Building and customizing solutions using Microsoft 365 Copilot APIs and tools
The error indicates that the account trying to access Opal is not recognized as having Opal access, even though a group was configured. Focus on verifying group assignment and membership in the places that control Opal access.
Use these checks:
- Confirm Opal is enabled for the correct group in Microsoft 365
- A Global administrator must go to the Microsoft 365 admin center.
- Navigate to Copilot → Settings.
- Locate the user access setting Opal (Frontier).
- Verify that the Entra ID security group created for Opal is actually selected here.
- If a different group is selected, add the intended group or move the user into the group that is configured.
- Verify the user is really in the group that has Opal access
- In the Microsoft Entra admin center, go to Entra ID → Groups → All groups.
- Open the group that is configured under Opal (Frontier) in the Microsoft 365 admin center.
- Select Members and confirm the Copilot user account is listed.
- If using a dynamic group, check Dynamic membership rules and ensure the user meets the rule criteria.
- Ensure the group owner is also in the group
The Opal FAQ notes that if a user sees a "You don't have access" message, it is necessary to:
- Verify the user is part of the correct security group included in the Microsoft 365 admin center setting.
- Ensure the owner of the security group is also a member of that group. If the group owner is not a member, add the owner as a member and wait a short period, then sign out and sign back in.
- Sign out and sign in again
After any change (group membership or Opal (Frontier) setting):
- Sign out of all Microsoft 365 sessions for that user.
- Close all browser windows.
- Open a new private/incognito session and sign back in, then try accessing Opal Center again from the Microsoft 365 Copilot app under Frontier.
If the message persists, re-check that:
- The exact group that appears under Opal (Frontier) in the Microsoft 365 admin center is the same group where the user is a member.
- There are no typos or multiple similarly named groups.
References: