Microsoft Copilot Studio
SailPoint Entro extends its existing Azure integration to discover and monitor AI agents built on Microsoft Copilot Studio, Microsoft's low-code platform for building AI agents within the Power Platform ecosystem.
Overview
Once enabled, SailPoint Entro enumerates every Dataverse-backed Power Platform environment in your tenant and surfaces each Copilot Studio agent in your AI Inventory with:
- Owner identity - the user or team that owns the agent, resolved to their Entra object ID.
- Deployment surface - Teams, Microsoft 365 Copilot, web, and whether the agent is published.
- Connected resources - knowledge sources, connectors, MCP servers, Power Automate flows, and websites the agent can reach, plus the connection and connection owner behind each one.
- Access and authentication settings - who can use the agent and how users authenticate to it.
- Session activity - a summary of recent conversations, including what users asked and which tools the agent called.
Note
This integration builds on your existing SailPoint Entro Azure App Registration. Complete the Azure integration onboarding before enabling Copilot Studio discovery.
Integration Highlights
- Discovers Copilot Studio agents across Power Platform environments in your tenant, including Production, Sandbox, Trial, Developer, Default, and Teams.
- Uses one interactive sign-in for the tenant. There are no per-environment prompts and no client secret.
- Operates through a dedicated application user provisioned per Dataverse environment. No credentials are passed to SailPoint Entro during setup.
- The onboarding script is idempotent. Re-run it after new environments are created and it only adds what is missing.
- Per-environment access report so you always know which environments SailPoint Entro can and cannot read.
Architecture
SailPoint Entro reads Copilot Studio data through the Power Platform admin API and the Dataverse Web API of each environment - not through Azure Resource Manager and not through Microsoft Graph.
flowchart LR
subgraph onboarding ["Onboarding script - run once by your admin"]
A["Admin signs in<br/>device code"] --> B["Register the SailPoint Entro app as<br/>Power Platform management app"]
B --> C["List environments"]
C --> D["Add application user +<br/>System Administrator<br/>per environment"]
end
subgraph discovery ["SailPoint Entro discovery - continuous, service principal"]
E["SailPoint Entro app registration"] --> F["Power Platform admin API<br/>list environments"]
F --> G["Dataverse Web API per environment<br/>agents, components, connections, sessions"]
end
B -.->|enables| F
D -.->|enables| G
Entra ID permissions alone do not grant access to Dataverse, which is why two Power Platform-specific grants are needed on top of the Graph permissions from the Azure integration:
- Management-app registration (tenant-wide, once). Registers the SailPoint Entro app as a Power Platform management app, which allows a service principal to call the Power Platform admin API and enumerate environments. Without it, every call is refused with
Caller is not an authorized app. - Application user per environment with a security role that can read agents and their components.
Authentication model: The onboarding script uses an interactive device-code flow signed in as a Global Administrator or Power Platform Administrator, and performs both grants as that admin. This is a one-time provisioning step. After setup, SailPoint Entro authenticates with the App Registration credentials already stored from your Azure integration. The admin session is never stored.
Prerequisites
- The Azure integration is already connected in SailPoint Entro, providing an existing App Registration with a
ClientIdandTenantId. - An account holding Global Administrator or Power Platform Administrator for the interactive sign-in.
- PowerShell 7.x or later on macOS, Linux, or Windows (no additional modules - the script uses REST calls only).
- At least one Dataverse-backed Power Platform environment in your tenant.
- Outbound HTTPS connectivity to:
https://login.microsoftonline.comhttps://api.bap.microsoft.comhttps://*.crm*.dynamics.com(your Dataverse environments)https://api.entro.security
Required Permissions
Graph API Permissions (On Your Existing App Registration)
These permissions are part of the Microsoft Copilot permission group already defined in the Azure integration. Verify they are granted on your App Registration.
| Permission | Purpose |
|---|---|
AiEnterpriseInteraction.Read.All |
Read Copilot enterprise AI interaction metadata |
Reports.Read.All |
Access usage and activity reports for discovery |
ExternalConnection.Read.All |
Read external connection metadata used by Copilot agents |
AppCatalog.Read.All |
Enumerate app catalog entries and agent metadata |
If these permissions are not yet applied, re-run the Azure onboarding script or add them manually under App Registration > API permissions > Microsoft Graph > Application permissions.
Power Platform Management-App Registration (Provisioned by the Onboarding Script)
| Grant | Scope | Purpose |
|---|---|---|
| Management app registration | Tenant-wide | Allows the SailPoint Entro service principal to call the Power Platform admin API and list environments. Equivalent to New-PowerAppManagementApp. No Entra directory role is required. |
Dataverse Application User and Role (Provisioned by the Onboarding Script)
| Role | Scope | Purpose |
|---|---|---|
| System Administrator | Per Dataverse environment | Read agents (bot), their topics, knowledge sources, and actions (botcomponent), connection references, owner identities, and session transcripts (conversationtranscript). |
Note
Why System Administrator? It is the only built-in role that the Power Platform admin API can assign in a single call and that exists in every environment. The SailPoint Entro application user performs no write operations. Agents, flows, and configurations are not modified.
If you require a narrower role, create a custom role with organization-level Read on bot, botcomponent, connectionreference, systemuser, team, and conversationtranscript. Deploy it to every environment as a managed solution, and run the script with -RoleName "<your role>".
Onboarding Steps
To enable Copilot Studio discovery:
1. Locating Your App Registration Credentials
Retrieve the ClientId and TenantId from your existing SailPoint Entro Azure integration:
- Go to the SailPoint Entro Dashboard.
- Go to Management > Accounts & Integrations.
- Open your Azure account and copy the Client ID and Tenant ID.
These are the same values used to run the onboarding script.
2. Downloading the Onboarding Script
Download Entro-Copilot-Studio-Onboarding.ps1 (version 2.0).
3. Running the Script
Open PowerShell 7.x and run:
pwsh ./Entro-Copilot-Studio-Onboarding.ps1 `
-ClientId "<your-app-client-id>" `
-TenantId "<your-tenant-id>"
By default the script covers all environment types. Copilot Studio agents are built in personal Developer environments and in the Default environment as often as in Production, so only narrow the scope deliberately:
# Preview: sign in, change nothing, print what would be done per environment
pwsh ./Entro-Copilot-Studio-Onboarding.ps1 -ClientId "<id>" -TenantId "<id>" -DryRun
# Production environments only
pwsh ./Entro-Copilot-Studio-Onboarding.ps1 -ClientId "<id>" -TenantId "<id>" -EnvironmentType Production
# Specific environments by Dataverse URL (bypasses enumeration)
pwsh ./Entro-Copilot-Studio-Onboarding.ps1 -ClientId "<id>" -TenantId "<id>" `
-EnvironmentUrls "https://org1.crm.dynamics.com","https://org2.crm.dynamics.com"
What the Script Does
| Step | Action | Why |
|---|---|---|
| 1 | Registers the SailPoint Entro app as a Power Platform management app. Skipped if already registered. | Lets SailPoint Entro enumerate environments and call admin endpoints. |
| 2 | Lists every environment in the tenant with its Dataverse URL. | Environments without Dataverse are skipped. The rest are filtered by -EnvironmentType. |
| 3 | Creates an application user for the SailPoint Entro app and grants System Administrator, through the admin API. | One call per environment with the same admin token. There is no per-environment sign-in. Falls back to direct Dataverse calls if the admin API refuses the request, or if a custom -RoleName is requested. |
| 4 | Verifies the application user exists, is enabled, and holds the role. | Silent and best-effort. If Dataverse cannot be read without another prompt, the row is marked Unverified instead of asking you to sign in again. |
| 5 | Writes a CSV report and prints anything that still needs attention. | One row per environment. |
Script Parameters
| Parameter | Required | Default | Description |
|---|---|---|---|
-ClientId |
Yes | - | Application (Client) ID of your SailPoint Entro App Registration. |
-TenantId |
Yes | - | Your Microsoft Entra tenant ID. |
-EnvironmentType |
No | All |
Filter environments by type: Production, Sandbox, Trial, Developer, Default, Teams, or All. |
-EnvironmentUrls |
No | - | Provision specific Dataverse org URLs directly, bypassing enumeration. Uses the Dataverse path. Management-app registration is not possible in this mode. |
-RoleName |
No | System Administrator |
Dataverse security role to assign. Any other value uses the Dataverse path, and the role must already exist in every environment. |
-PublicClientId |
No | 892b2344-b2c5-4751-b6f7-44e43a4fdb51 (SailPoint CLI) |
The app registration used for your interactive sign-in. Refer to Sign-In Client. |
-SkipManagementAppRegistration |
No | off | Do not register the management app, if you already did so by other means. |
-DataverseOnly |
No | off | Never use the admin API. Provision through Dataverse only. |
-DryRun |
No | off | Sign in, then only print what would be done. No changes. |
-ReportPath |
No | ./entro-onboarding-report.csv |
Output path for the CSV provisioning report. |
4. Completing the Sign-In
The script prints a device code:
To sign in, use a web browser to open the page https://login.microsoft.com/device
and enter the code XXXXXXXX to authenticate.
Sign in as a Global Administrator or Power Platform Administrator. The sign-in is requested by SailPoint CLI, a public client that only asks for delegated permissions. Refer to Sign-In Client. The first time, select Consent on behalf of your organization so later runs are silent.
This is the only interactive step. The summary at the end shows Interactive sign-ins: 1. The script does not store or transmit your credentials.
5. Reviewing the Provisioning Report
On completion, the script prints a summary and saves a CSV report to -ReportPath (default ./entro-onboarding-report.csv).
Example output:
[4/4] Summary
Management app: Registered
Environments: 6
Provisioned: 6
Skipped (disabled): 0
Unverified: 0
Failed: 0
Interactive sign-ins: 1
Report: ./entro-onboarding-report.csv
The CSV has one row per environment:
| Column | Values |
|---|---|
EnvironmentName, EnvironmentId, EnvironmentType, IsDefault, OrgUrl |
Environment identity and its Dataverse URL. |
Path |
AdminApi, AdminApi->Dataverse (admin API refused, direct provisioning used), or Dataverse. |
AppUserStatus |
Created, AlreadyExists, Skipped (Dataverse disabled), or DryRun. |
RoleStatus |
SystemAdministrator, Assigned, or AlreadyAssigned. |
Verified |
Verified, Unverified (could not read Dataverse silently - confirm in the admin center), NotFound, Disabled, or MissingRole. |
Roles |
Security roles the application user holds. |
Error, Hint |
Failure text and, where the script recognizes the cause, what to do. |
Review failed or unverified environments before proceeding. Refer to Troubleshooting.
6. Triggering Discovery in SailPoint Entro
Once provisioning is complete, return to the SailPoint Entro Dashboard:
- Go to Management > Accounts & Integrations.
- Open your Azure account.
- Select Sync Now to trigger an immediate Copilot Studio discovery scan.
SailPoint Entro begins enumerating Copilot Studio agents across provisioned environments. Initial discovery may take a few minutes depending on the number of environments and agents.
Sign-In Client: SailPoint CLI or Your Own App Registration
The device-code page shows the name of the app registration that requests the token. By default that is SailPoint CLI (892b2344-b2c5-4751-b6f7-44e43a4fdb51), a multi-tenant public client owned by SailPoint. It holds no secret, no application permissions, and no role in your tenant. It only requests delegated permissions so the script can act as the signed-in admin:
| Permission shown on the consent page | What it is for |
|---|---|
Dynamics CRM - Access Common Data Service as you (user_impersonation) |
Reading and provisioning inside each Dataverse environment as you. |
PowerApps Service - Access the PowerApps Service API (User) |
Calling the Power Platform admin API as you. |
Maintain access to data you have given it access to (offline_access) |
A refresh token, so one sign-in covers every environment. |
Option: Use Your Own App Registration Instead
If your policy prohibits consenting to third-party applications, create an equivalent public client in your own tenant and pass its ID with -PublicClientId. You can delete it after onboarding. SailPoint Entro never uses it.
| Setting | Value |
|---|---|
| Name | Anything, for example Entro Onboarding CLI. |
| Supported account types | Accounts in this organizational directory only (single tenant). |
| Authentication → Allow public client flows | Yes. |
| API permissions (delegated) | Dynamics CRM → user_impersonation; PowerApps Service → User; Microsoft Graph → openid, offline_access. |
| Grant admin consent | Yes, so the sign-in never prompts for consent. |
Or let Azure CLI do it. New-CustomerSignInApp.sh creates the app with these settings, grants admin consent, and prints the ID.
az login --tenant <your-tenant-id>
./New-CustomerSignInApp.sh "Entro Onboarding CLI"
pwsh ./Entro-Copilot-Studio-Onboarding.ps1 -ClientId "<entro-app-client-id>" -TenantId "<your-tenant-id>" -PublicClientId "<printed-app-id>"
If consent to a non-Microsoft app is blocked, Microsoft's first-party Dynamics client 51f81489-12ee-4a9e-aaae-a2591f45987d also works as -PublicClientId. The device-code page then shows a Microsoft product name.
Verification
After the sync completes:
- Go to AI Inventory in the SailPoint Entro Dashboard.
- Filter by Platform: Copilot Studio.
- Confirm that agents appear with their environment, owner, deployment surface, and connected resources populated.
- Open your Azure account under Accounts & Integrations and check the per-environment access status. Every environment you onboarded should show as readable. Environments listed as no application user were not covered by the script run (for example, created afterwards). Re-run the script to add them.
Security & Compliance
- The onboarding script does not read your business data. It registers the SailPoint Entro app as a management app, creates an application user, and assigns a Dataverse role.
- Authentication is delegated only. You sign in interactively. No client secret is used or accepted by the script, and nothing is transmitted to SailPoint Entro during script execution.
- The sign-in client (SailPoint CLI or your own) holds no secret, no application permissions, and no role in your tenant.
- Communication between SailPoint Entro and Microsoft APIs uses HTTPS / TLS 1.2+.
- The SailPoint Entro application user performs read-only discovery. Agents, flows, environments, and configurations are not created or modified.
- Session data is ingested as summaries only (user messages, tools offered, tools called). Raw conversation transcripts remain in your Dataverse.
- To revoke access, delete or disable the application user in each environment, and remove the management-app registration (
Remove-PowerAppManagementApporDELETE …/adminApplications/{appId}). - Fully aligned with SOC 2 Type II, ISO 27001, and GDPR requirements.
Troubleshooting
No Environments to Process
Symptom: No Dataverse environments to process.
Fix: The -EnvironmentType filter matched nothing, or no environment in the tenant has a Dataverse database. Run with the default (All) or check the Power Platform admin center.
Agents not appearing after sync, Entro reports "Caller is not an authorized app"
Symptom: Agents do not appear after sync, and SailPoint Entro reports Caller is not an authorized app.
Cause: The management-app registration is missing. The script was run with -SkipManagementAppRegistration or with -EnvironmentUrls, which cannot register it.
Fix: Run the script once without those switches. The first summary line should read Management app: Registered or AlreadyRegistered.
More Than One Interactive Sign-In
Symptom: The summary shows Interactive sign-ins: 2 or more, and lines such as silent token for https://<org>.crm.dynamics.com refused: … above it.
Cause: The sign-in client is not consented for one of the audiences (Dynamics CRM or PowerApps Service) in your tenant.
Fix: Sign in as a Global Administrator and consent on behalf of the organization, or use your own app registration with admin consent granted.
Unverified in the Report
Cause: The provisioning call succeeded, but the signed-in admin could not read that environment's Dataverse silently, so the script could not confirm the result.
Fix: In the Power Platform admin center, go to the environment, then Settings > Users + permissions > Application users. Confirm the SailPoint Entro app is listed with the System Administrator role. No re-run is needed if it is.
Error 0x8004a104: Organization Is Disabled
Symptom: 0x8004a104 … organization … is currently disabled.
Cause: The environment's Dataverse database is turned off.
Fix: None needed. The script marks the environment Skipped. There is nothing to discover in a disabled environment.
Environment in Administration Mode
Symptom: … administration mode … in the error column.
Fix: Only System Administrator and System Customizer users can call into an environment in admin mode. Disable admin mode temporarily and re-run for that environment, or accept that SailPoint Entro cannot read it until admin mode is lifted.
Blocked by the Dataverse IP Firewall
Symptom: … IP address … blocked … on Managed Environments with an IP firewall.
Fix: Run the script from an allowed network, and allow-list SailPoint Entro's egress addresses for discovery. Environment listing still works. Only Dataverse reads are blocked.
Forbidden or Unauthorized on a Specific Environment
Cause: The environment is restricted by a security group and the signed-in admin is not a member, or the account is not a Power Platform administrator.
Fix: Add the admin to the environment's security group, or use a Power Platform Administrator, then re-run for that environment:
pwsh ./Entro-Copilot-Studio-Onboarding.ps1 `
-ClientId "<id>" -TenantId "<id>" -SkipManagementAppRegistration `
-EnvironmentUrls "https://<failed-org>.crm.dynamics.com"
Device Code Sign-In Times Out
Symptom: Timed out waiting for sign-in.
Fix: Re-run the script. The device code expires after 15 minutes. Complete the browser authentication promptly after the code is displayed.
Environment Was Being Provisioned
Symptom: Could not connect or transient API errors.
Fix: Wait a few minutes for the environment to finish provisioning, then re-run targeting that environment with -EnvironmentUrls.
Agents Not Appearing in AI Inventory After Sync
Checks:
- Confirm the provisioning report shows
Verified, orUnverifiedwith the application user visible in the admin center, for the expected environments. - Check the per-environment access status on your Azure account in SailPoint Entro. Environments shown as no application user or missing role were not fully onboarded.
- Verify the Graph API permissions are granted and admin-consented on the App Registration.
- Trigger a manual sync from Accounts & Integrations. Select Sync Now.
Environments Created After Onboarding
The application user is created per environment, so an environment created later is not covered until the script is run again. The script is idempotent. Re-running it adds the missing application users and leaves everything else untouched. SailPoint Entro's per-environment access status shows environments that still need it.