Skip to main content

Microsoft Copilot Integration

Microsoft Copilot Integration connects the agents you build in Microsoft Copilot Studio to WonderFence, so this project's enforcement policies apply inside those agents. Open it from Account Settings → Integrations → Microsoft Copilot Integration.

Note: Microsoft Copilot Integration is off by default and is enabled per project by Alice. If you don't see Microsoft Copilot Integration under Account Settings → Integrations, ask Alice to turn it on. This covers the guardrails integration only — the Microsoft Copilot option in How was the agent built on the Add Application form is available to every project, so you can red-team a Copilot agent without it.

There are two ways to connect, and they can be used together:

  • Environment security provider (ESP) — Microsoft's external security provider, enabled once per Power Platform environment. It covers every agent in that environment automatically, whatever type it is. Copilot calls Alice only as an agent is about to run a tool, so a prompt that triggers no tool call goes unchecked, and a reply cannot be blocked as it is sent.
  • Agent guardrail solution — a Copilot Studio solution you install on individual agents. It adds two topics that check every prompt and every response, but works only with standard agents.

Both check traffic against the same enforcement policies: a violating turn can be blocked as it happens, and every detection is recorded in Data Explorer. Each agent gets its own application in Application Inventory the first time it sends traffic, named after the agent in Copilot Studio, so you can tune protection agent by agent by changing which applications a policy covers. Agents are matched by ID, so renaming an application is safe.

A newly encountered agent starts out assigned your project's default enforcement policies, so it is protected from its first message rather than waiting for someone to assign policies. Unless someone has narrowed that default — from Application Inventory → Apply Policies, or on the Add Application form — it is every enforcement policy your project has at that moment. Which of those policies actually applies to a given message still depends on the policy's own configuration, so an assigned policy is not always a policy that runs. Narrow or widen any agent's coverage afterwards from Application Inventory → Apply Policies. A project with no enforcement policies yet is the one exception: the agent still appears in Application Inventory, but nothing is checked until you assign a policy to it. If every policy the default names has since been deleted, new agents fall back to the project's whole policy set rather than being left unprotected.

To describe and protect an agent before it goes live, create the application yourself from Application Inventory → Add Application and put the agent's ID in Application ID. That agent's traffic is then attributed to the application you set up, with the policies you chose, rather than to an automatically created one.

The page itself carries the setup steps for both options and the solution download.

→ Go to the Microsoft Copilot Integration page