Forum Discussion

MB12345's avatar
MB12345
Copper Contributor
Sep 28, 2026

Best practice for Copilot Studio agents and SharePoint libraries with unique permissions?

We recently ran into an issue where a Copilot Studio agent was unable to retrieve content from SharePoint libraries that have unique permissions and nested folder structures. Users with elevated permissions were able to retrieve results, while users with read-only/visitor access could not, even though they had access to the underlying documents.

We've observed similar behavior across multiple agents and suspect the library's unique permission structure is impacting indexing or content retrieval.

For organizations that use SharePoint libraries with extensive unique permissions, nested folders, and restricted access models:

  • What is the recommended approach when using these libraries as knowledge sources for Copilot Studio agents?
  • Are there known limitations or best practices regarding unique permissions and nested folders?
  • Is it better to simplify permissions, create dedicated access groups, flatten the folder structure, or maintain separate agent-specific content locations?
  • How are others balancing security requirements with reliable agent retrieval?

We'd appreciate any guidance, best practices, or lessons learned from similar implementations.

1 Reply

  • sohnash's avatar
    sohnash
    Iron Contributor

    Hello MB12345​ , I'm curious which method did you use to connect your SharePoint libraries to the agent - one (on top) is a dataverse indexed option while the other (at the bottom) is a live connection? I wonder if the issue is related to this.

    I have not worked on cases where library folders/files have complex unique permissions. I'd assume based on the documentation that the agent picks up the content the user has access to. But if that is not working, we'd have to check more.

     

    If there is an opportunity to simplify permissions and restructure (e.g. separate document libraries instead of folders with unique permission), that should always be explored before designing the agent.