Forum Discussion
Minimum Environment Permissions (Security Roles) for Copilot Studio Agent in Teams?
Your test shows that SharePoint read access alone is insufficient for the agent’s first query, while temporary maker/editor roles initialize access. End users should not need Environment Maker, Bot Contributor, or editor access to chat. Microsoft says chat users can receive “User – can use the agent,” but connector-backed unstructured knowledge needs a Dataverse role, such as Basic User. For OneDrive and SharePoint content stored in Dataverse, that role needs read privileges on Plug-in Assembly, Plug-in Type, SDK Message, SDK Message Processing Step, and SDK Message Processing Step Image. Assign that least-privilege role to a fresh test user, keep the agent shared for chat, require authentication, and verify direct read access to the SharePoint content. Test in Teams without opening Copilot Studio. Persistence after revocation is not proof of supported access; cached tokens or already-provisioned state are possibilities, not documented guarantees. Validate after sign-out and token expiry.