AAgentProof

Help · No environments found

No environments found

After you connect Microsoft, AgentProof lists the Power Platform environments your account can see. If that list comes back empty, this covers the common causes and exactly what to do next. You can always add a non-Microsoft agent to keep moving.

  • No environments found after connecting Microsoft

    What happened

    You completed the Microsoft sign-in (real OAuth) and AgentProof connected successfully, but when it asked Microsoft for your Power Platform environments, the list came back empty. The connection itself is fine; there were simply no environments visible to the account you signed in with. Live environment discovery is still being enabled, so in some cases the connection succeeds before the discovery list is available for your workspace.

    Why it matters

    AgentProof can only assess an agent that lives in an environment it can see, and it deliberately mirrors exactly what Microsoft returns for your account; it never elevates your permissions or invents environments. An empty list almost always means an account, tenant, role, or rollout situation rather than a fault, so it is usually quick to resolve.

    What to do next

    1. Confirm you signed in with the correct Microsoft work or school account (not a personal account), in the tenant that owns the environments you want to assess.
    2. Check the Power Platform admin center (admin.powerplatform.microsoft.com) to confirm this tenant has environments and that your account can see them. If you cannot see them there, AgentProof cannot either; that is by design.
    3. Confirm your account has a Power Platform / environment role in the tenant.
    4. If you have more than one account, use Reconnect Microsoft and explicitly pick the account that owns the environments.
    5. If live discovery is still being enabled, or you just want to keep moving, use Add a non-Microsoft agent to describe an agent in plain English and build a compliance-readiness record now.

    What information to include

    1. The Microsoft work or school account you signed in with.
    2. Your tenant or organisation name and your workspace name.
    3. Whether you can see the environments in the Power Platform admin center.
    4. Which environment role your account has, and roughly when you tried.

    When to contact support

    If you have confirmed the right account and tenant, you can see environments in the Power Platform admin center, your account has an environment role, and the list is still empty, email [email protected]. Tell us your workspace and roughly when you tried; do not send any tokens, passwords, or secrets.

  • Microsoft did not allow the environment list (permissions or admin consent)

    What happened

    AgentProof signed in to Microsoft, but Microsoft declined the read-only request to list your Power Platform environments. This is usually a tenant permissions setting: either your account lacks an environment administrator role, or your organisation has not yet granted the one-time admin consent that lets AgentProof read environment metadata. AgentProof did not read any business records.

    Why it matters

    Environment discovery depends on a documented, read-only Microsoft permission. Until your tenant allows it, the list cannot load; but this is a one-time approval, not a recurring problem, and it is handled entirely on your side in Microsoft.

    What to do next

    1. Use Copy admin troubleshooting text in the panel and send it to your Power Platform or Microsoft Entra administrator. It contains the exact, plain-English request and safe diagnostic details only, never tokens or secrets.
    2. Ask your administrator to grant your account a Power Platform / environment administrator role, and to grant admin consent for AgentProof read-only environment-metadata permission if it has not been granted yet.
    3. Once your administrator confirms, click Retry discovery.
    4. If you cannot get this resolved right away, use Add a non-Microsoft agent so you can still produce a compliance-readiness record in the meantime.

    What information to include

    1. Your tenant or organisation name and your workspace name.
    2. Whether your administrator has granted the environment role and the one-time admin consent.
    3. The exact permission or consent message shown on screen.
    4. The time of the failed attempt, never any token, secret, or sign-in link.

    When to contact support

    If your administrator has granted the role and admin consent and discovery still fails, email [email protected] with your workspace name and the time of the failed attempt. Do not include any tokens, secrets, or sign-in links.

  • You may have connected a different Microsoft tenant

    What happened

    AgentProof detected that the account you connected may belong to a different Microsoft tenant than the one you expected. AgentProof can only see environments that belong to the tenant of the account you signed in with.

    Why it matters

    If you have access to more than one organisation, it is easy to pick the wrong account at the Microsoft prompt and land in a tenant that has no relevant environments. The fix is simply reconnecting with the right account.

    What to do next

    1. Click Reconnect Microsoft and, at the Microsoft prompt, explicitly choose the account that belongs to the tenant you want to assess.
    2. If you are unsure which tenant owns your environments, confirm in the Power Platform admin center, or ask your IT administrator.
    3. If you need to proceed before sorting this out, use Add a non-Microsoft agent.

    What information to include

    1. The tenant or organisation name you intended to connect.
    2. The Microsoft account you actually signed in with.
    3. Your workspace name.
    4. The mismatch message shown on screen, never any token or tenant secret.

    When to contact support

    If you are confident you connected the correct tenant but AgentProof still reports a mismatch, email [email protected] with your workspace name. Never paste tokens or tenant secrets.

  • AgentProof could not reach Microsoft's service

    What happened

    AgentProof could not reach Microsoft Power Platform service to list your environments. This usually means a network firewall or a Microsoft conditional-access policy is blocking the connection, or Microsoft service was briefly unavailable, not that anything is wrong with your account.

    Why it matters

    When the upstream call cannot complete, AgentProof reports it honestly rather than showing a misleading empty list or guessing a cause. Most of the time a retry, or a quick network or policy check, resolves it.

    What to do next

    1. Click Retry discovery; brief Microsoft outages and transient network issues often clear on their own.
    2. If it persists, ask your IT administrator whether a firewall or conditional-access policy is blocking access to the Power Platform admin API, and to allow the read-only connection.
    3. Use Add a non-Microsoft agent if you need to continue while this is investigated.

    What information to include

    1. Your workspace name.
    2. The approximate times you retried discovery.
    3. Whether your IT team has confirmed nothing on their side is blocking it.
    4. The exact wording of the could-not-reach message.

    When to contact support

    If retries keep failing and your IT team confirms nothing on their side is blocking it, email [email protected] with your workspace name and the approximate times you tried, so we can check for an upstream issue. Do not send tokens or secrets.

  • Discovery has not run yet, or the session needs refreshing

    What happened

    Your Microsoft tenant is connected and verified, but AgentProof either has not looked for environments yet, needs a short-lived metadata access session to finish, or a previous connection has expired and needs reconnecting.

    Why it matters

    Discovery is an explicit, read-only step rather than something that runs silently in the background, so occasionally you simply need to start it or refresh the session. None of this affects any data already in your workspace.

    What to do next

    1. If the panel offers Run discovery or Retry discovery, click it to list the environments your account can see.
    2. If you are asked to Continue with Microsoft, you will briefly see Microsoft account confirmation and then return to AgentProof; pick the same work account that owns your environments.
    3. If you see Reconnect Microsoft, your earlier connection can no longer be used; reconnect with the same work account to restore discovery.

    What information to include

    1. Your workspace name.
    2. Which control you used (Run discovery, Retry discovery, Continue with Microsoft, or Reconnect Microsoft).
    3. The work account that owns your environments.
    4. The steps you took and what you saw, never any token, secret, or sign-in link.

    When to contact support

    If you run discovery or reconnect repeatedly and never reach a list of environments, email [email protected] with your workspace name and the steps you took. Do not paste tokens, secrets, or sign-in links.

Still empty after checking the above?

Contact support with your workspace name and roughly when you tried. Please do not send any tokens, passwords, or secrets.

Email support →