To use SharePoint as knowledge in Copilot Studio, open the agent, select Add knowledge, choose SharePoint in the Featured section, and enter the site or folder URL; the agent then searches that location and its subfolders through Microsoft Graph, using the signed-in user's permissions. When the agent can't answer from SharePoint, it fails silently, so check authentication and scopes, the user's read access, Microsoft Search indexing, file type and size limits, encrypted files and Restricted SharePoint Search, in that order.
Who this is for and what you will have at the end
This guide is for Copilot Studio makers and the Microsoft 365 or Entra administrators who support them. It covers the fully integrated SharePoint knowledge option, which grounds generative answers on SharePoint pages and documents and respects permissions per user.
At the end you will have:
- An agent grounded on one or more SharePoint sites, with the authentication option that matches its channels.
- A working app registration and scope list for agents that use manual authentication.
- Optional SharePoint list knowledge and search filters.
- A troubleshooting sequence for the "no response" behavior, including the fixes Microsoft documents for each cause.
If the agent identity itself needs governance, see the companion guide on governing Copilot Studio agents with Microsoft Entra Agent ID.
How SharePoint knowledge works
When a user asks something that no topic handles, the agent runs a search against the registered SharePoint URL and all its subpaths. Copilot Studio uses Microsoft Search indexing, takes the top three search results, and summarizes them into a response with citations. A few behaviors follow from that design:
- The agent only sees what the user can open. Calls are made on behalf of the user chatting with the agent. At minimum the user needs Read permission on the site or list. Without it, the agent returns no results and no error.
- Scope is the URL you register. The agent never reads parent folders, sibling folders or other sites unless you add them separately. Hyperlinks inside a registered page or document aren't followed either.
- Search drives everything. If SharePoint search can't find a document, neither can the agent.
- Sensitivity labels trim results, but encryption blocks grounding. The agent surfaces only label-permitted content, and it can't extract content from files protected by encrypting labels, Double Key Encryption or passwords. Those files can show as Ready and still produce no response.
There are two SharePoint options in the Add knowledge dialog. The SharePoint tile in Featured is the integrated option covered here. The SharePoint option in the Upload file section uploads individual files or folders and synchronizes them, and it's also where SharePoint lists are added.
Prerequisites and limits
| Item | Requirement or limit |
|---|---|
| User permission | At least Read on the site, library or list |
| Site URLs | Up to 25 SharePoint site URLs per agent with generative orchestration |
| URL format | sharepoint.com domain; omit https:// |
| Supported files | Word (DOC, DOCX), PowerPoint (PPT, PPTX) and PDF |
| Pages | Modern pages only; modern pages with SPFx components, classic ASPX pages, accordion navigation and custom CSS aren't used |
| File size | Under 7 MB without a Microsoft 365 Copilot license in the tenant; up to 200 MB with a license and tenant graph grounding turned on |
| Guests | Not supported for SharePoint generative answers in SSO-enabled apps |
| Tenant setting | Restricted SharePoint Search must not block the sites |
Some question types can't be answered at all. Queries that reference a file by name ("what does file-name.pdf say"), ask for file counts or folder listings, or filter on column metadata aren't supported. Structured files such as XLSX can be added, but the agent can't write and run code, so analytical answers might be weak.
Step 1: Choose the authentication option
Authentication decides whether the agent can read SharePoint at all. Configure it under Settings > Security > Authentication, and remember that changes only take effect after you publish.
| Option | SharePoint knowledge | Channels | Notes |
|---|---|---|---|
| No authentication | Doesn't work | Any | The agent doesn't retrieve SharePoint information |
| Authenticate with Microsoft | Works, no app registration | Teams + Microsoft 365 (also Power Apps and Microsoft Copilot) | Default for new agents; required for tenant graph grounding with semantic search |
| Authenticate manually | Works with Entra ID providers | Other channels such as a custom website | Requires an app registration and the SharePoint scopes; Generic OAuth 2 isn't supported for SharePoint |
Agents created in Copilot Studio and in Teams default to Authenticate with Microsoft. The Teams + Microsoft 365 channel only supports that option; choosing anything else blocks the channel. If a previously published agent used manual authentication and you switch it back for Teams, republish it. The change can take a few hours to reach users, and typing "start over" in the chat forces the latest version.
Step 2: Add the SharePoint site
- Open the agent and select Add knowledge from the Overview or Knowledge page.
- In Featured, select SharePoint.
- Enter the URL. Separate several URLs with Shift + Enter. You can also insert a Custom, System or Environment variable to resolve the URL at runtime.
- Enter a name and a detailed description. With generative orchestration, the description is how the orchestrator decides when to use this source.
- Select Add to agent.
Register the narrowest path that contains the content, such as a specific document library folder, rather than the root of a large site. If someone renames the site or folder later, the link can break; ask the SharePoint administrator to confirm permissions on the new location and update the knowledge source with the new link.
Step 3: Add SharePoint lists (optional)
Lists are ingested into Dataverse and indexed, with a live connection so queries use current data.
- Select Add knowledge, then SharePoint in the Upload file section.
- Select Browse items to pick from My Lists and Recent Lists, or paste a list URL. A shared list that doesn't appear in Recent Lists can be added by URL, or by opening it in SharePoint once.
- Select the lists, choose Confirm selection, add a name and description, and select Add to agent.
Microsoft recommends no more than 10 lists per agent for the best results. Lists over 35,000 rows reduce quality and increase latency, and list queries only return data from the first 2,048 rows. Document libraries aren't supported as lists, list views can't be selected, and the Attachments column isn't reasoned over. Dataverse search must be turned on in the environment.
Step 4: Turn on tenant graph grounding when you can
The Tenant graph grounding with semantic search setting on the agent's Generative AI settings page uses the semantic index to retrieve more context with better precision. It needs:
- Generative orchestration turned on.
- Authenticate with Microsoft as the authentication option. With any other option the setting can't be changed.
- A Microsoft 365 Copilot license assigned to at least one user in the same tenant, so a semantic index exists.
Users who have Microsoft 365 Copilot licenses already use it by default. Turning it on extends it to unlicensed users at an extra cost billed in Copilot Credits. It also raises the SharePoint file limit to 200 MB. If the tenant has no Copilot license, or response quality drops, turn it off. The Copilot license assignment checklist covers getting those licenses in place.
Step 5: Configure manual authentication for other channels
Use this when the agent is published somewhere other than Teams and Microsoft 365. You need an admin account in the same tenant as the agent.
Create the app registration
- In the Azure portal, go to App registrations > New registration. Create a new registration; don't reuse an existing one.
- Select Accounts in this organizational directory only (single tenant), leave Redirect URI blank, and select Register.
- Copy the Application (client) ID.
- Under Authentication, select Add a platform > Web and enter the redirect URI. For Europe, use the
europe.token.botframework.comhost instead. You can also copy the value from the Redirect URL box in Copilot Studio.
https://token.botframework.com/.auth/web/redirect- Select both Access tokens (used for implicit flows) and ID tokens (used for implicit and hybrid flows), then Configure.
Add credentials
Microsoft recommends federated credentials, which avoid stored secrets:
- In Copilot Studio, go to Settings > Security > Authentication and select Authenticate manually. Leave Require users to sign in on.
- Set Service provider to Microsoft Entra ID V2 with federated credentials and enter the client ID. Select Save.
- Copy the Federated credential issuer and Federated credential value that appear.
- In the app registration, go to Certificates & secrets > Federated credentials > Add credential, choose Other issuer, paste the issuer and value, name it, and select Add.
If federated credentials aren't possible, use Microsoft Entra ID V2 with client secrets and the shortest practical secret expiry.
Grant permissions and set scopes
- In the app registration, open API permissions > Add a permission > Microsoft Graph > Delegated permissions.
- Add openid and profile, and the SharePoint permissions Sites.Read.All and Files.Read.All.
- Select Grant admin consent for your tenant. If the button is unavailable, ask a tenant administrator to grant consent.
- In Copilot Studio, enter the scopes in the Scopes field, then save and publish:
profile openid Sites.Read.All Files.Read.AllThese scopes don't give users any extra access. They let the agent retrieve content the user can already read. To test, publish the agent, send a message in the Test your agent pane, select Login, sign in, and paste the validation code back into the chat.
Step 6: Narrow results with filters
On the Knowledge page, select the SharePoint source, open the ... menu, select Edit, then Advanced settings. Build conditions on Title, Author, Modified by or Modified on, with a static value, a user-provided global variable or a system variable. A common filter is Modified on "on or after" a date to exclude stale documents.
If you want the agent to answer only from the filtered source, also turn off Web Search, the agent-level general knowledge setting, and the topic-level general knowledge option in the generative answers node. The agent then returns "no response" when the filtered source has no match, which is usually what you want for policy content.
Verify the agent
- Sign in as a test user who has Read access to the site but no admin rights, and ask a question whose answer appears in exactly one document.
- Confirm the response cites that document.
- Ask the same question as a user without access. The agent should return no answer, not an error.
- Ask the question in Microsoft 365 Copilot Chat as the first user. If Copilot Chat also can't find it, the problem is permissions or indexing rather than the agent.
Troubleshooting
When the agent replies with something like "I'm not sure how to help with that. Can you try rephrasing?", work through these causes.
| Symptom | Cause | Fix |
|---|---|---|
| No answer for any SharePoint question | No authentication selected, or manual auth missing scopes or consent | Use Authenticate with Microsoft, or add Sites.Read.All and Files.Read.All to the app registration and the Scopes field, grant consent, publish |
| No answer for every user and every site | Restricted SharePoint Search is on | Confirm with the SharePoint administrator, or add the sites to the allowed list |
| One user gets answers, another doesn't | Missing Read permission | Have the user open the exact document path; fix permissions without relying only on folder inheritance |
| New documents never appear | Not yet indexed | Search for a unique keyword in SharePoint; if missing, wait or use Re-index site |
| A large PDF is never used | Over 7 MB without a Copilot license in the tenant | Split the file, or license Copilot and turn on tenant graph grounding |
| Specific files show Ready but give no answer | Encrypting label, Double Key Encryption or password | Publish an unprotected copy to a location the agent uses |
| Answers stopped after a site rename | Broken source link | Regenerate the link and update the knowledge source |
| Topic-level node never uses the site | Search only selected sources excludes it | Add the source to the node or turn the option off |
| List source returns nothing | Dataverse search off, or too many rows or lists | Turn on Dataverse search; split large lists |
| Guest users get no SharePoint answers | Not supported in SSO-enabled apps | Use a different source for guest content |
To reindex, the site administrator goes to Site information > View all site settings > Search and offline availability > Re-index site.
Content moderation can also suppress an answer without telling the user. If the agent sends telemetry to Application Insights, this query, shortened from the one in Microsoft's troubleshooting article, finds filtered responses (replace myCopilot with your role instance):
customEvents
| extend cd = todynamic(customDimensions)
| extend conversationId = tostring(cd.conversationId)
| extend topic = tostring(cd.TopicName)
| extend message = tostring(cd.Message)
| extend result = tostring(cd.Result)
| where name == "GenerativeAnswers" and result contains "Filtered"
| where cloud_RoleInstance == "myCopilot"
| project cloud_RoleInstance, name, timestamp, conversationId, topic, message, result
| order by timestamp descLowering the moderation level on the Generative AI settings page or the generative answers node returns more answers, at the cost of a weaker harmful-content filter.
Checklist
- Authentication matches the channels: Authenticate with Microsoft for Teams and Microsoft 365, Entra ID manual authentication elsewhere.
- Manual setups have the redirect URI, federated credential, delegated
Sites.Read.AllandFiles.Read.All, admin consent, and the scopes in Copilot Studio. - Site URLs registered without
https://, as narrowly as possible, with detailed descriptions. - Content is modern pages, DOCX, PPTX or PDF, unencrypted, and under the applicable size limit.
- Restricted SharePoint Search checked; Dataverse search on for list sources.
- Tenant graph grounding evaluated if the tenant has Copilot licenses.
- Tested as a reader, a non-reader and in Copilot Chat.
For the architecture behind permission-aware retrieval over enterprise content, see the production LLMOps and enterprise RAG architecture.
References
- Add SharePoint as a knowledge source - Microsoft Copilot Studio
- SharePoint knowledge sources don't return results
- Quotas and limits - Microsoft Copilot Studio
- Knowledge sources summary - Microsoft Copilot Studio
- Configure user authentication - Microsoft Copilot Studio
- Configure user authentication with Microsoft Entra ID - Microsoft Copilot Studio