Integration capabilities
Before you start
1. Create the MCP consumer
In Agent Gateway → Consumers, create a consumer with protocol MCP and auth OAuth2, bind the registries and toolkit you want the agent to have, then copy the URL from the Connect tab:Use an Identity-based consumer when different people should see different tools. The
caller’s identity selects the roles, which determine
the registries and toolkit available to that caller.
2. Add the MCP tool in Copilot Studio
- Create a tool → MCP.
- Set Authentication → OAuth → Dynamic discovery.
- Paste the consumer URL from step 1 as the server URL. Leave the defaults. If Power Automate opens, no changes are needed there.
3. Build the agent and activate the connection
- Create an agent and add the MCP Server tool from step 2.
- On the first run, activate every connection when prompted, including the MCP Server itself.
- Complete the NeuralTrust or IdP login if prompted. If an upstream registry uses OAuth (forwarded) and the user has not connected it, the first tool call returns a connection link. After authorization, TrustGate stores and refreshes the credential.
4. Verify
- Submit a request that invokes a tool from a bound registry.
- Confirm the agent lists only the tools granted by the consumer’s toolkit.
- Confirm the call in TrustGate telemetry. See Metrics.
Optional: inspect tool calls and results
The preceding steps configure an access-only connection. To evaluate the content of MCP traffic with TrustGuard:- Follow the TrustGate integration to create a TrustGate collector and assign a TrustGuard runtime policy. Add Input rules for tool calls and Output rules for tool results. Start in Observe mode.
- In Agent Gateway → Policies → Catalog, add TrustGuard. Select
the collector, set direction to
request_response, and target the Copilot Studio consumer. Keep the guardrail in Observe while testing. - Invoke a tool and confirm the input and output decisions in TrustGuard Activity.
- After reviewing the decisions, switch the runtime policy and guardrail to Enforce.
In Observe mode, findings are recorded without blocking or rewriting traffic.
If a transform cannot be applied safely in Enforce mode, TrustGate blocks
instead of forwarding unmasked content. Redaction applies to DLP outcomes only.
Reference
Coverage
Microsoft hosts model execution, so neither setup evaluates the agent’s prompts or model responses.
Limits. TrustGuard inspects text tool content routed through TrustGate. It
does not inspect non-text image, audio, or resource content blocks. To limit call
frequency, attach the Per-Tool Rate
Limiter policy. The Tool Injection policy
applies only to LLM traffic and does not affect MCP.
Configuration
MCP endpoint. Each MCP consumer has astreamable-http endpoint. The agent
receives the merged catalog from the registries assigned to that consumer:
/mcp. Copy the URL from the Connect tab instead of assembling it
manually.
Agent authentication. TrustGate acts as an OAuth2 authorization server for
connecting agents and supports Dynamic discovery:
The consumer configuration determines which IdP handles the login. See
Auth.
Upstream authentication is separate. Authenticating Copilot Studio to
TrustGate is not the same as authenticating TrustGate to the MCP servers behind
it. Configure the latter with
mcp_target.auth.mode on the registry: none,
static, client_credentials, passthrough, exchange or forwarded.
forwarded requires the user to provide consent on first use.
Tool names. Unique names pass through unchanged; a collision is prefixed with
the registry name (asana_create_task). Use the name shown to the agent when
configuring tool restrictions.
Fail mode. fail_mode on the consumer decides what happens when an upstream
server is unavailable. open skips the failed server; closed fails the call.
For role-based consumers the effective mode is open only when every
contributing role declares it open.
Troubleshooting
Related
- MCP Gateway: consumers, catalog merging, toolkits, and upstream authentication
- TrustGate and TrustGuard: collector, policy, verdict, and failure behavior
- TrustGate guardrails: configure the optional policy
- Consumers: slugs, routing modes, and the Connect tab
- TrustGate authentication: OAuth2 authentication for MCP consumers
- Okta and Entra ID: IdP applications and redirect URIs
- Roles: identity-scoped toolkits
- Microsoft Copilot Studio documentation: Microsoft reference