To control what Copilot Studio agents can access and where they can be published, combine a Power Platform environment strategy with data policies created in the Power Platform admin center under Security > Data and privacy > Data policy. Route makers out of the default environment into managed developer environments, build production agents in dedicated environments, and in each policy block the Copilot Studio virtual connectors you don't want, such as Chat without Microsoft Entra ID authentication in Copilot Studio, Knowledge source with public websites and data in Copilot Studio, HTTP and specific channels.
Who this is for and what you will have at the end
This guide is for Power Platform and Microsoft 365 administrators who need to let people build agents without letting those agents publish unauthenticated chat, ground on arbitrary websites or call any API.
At the end you will have:
- An environment layout with a locked-down default environment, routed developer environments and dedicated production environments.
- Data policies that govern Copilot Studio authentication, knowledge sources, connectors, HTTP, skills and channels.
- Endpoint filtering for allowed SharePoint sites, websites and HTTP endpoints.
- A way to find agents that violate policy before they break in production.
How data policies govern agents
Data policies, previously called DLP policies, classify connectors into three data groups: Business, Non-business and Blocked. Connectors in the same group can share data; connectors in different groups can't be used together; blocked connectors can't be used at all.
Copilot Studio adds virtual connectors that don't call a REST API but switch agent features on and off. Blocking one prevents makers from publishing an agent that uses that feature. Key points:
- Enforcement is real time and applies to all tenants. Since early 2025, exemptions are no longer supported.
- Connectors introduced after 2019, including Chat without Microsoft Entra ID authentication in Copilot Studio and Direct Line channels in Copilot Studio, are likely to land in the default Non-business group. If your policies block the non-business group by default, these features break.
- When a policy changes, existing apps, flows and agents are re-evaluated; violating resources are suspended and connections to blocked connectors are disabled. Full enforcement usually takes under an hour and can take up to 24 hours in large tenants.
- Microsoft says the Copilot Studio virtual connectors are evolving into dedicated governance rules, and advanced connector policies don't support virtual connectors. Data policies remain the control for them today.
Prerequisites
| Task | Role |
|---|---|
| Tenant-level data policies, environment routing, environment groups | Power Platform Administrator |
| Environment-level data policy | Environment Admin, or System Administrator for environments with Dataverse |
| Configure Copilot Studio data policies | Tenant admin or Environment Admin |
Environment admins can't edit or delete policies created by a tenant admin, and environment-level policies can't override tenant-wide policies. Environment groups and environment routing require managed environments, which are a premium capability: users need premium licenses to run assets in managed developer environments.
Step 1: Design the environment layout
Environments are the security boundary for agents, their connections and their Dataverse data. The following layout follows the environment groups in Microsoft's adoption guidance (Development, Shared Development, UAT and Production, plus a restricted default environment); the data policy column is a suggested starting point rather than a Microsoft default:
| Tier | Environment type | Purpose | Data policy stance |
|---|---|---|---|
| Personal productivity | Default (renamed, for example "Personal Productivity") | Microsoft 365 customizations | Strictest: unblockable connectors only |
| Development | Developer, created by environment routing, in a "Development" environment group | Each maker's isolated workspace | Tenant-level policy only |
| Shared development | Sandbox or production | Projects with several makers | Project-specific policy |
| Test | Sandbox | User acceptance testing | Same policy as production |
| Production | Production, managed | Published agents | Explicit allow list for the agent's needs |
Notes that matter for Copilot Studio:
- Use a non-default production environment for agents you deploy to production.
- An environment needs a Dataverse database and a supported region to appear in the Copilot Studio environment switcher.
- Don't build agents in the Microsoft Copilot Chat environment; it exists for billing Microsoft 365 scenarios and isn't shown in Copilot Studio.
- Trial environments expire after 30 days and their agents are deleted. Convert them to production if the work must be kept.
- Restrict creation of new production environments to admins and handle requests through a form or the CoE Starter Kit.
Environment groups
Create groups such as Development, Shared Development, UAT and Production. An environment must be managed to join a group and can be in only one group. Group rules, for example sharing limits, usage insights, maker welcome content, solution checker enforcement and backup retention, lock the corresponding environment settings so an environment admin can't override them.
Environment groups don't have a rule that applies a data policy. Align them by naming: create a data policy with the same name as each group and scope it to that group's environments.
Step 2: Turn on environment routing
Environment routing sends makers to their own personal developer environment when they open Copilot Studio, Power Apps or Power Automate, instead of the default environment.
- In the Power Platform admin center, select Manage > Tenant settings > Environment routing.
- Under Turn on environment routing for, select the product portals, including Copilot Studio.
- Select New rule, name it, apply it to Everyone or to specific security groups, and choose the environment group (for example Development) that new developer environments join.
- Order the rules with the arrow icons; the first matching rule wins. Select Save.
Routed environments are managed, makers become admins of their own environment, and the preconfigured settings include sharing limited to five individuals with no security group sharing, solution checker set to Warn and usage insights on. No specific data policy is assigned to routed environments: they inherit your tenant-level data policies. That's why a sensible tenant-wide baseline matters.
Step 3: Lock down the default environment
Microsoft's guidance for the default environment is to block new connectors and restrict makers to basic, unblockable connectors:
- In the Power Platform admin center, go to Security > Data and privacy > Data policy and select + New Policy. Name it, for example, "Default environment - personal productivity".
- On Prebuilt connectors, move every unblockable connector to Business and every blockable connector to Blocked. Unblockable connectors include SharePoint, OneDrive for Business, Microsoft Teams, Microsoft 365 Outlook, Dataverse, Approvals and Microsoft Copilot Studio.
- Use Set default group to decide where future connectors land. Microsoft's general recommendation is to keep Non-business as the default and classify new connectors after review; for a default environment where you block everything blockable, decide deliberately and document it.
- On Custom connectors, add a rule that blocks all URL patterns (the
*entry, which defaults to Ignore). - On Scope, choose Add multiple environments and select only the default environment.
- Review and select Create policy.
This blocks the Copilot Studio virtual connectors too, so agents can't be published from the default environment.
Step 4: Create the production agent policy
For production environments, classify the Copilot Studio connectors according to what each agent legitimately needs:
| To prevent makers from... | Block this connector |
|---|---|
| Publishing agents without authentication | Chat without Microsoft Entra ID authentication in Copilot Studio |
| Using uploaded local files as knowledge | Knowledge source with documents in Copilot Studio |
| Using SharePoint or OneDrive as knowledge | Knowledge source with SharePoint and OneDrive in Copilot Studio |
| Using public websites as knowledge | Knowledge source with public websites and data in Copilot Studio |
| Making HTTP requests from topics | HTTP |
| Using skills | Skills with Copilot Studio |
| Connecting to Application Insights | Application Insights in Copilot Studio |
| Publishing to Direct Line (demo website, custom websites, mobile apps) | Direct Line channels in Copilot Studio |
| Publishing to Teams and Microsoft 365 | Microsoft Teams + Microsoft 365 Channel in Copilot Studio |
| Publishing to SharePoint, Facebook, WhatsApp or Dynamics 365 Customer Service | SharePoint channel, Facebook channel, WhatsApp channel or Omnichannel in Copilot Studio |
| Using a Power Platform connector as a tool | That connector (this also blocks MCP server tools that rely on it) |
Two cautions. Blocking Knowledge source with documents in Copilot Studio only stops local uploads; it doesn't block SharePoint or OneDrive files. And an agent must have at least one allowed channel, or it can't be published.
Also keep the connectors one agent uses together in the same data group. A Business-classified SharePoint connector and a Non-business HTTP connector in the same agent is a violation even though neither is blocked.
Allow only specific endpoints
Instead of blocking a connector outright, use endpoint filtering for HTTP, Knowledge source with public websites and data in Copilot Studio and Knowledge source with SharePoint and OneDrive in Copilot Studio:
- On Assign connectors, select the three dots next to the connector.
- Select Configure connector > Connector endpoints.
- Add the allowed or denied endpoints or patterns, such as the specific SharePoint sites an HR agent may ground on, and select Save. Check the connector endpoint filtering documentation for the pattern syntax each connector accepts.
On the Define scope page, choose Add multiple environments for the production group's environments, or Exclude certain environments when building a tenant-wide baseline.
Step 5: Keep the number of policies small
All policies that apply to an environment are evaluated together. Blocked in any policy wins. For Business and Non-business, each additional policy splits the connector space further: three policies can fragment connectors into eight groups, and only connectors in the same resulting group can be combined. Microsoft recommends applying as few data policies as possible to any environment. A practical pattern is one tenant-wide baseline plus one policy per environment group.
Step 6: Point makers to help
Data policy errors in Copilot Studio can show a contact email and a "Learn more" link. Set them with the Power Apps administration module; the setting applies to all Power Platform apps in the tenant.
Install-Module -Name Microsoft.PowerApps.Administration.PowerShell -Scope CurrentUser
Add-PowerAppsAccount
$ContactDetails = [pscustomobject] @{ Enabled = $true; Email = "powerplatform-admins@contoso.com" }
$ErrorMessageDetails = [pscustomobject] @{ Enabled = $true; Url = "https://contoso.sharepoint.com/sites/governance/agents" }
$ErrorSettingsObj = [pscustomobject] @{ ErrorMessageDetails = $ErrorMessageDetails; ContactDetails = $ContactDetails }
New-PowerAppDlpErrorSettings -TenantId "<tenant ID>" -ErrorSettings $ErrorSettingsObj
# Review existing data policies
Get-DlpPolicyUse Set-PowerAppDlpErrorSettings with the same object to update an existing configuration.
Verify enforcement
- Open Copilot Studio in a production environment and try to add a blocked knowledge source or channel. Blocked capabilities appear disabled, with a hover explanation.
- Add an HTTP request node to a topic in an environment where HTTP is blocked, save and try to publish. An error banner with Details appears, and Publish is unavailable.
- On the Channels page, expand the error and select Download. The workbook has a DLP violations sheet (policy name, policy ID, connector and data group) and a Blocked channels sheet.
- Confirm that an agent with No authentication can't be published where the unauthenticated chat connector is blocked.
- Allow up to 24 hours for enforcement in large tenants before concluding a policy isn't working.
Troubleshooting
| Symptom or message | Cause and fix |
|---|---|
| "You have errors in your draft that will prevent publishing. Due to a recent data policy change..." | A policy now blocks something the agent uses. Download the violations and adjust the agent or the policy. |
| "You need to configure at least one channel (for example, Teams) due to recent data policy changes." | All configured channels are blocked. Allow one channel or configure an allowed one. |
Raw error shows DlpViolationError with violationType BlockedConnector | "At least one connector here has been blocked by your admin." Unblock it or remove it from the agent. |
| Users see "Error code: DataLossPreventionViolation" | The published agent violates a policy. Fix the violation and republish. |
| Website or Direct Line deployment broke after a policy change | Direct Line channels in Copilot Studio sits in a blocked or different data group, often via the default group. Reclassify it in the relevant policy. |
| Environment missing from the Copilot Studio switcher | No Dataverse database, or an unsupported region. |
| Environment admin can't change a policy | It's a tenant-level policy; only a Power Platform Administrator can edit it. |
The CoE Starter Kit Power BI dashboard lists agents and environments, which helps find affected agents before a policy change.
Closing checklist
- Default environment renamed and covered by a strict data policy, including a block-all custom connector rule.
- Environment routing on for Copilot Studio, routing into a managed Development group.
- Production agents in dedicated, managed, non-default environments created by admins.
- Unauthenticated chat, unneeded knowledge sources, HTTP, skills and unused channels blocked per environment group, with endpoint filtering where partial access is needed.
- At most a baseline plus one policy per environment.
- Error contact and Learn more link configured.
- Agent interactions monitored in DSPM for AI, and external knowledge brought in through Copilot connectors with source permissions intact.
References
- https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention
- https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-dlp-troubleshooting
- https://learn.microsoft.com/en-us/microsoft-copilot-studio/environments-first-run-experience
- https://learn.microsoft.com/en-us/power-platform/admin/wp-data-loss-prevention
- https://learn.microsoft.com/en-us/power-platform/admin/prevent-data-loss
- https://learn.microsoft.com/en-us/power-platform/admin/dlp-connector-classification
- https://learn.microsoft.com/en-us/power-platform/admin/dlp-combined-effect-multiple-policies
- https://learn.microsoft.com/en-us/power-platform/admin/default-environment-routing
- https://learn.microsoft.com/en-us/power-platform/guidance/adoption/environment-strategy
- https://learn.microsoft.com/en-us/power-platform/admin/powerapps-powershell