← All insights Guide

Copilot Studio authentication: no auth, Microsoft, manual

Copilot Studio has three authentication modes: no authentication, Authenticate with Microsoft, and Authenticate manually, as at 23 September 2026.

The short version: Copilot Studio has three authentication modes, as at 23 September 2026: No authentication, Authenticate with Microsoft, and Authenticate manually. Teams and Microsoft 365 Copilot only work with Authenticate with Microsoft; pick anything else and those two channels are blocked outright. No authentication can't use tools that need a user's own credentials.

The three modes Microsoft ships

ModeWhat it doesChannels
No authenticationAgent never asks anyone to sign in; only public information and resources are reachableAny channel, but tools needing user credentials are blocked
Authenticate with MicrosoftSets up Entra ID authentication for Teams automatically, no manual configurationTeams + Microsoft 365 only
Authenticate manuallyYou configure your own identity provider and app registrationRequired for any channel other than Teams + Microsoft 365

That last row is the one that surprises people: as at 23 September 2026, Microsoft states plainly that Teams and Microsoft 365 Copilot channels only support Authenticate with Microsoft, and selecting anything else gets those two channels blocked, not degraded.

What Authenticate with Microsoft sets up for Teams

This option is the default on a new agent. It configures Microsoft Entra ID authentication for Teams, Power Apps and Microsoft 365 Copilot with no manual app registration at all. Because Teams already identifies whoever's signed in, users aren't prompted to sign in again inside Teams unless the agent needs a wider scope than Teams already grants. The authoring canvas gets two variables to work with, User.ID and User.DisplayName; the two that need a real token, User.AccessToken and User.IsLoggedIn, aren't available under this mode. If a topic needs those, Authenticate manually is the only option.

What manual Entra ID setup needs

Authenticate manually supports five service providers: Microsoft Entra ID V2 with federated credentials, Microsoft Entra ID V2 with certificates, Microsoft Entra ID V2 with client secrets, plain Microsoft Entra ID, and Generic OAuth2 for a non-Microsoft identity provider such as Google or Facebook. Microsoft recommends federated credentials first: Copilot Studio auto-creates a federated identity credential in the Azure app registration, so authentication runs on short-lived OpenID Connect tokens rather than a client secret someone has to rotate and guard. Whichever provider you pick, the change only takes effect once the agent is published, so plan authentication changes before a release rather than mid-incident.

What it means for a firm under 20 staff

If the agent only ever needs to live in Teams, the decision makes itself: Authenticate with Microsoft is mandatory there anyway, and it needs zero setup. Manual Entra ID only earns its keep once the agent is going somewhere other than Teams or Microsoft 365 Copilot, most often a custom website embed or another channel where you still want signed-in access rather than an open "No authentication" agent. A firm under 20 staff publishing only to Teams essentially never needs to touch an Azure app registration for this. None of these choices change what an agent costs to run; that's the message mix covered in the Copilot Studio pricing breakdown.

Common questions

What are the three authentication options in Copilot Studio?

No authentication, Authenticate with Microsoft, and Authenticate manually, as at 23 September 2026. No authentication skips sign-in entirely and can't use tools that require a user's own credentials. Authenticate with Microsoft auto-configures Entra ID for Teams. Authenticate manually lets you wire up your own identity provider for any other channel.

Which authentication option does Microsoft Teams require?

Authenticate with Microsoft. Teams and Microsoft 365 Copilot channels only support this option; choosing No authentication or Authenticate manually blocks the agent from both channels outright.

What does setting up manual Entra ID authentication need?

An Azure App Registration, then one of five service providers in Copilot Studio: Microsoft Entra ID V2 with federated credentials (Microsoft's recommended, secretless option), with certificates, with client secrets, plain Microsoft Entra ID, or Generic OAuth2 for a non-Microsoft identity provider. Federated credentials avoid storing a secret at all, exchanging short-lived OpenID Connect tokens instead.

Balu Premkumar, founder of Kove

Not sure which mode your agent needs?

Free 30-minute call. Tell me which channels you're publishing to and I'll tell you which authentication mode fits.

Book a call

Not sure which licence this limit lands you on?

The licence picker walks the questions that decide it and gives the NZ price.

Christchurch-based · I reply within 1 working day