Skip to main content

Microsoft Copilot Studio Collector​

Microsoft Copilot Studio enables organizations to build custom AI agents that integrate with enterprise tools and services.

You can use AIDR as an external threat detection provider for Copilot Studio agents. After you configure the integration, Copilot Studio sends tool invocation context to AIDR before the agent executes any tool. AIDR analyzes the tool name and input parameters against your policy rules and returns an allow or block decision.

Considerations:
  • Input scanning: AIDR analyzes only the tool name and input parameters from the tool invocation payload. Copilot Studio includes the user prompt, recent conversation history, and other context fields in the request, but AIDR doesn't analyze them. By the time Copilot Studio calls the threat detection endpoint, the user has already submitted the prompt to the agent LLM. The LLM responds with the tool invocation.

  • Output scanning: Copilot Studio's external threat detection interface calls AIDR before tool execution, not after. The collector doesn't scan tool outputs.

  • Data transformations: Copilot Studio's external threat detection interface supports only allow or block decisions on the entire tool invocation. If you select a transforming action in a detector rule, the action works in report-only mode and allows the request.

  • Response timeout: Copilot Studio imposes a one-second response limit on the threat detection endpoint. If AIDR doesn't respond within one second, Copilot Studio applies the configured threat detection error behavior, either allow or block.

For more info about the data and capabilities that Copilot Studio exposes to external threat detection providers, see the Microsoft article Enable external threat detection and protection for Copilot Studio custom agents .

How it works​

  1. A Copilot Studio agent selects a tool to invoke.
  2. Before executing the tool, the agent sends the invocation context to AIDR: user prompt, recent conversation history, tool name, tool input parameters, and metadata.
  3. AIDR analyzes the tool name and input parameters against the policy assigned to the collector.
  4. AIDR responds with either allow or block.
  5. The agent proceeds with or skips the tool invocation based on the response.

Requirements​

  • Microsoft:
    • Entra tenant where you can register applications
    • User with the Global Administrator or Privileged Role Administrator role to grant admin consent
    • User with the Power Platform Administrator role to configure threat detection
    • Copilot Studio: Agents that use generative orchestration. Classic agents are not supported.
note:

In generative orchestration mode, the agent dynamically selects which tools to invoke based on conversation context. Classic agents that use manually authored topics and fixed action flows don't support external threat detection.

Register Copilot Studio collector​

  1. On the Collectors page, click + Collector.

  2. Select Copilot Studio as the collector type, and then click Next.
  3. On the Add a Collector screen:

    • Collector Name: Enter a descriptive name for the collector. This name appears in dashboards and reports.
    • Logging: Select whether to log prompt data and model responses, or only metadata sent to AIDR. You can also exclude prompt content in access rule action settings .
    • Optional. Policy: Assign a policy to evaluate tool invocation data. Only input rules apply to this collector type.
    • The assigned policy determines which detections run on data sent to AIDR. Policies define rules for detecting malicious activity, sensitive data exposure, topic violations, and other risks in AI interactions.

      • Select an existing policy available for this collector type.

        The selected policy name appears under the drop-down list. After you save the collector registration, this label becomes a link to the corresponding policy page.

        You can create a policy on the Policies page.

      • You can select No Policy, Log Only. Without a policy, AIDR records activity for visibility and analysis without applying detection rules.

  1. Enter your Entra Tenant ID for the Microsoft Entra tenant where your Copilot Studio environment resides.
  2. Click Save.

This opens the collector details page, where you can:

  • Update the collector name, logging preference, and policy assignment.
  • Click the policy link to view the policy details.
  • Copy credentials and AIDR base URL from the Config tab to call AIDR APIs.
  • View installation instructions for the collector type on the Install tab.
  • View the collector configuration activity logs.

To open the collector details later, select your collector from the list on the Collectors page.

Deploy collector​

To deploy the Copilot Studio collector, configure settings in both Microsoft Entra ID and the Power Platform admin center. Follow the steps on the Install tab of your collector details page. The tab provides the pre-computed values.

The following sections describe each step in detail.

An administrator must grant admin consent to the AIDR collector enterprise application in your Entra tenant. Granting consent creates a service principal in your tenant and allows AIDR to participate in the Federated Identity Credential (FIC) authentication flow.

  1. Use the admin consent URL on the Install tab to grant consent. You need an account with the Global Administrator or Privileged Role Administrator role.
  2. A Permissions requested screen opens with these details:
    • The AIDR collector enterprise application name for your cloud. If accepted, this name appears under Enterprise applications in the Microsoft Entra admin center. For example, AIDR Copilot Studio Collector - us-2.
    • An unverified publisher label with a This application is not published by Microsoft or your organization statement and no publisher links. This label is expected.
    • A single requested permission: Sign in and read user profile. This permission appears for Microsoft Graph API as the User.Read delegated claim under the application Permissions in the Microsoft Entra admin center. The application does not request access to any other resources.
  3. Click Accept.

After you grant consent, verify that the application appears under Entra ID > Enterprise apps in the Microsoft Entra admin center.

Step 2: Register a Microsoft Entra application​

To establish trust between Copilot Studio and CrowdStrike AIDR, create an app registration in your tenant.

  1. In the Microsoft Entra admin center, go to App registrations.
  2. Click + New registration.
  3. Set the name, such as CrowdStrike - Copilot Studio Integration.
  4. Select the single tenant option from the supported account types.
  5. Click Register.
  6. Copy the Application (client) ID for use in later steps.

Step 3: Configure Federated Identity Credential​

The app registration does not require any API permission grants. Instead, configure a Federated Identity Credential (FIC). This credential enables Copilot Studio to authenticate to CrowdStrike AIDR without client secrets or scoped permissions.

  1. Open the app registration, and then go to Manage > Certificates & secrets > Federated credentials.
  2. Click + Add credential.
  3. Select the scenario: Other issuer.
  4. Set Issuer to the value shown on the Install tab.

    Example issuer URL
    https://login.microsoftonline.com/<tenant-id>/v2.0
  5. Set Type to Explicit subject identifier.
  6. Set Value to the Subject value shown on the Install tab. The AIDR console computes this value from your Entra Tenant ID and the CrowdStrike endpoint URL.
  7. Enter a descriptive Name for the credential.
  8. Click Add.

Step 4: Configure threat detection in Power Platform admin center​

Connect Copilot Studio to CrowdStrike AIDR as an external threat detection provider.

  1. Log in to the Power Platform admin center .
  2. Go to Security > Threat detection > Additional threat detection.
  3. Select the target environment, and then click Set up.
  4. Enable Allow Copilot Studio to share data with a threat detection provider.
  5. Enter the Azure Entra App ID, which is the Application (client) ID from Step 2.
  6. Enter the Endpoint link shown on the Install tab.

    Example endpoint link
    https://api.collector-crowdstrike.com/aidr/guards/v1/copilot_studio
  7. Under Set error behavior, select the default action when AIDR is unavailable:
    • Allow the agent to respond (fail-open): The agent proceeds with tool execution.
    • Block the query (fail-closed): The agent stops and notifies the user.
  8. Click Save. Saving validates the connection to the AIDR endpoint. If the Entra application or FIC is misconfigured, validation fails. Click Copy error info for diagnostics.

Step 5: Verify the integration​

  1. In your configured environment, open a Copilot Studio agent that uses generative orchestration.
  2. In the agent test pane, send a message that triggers a tool invocation.
  3. Confirm that the tool invocation event appears on the Findings page in the AIDR console.

Data shared with AIDR​

Copilot Studio sends this data to AIDR for each tool invocation.

FieldDescription
User messageThe user's most recent prompt
Chat historyRecent messages exchanged between the user and the agent
Agent reasoningThe agent's explanation for selecting the tool
Tool definitionThe tool name, description, and input and output parameter schemas
Tool inputsThe specific parameter values the agent intends to pass to the tool
Previous tool outputsResults from tools already executed in the current plan
Conversation metadataThe agent ID, tenant ID, environment ID, user ID, conversation ID, and whether the agent is published
note:

AIDR analyzes only the tool name and input parameters.

AIDR logs the most recent user message, conversation history, and tool inputs.

Next steps​

  • View collected data on Visibility and Findings pages. Analyze it in Next-Gen SIEM to decide on further implementation steps.

  • Determine which policy to apply:

    • Start with monitoring policies and report actions.
    • Apply protection to identified risks by enforcing blocking and data transformation actions based on your organization’s AI usage guidelines.
  • For more info, see Collector Categories.

©2026 CrowdStrike. All rights reserved.

PrivacyTerms of UseLegal Notices