AAgentProof

Help · Microsoft connection

Microsoft connection

How to connect your Microsoft tenant, what each connection state means, and what to do when discovery or access does not behave as expected. AgentProof uses the connection only to read environment and agent configuration metadata — it never modifies your tenant and never reads your business records.

  • Connecting your Microsoft tenant

    What happened

    You opened the Microsoft setup wizard (Workspace, Environments, Set up, Microsoft) to link your tenant so AgentProof can see your Power Platform environments and Copilot Studio agents. Connecting runs a real Microsoft (Entra ID) sign-in using Microsoft standard consent; AgentProof uses the connection only to read environment and agent configuration metadata - it never modifies your tenant.

    Why it matters

    The connection is the source of truth for everything downstream. Until a Microsoft tenant is connected, AgentProof has nothing to discover and cannot build a real compliance-readiness record from live tenant data. AgentProof reads only environment and agent configuration metadata, never your business records.

    What to do next

    1. Sign in to AgentProof first (magic-link sign-in) and make sure you are the workspace owner; the connection is saved against your workspace.
    2. Click Connect Microsoft and complete the Entra ID sign-in.
    3. After Microsoft sign-in you are returned to AgentProof and the connection state chip updates.
    4. Confirm the chip reads 'Connected (live discovery enabled)' or 'Sign-in proven - live discovery pending'; both are healthy outcomes.

    What information to include

    1. Your tenant or organisation name.
    2. The Microsoft account you signed in with.
    3. The connection state chip text shown on screen.
    4. The approximate time of your attempt, and a screenshot of the connection panel (no tokens).

    When to contact support

    If the wizard will not start, the Connect Microsoft button does nothing, or you are returned without any state change, contact [email protected] with the time of your attempt and the state chip text. Do not paste any tokens or secrets.

  • Sign-in proven, live discovery pending

    What happened

    Your Microsoft sign-in completed and was recorded against your workspace, but the live discovery step (listing your environments and agents directly from Microsoft) has not yet run. The chip shows in a neutral or positive colour, not a warning.

    Why it matters

    This is a real, successful sign-in. Live discovery is the part of the connector still being enabled across tenants. Your connection is genuine and durable; only the automatic listing of environments and agents is pending.

    What to do next

    1. Treat the connection as established; you do not need to reconnect.
    2. Live environment and agent discovery runs automatically once enabled for your tenant; no action is required from you to turn it on.
    3. In the meantime you can still progress a compliance-readiness record by adding your agents manually, so you get a real readiness score and compliance-readiness record while live discovery is being finished.

    What information to include

    1. Your tenant or organisation name.
    2. Your workspace name.
    3. How long the connection has shown sign-in proven, live discovery pending.
    4. Whether you want a discovery status or help adding agents manually.

    When to contact support

    If you have been in this state for an extended period and want a status on live discovery for your tenant, or you would like help adding agents manually, email [email protected].

  • No environments found

    What happened

    The connector reached your tenant but the environment list came back empty, or live environment discovery has not run yet for your tenant. The connection itself is fine; there are simply no environments visible to the account you signed in with right now.

    Why it matters

    Environments are the containers AgentProof discovers agents inside. With zero environments there is nothing to enumerate agents from, so a live-data compliance-readiness record cannot be built yet. This is almost always an account, tenant, role, or rollout matter rather than a broken connection.

    What to do next

    1. Confirm you signed in with the correct Microsoft work or school account (not a personal account), in the tenant that owns the environments.
    2. Open the Power Platform admin center (admin.powerplatform.microsoft.com) to confirm this tenant has environments and that your account can see them.
    3. Confirm your account has a Power Platform / environment administrator role; listing environments usually requires it.
    4. If you have several accounts, use Reconnect Microsoft and pick the account that owns the environments, then Retry discovery.
    5. While live discovery is being enabled, add an agent manually so you can still produce a compliance-readiness record.

    What information to include

    1. The Microsoft work or school account you signed in with.
    2. Your tenant or organisation name and your workspace name.
    3. Whether you can see the environments in the Power Platform admin center.
    4. Which environment role your account has.

    When to contact support

    If you have confirmed the right account, tenant, and role, and environments you can see in Microsoft still do not appear in AgentProof, contact [email protected]. Mention that you reached the no-environments state so we can confirm whether live discovery is enabled for your workspace.

  • No agents found inside an environment

    What happened

    Your environments are listed, but an environment you opened shows no agents. 'No agents found' is shown inside an environment, not on the environments list. Live agent discovery is still being enabled, so depending on rollout you may see this even where agents exist.

    Why it matters

    A compliance-readiness record is built against an agent. If an environment is genuinely empty there is nothing to document there yet; if it should contain agents, it usually points to visibility, role scope, or live discovery still being enabled.

    What to do next

    1. Open the specific environment to load the agents inside it.
    2. Confirm the environment is the one that contains your agents, and that your account can see them in that environment.
    3. Confirm there are published Copilot Studio agents in the environment that your signed-in account can see.
    4. While agent discovery is being enabled, add an agent manually (describe what it does, who it talks to, and what it can act on) so you can produce a compliance-readiness record now.

    What information to include

    1. The exact environment name you opened.
    2. Your tenant or organisation name and your workspace name.
    3. Whether you can see the agents in Copilot Studio or the Power Platform admin center.
    4. A brief description of the agent you expected to find.

    When to contact support

    If an environment that you know contains agents shows none even though your account can see them in Microsoft, contact [email protected] with the environment name.

  • Admin consent required or permissions denied

    What happened

    The sign-in worked, but the read-only Power Platform / Copilot Studio scopes AgentProof requests need your Entra ID tenant administrator consent, or those permissions were declined. Depending on the cause you may see 'permission needed', 'admin consent needed', or 'service unreachable'. AgentProof has not read any business records.

    Why it matters

    These are tenant-side settings, not failures of your AgentProof account. Until consent for the read-only scopes is granted, the connector cannot list your environments or agents. AgentProof only ever requests read access; it does not modify your tenant.

    What to do next

    1. Identify your Microsoft (Entra ID) tenant administrator.
    2. Ask them to grant the one-time admin consent for AgentProof read-only environment-metadata permission on the consent screen.
    3. Use Copy admin troubleshooting text to send them the exact request; it contains no tokens or secrets.
    4. If a network firewall or conditional-access policy is blocking access to the Power Platform admin API, ask IT to allow the read-only connection, then Retry discovery.
    5. In the meantime, add an agent manually to keep moving.

    What information to include

    1. The exact status word you see (for example Permission needed or Admin consent needed).
    2. Your tenant or organisation name and your workspace name.
    3. Whether your administrator has granted the one-time admin consent and the environment role.
    4. Whether a firewall or conditional-access policy might be blocking the connection.

    When to contact support

    If your administrator has granted consent and the correct role, removed any blocking policy, and discovery still fails, email [email protected] with the status word you see (for example 'Permission needed' or 'Admin consent needed').

  • You may have connected a different Microsoft tenant

    What happened

    AgentProof detected that the account you connected may belong to a different Microsoft tenant than the one you expected. AgentProof can only see environments that belong to the tenant of the account you signed in with.

    Why it matters

    If you have access to more than one organisation, it is easy to pick the wrong account at the Microsoft prompt and land in a tenant that has no relevant environments. The fix is simply reconnecting with the right account.

    What to do next

    1. Click Reconnect Microsoft and, at the Microsoft prompt, explicitly choose the account that belongs to the tenant you want to assess.
    2. If you are unsure which tenant owns your environments, confirm in the Power Platform admin center, or ask your IT administrator.
    3. If you need to proceed before sorting this out, add an agent manually.

    What information to include

    1. The tenant or organisation name you intended to connect.
    2. The Microsoft account you actually signed in with.
    3. Your workspace name.
    4. The mismatch message shown on screen, never any token or tenant secret.

    When to contact support

    If you are confident you connected the correct tenant but AgentProof still reports a mismatch, email [email protected] with your workspace name. Never paste tokens or tenant secrets.

  • Reconnect required — connection expired or revoked

    What happened

    Your workspace was connected before, but the stored Microsoft connection can no longer be used; it was revoked in your tenant, or the saved credentials are no longer valid.

    Why it matters

    This is not a first-time setup. Discovery and scoring pause until the connection is refreshed, but your workspace and past compliance-readiness records are unaffected.

    What to do next

    1. Open Workspace, Environments, Set up, Microsoft.
    2. Click Connect Microsoft to reconnect and refresh the credentials, using the same work account you used originally.
    3. If it was revoked in your tenant, check with your tenant admin that AgentProof read-only access is still permitted before reconnecting.

    What information to include

    1. Your tenant or organisation name and your workspace name.
    2. The work account you originally connected with.
    3. Whether the connection was revoked in your tenant.
    4. The time of your most recent reconnect attempt.

    When to contact support

    If reconnecting repeatedly drops back to reconnect-required, email [email protected] with the time of your most recent attempt.

  • We could not load your Microsoft connection right now

    What happened

    AgentProof could not read your connection status at that moment. This is a temporary read problem, not a disconnection.

    Why it matters

    AgentProof deliberately will not claim 'not connected' without confirming it. Your existing connection is safe; the status was simply unreadable for a moment.

    What to do next

    1. Refresh the page.
    2. If the message persists, you can safely reconnect from Workspace, Environments, Set up, Microsoft; your existing connection will not be lost.

    What information to include

    1. Your workspace name.
    2. The exact wording of the could-not-load message.
    3. Whether refreshing the page cleared it.
    4. The approximate time you saw the message.

    When to contact support

    If the status stays unavailable after a refresh and a reconnect attempt, email [email protected].

Need a person?

If a state chip or blocker message is unclear, contact support and include your workspace and the exact wording shown on the Microsoft setup wizard. Never paste tokens or secrets.

Email support →