Create an AI connection for Copilot Studio in AI Control Tower using the AI Service Graph Connector for Microsoft (version 3.1.7).
Copilot Studio prerequisites
Complete the following steps in your Power Platform environment before creating a Copilot connection.
Register an Application in Microsoft Entra ID
Register an application to obtain OAuth credentials for the connector.
To register the application:
Grant application access to your Copilot environment
Configure the application as a user in your Copilot environment.
To configure application access:
- Open the Power Platform admin Center.
- Navigate to Environments and select your Copilot environment.
- Go to Settings > Users + Permissions > Application users.
- Select New App User and add your application using the Client ID from step 1.
- Assign the following security roles to the application user:
- Basic User
- System administrator
If you don't want to create a System administrator role, you can create a Copilot Studio dataverse custom role. For custom role creation, see Create a Copilot Studio Dataverse custom role.
Note: You can obtain the Environment ID from Settings > Session details > Environment ID in your environment.
Multi-Environment Support
You can discover agents from multiple Copilot environments using a single connection. To configure multi-environment discovery:
- Enter multiple environment IDs as comma-separated values in the Environment ID field (examples: env-id-1, env-id-2, env-id-3).
- The same OAuth credentials (Client ID and Client Secret) are used for all environments.
- Verify that the application user is configured in each environment with the required security roles.
- Each environment will be tested and discovered separately during the import process.
Before you begin
Role required: sn_ai_disc.discovery_admin and sn_cmdb_int_util.sgc_admin
Procedure
-
Navigate to .
-
Select AI connector for Microsoft from the available connectors and then select Create connection.
-
Review setup instructions page displays.
Note: Verify to review the setup instructions and automation script.
-
Select I have read the setup instructions check box.
-
Select Continue.
Select authentication type page appears.
-
Choose the authentication type from the drop-down and select Submit.
-
Select Client credentials and skip to step 10.
-
Select Certificate-based authentication.
-
Create X.509 certificate:
Note: You can create a new certificate or use an existing one.
-
Select New.
-
Enter theName.
-
Enter the Key store password.
-
Select +Add file to add an attachment.
-
Select Save.
-
Select the newly created certificate and select Continue.
-
Create and test connection:
-
Under Select source systems select the Copilot check box.
-
Enter the Connection Name.
-
Enter the Tenant ID.
-
Enter the OAuth Client ID.
-
Enter the Keystore.
-
Enter the Keystore password.
-
Enter the Thumbprint.
-
Enter the Environment URLs.
Note: The Region and Resource name fields are optional. You can enter multiple Environment URLs by separating them with a comma.
-
Configure import schedule:
-
Open the Copilot scheduled job.
-
Verify that both the parent-scheduled jobs, Discovery and Execution are active as they’re shipped out inactive.
Note: Ensure to execute the Discovery-scheduled job first.
-
Select Run according to your preference.
-
To run frequency by demand, select Execute Now.
Note: This is an optional step as the schedule imports run according to the schedule.
-
Select Continue.
-
Select Confirm connection setup activity to verify whether the connection was configured.
Result
Select View all connections to review the connection details. The created connection appears in the Installed connections list.