logo
search
Copilot Permission Problems

How to Restrict Access to a Copilot Agent on a SharePoint Site

Maira MehtabMaira Mehtab Sep 22, 2026 869 views

Question details

The user needs to restrict access to a newly deployed Copilot Studio agent on a SharePoint site, ensuring only selected users or groups can interact with it during the testing phase.

Product
Microsoft SharePoint / Copilot Studio
Device & OS
not provided
Scenario
Testing a new Copilot Studio agent deployed to a SharePoint site before executing a wider organizational rollout.
Observed behavior
The deployed Copilot agent is currently accessible to everyone in the organization, lacking restricted user or group permissions for isolated testing.
Before you start

Ensure you have Site Owner privileges on the SharePoint site and Global or Teams Administrator rights in the Microsoft 365 Admin Center to modify user access and app deployment settings.

Solution 1Recommended

Restrict Access via SharePoint Site Permissions

Modify the permission levels of the specific SharePoint site or the agent file to control exactly who can view and interact with the Copilot agent.

If your agent is tied directly to a SharePoint site or specific document libraries, the easiest way to limit visibility is by adjusting the site's native access controls.

1
Navigate to Site Permissions

Open your SharePoint site, click the Settings gear icon in the top right corner, and select 'Site permissions'.

2
Review Current Access

Check if 'Everyone', 'Everyone except external users', or broad organizational groups are listed under Site Members or Site Visitors.

3
Remove Broad Permissions

Remove the broad groups from the site access list to ensure the site and its connected agent are no longer public.

4
Add Specific Testers

Click 'Share site' or 'Invite people', enter the email addresses of your specific testers or a dedicated testing group, and assign them the appropriate access level.

File-Level Permissions: You can also break permission inheritance on the specific agent file or document library to apply unique permissions without altering the entire site's access.
Free Microsoft Office alternative

Try WPS Office for Seamless Document Collaboration

While configuring complex access policies for Microsoft 365 agents, you might want a simpler, lightweight suite for your everyday document tasks. WPS Office provides excellent compatibility with Microsoft Office formats without the hefty licensing or complicated admin controls.

  1. 1. Download the Installer: Visit the official WPS Office website and click the free download button.
  2. 2. Install the Software: Run the downloaded installer file and follow the quick setup instructions.
  3. 3. Open Your Files: Launch WPS Office and seamlessly open or edit your existing Microsoft Office documents without format distortion.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight installation and an intuitive, familiar user interface.Built-in robust PDF editing, merging, and conversion tools.Free core features suitable for both individual productivity and seamless enterprise use.
microsoft office alternative - wps office

Frequently Asked Questions

Why is my Copilot agent visible to everyone by default?

When deploying an agent to a SharePoint site or via the admin center, it often defaults to 'Entire Organization' or inherits the broad site permissions. You must manually restrict this during the deployment configuration.

Can I restrict Copilot access to a single specific file instead of the whole site?

Yes, you can break permission inheritance on a specific document or library in SharePoint. By assigning unique permissions to that file, you limit who can trigger the Copilot agent on that content.

What admin roles are required to change Integrated Apps settings?

To manage Integrated Apps access in the Microsoft 365 Admin Center, you typically need to be assigned the Global Administrator, Application Administrator, or Teams Administrator role.

Will restricting access in SharePoint remove the app from Teams?

No, SharePoint permissions only control access to the site and files. If the agent is also published to Teams as an app, you must update the app assignment in the Microsoft 365 Admin Center or Teams Admin Center.