Skip to main content

Microsoft Copilot Studio

The Microsoft Copilot Studio integration works in two ways:

PartWhat it doesWhere you set it up
Runtime threat detectionCopilot Studio asks QuilrAI to allow or block each tool execution.An LLM Gateway app plus Power Platform admin center (see Runtime threat detection)
Inventory and activityDiscovers Copilot Studio agents, their Dataverse definitions, capabilities, governance, and sanitized activity metadata.Settings › Integrations, Microsoft Copilot Studio card

Inventory and activity​

Where it shows up​

  • Overview › Agentic estate: under Connected platforms.
  • Agents: the Microsoft Copilot Studio source chip.
  • Graph: the Copilot chip.

Set it up​

On the Library tab of Settings › Integrations, click Install on the Microsoft Copilot Studio card and fill in:

FieldWhat to enter
Integration nameA tenant-visible name for this installation. Required.
Microsoft tenantYour Microsoft tenant name or directory ID.
Environment scopeThe Power Platform environment this connection covers.
Dataverse URLThe Dataverse environment URL for that environment.
Credential referenceOptional, non-secret identity reference. Do not enter a client secret, token or API key.

Check that it works​

The card shows INSTALLED on the Installed tab, and Copilot Studio agents appear on Agents under the Microsoft Copilot Studio source chip.

Permissions for runtime threat detection​

WhoGrants
A Microsoft 365 or Power Platform admin (an Entra ID role that can grant tenant-wide admin consent)Admin consent for the QuilrAI Microsoft Entra application. See Admin consent.
A Power Platform adminTurns on additional threat detection for each environment in Power Platform admin center.
A QuilrAI admin who can create LLM Gateway appsCreates the copilot_studio app and key.

Threat detection is configured per Power Platform environment: repeat the Power Platform steps for each environment whose agents you want to protect.

Runtime threat detection​

Copilot Studio calls QuilrAI before a tool executes. QuilrAI scans the user's recent prompt context and proposed tool inputs, then returns an allow/block decision. This integration checks content without forwarding an LLM request to a provider.

When to use it​

Use the Copilot Studio integration when you want to:

  • Block sensitive data before a Copilot tool receives it
  • Prevent risky tool inputs generated from a user prompt
  • Log Copilot tool-execution checks alongside other QuilrAI gateway logs
  • Apply the same PII, PHI, PCI, financial, adversarial, and custom-intent policies you use elsewhere

Microsoft external threat detection is called for generative agents that use generative orchestration. Microsoft skips this flow for classic agents.

Endpoint​

Create a QuilrAI key with provider copilot_studio, then use the closest regional endpoint as the external threat detection base URL:

https://guardrails-usa-2.quilr.ai/copilot_studio/sk-quilr-xxx

The example uses US East. Choose the nearest regional base URL for your tenant:

EndpointRegionEndpoint base
Global (auto-routed)Nearesthttps://guardrails.quilr.ai/copilot_studio/sk-quilr-xxx
USA 1US Central Westhttps://guardrails-usa-1.quilr.ai/copilot_studio/sk-quilr-xxx
USA 2US Easthttps://guardrails-usa-2.quilr.ai/copilot_studio/sk-quilr-xxx
India 1Mumbaihttps://guardrails-india-1.quilr.ai/copilot_studio/sk-quilr-xxx
India 2Mumbaihttps://guardrails-india-2.quilr.ai/copilot_studio/sk-quilr-xxx
JapanTokyohttps://guardrails-jp-1.quilr.ai/copilot_studio/sk-quilr-xxx
EuropeEuropehttps://guardrails-europe-1.quilr.ai/copilot_studio/sk-quilr-xxx

Treat this URL as a secret. The QuilrAI key is part of the path because Copilot Studio controls the webhook request format.

Routes​

Copilot Studio appends these paths to the endpoint base:

RoutePurpose
POST /validateChecks that the QuilrAI endpoint is reachable and ready.
POST /analyze-tool-executionSends proposed tool execution context for allow/block evaluation.

For example, if the endpoint base is https://guardrails-usa-2.quilr.ai/copilot_studio/sk-quilr-xxx, Copilot Studio calls:

https://guardrails-usa-2.quilr.ai/copilot_studio/sk-quilr-xxx/validate
https://guardrails-usa-2.quilr.ai/copilot_studio/sk-quilr-xxx/analyze-tool-execution

Copilot Studio may also include an api-version query parameter. QuilrAI ignores unknown query parameters.

A Microsoft 365 or Power Platform admin must grant tenant-wide consent to the QuilrAI Microsoft Entra application before the organization can use the QuilrAI Copilot Studio integration.

Grant admin consent

Use this same Microsoft Entra App ID when Power Platform asks for the Azure Entra App ID:

54abe80d-4f95-4e44-a19a-d360e5cdb617

Power Platform setup​

  1. In QuilrAI, open Settings > LLM Gateway > Create App, choose App-only credentials and select the Copilot Studio tile (guardrails only, no models).
  2. Copy the full endpoint base URL, including the sk-quilr-... key.
  3. Have a Microsoft 365 or Power Platform admin grant tenant-wide consent for the QuilrAI Copilot Studio integration.
  4. Open Power Platform admin center.
  5. Go to Security and then Threat detection.
  6. Select Additional threat detection.
  7. Select the environment, then select Set up.
  8. Enable Allow Copilot Studio to share data with a threat detection provider.
  9. Enter the QuilrAI Microsoft Entra App ID: 54abe80d-4f95-4e44-a19a-d360e5cdb617.
  10. Enter the QuilrAI endpoint base URL as the endpoint link.
  11. Choose the Power Platform error behavior and save.
  12. Verify: Power Platform calls the /validate route when you save. Then run a test agent with a tool and a prompt containing a harmless test value your policy blocks, and check that the tool call is blocked and the check appears in your LLM Gateway logs.

Microsoft documents the setup flow in Enable external threat detection and protection for Copilot Studio custom agents. Their webhook contract is documented in Build a runtime threat detection system for Copilot Studio agents.

What QuilrAI scans​

For analyze-tool-execution, QuilrAI scans:

  • Recent user messages from plannerContext.chatHistory
  • plannerContext.userMessage when chat history does not provide user text
  • Scalar values inside inputValues, including nested object and array values

QuilrAI stores Copilot metadata for review, including conversation ID, tool name, tool ID, correlation ID, and user/tenant identifiers when Copilot provides them.

If Copilot includes a bearer token, QuilrAI uses available claims such as email, preferred_username, upn, oid, sub, and tid for identity-aware logging. The webhook is authenticated by the QuilrAI key in the endpoint path.

Decision behavior​

QuilrAI resultCopilot response
Allowed or monitored{"blockAction": false}
Blocked{"blockAction": true, "reasonCode": 112, ...}
Redacted or partial-redactedBlocked
No user input/tool values foundAllowed with reason: "no_user_input"
DLP timeout/internal errorAllowed with fail-open diagnostics

Copilot Studio expects a fast decision. QuilrAI returns a fail-open allow decision on DLP timeout or internal DLP errors so the agent can continue during temporary guardrail service interruptions.

Redaction-style actions become blocks because Copilot Studio cannot accept rewritten tool input from the external threat detection response. Use monitor actions for detections you want to observe without blocking.

Response examples​

Allow:

{
"blockAction": false
}

Block:

{
"blockAction": true,
"reasonCode": 112,
"reason": "content_blocked",
"diagnostics": "{\"reason\":\"content_blocked\",\"categories\":[\"email\"]}"
}

Validation:

{
"isSuccessful": true,
"status": "OK"
}

Troubleshooting​

ErrorCause
Invalid Copilot Studio API key in pathThe endpoint URL does not include a valid sk-quilr-* key.
The provided Copilot Studio API key is invalid or has been revokedThe key was deleted or does not exist.
The provided Copilot Studio API key has expiredThe QuilrAI key has expired.
This endpoint requires a copilot_studio API keyThe key exists but was created for another provider.
Power Platform cannot save the endpointCheck the endpoint URL, Microsoft Entra app configuration, and Power Platform admin permissions.