logo
search
Copilot License Issues

How to Configure Copilot Agent Licensing and Dataverse Permissions

Maira MehtabMaira Mehtab Sep 22, 2026 868 views

Question details

Organizations need guidance on licensing and securing internal Copilot agents connected to Dataverse, ensuring access is restricted by department and blocked from the public.

Product
Microsoft Copilot and Dataverse
Device & OS
not provided
Scenario
Deploying an internal Copilot agent while enforcing strict departmental access control and preventing unauthorized external access.
Observed behavior
Administrators must properly configure Copilot agent licenses, environment authentication, Microsoft Entra ID groups, and Dataverse security roles to define exact usage permissions.
Before you start

Ensure you have Power Platform Administrator or Global Administrator privileges in your Microsoft tenant to configure Dataverse roles and Microsoft Entra ID access groups.

Solution 1Recommended

Configure Microsoft Entra ID and Dataverse Security Roles

Use Microsoft Entra ID groups combined with Dataverse security roles to strictly control which departments can access the Copilot agent and its underlying data.

Internal Copilot agents rely on strict tenant-level policies. By mapping specific Entra ID groups to specialized Dataverse security roles, you ensure that only licensed employees within designated departments can interact with the agent.

1
Create Departmental Access Groups

Log in to the Microsoft Entra admin center, navigate to 'Groups', and create specific security groups for the departments (e.g., HR, Finance) that need access to the agent.

2
Assign Copilot Licenses

Navigate to 'Billing' > 'Licenses' in the Microsoft 365 admin center and assign the required Copilot agent licenses to the newly created departmental groups.

3
Configure Dataverse Security Roles

Open the Power Platform admin center, select your target Dataverse environment, go to 'Settings' > 'Users + permissions' > 'Security roles', and create custom roles restricting access to specific department tables.

4
Map Groups to Security Roles

In the same environment settings, navigate to 'Teams', create an Entra ID group team linking your department group, and assign the custom Dataverse security role to this team.

5
Disable Public Sharing

In your Copilot Studio or agent configuration settings, navigate to the 'Security' > 'Authentication' tab, select 'Require users to sign in', and ensure 'No authentication' (public sharing) is disabled.

6
Validate Access

Test the Copilot agent deployment using dedicated test accounts inside and outside the configured department groups to ensure the data boundary holds.

Tenant-specific Licensing Guidance: Since enterprise licensing models frequently update, it is highly recommended to consult the Microsoft Copilot Q&A forum or open a ticket with Microsoft Support for tenant-specific licensing questions.
Free Microsoft Office alternative

Experience Lightweight, AI-Powered Productivity with WPS Office

While configuring Microsoft Copilot and Dataverse environments requires complex enterprise licensing and permissions management, you can still enjoy powerful AI assistance for your daily document tasks with WPS Office. WPS Office is a free, lightweight, and highly compatible alternative to Microsoft Office that includes built-in AI tools for writing, summarizing, and data analysis without the steep learning curve.

  1. 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
  2. 2. Install WPS Office: Run the downloaded installation file and follow the quick on-screen setup prompts.
  3. 3. Launch and Explore AI Features: Open WPS Office, create a new document, and click the WPS AI button to start generating or summarizing content instantly.
Built-in WPS AI to help you draft, summarize, and analyze documents easily without complex enterprise setups.Fully compatible with Microsoft Office formats including Word (.docx), Excel (.xlsx), and PowerPoint (.pptx).Lightweight architecture ensures smooth performance even on older devices and operating systems.Completely free to use with a familiar tabbed interface for seamless migration.
QA img-9

Frequently Asked Questions

Do I need a premium license for every employee to use an internal Copilot agent?

Generally, users interacting with internal Copilot agents connected to enterprise data sources like Dataverse require an appropriate Copilot license. You should review your specific Microsoft 365 licensing agreement or check the Microsoft admin center for exact requirements.

How can I completely block public access to my Copilot agent?

You must disable public sharing in the agent's environment settings. Go to the authentication settings of the agent, require user sign-in via Microsoft Entra ID, and ensure that anonymous or unauthenticated access is explicitly turned off.

Can I limit Copilot responses so users only see their own department's data?

Yes. By configuring Dataverse security roles and assigning them to specific Microsoft Entra ID groups, Copilot will respect these data boundaries and only retrieve or generate responses based on the data the logged-in user is authorized to see.