Microsoft Agent 365 Catalog Management

Microsoft Agent 365 provides a unified catalog of Microsoft 365 Copilot agents across multiple platforms. The Microsoft Entra SaaS connector aggregates catalog packages from this catalog as machine identities through the Microsoft Agent 365 dataset.

Important
Your organization must have SailPoint Agentic Fabric to use this feature. Contact your Customer Success team for more information. For more information, refer to SailPoint Agentic Fabric.

Supported Features

  • Aggregation of Microsoft Agent 365 catalog packages

  • Activate and deactivate (enable and disable) catalog packages for Azure AI Foundry, Microsoft 365 Copilot Agent Builder platforms, and other platforms

    Note

    Copilot Studio agents appear in the Microsoft Agent 365 catalog for visibility, but block and unblock operations are not supported for Copilot Studio catalog packages. To manage Copilot Studio agents, select Enable Microsoft Copilot Studio Agents instead. For more information, refer to Microsoft Copilot Studio Agents Management.

Prerequisites

  • To enable Microsoft Agent 365 requires a Microsoft Agent 365 tenant license.

  • The Microsoft Agent 365 catalog configuration requires a refresh token grant type. Provide a refresh token with the required permissions to aggregate and manage Microsoft Agent 365 agents.

    Note
    Configure the refresh token based on your source Connection Settings:

    • If source connection settings uses the Refresh Token grant type — No action needed. The connector automatically uses the refresh token from your main connection settings.

    • If source connection settings uses the Client Credentials grant type — You must generate a separate refresh token and enter it in the Refresh Token field under Machine Identity Governance Settings.

    For more information, refer to Generating a Refresh Token.

Required Permissions

The Microsoft Graph API requires delegated permissions and a refresh token to aggregate and manage Microsoft Agent 365 catalog packages. In your Microsoft Entra app registration, add the following delegated API permissions:

API

Permission

Type

Description / Purpose

Microsoft Graph

CopilotPackages.ReadWrite.All

Delegated

Aggregate and manage (block and unblock) Microsoft Agent 365 catalog packages. Admin consent is required.

Microsoft Graph

offline_access

Delegated

Issues a refresh token for persistent access.

Microsoft Graph

User.Read

Delegated

Required for the sign-in flow to obtain the initial refresh token.

Important
Grant admin consent for CopilotPackages.ReadWrite.All before configuring Microsoft Agent 365 in the source.

Enabling Machine Identity Governance

  1. In ISC, go to your Microsoft Entra SaaS source configuration page.

  2. Select the Machine Identity Governance Settings tab.

  3. Select Enable Microsoft Agent 365 if your tenant is licensed for Microsoft Agent 365. When enabled, all platform checkboxes below are checked by default, and the connector aggregates packages from every platform:

    • Manage Azure AI Foundry Agents

    • Manage Microsoft Copilot Studio Agents

    • Manage Microsoft 365 Copilot Agents

    • Manage Other Platform Agents

    Clear any checkbox to stop aggregating packages from that platform.

  4. (Optional) If your source uses the Client Credentials grant type, enter a separately generated refresh token in the Refresh Token field.

  5. Select Save.

Note

  • If the platform checkboxes appear unchecked on an existing source, follow these steps to reset them:

    1. Turn off Enable Microsoft Agent 365 and select Save.

    2. Turn it back on and select Save again.

    This resets all platform checkboxes to their default (checked) state.

  • If you do not have an Microsoft Agent 365 tenant license, choose one of these options based on what you use:

Supported Resources

For more information, refer to Microsoft Agent 365 Catalog Resources.