Configure the environment
Set up the external-provider connection for the intended Power Platform environment and establish the documented authenticated provider contract.
Add an independent action decision through Microsoft’s external threat-detection provider integration.
A Copilot Studio agent can select a legitimate tool for an inappropriate operation. Business policy needs the proposed action context while the platform can still stop execution.
Set up the external-provider connection for the intended Power Platform environment and establish the documented authenticated provider contract.
For generative agents using generative orchestration, the external-provider path requests an allow-or-block decision before proposed tool execution.
Test the chosen agents and tools, review the returned decisions, and verify error behaviour before expanding the deployment.
Retain Microsoft-native identity, permissions, prompt protections and platform governance. For Copilot Studio workflows using MCP tools, separately identify where provider checks and MCP gateway checks apply.
Try a local scenario, then bring your workflow to a deployment review. Start with one agent and one tool, and see exactly where the action can be stopped.