Skip to content

Microsoft Copilot Studio

SailPoint Entro extends its existing Azure integration to discover and monitor AI agents built on Microsoft Copilot Studio, Microsoft's low-code platform for building AI agents within the Power Platform ecosystem.


Overview

Once enabled, SailPoint Entro enumerates every Dataverse-backed Power Platform environment in your tenant and surfaces each Copilot Studio agent in your AI Inventory with:

  • Owner identity - the user or team that owns the agent, resolved to their Entra object ID.
  • Deployment surface - Teams, Microsoft 365 Copilot, web, and whether the agent is published.
  • Connected resources - knowledge sources, connectors, MCP servers, Power Automate flows, and websites the agent can reach, plus the connection and connection owner behind each one.
  • Access and authentication settings - who can use the agent and how users authenticate to it.
  • Session activity - a summary of recent conversations, including what users asked and which tools the agent called.

Note

This integration builds on your existing SailPoint Entro Azure App Registration. Complete the Azure integration onboarding before enabling Copilot Studio discovery.


Integration Highlights

  • Discovers Copilot Studio agents across Power Platform environments in your tenant, including Production, Sandbox, Trial, Developer, Default, and Teams.
  • Uses one interactive sign-in for the tenant. There are no per-environment prompts and no client secret.
  • Operates through a dedicated application user provisioned per Dataverse environment. No credentials are passed to SailPoint Entro during setup.
  • The onboarding script is idempotent. Re-run it after new environments are created and it only adds what is missing.
  • Per-environment access report so you always know which environments SailPoint Entro can and cannot read.

Architecture

SailPoint Entro reads Copilot Studio data through the Power Platform admin API and the Dataverse Web API of each environment - not through Azure Resource Manager and not through Microsoft Graph.

flowchart LR
  subgraph onboarding ["Onboarding script - run once by your admin"]
    A["Admin signs in<br/>device code"] --> B["Register the SailPoint Entro app as<br/>Power Platform management app"]
    B --> C["List environments"]
    C --> D["Add application user +<br/>System Administrator<br/>per environment"]
  end
  subgraph discovery ["SailPoint Entro discovery - continuous, service principal"]
    E["SailPoint Entro app registration"] --> F["Power Platform admin API<br/>list environments"]
    F --> G["Dataverse Web API per environment<br/>agents, components, connections, sessions"]
  end
  B -.->|enables| F
  D -.->|enables| G

Entra ID permissions alone do not grant access to Dataverse, which is why two Power Platform-specific grants are needed on top of the Graph permissions from the Azure integration:

  • Management-app registration (tenant-wide, once). Registers the SailPoint Entro app as a Power Platform management app, which allows a service principal to call the Power Platform admin API and enumerate environments. Without it, every call is refused with Caller is not an authorized app.
  • Application user per environment with a security role that can read agents and their components.

Authentication model: The onboarding script uses an interactive device-code flow signed in as a Global Administrator or Power Platform Administrator, and performs both grants as that admin. This is a one-time provisioning step. After setup, SailPoint Entro authenticates with the App Registration credentials already stored from your Azure integration. The admin session is never stored.


Prerequisites

  • The Azure integration is already connected in SailPoint Entro, providing an existing App Registration with a ClientId and TenantId.
  • An account holding Global Administrator or Power Platform Administrator for the interactive sign-in.
  • PowerShell 7.x or later on macOS, Linux, or Windows (no additional modules - the script uses REST calls only).
  • At least one Dataverse-backed Power Platform environment in your tenant.
  • Outbound HTTPS connectivity to:
    • https://login.microsoftonline.com
    • https://api.bap.microsoft.com
    • https://*.crm*.dynamics.com (your Dataverse environments)
    • https://api.entro.security

Required Permissions

Graph API Permissions (On Your Existing App Registration)

These permissions are part of the Microsoft Copilot permission group already defined in the Azure integration. Verify they are granted on your App Registration.

Permission Purpose
AiEnterpriseInteraction.Read.All Read Copilot enterprise AI interaction metadata
Reports.Read.All Access usage and activity reports for discovery
ExternalConnection.Read.All Read external connection metadata used by Copilot agents
AppCatalog.Read.All Enumerate app catalog entries and agent metadata

If these permissions are not yet applied, re-run the Azure onboarding script or add them manually under App Registration > API permissions > Microsoft Graph > Application permissions.

Power Platform Management-App Registration (Provisioned by the Onboarding Script)

Grant Scope Purpose
Management app registration Tenant-wide Allows the SailPoint Entro service principal to call the Power Platform admin API and list environments. Equivalent to New-PowerAppManagementApp. No Entra directory role is required.

Dataverse Application User and Role (Provisioned by the Onboarding Script)

Role Scope Purpose
System Administrator Per Dataverse environment Read agents (bot), their topics, knowledge sources, and actions (botcomponent), connection references, owner identities, and session transcripts (conversationtranscript).

Note

Why System Administrator? It is the only built-in role that the Power Platform admin API can assign in a single call and that exists in every environment. The SailPoint Entro application user performs no write operations. Agents, flows, and configurations are not modified.

If you require a narrower role, create a custom role with organization-level Read on bot, botcomponent, connectionreference, systemuser, team, and conversationtranscript. Deploy it to every environment as a managed solution, and run the script with -RoleName "<your role>".


Onboarding Steps

To enable Copilot Studio discovery:

1. Locating Your App Registration Credentials

Retrieve the ClientId and TenantId from your existing SailPoint Entro Azure integration:

  1. Go to the SailPoint Entro Dashboard.
  2. Go to Management > Accounts & Integrations.
  3. Open your Azure account and copy the Client ID and Tenant ID.

These are the same values used to run the onboarding script.

2. Downloading the Onboarding Script

Download Entro-Copilot-Studio-Onboarding.ps1 (version 2.0).

29KB
Entro-Copilot-Studio-Onboarding.ps1
powershell

3. Running the Script

Open PowerShell 7.x and run:

pwsh ./Entro-Copilot-Studio-Onboarding.ps1 `
  -ClientId "<your-app-client-id>" `
  -TenantId "<your-tenant-id>"

By default the script covers all environment types. Copilot Studio agents are built in personal Developer environments and in the Default environment as often as in Production, so only narrow the scope deliberately:

# Preview: sign in, change nothing, print what would be done per environment
pwsh ./Entro-Copilot-Studio-Onboarding.ps1 -ClientId "<id>" -TenantId "<id>" -DryRun

# Production environments only
pwsh ./Entro-Copilot-Studio-Onboarding.ps1 -ClientId "<id>" -TenantId "<id>" -EnvironmentType Production

# Specific environments by Dataverse URL (bypasses enumeration)
pwsh ./Entro-Copilot-Studio-Onboarding.ps1 -ClientId "<id>" -TenantId "<id>" `
  -EnvironmentUrls "https://org1.crm.dynamics.com","https://org2.crm.dynamics.com"

What the Script Does

Step Action Why
1 Registers the SailPoint Entro app as a Power Platform management app. Skipped if already registered. Lets SailPoint Entro enumerate environments and call admin endpoints.
2 Lists every environment in the tenant with its Dataverse URL. Environments without Dataverse are skipped. The rest are filtered by -EnvironmentType.
3 Creates an application user for the SailPoint Entro app and grants System Administrator, through the admin API. One call per environment with the same admin token. There is no per-environment sign-in. Falls back to direct Dataverse calls if the admin API refuses the request, or if a custom -RoleName is requested.
4 Verifies the application user exists, is enabled, and holds the role. Silent and best-effort. If Dataverse cannot be read without another prompt, the row is marked Unverified instead of asking you to sign in again.
5 Writes a CSV report and prints anything that still needs attention. One row per environment.

Script Parameters

Parameter Required Default Description
-ClientId Yes - Application (Client) ID of your SailPoint Entro App Registration.
-TenantId Yes - Your Microsoft Entra tenant ID.
-EnvironmentType No All Filter environments by type: Production, Sandbox, Trial, Developer, Default, Teams, or All.
-EnvironmentUrls No - Provision specific Dataverse org URLs directly, bypassing enumeration. Uses the Dataverse path. Management-app registration is not possible in this mode.
-RoleName No System Administrator Dataverse security role to assign. Any other value uses the Dataverse path, and the role must already exist in every environment.
-PublicClientId No 892b2344-b2c5-4751-b6f7-44e43a4fdb51 (SailPoint CLI) The app registration used for your interactive sign-in. Refer to Sign-In Client.
-SkipManagementAppRegistration No off Do not register the management app, if you already did so by other means.
-DataverseOnly No off Never use the admin API. Provision through Dataverse only.
-DryRun No off Sign in, then only print what would be done. No changes.
-ReportPath No ./entro-onboarding-report.csv Output path for the CSV provisioning report.

4. Completing the Sign-In

The script prints a device code:

To sign in, use a web browser to open the page https://login.microsoft.com/device
and enter the code XXXXXXXX to authenticate.

Sign in as a Global Administrator or Power Platform Administrator. The sign-in is requested by SailPoint CLI, a public client that only asks for delegated permissions. Refer to Sign-In Client. The first time, select Consent on behalf of your organization so later runs are silent.

This is the only interactive step. The summary at the end shows Interactive sign-ins: 1. The script does not store or transmit your credentials.

5. Reviewing the Provisioning Report

On completion, the script prints a summary and saves a CSV report to -ReportPath (default ./entro-onboarding-report.csv).

Example output:

[4/4] Summary
  Management app:     Registered
  Environments:       6
  Provisioned:        6
  Skipped (disabled): 0
  Unverified:         0
  Failed:             0
  Interactive sign-ins: 1
  Report:             ./entro-onboarding-report.csv

The CSV has one row per environment:

Column Values
EnvironmentName, EnvironmentId, EnvironmentType, IsDefault, OrgUrl Environment identity and its Dataverse URL.
Path AdminApi, AdminApi->Dataverse (admin API refused, direct provisioning used), or Dataverse.
AppUserStatus Created, AlreadyExists, Skipped (Dataverse disabled), or DryRun.
RoleStatus SystemAdministrator, Assigned, or AlreadyAssigned.
Verified Verified, Unverified (could not read Dataverse silently - confirm in the admin center), NotFound, Disabled, or MissingRole.
Roles Security roles the application user holds.
Error, Hint Failure text and, where the script recognizes the cause, what to do.

Review failed or unverified environments before proceeding. Refer to Troubleshooting.

6. Triggering Discovery in SailPoint Entro

Once provisioning is complete, return to the SailPoint Entro Dashboard:

  1. Go to Management > Accounts & Integrations.
  2. Open your Azure account.
  3. Select Sync Now to trigger an immediate Copilot Studio discovery scan.

SailPoint Entro begins enumerating Copilot Studio agents across provisioned environments. Initial discovery may take a few minutes depending on the number of environments and agents.


Sign-In Client: SailPoint CLI or Your Own App Registration

The device-code page shows the name of the app registration that requests the token. By default that is SailPoint CLI (892b2344-b2c5-4751-b6f7-44e43a4fdb51), a multi-tenant public client owned by SailPoint. It holds no secret, no application permissions, and no role in your tenant. It only requests delegated permissions so the script can act as the signed-in admin:

Permission shown on the consent page What it is for
Dynamics CRM - Access Common Data Service as you (user_impersonation) Reading and provisioning inside each Dataverse environment as you.
PowerApps Service - Access the PowerApps Service API (User) Calling the Power Platform admin API as you.
Maintain access to data you have given it access to (offline_access) A refresh token, so one sign-in covers every environment.

Option: Use Your Own App Registration Instead

If your policy prohibits consenting to third-party applications, create an equivalent public client in your own tenant and pass its ID with -PublicClientId. You can delete it after onboarding. SailPoint Entro never uses it.

Setting Value
Name Anything, for example Entro Onboarding CLI.
Supported account types Accounts in this organizational directory only (single tenant).
Authentication → Allow public client flows Yes.
API permissions (delegated) Dynamics CRM → user_impersonation; PowerApps Service → User; Microsoft Graph → openid, offline_access.
Grant admin consent Yes, so the sign-in never prompts for consent.

Or let Azure CLI do it. New-CustomerSignInApp.sh creates the app with these settings, grants admin consent, and prints the ID.

2KB
New-CustomerSignInApp.sh
shell
az login --tenant <your-tenant-id>
./New-CustomerSignInApp.sh "Entro Onboarding CLI"
pwsh ./Entro-Copilot-Studio-Onboarding.ps1 -ClientId "<entro-app-client-id>" -TenantId "<your-tenant-id>" -PublicClientId "<printed-app-id>"

If consent to a non-Microsoft app is blocked, Microsoft's first-party Dynamics client 51f81489-12ee-4a9e-aaae-a2591f45987d also works as -PublicClientId. The device-code page then shows a Microsoft product name.


Verification

After the sync completes:

  1. Go to AI Inventory in the SailPoint Entro Dashboard.
  2. Filter by Platform: Copilot Studio.
  3. Confirm that agents appear with their environment, owner, deployment surface, and connected resources populated.
  4. Open your Azure account under Accounts & Integrations and check the per-environment access status. Every environment you onboarded should show as readable. Environments listed as no application user were not covered by the script run (for example, created afterwards). Re-run the script to add them.

Security & Compliance

  • The onboarding script does not read your business data. It registers the SailPoint Entro app as a management app, creates an application user, and assigns a Dataverse role.
  • Authentication is delegated only. You sign in interactively. No client secret is used or accepted by the script, and nothing is transmitted to SailPoint Entro during script execution.
  • The sign-in client (SailPoint CLI or your own) holds no secret, no application permissions, and no role in your tenant.
  • Communication between SailPoint Entro and Microsoft APIs uses HTTPS / TLS 1.2+.
  • The SailPoint Entro application user performs read-only discovery. Agents, flows, environments, and configurations are not created or modified.
  • Session data is ingested as summaries only (user messages, tools offered, tools called). Raw conversation transcripts remain in your Dataverse.
  • To revoke access, delete or disable the application user in each environment, and remove the management-app registration (Remove-PowerAppManagementApp or DELETE …/adminApplications/{appId}).
  • Fully aligned with SOC 2 Type II, ISO 27001, and GDPR requirements.

Troubleshooting

No Environments to Process

Symptom: No Dataverse environments to process.

Fix: The -EnvironmentType filter matched nothing, or no environment in the tenant has a Dataverse database. Run with the default (All) or check the Power Platform admin center.

Agents not appearing after sync, Entro reports "Caller is not an authorized app"

Symptom: Agents do not appear after sync, and SailPoint Entro reports Caller is not an authorized app.

Cause: The management-app registration is missing. The script was run with -SkipManagementAppRegistration or with -EnvironmentUrls, which cannot register it.

Fix: Run the script once without those switches. The first summary line should read Management app: Registered or AlreadyRegistered.

More Than One Interactive Sign-In

Symptom: The summary shows Interactive sign-ins: 2 or more, and lines such as silent token for https://<org>.crm.dynamics.com refused: … above it.

Cause: The sign-in client is not consented for one of the audiences (Dynamics CRM or PowerApps Service) in your tenant.

Fix: Sign in as a Global Administrator and consent on behalf of the organization, or use your own app registration with admin consent granted.

Unverified in the Report

Cause: The provisioning call succeeded, but the signed-in admin could not read that environment's Dataverse silently, so the script could not confirm the result.

Fix: In the Power Platform admin center, go to the environment, then Settings > Users + permissions > Application users. Confirm the SailPoint Entro app is listed with the System Administrator role. No re-run is needed if it is.

Error 0x8004a104: Organization Is Disabled

Symptom: 0x8004a104 … organization … is currently disabled.

Cause: The environment's Dataverse database is turned off.

Fix: None needed. The script marks the environment Skipped. There is nothing to discover in a disabled environment.

Environment in Administration Mode

Symptom: … administration mode … in the error column.

Fix: Only System Administrator and System Customizer users can call into an environment in admin mode. Disable admin mode temporarily and re-run for that environment, or accept that SailPoint Entro cannot read it until admin mode is lifted.

Blocked by the Dataverse IP Firewall

Symptom: … IP address … blocked … on Managed Environments with an IP firewall.

Fix: Run the script from an allowed network, and allow-list SailPoint Entro's egress addresses for discovery. Environment listing still works. Only Dataverse reads are blocked.

Forbidden or Unauthorized on a Specific Environment

Cause: The environment is restricted by a security group and the signed-in admin is not a member, or the account is not a Power Platform administrator.

Fix: Add the admin to the environment's security group, or use a Power Platform Administrator, then re-run for that environment:

pwsh ./Entro-Copilot-Studio-Onboarding.ps1 `
  -ClientId "<id>" -TenantId "<id>" -SkipManagementAppRegistration `
  -EnvironmentUrls "https://<failed-org>.crm.dynamics.com"

Device Code Sign-In Times Out

Symptom: Timed out waiting for sign-in.

Fix: Re-run the script. The device code expires after 15 minutes. Complete the browser authentication promptly after the code is displayed.

Environment Was Being Provisioned

Symptom: Could not connect or transient API errors.

Fix: Wait a few minutes for the environment to finish provisioning, then re-run targeting that environment with -EnvironmentUrls.

Agents Not Appearing in AI Inventory After Sync

Checks:

  • Confirm the provisioning report shows Verified, or Unverified with the application user visible in the admin center, for the expected environments.
  • Check the per-environment access status on your Azure account in SailPoint Entro. Environments shown as no application user or missing role were not fully onboarded.
  • Verify the Graph API permissions are granted and admin-consented on the App Registration.
  • Trigger a manual sync from Accounts & Integrations. Select Sync Now.

Environments Created After Onboarding

The application user is created per environment, so an environment created later is not covered until the script is run again. The script is idempotent. Re-running it adds the missing application users and leaves everything else untouched. SailPoint Entro's per-environment access status shows environments that still need it.