web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Copilot Studio / Copilot Agent with MCP...
Copilot Studio
Suggested Answer

Copilot Agent with MCP Authentication - Problem with login

(1) ShareShare
ReportReport
Posted on by 2
Hello,
We are building a Copilot Studio agent that connects to our MCP server using OAuth authentication for end users.  
We have configured an OBO flow so that the agent should access backend resources on behalf of the Teams user, and based on that we expect no manual setup.  
However, users are still required to create a Power Platform connection in Copilot Studio before they can use the agent in Teams.  
 
We want to confirm:  
1) Is this per-user connection prompt required by design when using delegated OAuth for connectors in Copilot Studio?  
2) Is there a supported way to provision or share delegated connections *without users needing to manually create or approve them in Studio*?  
3) If this is a known limitation or UX issue, is there a roadmap for allowing smoother login/consent flows when deploying agents to Teams?  
Our goal is:  
- User experience should *not* require interacting with Copilot Studio at all  
- Users should be able to access the agent the first time they open it in Teams  
- Delegated access must use the user’s identity
Thanks in advance for your guidance.
Best regards,
I have the same question (0)
  • Suggested answer
    Nivedipa-MSFT Profile Picture
    Microsoft Employee on at
    Hello  ,
    Users need to manually set up a Power Platform connection in Copilot Studio before using an OAuth-enabled agent in Teams, even with the OBO flow.

    Answers:

    1) Is a per-user connection prompt required by design?

    Yes, this is necessary. For delegated (OAuth) connections, each user must:

    • Grant permission consent
    • Create their own connection instance
    • This is a Power Platform security measure, not an issue with Copilot Studio

    2) Is it possible to provision or share delegated connections automatically?

    Not for delegated authentication. Alternatives include:

    • Service Principal (non-delegated): Use app-only authentication with a shared connection—no per-user setup, but user context is lost
    • Pre-provisioned connections: Admins can create connections, but users still need to provide consent
    • Custom connector with SSO: Can lower friction but still requires initial consent

    3) Is there a roadmap for smoother connection flows?

    Microsoft is aware of the issue, but there is no public timeline. Currently:

    • Power Platform connections require explicit user consent for delegated scenarios
    • This is intentional for security and compliance
    • The friction is recognized, but not prioritized for resolution at this time

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Launch!

Jump in, show your community spirit, and win prizes!

Kudos to our 2025 Community Spotlight Honorees

Expanding mentorship, skilling, and AI innovation

Congratulations to the May Top 10 Community Leaders!

These are the community rock stars!

Leaderboard > Copilot Studio

#1
Valantis Profile Picture

Valantis 277

#2
11manish Profile Picture

11manish 206

#3
sannavajjala87 Profile Picture

sannavajjala87 156 Super User 2026 Season 1

Last 30 days Overall leaderboard