Connect Microsoft 365 Copilot to a gateway
Add an MCP gateway to a Copilot Studio agent with a sign-in through Entra ID.
Microsoft 365 Copilot reaches an MCP gateway through an agent built in Copilot Studio, where the gateway is added as a tool, after which the agent uses the gateway's tools in Copilot chats. The tool is backed by a custom connector that Copilot Studio creates in the Power Platform environment, and that connector is what signs people in. A gateway connected this way has OAuth on and the identity provider is Entra ID.
The tool form
- Open the agent in Copilot Studio, go to Tools and choose Add a tool > New tool > Model Context Protocol.
- Enter the gateway's URL as the Server URL, e.g.
https://api.example.com/mcp/billing, with a name and a description. - Under Authentication, choose OAuth 2.0 and fill in the fields from the registration made for Copilot Studio, as described below:
| Field | Value |
|---|---|
| Client ID | The Application (client) ID of the registration |
| Client secret | The secret created for it |
| Authorization URL | https://login.microsoftonline.com/<tenant-id>/oauth2/v2.0/authorize |
| Token URL template | https://login.microsoftonline.com/<tenant-id>/oauth2/v2.0/token |
| Refresh URL | The same token URL |
| Scopes | openid profile offline_access api://zato-mcp/access, the gateway's Scopes field |
- Create the tool. Copilot Studio creates the connector and shows its Redirect URL - the person managing the tenant adds it to the registration, as described below, before the first sign-in.
A gateway without OAuth, secured with an API key, is added with the API key authentication option instead, where the key is entered once for the connector.
What the identity provider needs
The registration for Copilot Studio is a confidential client, unlike the other clients' ones:
- A client secret under Certificates and secrets.
- The Web platform under Authentication, with the redirect URL Copilot Studio shows after the tool is created. The URL has the form
https://global.consent.azure-apim.net/redirect/<connector-slug>, the slug comes from the tool's name, and renaming the tool or creating a new connection gives a new URL that needs adding as well. Entra ID names the expected URL in itsAADSTS50011error when one is missing. - The API's scope and
offline_accessunder API permissions, with admin consent, as described on the OAuth page.
The sign-in
- In the agent's test pane, or in the Copilot chat once the agent is published, the first request that needs the gateway shows a card asking the person to connect.
- The card opens Entra ID's sign-in page, with the organization's single sign-on.
- After the sign-in, the request continues and the gateway's tools are used from then on.
The connector keeps the token per person and refreshes it with the refresh URL until the session ends. Connections under the person's Power Platform settings is where it can be removed.
When access is refused
A person whose token the gateway does not accept - outside the group the gateway's bearer definition lists - sees the tool fail in the chat, with the agent reporting that it could not reach the tool, and the connection card is offered again. The reason is in the gateway's audit log, in the Reason column of the auth-failed event, next to the person's name.
See also
| Feature | What it does |
|---|---|
| OAuth | How the sign-in works and the Entra ID registrations behind it |
| Sharing with clients | The export with the gateway's address and the other clients' snippets |
| MCP gateways | Configuration and the governance controls |