Skip to main content

Connect Microsoft

Waxell discovers and governs the agents your organization runs in Microsoft 365 Copilot, Copilot Studio, and Azure AI Foundry — tenant-wide, across every Power Platform environment.

Onboarding is a single Global-Admin consent click. There is no app to register and no client secret to create or paste: you approve Waxell's application once, and a service principal is provisioned in your tenant with read-only permissions.

What Waxell can see

Read-only inventory and activity, nothing more:

  • Agent inventory — the Copilot agent catalog and, per environment, Copilot Studio agents (including drafts), plus Azure AI Foundry agents.
  • Activity — Copilot conversation transcripts and Foundry run traces, turned into governed runs attributed to each agent and the user who ran it.

Waxell never sends, edits, or deletes anything on your behalf during discovery.

  1. In Waxell, go to Governance → Agent Discovery → Connect and choose Microsoft 365 Copilot (or Azure AI Foundry).
  2. Click Connect with admin consent. You'll be taken to Microsoft's admin-consent screen.
  3. Sign in as a Global Administrator and approve. Microsoft returns you to Waxell, and the connection shows consent granted for your tenant.
  4. Click Sync. Waxell enumerates your Power Platform environments and discovers agents across all of them.

That's it — no app registration, no secret, and consent is tenant-wide, so it covers every user and environment.

Tenant-wide discovery

Waxell uses the Power Platform admin environments API to sweep every environment in your tenant, not just a default one — so Copilot Studio agents built in any environment are discovered. For the per-environment Dataverse detail, the consented service principal is added automatically where your tenant allows it; environments that require an explicit application user are listed in the connection so an admin can add it in one step.

Prefer to bring your own app?

Security-strict tenants can use their own single-tenant Entra app instead of Waxell's shared app:

  1. Register an Entra application in your tenant with the read-only Graph, Dataverse, and Power Platform permissions listed on the connection screen, and create a client secret.
  2. In the connector, choose Use your own app registration + secret instead.
  3. Enter the Directory (tenant) ID, Application (client) ID, and paste the client secret. The secret is encrypted at rest and never displayed again.
  4. Click Sync.

Both paths produce the same read-only discovery; admin consent is simply the zero-setup option.

Azure AI Foundry

Foundry connects the same way — admin consent (or your own app) — and adds a project endpoint so Waxell can list that project's agents and pull their run traces from your Azure Monitor / Application Insights telemetry.

What you get

Discovered Microsoft agents appear in your cross-cloud fleet under Governance → Agent Discovery, alongside your Google and AWS agents. Their conversations and runs flow onto the Executions screen, attributed to the acting user, and every governance policy you author applies to them.

Revoking access

Remove admin consent for the Waxell application from the Microsoft Entra admin center at any time, or delete the connection in Waxell. Either ends access immediately; discovered inventory is retained as history until you remove it.