The process of building custom applications and tools that interact with Microsoft SharePoint, including SharePoint Online in Microsoft 365.
Hi Najiya,
If your goal is to embed a Microsoft Copilot Studio agent in a SharePoint Framework (SPFx) web part and allow the agent to recognize the currently signed-in SharePoint user without requiring an additional sign-in prompt, I recommend configuring Authenticate manually with Microsoft Entra ID v2 and implementing Single Sign-On (SSO). This configuration allows the agent to leverage the user's existing SharePoint session and obtain user context seamlessly.
To set up this scenario, I recommend following the steps below:
- In Copilot Studio, open your agent and navigate to: Settings > Security > Authentication
- Select Authenticate manually, enable Require users to sign in, and configure Microsoft Entra ID v2 as the identity provider. Microsoft recommends using federated credentials where possible.
- Create two app registrations in Microsoft Entra ID:
- An authentication app registration for the Copilot Studio agent.
- A canvas/client app registration for the SPFx web part and SSO integration.
- In the agent authentication app registration:
- Configure the required redirect URL.
- Expose an API and create a custom scope.
- Add the token exchange URL in the agent's authentication settings.
- In the SPFx web part, use the SharePoint Framework token provider to obtain an access token for the currently signed-in user. Pass this token through the custom canvas SSO flow when Copilot Studio sends an OAuth token exchange request. This allows the agent to populate authentication variables such as:
-
User.IsLoggedIn -
User.DisplayName -
User.Id -
User.AccessToken
As a result, the agent can personalize conversations and access permitted resources on behalf of the signed-in user.
- If your SPFx web part communicates with the agent using Direct Line, enable Web channel security and generate Direct Line tokens through a secure server-side component. Avoid exposing the Direct Line secret in client-side SPFx code, as browser users can inspect JavaScript and potentially compromise the secret.
- Save the configuration and publish the agent again, as authentication changes do not take effect until the agent is republished.
Additionally, I would not recommend selecting No authentication, as the agent would not be able to identify users or access user-specific information and would only be able to work with public resources.
For more detailed guidance, please refer to the following Microsoft Learn articles:
- Configure user authentication - Microsoft Copilot Studio
- Configure single sign-on with Microsoft Entra ID - Microsoft Copilot Studio
- Configure user authentication with Microsoft Entra ID
I hope this information helps. Should you have any questions or concerns, please feel free to let me know.
Warm regards.