How to Restrict Access to a Copilot Agent on a SharePoint Site
Question details
The user needs to restrict access to a newly deployed Copilot Studio agent on a SharePoint site, ensuring only selected users or groups can interact with it during the testing phase.
- Product
- Microsoft SharePoint / Copilot Studio
- Device & OS
- not provided
- Scenario
- Testing a new Copilot Studio agent deployed to a SharePoint site before executing a wider organizational rollout.
- Observed behavior
- The deployed Copilot agent is currently accessible to everyone in the organization, lacking restricted user or group permissions for isolated testing.
Ensure you have Site Owner privileges on the SharePoint site and Global or Teams Administrator rights in the Microsoft 365 Admin Center to modify user access and app deployment settings.
Restrict Access via SharePoint Site Permissions
Modify the permission levels of the specific SharePoint site or the agent file to control exactly who can view and interact with the Copilot agent.
If your agent is tied directly to a SharePoint site or specific document libraries, the easiest way to limit visibility is by adjusting the site's native access controls.
Open your SharePoint site, click the Settings gear icon in the top right corner, and select 'Site permissions'.
Check if 'Everyone', 'Everyone except external users', or broad organizational groups are listed under Site Members or Site Visitors.
Remove the broad groups from the site access list to ensure the site and its connected agent are no longer public.
Click 'Share site' or 'Invite people', enter the email addresses of your specific testers or a dedicated testing group, and assign them the appropriate access level.
Manage Access via Microsoft 365 Admin Center
Use the Microsoft 365 Admin Center to adjust Integrated Apps settings and limit agent availability to specific users.
Try WPS Office for Seamless Document Collaboration
While configuring complex access policies for Microsoft 365 agents, you might want a simpler, lightweight suite for your everyday document tasks. WPS Office provides excellent compatibility with Microsoft Office formats without the hefty licensing or complicated admin controls.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button.
- 2. Install the Software: Run the downloaded installer file and follow the quick setup instructions.
- 3. Open Your Files: Launch WPS Office and seamlessly open or edit your existing Microsoft Office documents without format distortion.

Frequently Asked Questions
Why is my Copilot agent visible to everyone by default?
When deploying an agent to a SharePoint site or via the admin center, it often defaults to 'Entire Organization' or inherits the broad site permissions. You must manually restrict this during the deployment configuration.
Can I restrict Copilot access to a single specific file instead of the whole site?
Yes, you can break permission inheritance on a specific document or library in SharePoint. By assigning unique permissions to that file, you limit who can trigger the Copilot agent on that content.
What admin roles are required to change Integrated Apps settings?
To manage Integrated Apps access in the Microsoft 365 Admin Center, you typically need to be assigned the Global Administrator, Application Administrator, or Teams Administrator role.
Will restricting access in SharePoint remove the app from Teams?
No, SharePoint permissions only control access to the site and files. If the agent is also published to Teams as an app, you must update the app assignment in the Microsoft 365 Admin Center or Teams Admin Center.




