Harden Copilot Studio Agents
Harden a low-code agent at build time, before it becomes an enterprise asset, by combining Power Platform data-policy guardrails with Copilot Studio security settings that govern authentication, knowledge, tools, channels, and runtime protection.
Core capabilities
-
Set the Power Platform data policy before publish — classify connectors and allow or block knowledge sources, skills, outbound HTTP, publication channels, and autonomous triggers — to close exfiltration, oversharing, and excessive-permission paths
-
Require the agent to authenticate users at build time, so a published agent never answers anonymously with corporate data
-
Run the agent's tools and connectors under each end user's own credentials so actions stay least-privileged and attributable to the person who triggered them
-
Verify each agent shows Protected — threat detection active, authentication adequate, no policy violations — before and after publishing
Supporting capabilities 2
-
Capture agent authoring, configuration, and interaction activity in Purview for accountability and later investigation
-
Stream agent and Power Platform activity into Sentinel and apply analytics rules so suspicious runtime behavior is detected alongside other tenant signals