Building and customizing solutions using Microsoft 365 Copilot APIs and tools
For agents in Copilot Studio that use connectors, the behavior depends on how the connector is added and how credentials are configured.
- To have knowledge sources use a shared (maker) connection instead of prompting each user for their own credentials:
- Configure the agent to use an authenticated channel as required for maker-provided credentials. For example, follow the guidance in Configure user authentication in Copilot Studio when publishing to channels.
- Ensure the connector tool or knowledge source is configured to use maker-provided credentials. For tools, this is done on the connector tool Overview page under Details > Additional details > Credentials to use, where Maker-provided credentials must be selected.
- Share the underlying connection with the users who will access the agent, granting them Can use + share permission so they can use the existing connection without creating their own:
- Go to
make.powerapps.com. - Select Connections.
- Select the Snowflake connection and choose Share.
- Add the target users and set Permission to Can use + share.
- Go to
- For using the Snowflake connector as a tool (for actions such as submitting SQL statements):
- Add the connector as a tool to the agent and configure it.
- On the connector tool Overview page, under Details > Additional details > Credentials to use, select Maker-provided credentials.
- Ensure the connection associated with that tool is the service principal–based connection and is shared with the intended users as described above.
- Limitations and channel considerations:
- Single sign-on (SSO) is not supported for connectors when an agent uses custom Active Directory authentication and is deployed to Microsoft Teams. In that configuration, users must authenticate to each connector manually, and the agent cannot rely on SSO. Ensure connections are correctly configured in Copilot Studio for the target channel.
These steps allow an agent to use a shared connector connection (such as a service principal) for both knowledge and tools, instead of requiring each user to authenticate individually, within the constraints of the channel’s authentication model.
References: