In Copilot Studio, how can I share/deploy an Agent that uses a Snowflake connector? We already set up the service principal account

Edward 86 Reputation points
2026-05-29T15:28:17.2433333+00:00

Hello,

We created an Agent and referred to the official Snowflake connector documentation to set up a service principal as well. The service principal account works well and we were able to add it (Snowflake database/schema) as Knowledge. When I tested the Agent or its connector (in Copilot Studio using 'Test Session' on the right side), I can provide a query and it successfully retrieve me data. So far so good... however:

  1. (Knowledge) When I deploy the Agent to a user and the person a asks a question (or provide a prompt) from Snowflake, they are asked to log in or authenticate. It doesn't seem to use the service principal account we set up... Is there a way to correct this issue?
  2. (Tools) I see that I can also use a Snowflake connector under 'Tools' ("Submit SQL Statement", "Check the Status...", and "Cancel the Execution of a Statement"). Is it possible to use the service principal account for this? I see 'Credentials to use' and set it to Maker-provided credentials but can't find a way
Microsoft Copilot | Microsoft 365 Copilot | Development
0 comments No comments

Answer accepted by question author

AI answer

2026-05-29T15:28:40.2466667+00:00

For agents in Copilot Studio that use connectors, the behavior depends on how the connector is added and how credentials are configured.

  1. To have knowledge sources use a shared (maker) connection instead of prompting each user for their own credentials:
    • Configure the agent to use an authenticated channel as required for maker-provided credentials. For example, follow the guidance in Configure user authentication in Copilot Studio when publishing to channels.
    • Ensure the connector tool or knowledge source is configured to use maker-provided credentials. For tools, this is done on the connector tool Overview page under Details > Additional details > Credentials to use, where Maker-provided credentials must be selected.
    • Share the underlying connection with the users who will access the agent, granting them Can use + share permission so they can use the existing connection without creating their own:
      1. Go to make.powerapps.com.
      2. Select Connections.
      3. Select the Snowflake connection and choose Share.
      4. Add the target users and set Permission to Can use + share.
    When configured this way, the agent uses the maker’s connection (for example, a service principal–based connection) rather than prompting each user to authenticate individually, subject to the authentication limitations of the channel.
  2. For using the Snowflake connector as a tool (for actions such as submitting SQL statements):
    • Add the connector as a tool to the agent and configure it.
    • On the connector tool Overview page, under Details > Additional details > Credentials to use, select Maker-provided credentials.
    • Ensure the connection associated with that tool is the service principal–based connection and is shared with the intended users as described above.
  3. Limitations and channel considerations:
    • Single sign-on (SSO) is not supported for connectors when an agent uses custom Active Directory authentication and is deployed to Microsoft Teams. In that configuration, users must authenticate to each connector manually, and the agent cannot rely on SSO. Ensure connections are correctly configured in Copilot Studio for the target channel.

These steps allow an agent to use a shared connector connection (such as a service principal) for both knowledge and tools, instead of requiring each user to authenticate individually, within the constraints of the channel’s authentication model.


References:

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

1 person found this answer helpful.

2 additional answers

Sort by: Newest
  1. Edward 86 Reputation points
    2026-05-29T16:59:41.46+00:00

    Thank you, it worked.

    I had to share the connection with a user and had to restart the computer.

    Was this answer helpful?

    0 comments No comments

  2. Edward 86 Reputation points
    2026-05-29T15:46:53.8266667+00:00

    The connection is set up and successful. For the 'Tools', I already configured the Snowflake connector to use 'Maker-provided credentials'. I also went to the Agent's Setting -> Connection Settings to confirm the connection is good (Green check).

    However, when i use the connector as 'Tools' to submit a SQL statement, it fails 400 or 401.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.