Skip to main content
Microsoft Copilot Studio is a low-code Power Platform service used to build conversational agents. Makers define instructions, add knowledge sources and tools, and publish agents to Teams, websites, or Microsoft 365. TrustGate connects Copilot Studio to MCP servers. The default setup manages tool access and identity without inspecting tool payloads. Microsoft hosts model execution, so TrustGate cannot inspect agent prompts or model responses. To inspect MCP tool calls and results, attach an optional TrustGuard policy to the TrustGate consumer. The policy runs before a tool call reaches the MCP server and before its result returns to Copilot Studio.

Integration capabilities

Before you start

Do not configure client credentials manually. TrustGate publishes OAuth metadata and supports Dynamic Client Registration, so Copilot Studio registers itself. If Copilot Studio asks for a Client ID or Client secret, confirm that authentication is set to Dynamic discovery and that the server URL is the endpoint copied from Connect.

1. Create the MCP consumer

In Agent GatewayConsumers, create a consumer with protocol MCP and auth OAuth2, bind the registries and toolkit you want the agent to have, then copy the URL from the Connect tab:
Authentication options. The Copilot Studio configuration is the same for both options; only the consumer configuration changes.
Use an Identity-based consumer when different people should see different tools. The caller’s identity selects the roles, which determine the registries and toolkit available to that caller.

2. Add the MCP tool in Copilot Studio

  1. Create a tool → MCP.
  2. Set Authentication → OAuthDynamic discovery.
  3. Paste the consumer URL from step 1 as the server URL. Leave the defaults. If Power Automate opens, no changes are needed there.

3. Build the agent and activate the connection

  1. Create an agent and add the MCP Server tool from step 2.
  2. On the first run, activate every connection when prompted, including the MCP Server itself.
  3. Complete the NeuralTrust or IdP login if prompted. If an upstream registry uses OAuth (forwarded) and the user has not connected it, the first tool call returns a connection link. After authorization, TrustGate stores and refreshes the credential.

4. Verify

  1. Submit a request that invokes a tool from a bound registry.
  2. Confirm the agent lists only the tools granted by the consumer’s toolkit.
  3. Confirm the call in TrustGate telemetry. See Metrics.

Optional: inspect tool calls and results

The preceding steps configure an access-only connection. To evaluate the content of MCP traffic with TrustGuard:
  1. Follow the TrustGate integration to create a TrustGate collector and assign a TrustGuard runtime policy. Add Input rules for tool calls and Output rules for tool results. Start in Observe mode.
  2. In Agent GatewayPoliciesCatalog, add TrustGuard. Select the collector, set direction to request_response, and target the Copilot Studio consumer. Keep the guardrail in Observe while testing.
  3. Invoke a tool and confirm the input and output decisions in TrustGuard Activity.
  4. After reviewing the decisions, switch the runtime policy and guardrail to Enforce.
In Observe mode, findings are recorded without blocking or rewriting traffic. If a transform cannot be applied safely in Enforce mode, TrustGate blocks instead of forwarding unmasked content. Redaction applies to DLP outcomes only.

Reference

Coverage

Microsoft hosts model execution, so neither setup evaluates the agent’s prompts or model responses. Limits. TrustGuard inspects text tool content routed through TrustGate. It does not inspect non-text image, audio, or resource content blocks. To limit call frequency, attach the Per-Tool Rate Limiter policy. The Tool Injection policy applies only to LLM traffic and does not affect MCP.

Configuration

MCP endpoint. Each MCP consumer has a streamable-http endpoint. The agent receives the merged catalog from the registries assigned to that consumer:
The slug is the first path segment on the consumer’s proxy URL, and the path must end in /mcp. Copy the URL from the Connect tab instead of assembling it manually. Agent authentication. TrustGate acts as an OAuth2 authorization server for connecting agents and supports Dynamic discovery: The consumer configuration determines which IdP handles the login. See Auth. Upstream authentication is separate. Authenticating Copilot Studio to TrustGate is not the same as authenticating TrustGate to the MCP servers behind it. Configure the latter with mcp_target.auth.mode on the registry: none, static, client_credentials, passthrough, exchange or forwarded. forwarded requires the user to provide consent on first use. Tool names. Unique names pass through unchanged; a collision is prefixed with the registry name (asana_create_task). Use the name shown to the agent when configuring tool restrictions. Fail mode. fail_mode on the consumer decides what happens when an upstream server is unavailable. open skips the failed server; closed fails the call. For role-based consumers the effective mode is open only when every contributing role declares it open.

Troubleshooting