Microsoft 365 Copilot Integration
The Microsoft 365 Copilot integration retrieves Copilot enterprise interaction data from your Microsoft 365 tenant and adds discovered activity to the Inventory. Use this integration to see who uses Copilot, where it is used, and how often it is used across Microsoft 365 applications, such as Teams, Outlook, and Word.
Prerequisites
Before you configure the integration, make sure that:
-
Your organization has a Microsoft 365 tenant.
-
Microsoft 365 Copilot licenses are assigned to the users you want to discover.
-
You have an administrator account in the tenant with one of these roles:
-
Global Administrator
-
Privileged Role Administrator
-
-
You can grant tenant-wide admin consent to a multi-tenant application.
|
|
Note - Workforce AI Security uses a pre-registered multi-tenant Azure AD application. You do not need to register an Azure AD application yourself. |
Permissions
When you complete the admin consent flow, you grant the Workforce AI Security application read-only application permissions in your Microsoft 365 tenant. These permissions allow Workforce AI Security to:
-
Enumerate users in the tenant.
-
Read Microsoft 365 Copilot enterprise interaction history.
Configuring the Integration
To configure the integration:
-
From the left menu, select Integrations and then click M365 Copilot.
-
On the side panel, click Connect to M365 Copilot.
-
When you are redirected to Microsoft, sign in with a Global Administrator or Privileged Role Administrator account.
-
Review the requested permissions.
-
Click Accept to grant tenant-wide admin consent.
-
After Microsoft redirects you back to Workforce AI Security, make sure the integration status changes to Connected.
After the connection is established, the integration panel shows the connected tenant ID.
Scanning
After you connect the integration, you can run scans to collect Microsoft 365 Copilot usage data. You can run a scan manually or configure periodic scans.
-
Manual scan - Click Scan Now in the integration card. During the scan, the button shows Scanning… and is disabled.
-
Periodic scan - Use the scan frequency setting in the integration card to define how often Workforce AI Security scans the integration.
Setting
Scan frequency
Off
Disabled. The integration runs only when you start a manual scan.
Daily
Every 24 hours.
Weekly
Every 7 days.
When periodic scans are enabled, the integration panel shows the last scan time and the next scan time.
Inventory
After the scan completes, Workforce AI Security lists discovered Microsoft 365 Copilot usage in Inventory > Agents.
Workforce AI Security creates cloud AI agent entries based on the Microsoft 365 Copilot user and the Microsoft 365 application or channel where Copilot was used. For example, usage can be represented separately for Copilot activity in Teams, Outlook, Word, and other Microsoft 365 apps.
Agent details
For each Microsoft 365 Copilot agent, Workforce AI Security shows usage details that can include:
-
Owner, based on the user principal name
-
Microsoft 365 application or channel, such as Teams, Outlook, or Word
-
Activity count
-
Activity timestamps