Which authentication type in agent settings , if i need to embed my copilot studio agent in sharepoint spfx?

Najiya Nasrin M 0 Reputation points
2026-09-25T09:37:22.26+00:00

Still me working in a copilot studio agent. i need to embed my copilot studio agent in SharePoint SPFx. need to set authentication and configure agent without login prompt, but agent should understand the user details who already logged in SharePoint. which agent authentication should i choose?

how it configure?

Microsoft 365 and Office | SharePoint | Development
0 comments No comments

1 answer

Sort by: Most helpful
  1. Kristen Tran 2,040 Reputation points Independent Advisor
    2026-09-25T09:59:25.94+00:00

    Hi Najiya,

    If your goal is to embed a Microsoft Copilot Studio agent in a SharePoint Framework (SPFx) web part and allow the agent to recognize the currently signed-in SharePoint user without requiring an additional sign-in prompt, I recommend configuring Authenticate manually with Microsoft Entra ID v2 and implementing Single Sign-On (SSO). This configuration allows the agent to leverage the user's existing SharePoint session and obtain user context seamlessly.

    To set up this scenario, I recommend following the steps below:

    1. In Copilot Studio, open your agent and navigate to: Settings > Security > Authentication
    2. Select Authenticate manually, enable Require users to sign in, and configure Microsoft Entra ID v2 as the identity provider. Microsoft recommends using federated credentials where possible.
    3. Create two app registrations in Microsoft Entra ID:
      • An authentication app registration for the Copilot Studio agent.
      • A canvas/client app registration for the SPFx web part and SSO integration.
    4. In the agent authentication app registration:
    • Configure the required redirect URL.
    • Expose an API and create a custom scope.
    • Add the token exchange URL in the agent's authentication settings.
    1. In the SPFx web part, use the SharePoint Framework token provider to obtain an access token for the currently signed-in user. Pass this token through the custom canvas SSO flow when Copilot Studio sends an OAuth token exchange request. This allows the agent to populate authentication variables such as:
    • User.IsLoggedIn
    • User.DisplayName
    • User.Id
    • User.AccessToken

    As a result, the agent can personalize conversations and access permitted resources on behalf of the signed-in user.

    1. If your SPFx web part communicates with the agent using Direct Line, enable Web channel security and generate Direct Line tokens through a secure server-side component. Avoid exposing the Direct Line secret in client-side SPFx code, as browser users can inspect JavaScript and potentially compromise the secret.
    2. Save the configuration and publish the agent again, as authentication changes do not take effect until the agent is republished.

    Additionally, I would not recommend selecting No authentication, as the agent would not be able to identify users or access user-specific information and would only be able to work with public resources.

    For more detailed guidance, please refer to the following Microsoft Learn articles:

    I hope this information helps. Should you have any questions or concerns, please feel free to let me know.

    Warm regards.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.