Require Microsoft authentication to protect Copilot Studio agents
Diesen Beitrag auf Deutsch lesen
The new environment-level control forces integrated Microsoft authentication, blocking unauthenticated Direct Line content while preserving the M365 Agents SDK path.
TL;DR
In Power Platform admin center, Security > Identity and access, Require Microsoft authentication forces Copilot Studio makers to use Authenticate with Microsoft. Raw Direct Line clients receive an error before content is shared, while the M365 Agents SDK continues working. Existing non-Integrated agents stop responding until makers update them.
Original by Adi Leibowitz, on The Custom Engine. Read the original
This is our own summary, not a republication or full translation.
Governance takeaway
- Admins/CoE: Set Require Microsoft authentication for employee-facing environments to close the pre-authentication content surface without disabling the M365 Agents SDK.
- Security/Compliance: Treat the setting as an identity control rather than a DLP channel toggle, because blocking Direct Line also breaks the SDK client path.
- Makers: Update agents using anything other than Integrated authentication before enforcement, because noncompliant published agents stop responding and cannot republish.
- Leadership/Business: Separate employee-facing and customer-facing agents into different environments so stricter authentication does not create avoidable disruption.
Frequently asked questions
What does Require Microsoft authentication do for Copilot Studio agents?
It forces makers to use Authenticate with Microsoft, so unauthenticated Direct Line clients receive an error before any agent content is shared.
Why should I keep Direct Line channels enabled for the M365 Agents SDK?
The SDK client uses the same Direct Line channel lever, so disabling that channel would break its delegated-auth integration path.
How can I find Copilot Studio agents affected by the authentication policy?
Use Copilot Studio Kit inventory and filter Dataverse Agent Details by End User Authentication Type. Anything other than Integrated is affected.
