Skip to main content

Microsoft Copilot Studio

Alice connects to Microsoft Copilot Studio as an Environment Security Provider (ESP), Microsoft's external threat-detection interface. Enabled once per Power Platform environment, it covers every agent in it: Copilot Studio calls Alice as an agent is about to run a tool, Alice evaluates the tool call, and a blocked tool call is suppressed live. Only tool calls are evaluated; Copilot Studio does not expose user prompts or agent responses to external security providers.

Status: Generally available · Evaluates: Tool calls · Vendor: Microsoft

Tool calls only, a limitation of the Copilot Studio security provider interface.

Setup​

Configuration: Entra tenant id (saved in Alice), Alice Copilot protection app registration

  1. An Entra admin grants organisation consent to the Alice Copilot protection application via the consent URL shown in Alice under Account Settings, Copilot Integration.
  2. In Alice, add your Entra tenant id(s) on that page and save.
  3. An Entra application admin registers the app with Microsoft's Create-CopilotWebhookApp.ps1 script (PowerShell Gallery), pointing it at the Alice endpoint, or manually with the federated credential values shown on the page.
  4. In the Power Platform admin center, configure the threat detection system for the environment. Every agent in it is covered from then on.

Good to know​

Enabled per project by Alice on request. Applies to generative-orchestration agents. Verdicts are allow or block; there is no mask. Each agent gets its own application in Application Inventory the first time it sends traffic.