How to Configure Copilot Agent Licensing and Dataverse Permissions
Question details
Organizations need guidance on licensing and securing internal Copilot agents connected to Dataverse, ensuring access is restricted by department and blocked from the public.
- Product
- Microsoft Copilot and Dataverse
- Device & OS
- not provided
- Scenario
- Deploying an internal Copilot agent while enforcing strict departmental access control and preventing unauthorized external access.
- Observed behavior
- Administrators must properly configure Copilot agent licenses, environment authentication, Microsoft Entra ID groups, and Dataverse security roles to define exact usage permissions.
Ensure you have Power Platform Administrator or Global Administrator privileges in your Microsoft tenant to configure Dataverse roles and Microsoft Entra ID access groups.
Configure Microsoft Entra ID and Dataverse Security Roles
Use Microsoft Entra ID groups combined with Dataverse security roles to strictly control which departments can access the Copilot agent and its underlying data.
Internal Copilot agents rely on strict tenant-level policies. By mapping specific Entra ID groups to specialized Dataverse security roles, you ensure that only licensed employees within designated departments can interact with the agent.
Log in to the Microsoft Entra admin center, navigate to 'Groups', and create specific security groups for the departments (e.g., HR, Finance) that need access to the agent.
Navigate to 'Billing' > 'Licenses' in the Microsoft 365 admin center and assign the required Copilot agent licenses to the newly created departmental groups.
Open the Power Platform admin center, select your target Dataverse environment, go to 'Settings' > 'Users + permissions' > 'Security roles', and create custom roles restricting access to specific department tables.
In the same environment settings, navigate to 'Teams', create an Entra ID group team linking your department group, and assign the custom Dataverse security role to this team.
In your Copilot Studio or agent configuration settings, navigate to the 'Security' > 'Authentication' tab, select 'Require users to sign in', and ensure 'No authentication' (public sharing) is disabled.
Test the Copilot agent deployment using dedicated test accounts inside and outside the configured department groups to ensure the data boundary holds.
Experience Lightweight, AI-Powered Productivity with WPS Office
While configuring Microsoft Copilot and Dataverse environments requires complex enterprise licensing and permissions management, you can still enjoy powerful AI assistance for your daily document tasks with WPS Office. WPS Office is a free, lightweight, and highly compatible alternative to Microsoft Office that includes built-in AI tools for writing, summarizing, and data analysis without the steep learning curve.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install WPS Office: Run the downloaded installation file and follow the quick on-screen setup prompts.
- 3. Launch and Explore AI Features: Open WPS Office, create a new document, and click the WPS AI button to start generating or summarizing content instantly.

Frequently Asked Questions
Do I need a premium license for every employee to use an internal Copilot agent?
Generally, users interacting with internal Copilot agents connected to enterprise data sources like Dataverse require an appropriate Copilot license. You should review your specific Microsoft 365 licensing agreement or check the Microsoft admin center for exact requirements.
How can I completely block public access to my Copilot agent?
You must disable public sharing in the agent's environment settings. Go to the authentication settings of the agent, require user sign-in via Microsoft Entra ID, and ensure that anonymous or unauthenticated access is explicitly turned off.
Can I limit Copilot responses so users only see their own department's data?
Yes. By configuring Dataverse security roles and assigning them to specific Microsoft Entra ID groups, Copilot will respect these data boundaries and only retrieve or generate responses based on the data the logged-in user is authorized to see.




