself. It is the architectural decision behind it. Microsoft has chosen to extend its existing identity control plane to agents, anchoring them in Microsoft Entra rather than creating a parallel AI governance model. That choice determines whether agents remain isolated experiments or become operable, governable components of an enterprise operating model, and it fundamentally changes the conversation organisations can have about scale, risk, and control.
Rather than starting with tools, features, or deployment models, leaders can start with outcomes. Questions of scale, risk, compliance, productivity, and operating model come first. Technology then follows as the enabler.
This is not the creation of a new or exceptional category of identity. It is the extension of established identity principles to agents. In practice, that means agents sit within familiar control structures, lifecycle expectations, and risk disciplines.
I view this as the right direction because it enables outcome‑led conversations, not technology‑led ones.
Agents Are Not a Special Case. They Are a Scaling Problem
Every leader eventually encounters the same constraint:
What works in isolation fails at scale. (A principle rooted in Russell Ackoff’s systems thinking)
Agents are no exception.
Once agents move beyond experimentation, they become persistent actors. They consume data and APIs, hold privilege, and directly influence operational and regulatory risk. At that point, the question is no longer whether an agent can perform a task. The question becomes whether the organisation can govern the outcome consistently and under change. Agent 365 matters here because it brings agents into the same identity and governance foundations already relied upon for people, applications, and services. Many organisations expected agents to require an entirely new governance layer. In practice, the harder work is extending existing discipline to a new class of actor.
Entra Turns AI Capability into a Sustainable Platform
What stands out in Microsoft’s approach is that it does not ask organisations to invent new governance models. Instead, it reinforces the models that should already exist and makes them applicable to agents.
Identity lifecycle is a prerequisite
If an organisation cannot clearly explain who owns an agent, why it exists, and when it should be retired, the issue is not AI readiness. It is identity maturity. This is where leadership intent meets operational reality. Ownership, sponsorship, expiry, and retirement are not administrative hygiene. They are the mechanisms that keep automation aligned to organisational outcomes.
Conditional Access becomes the control mechanism
Conditional Access is where identity becomes part of organisational decision‑making at runtime. In an administrative model, identity is largely static. Accounts are created, roles are assigned, and access persists until a review occurs. Control is periodic and retrospective. Identity records what something is, but it does not govern behaviour at the point of action.
Conditional Access changes this by making identity a runtime decision point. Every access request, whether from a human or an agent, is evaluated in context. Policy takes into account what is being accessed, the conditions under which the request is made, and the risk signals present at that moment.
For agents, this distinction is critical. Agents operate continuously and often with non‑trivial privilege. Without Conditional Access, access is assumed once granted. With Conditional Access, access remains conditional and continually justified. This is what allows leaders to approve agent adoption without approving uncontrolled risk. This is why anchoring Agent 365 in Entra is significant. Agents do not sit outside the control plane. They are governed by it.
Identity protection supports platform resilience
No responsible leader assumes their systems will never be misused. The practical implication of bringing agents into an identity‑first model is that detection, response, and recovery can follow the same patterns already used for other identities. This is how resilience is built, not by adding more capability, but by extending proven control mechanisms.
Governance and compliance are core requirements
A recurring failure in technology programmes is treating compliance as something to address later.
Once agents become material to how work is performed, governance becomes a requirement. Organisations need clear attribution, auditability, and the ability to demonstrate control under scrutiny. Regulators, auditors, and boards do not distinguish between human and non‑human actors. They distinguish between controlled and uncontrolled risk.
Why This Resonates with Leadership
In our work with clients, we repeatedly see the same progression as organisations move from owning capability to operating it responsibly. Licence discussions lead to value discussions. For boards, the question is whether agent adoption increases or reduces unmanaged risk. For regulators and auditors, the question is whether accountability and control can be demonstrated. For operating model owners, the question is whether agents can be scaled without creating fragility.
Agent 365 matters because it allows those questions to be answered using existing control structures, rather than introducing a new and unproven governance surface.
What leaders should consider next
Agents are becoming actors within every organisation. The question is no longer whether they will appear, but how many are already in use and where they are operating. So the first real challenge with agents is not policy or platform, but visibility. When leaders ask how many agents are operating, who owns them, and what they can access, the answers are often unclear.
In practice, adoption runs ahead of control and usage ahead of monitoring. That gap, between value realised and discipline applied, is where risk accumulates. Testing whether existing identity and governance assumptions hold under real agent usage is therefore one of the most valuable steps organisations can take once experimentation gives way to operation.
Blog
Microsoft 365 E7: What it really means for AI Governance and Identity
Microsoft 365 E7 marks a shift from AI adoption to AI governance, bringing identity, security, and automation together to help organisations scale AI safely, securely, and with full operational control.

Condatis Achieves Microsoft Identity and Access Management Specialisation

At Condatis, we’ve always believed that identity sits at the centre of every secure, scalable organisation. It underpins how people access systems, how data is protected, and increasingly, how organisations govern automation and AI.
That’s why I’m proud to share that Condatis has achieved the Identity and Access Management Specialisation from Microsoft. This recognition is not simply a milestone for our business, it’s a validation of the depth, consistency, and impact of the work our teams deliver for customers every day.
In today’s environment, identity has become business critical. Organisations are managing increasingly complex estates, spanning cloud platforms, SaaS applications, distributed workforces, and AI-driven services. Against that backdrop, the way identity is implemented matters.
To achieve this specialisation, we were required to go through a rigorous validation process led by Microsoft. This included detailed customer reference audits, technical assessments aligned to Microsoft best practices, and ongoing requirements to demonstrate consistent quality over time. For our customers, that means confidence. Confidence that the way we design and deliver identity solutions is not only aligned to industry best practice but independently verified. This specialisation isn’t awarded based on theoretical capability. Microsoft has validated that Condatis has delivered identity solutions in real customer environments, achieving measurable business outcomes and demonstrating repeatable success across different scenarios.

In practical terms, that means our customers are working with a partner that understands how identity operates in the real world and not just how it should work on paper.
There is also a broader benefit in how we engage with Microsoft itself. As a specialised partner, we are more closely aligned to Microsoft’s engineering teams, reference architectures, and product direction. That alignment ensures that the solutions we design are not only effective today but built with a clear view of where the platform, and the wider identity landscape, is heading. While we’re proud of the recognition, what matters most to me is what it represents. This achievement is the result of sustained effort from everyone at Condatis who have spent years solving complex identity challenges across a wide range of organisations.
Identity is not a simple discipline. It requires precision, deep technical understanding, and an appreciation for how systems, users, and processes interact at scale. Done well, it enables organisations to move faster and more securely. Done poorly, it becomes a source of risk and friction. Our teams consistently operate at that higher standard. This specialisation is a reflection of their expertise, their commitment, and the outcomes they deliver for our customers.
We are at a point where identity is no longer just part of the technology stack, it is becoming the foundation of how organisations operate. As businesses continue to adopt cloud services, modernise legacy platforms, and explore AI-driven capabilities, the number of identities they manage is growing rapidly. Not just people, but applications, services, and increasingly, autonomous agents. This introduces new challenges around access, governance, and control. Most organisations already have powerful identity tools available to them. The real challenge is ensuring those tools are implemented effectively, governed consistently, and aligned to how the business actually operates.
That is where the difference between capability and value becomes clear.
Achieving Microsoft’s IAM Specialisation is an important milestone, but it is not an endpoint. It strengthens our ability to support organisations as they modernise identity platforms, embed governance into day-to-day operations, and prepare for a future where identity plays an even more central role in security, compliance, and AI adoption.
For our customers, this recognition should provide reassurance.
Reassurance that you are working with a partner whose capabilities have been independently validated. Reassurance that your identity strategy is grounded in proven delivery. And reassurance that you are well positioned for what comes next.













