AI engineering

Copilot Studio SharePoint Knowledge: Set It Up and Fix No-Answer Errors

Add SharePoint sites and lists as Copilot Studio knowledge, choose the right authentication, and fix agents that answer "I'm not sure how to help with that."

12 min read
On this page

To use SharePoint as knowledge in Copilot Studio, open the agent, select Add knowledge, choose SharePoint in the Featured section, and enter the site or folder URL; the agent then searches that location and its subfolders through Microsoft Graph, using the signed-in user's permissions. When the agent can't answer from SharePoint, it fails silently, so check authentication and scopes, the user's read access, Microsoft Search indexing, file type and size limits, encrypted files and Restricted SharePoint Search, in that order.

Who this is for and what you will have at the end

This guide is for Copilot Studio makers and the Microsoft 365 or Entra administrators who support them. It covers the fully integrated SharePoint knowledge option, which grounds generative answers on SharePoint pages and documents and respects permissions per user.

At the end you will have:

  • An agent grounded on one or more SharePoint sites, with the authentication option that matches its channels.
  • A working app registration and scope list for agents that use manual authentication.
  • Optional SharePoint list knowledge and search filters.
  • A troubleshooting sequence for the "no response" behavior, including the fixes Microsoft documents for each cause.

If the agent identity itself needs governance, see the companion guide on governing Copilot Studio agents with Microsoft Entra Agent ID.

How SharePoint knowledge works

When a user asks something that no topic handles, the agent runs a search against the registered SharePoint URL and all its subpaths. Copilot Studio uses Microsoft Search indexing, takes the top three search results, and summarizes them into a response with citations. A few behaviors follow from that design:

  • The agent only sees what the user can open. Calls are made on behalf of the user chatting with the agent. At minimum the user needs Read permission on the site or list. Without it, the agent returns no results and no error.
  • Scope is the URL you register. The agent never reads parent folders, sibling folders or other sites unless you add them separately. Hyperlinks inside a registered page or document aren't followed either.
  • Search drives everything. If SharePoint search can't find a document, neither can the agent.
  • Sensitivity labels trim results, but encryption blocks grounding. The agent surfaces only label-permitted content, and it can't extract content from files protected by encrypting labels, Double Key Encryption or passwords. Those files can show as Ready and still produce no response.

There are two SharePoint options in the Add knowledge dialog. The SharePoint tile in Featured is the integrated option covered here. The SharePoint option in the Upload file section uploads individual files or folders and synchronizes them, and it's also where SharePoint lists are added.

Prerequisites and limits

ItemRequirement or limit
User permissionAt least Read on the site, library or list
Site URLsUp to 25 SharePoint site URLs per agent with generative orchestration
URL formatsharepoint.com domain; omit https://
Supported filesWord (DOC, DOCX), PowerPoint (PPT, PPTX) and PDF
PagesModern pages only; modern pages with SPFx components, classic ASPX pages, accordion navigation and custom CSS aren't used
File sizeUnder 7 MB without a Microsoft 365 Copilot license in the tenant; up to 200 MB with a license and tenant graph grounding turned on
GuestsNot supported for SharePoint generative answers in SSO-enabled apps
Tenant settingRestricted SharePoint Search must not block the sites

Some question types can't be answered at all. Queries that reference a file by name ("what does file-name.pdf say"), ask for file counts or folder listings, or filter on column metadata aren't supported. Structured files such as XLSX can be added, but the agent can't write and run code, so analytical answers might be weak.

Step 1: Choose the authentication option

Authentication decides whether the agent can read SharePoint at all. Configure it under Settings > Security > Authentication, and remember that changes only take effect after you publish.

OptionSharePoint knowledgeChannelsNotes
No authenticationDoesn't workAnyThe agent doesn't retrieve SharePoint information
Authenticate with MicrosoftWorks, no app registrationTeams + Microsoft 365 (also Power Apps and Microsoft Copilot)Default for new agents; required for tenant graph grounding with semantic search
Authenticate manuallyWorks with Entra ID providersOther channels such as a custom websiteRequires an app registration and the SharePoint scopes; Generic OAuth 2 isn't supported for SharePoint

Agents created in Copilot Studio and in Teams default to Authenticate with Microsoft. The Teams + Microsoft 365 channel only supports that option; choosing anything else blocks the channel. If a previously published agent used manual authentication and you switch it back for Teams, republish it. The change can take a few hours to reach users, and typing "start over" in the chat forces the latest version.

Step 2: Add the SharePoint site

  1. Open the agent and select Add knowledge from the Overview or Knowledge page.
  2. In Featured, select SharePoint.
  3. Enter the URL. Separate several URLs with Shift + Enter. You can also insert a Custom, System or Environment variable to resolve the URL at runtime.
  4. Enter a name and a detailed description. With generative orchestration, the description is how the orchestrator decides when to use this source.
  5. Select Add to agent.

Register the narrowest path that contains the content, such as a specific document library folder, rather than the root of a large site. If someone renames the site or folder later, the link can break; ask the SharePoint administrator to confirm permissions on the new location and update the knowledge source with the new link.

Step 3: Add SharePoint lists (optional)

Lists are ingested into Dataverse and indexed, with a live connection so queries use current data.

  1. Select Add knowledge, then SharePoint in the Upload file section.
  2. Select Browse items to pick from My Lists and Recent Lists, or paste a list URL. A shared list that doesn't appear in Recent Lists can be added by URL, or by opening it in SharePoint once.
  3. Select the lists, choose Confirm selection, add a name and description, and select Add to agent.

Microsoft recommends no more than 10 lists per agent for the best results. Lists over 35,000 rows reduce quality and increase latency, and list queries only return data from the first 2,048 rows. Document libraries aren't supported as lists, list views can't be selected, and the Attachments column isn't reasoned over. Dataverse search must be turned on in the environment.

Step 4: Turn on tenant graph grounding when you can

The Tenant graph grounding with semantic search setting on the agent's Generative AI settings page uses the semantic index to retrieve more context with better precision. It needs:

  • Generative orchestration turned on.
  • Authenticate with Microsoft as the authentication option. With any other option the setting can't be changed.
  • A Microsoft 365 Copilot license assigned to at least one user in the same tenant, so a semantic index exists.

Users who have Microsoft 365 Copilot licenses already use it by default. Turning it on extends it to unlicensed users at an extra cost billed in Copilot Credits. It also raises the SharePoint file limit to 200 MB. If the tenant has no Copilot license, or response quality drops, turn it off. The Copilot license assignment checklist covers getting those licenses in place.

Step 5: Configure manual authentication for other channels

Use this when the agent is published somewhere other than Teams and Microsoft 365. You need an admin account in the same tenant as the agent.

Create the app registration

  1. In the Azure portal, go to App registrations > New registration. Create a new registration; don't reuse an existing one.
  2. Select Accounts in this organizational directory only (single tenant), leave Redirect URI blank, and select Register.
  3. Copy the Application (client) ID.
  4. Under Authentication, select Add a platform > Web and enter the redirect URI. For Europe, use the europe.token.botframework.com host instead. You can also copy the value from the Redirect URL box in Copilot Studio.
https://token.botframework.com/.auth/web/redirect
  1. Select both Access tokens (used for implicit flows) and ID tokens (used for implicit and hybrid flows), then Configure.

Add credentials

Microsoft recommends federated credentials, which avoid stored secrets:

  1. In Copilot Studio, go to Settings > Security > Authentication and select Authenticate manually. Leave Require users to sign in on.
  2. Set Service provider to Microsoft Entra ID V2 with federated credentials and enter the client ID. Select Save.
  3. Copy the Federated credential issuer and Federated credential value that appear.
  4. In the app registration, go to Certificates & secrets > Federated credentials > Add credential, choose Other issuer, paste the issuer and value, name it, and select Add.

If federated credentials aren't possible, use Microsoft Entra ID V2 with client secrets and the shortest practical secret expiry.

Grant permissions and set scopes

  1. In the app registration, open API permissions > Add a permission > Microsoft Graph > Delegated permissions.
  2. Add openid and profile, and the SharePoint permissions Sites.Read.All and Files.Read.All.
  3. Select Grant admin consent for your tenant. If the button is unavailable, ask a tenant administrator to grant consent.
  4. In Copilot Studio, enter the scopes in the Scopes field, then save and publish:
profile openid Sites.Read.All Files.Read.All

These scopes don't give users any extra access. They let the agent retrieve content the user can already read. To test, publish the agent, send a message in the Test your agent pane, select Login, sign in, and paste the validation code back into the chat.

Step 6: Narrow results with filters

On the Knowledge page, select the SharePoint source, open the ... menu, select Edit, then Advanced settings. Build conditions on Title, Author, Modified by or Modified on, with a static value, a user-provided global variable or a system variable. A common filter is Modified on "on or after" a date to exclude stale documents.

If you want the agent to answer only from the filtered source, also turn off Web Search, the agent-level general knowledge setting, and the topic-level general knowledge option in the generative answers node. The agent then returns "no response" when the filtered source has no match, which is usually what you want for policy content.

Verify the agent

  1. Sign in as a test user who has Read access to the site but no admin rights, and ask a question whose answer appears in exactly one document.
  2. Confirm the response cites that document.
  3. Ask the same question as a user without access. The agent should return no answer, not an error.
  4. Ask the question in Microsoft 365 Copilot Chat as the first user. If Copilot Chat also can't find it, the problem is permissions or indexing rather than the agent.

Troubleshooting

When the agent replies with something like "I'm not sure how to help with that. Can you try rephrasing?", work through these causes.

SymptomCauseFix
No answer for any SharePoint questionNo authentication selected, or manual auth missing scopes or consentUse Authenticate with Microsoft, or add Sites.Read.All and Files.Read.All to the app registration and the Scopes field, grant consent, publish
No answer for every user and every siteRestricted SharePoint Search is onConfirm with the SharePoint administrator, or add the sites to the allowed list
One user gets answers, another doesn'tMissing Read permissionHave the user open the exact document path; fix permissions without relying only on folder inheritance
New documents never appearNot yet indexedSearch for a unique keyword in SharePoint; if missing, wait or use Re-index site
A large PDF is never usedOver 7 MB without a Copilot license in the tenantSplit the file, or license Copilot and turn on tenant graph grounding
Specific files show Ready but give no answerEncrypting label, Double Key Encryption or passwordPublish an unprotected copy to a location the agent uses
Answers stopped after a site renameBroken source linkRegenerate the link and update the knowledge source
Topic-level node never uses the siteSearch only selected sources excludes itAdd the source to the node or turn the option off
List source returns nothingDataverse search off, or too many rows or listsTurn on Dataverse search; split large lists
Guest users get no SharePoint answersNot supported in SSO-enabled appsUse a different source for guest content

To reindex, the site administrator goes to Site information > View all site settings > Search and offline availability > Re-index site.

Content moderation can also suppress an answer without telling the user. If the agent sends telemetry to Application Insights, this query, shortened from the one in Microsoft's troubleshooting article, finds filtered responses (replace myCopilot with your role instance):

customEvents
| extend cd = todynamic(customDimensions)
| extend conversationId = tostring(cd.conversationId)
| extend topic = tostring(cd.TopicName)
| extend message = tostring(cd.Message)
| extend result = tostring(cd.Result)
| where name == "GenerativeAnswers" and result contains "Filtered"
| where cloud_RoleInstance == "myCopilot"
| project cloud_RoleInstance, name, timestamp, conversationId, topic, message, result
| order by timestamp desc

Lowering the moderation level on the Generative AI settings page or the generative answers node returns more answers, at the cost of a weaker harmful-content filter.

Checklist

  • Authentication matches the channels: Authenticate with Microsoft for Teams and Microsoft 365, Entra ID manual authentication elsewhere.
  • Manual setups have the redirect URI, federated credential, delegated Sites.Read.All and Files.Read.All, admin consent, and the scopes in Copilot Studio.
  • Site URLs registered without https://, as narrowly as possible, with detailed descriptions.
  • Content is modern pages, DOCX, PPTX or PDF, unencrypted, and under the applicable size limit.
  • Restricted SharePoint Search checked; Dataverse search on for list sources.
  • Tenant graph grounding evaluated if the tenant has Copilot licenses.
  • Tested as a reader, a non-reader and in Copilot Chat.

For the architecture behind permission-aware retrieval over enterprise content, see the production LLMOps and enterprise RAG architecture.

References

Questions people ask

Why does my Copilot Studio agent say it can't help when the answer is in SharePoint?

The most common causes are the signed-in user lacking read access, missing Sites.Read.All and Files.Read.All scopes or consent in a manual authentication setup, content that isn't indexed by Microsoft Search, and files the agent can't process. None of these produce an error; the agent behaves as if no document exists.

Which authentication option should a SharePoint knowledge agent use?

Use Authenticate with Microsoft when the agent is published to Teams and Microsoft 365, because it needs no app registration and is required for tenant graph grounding with semantic search. Use Authenticate manually with a Microsoft Entra ID provider for other channels, and add the Sites.Read.All and Files.Read.All scopes.

What is the file size limit for SharePoint knowledge in Copilot Studio?

Without a Microsoft 365 Copilot license in the same tenant as the agent, generative answers only process SharePoint files under 7 MB. With a license in the tenant and tenant graph grounding with semantic search turned on, files up to 200 MB are supported.

Can guest users get answers from SharePoint knowledge in Copilot Studio?

No. Generative answers from SharePoint sources aren't available to guest users in SSO-enabled apps. Use a separate knowledge source, such as uploaded files, for content that guests need.

Copilot StudioSharePoint OnlineMicrosoft Entra IDGenerative Answers
  1. Build RAG Over SharePoint Documents Without Breaking Permissions

    Ground an internal AI assistant on SharePoint files so each user only gets answers from documents they can open, using the Copilot Retrieval API or Azure AI Search with ACL ingestion.

    AI engineering12 min read
  2. Azure OpenAI Keyless Access: Managed Identity, Entra ID and Private Endpoints

    Remove API keys from Azure OpenAI: call it with a managed identity and Entra ID RBAC, disable local auth, and reach it only through a private endpoint with public network access turned off.

    AI engineering12 min read
  3. Govern Copilot Studio Agents with Data Policies and an Environment Strategy

    Use Power Platform environments, environment routing and data policies to control which knowledge sources, connectors, HTTP calls and channels Copilot Studio agents can use and publish to.

    AI engineering11 min read