SaaS Agent Security
Onboard Microsoft Copilot Studio to SaaS Agent Security
Table of Contents
Expand All
|
Collapse All
SaaS Agent Security Docs
Onboard Microsoft Copilot Studio to SaaS Agent Security
Onboard Microsoft Copilot Studio to SaaS Agent Security to gain deep
visibility and security for your AI-powered Microsoft copilots and apps.
Onboard Microsoft Copilot Studio to SaaS Agent Security to gain deep visibility and
security for your AI-powered copilots and apps.
Prerequisites
- Ensure you configure the Microsoft Copilot Studio SaaS Security Posture Management connector before onboarding Microsoft Copilot Studio to SaaS Agent Security.
- Ensure you have Administrative privileges in the Microsoft Azure portal to register apps and grant API permissions.
- Ensure you have System Administrator or Power Platform Administrator role to add app users to the relevant environment.
Onboarding Microsoft Copilot Studio to SaaS Agent Security consists of the
following two main steps:
- Configure Permissions in Microsoft Azure—Create an app registration in your Microsoft Azure Portal to grant Palo Alto Networks® secure, read-only access to your Microsoft Copilot Studio environment.
- Onboard Microsoft Copilot Studio to SaaS Agent Security—Use the credentials generated during the configuration process to establish the connection the Palo Alto Networks SaaS Agent Security platform and your Microsoft Copilot Studio environment.
- Register a new app in Microsoft Azure.
- Log in to Microsoft Azure Portal.Navigate to or search for App registrations.Click + New Registrations.Enter a descriptive Name for the app. For example, PaloAltoNetworks_Agent_Security_Connector.Register.Configure API permissions for the new app.
- From the new app details page, select ManageAPI permissions.Click + Add a permission.Add the following Microsoft Graph permissions:
- Application.Read.All
- AuditLog.Read.All
- AuditLogsQuery-CRM.Read.All
- AuditLogsQuery.Read.All
Click Add permissions to save the app API permissions.The permissions you added require admin consent. On the Configured permissions page, Grant admin consent for <your-organization>.In the confirmation page, select Yes to grant admin consent for your organization.Create a Client Secret for the new app.- From the new app details page, select Managecertificates & secrets.Add a + New client secret.Enter a description (for example, SaaS_Security_Key) and select an expiration period.Add the Client Secret.Copy the Client Secret Value and store it in a secure location.Grant the app access in the Microsoft Power Platform admin center.
- Log in to Microsoft Power Platform Admin Center.Select ManageEnvironments and select your Copilot Studio environment.Select SettingsUsers + permissionsApplication users and click + New app user.Click + Add an app and search for the app you created in the previous step.Select the correct Business unit from the drop-down.Click the pencil icon next to Security roles and then assign the Service Reader role.Click Create to save the app access privileges.Gather the required information to onboard Microsoft Copilot Studio to SaaS Agent Security.
- Environment URL—Found on the environment's main page in the Microsoft Power Platform Admin Center.
- Application (Client) ID—Displayed in the app Overview in the Microsoft Azure Portal.
- Directory (Tenant) ID—Displayed in the app Overview in the Microsoft Azure Portal.
- Client Secret Value—The Client Secret you copied and stored in a secure location when creating the Client Secret for the app.
Onboard Microsoft Copilot Studio to SaaS Agent Security.- Log in to Strata Cloud Manager.Select ConfigurationAgent Security.Select Agent Platform Onboarding and select Microsoft Copilot Studio.Click Next to continue.Click Get Started.Enter the required credentials for the Microsoft Copilot Studio app.
- Tenant ID
- Client ID
- Client Secret
Enter the Environment URL for Microsoft Copilot Studio app.Click Add Environment to add additional Environment URLs if you have multiple Microsoft Copilot Studio environments you want to monitor with SaaS Agent Security.Click Next to validate the Microsoft Copilot Studio credentials and environment and complete the onboarding to SaaS Agent Security.SaaS Agent Security notifies you when Microsoft Copilot Studio successfully onboards. SaaS Agent Security returns one of the following errors if Microsoft Copilot Studio fails to onboard:- Permission Errors during Scan— Verify you entered all credentials correctly and that you granted Admin Consent when you configured the Azure API Permissions.
- Connection Test Fails— Confirm you assigned the Service Reader role in the Power Platform Admin Center.