Skip to main content
Administrator Guide
Last Updated: 2026-10-02
Configure Microsoft Agent Sync

Configure Microsoft Agent Sync

  • Identify your Microsoft Global Administrators. Microsoft agent sync uses application permissions that require admin consent in Microsoft Entra. Only Global Administrators can grant admin consent for your organization. Ensure a Microsoft Global Administrator is available so that they can grant admin consent during the course of the set up.
Security: These domains in the Agent System of Record functional area:
  • Agent Compliance
  • Agent Management Hub
  • Manage: Agents
  • Reports: Agent Reporting
  • Setup: Agents
These domains in the System functional area:
  • Reports: AI Agent Security
  • Security Configuration
This guide describes how to set up the one-time administrative bootstrap required to synchronize agents from Microsoft Copilot Studio (CPS) and Azure AI Foundry into the Workday Agent System of Record (ASOR).
  1. Configure Microsoft access:
    1. Register a new
      Service Principal
      (App Registration) to represent the Workday Agent Sync integration.
    2. Generate and save the Client ID and Client Secret to your clipboard for later use in Workday.
    3. Access the Power Platform Admin Center:
    4. Navigate to
      Manage
      Select Environment
      User + Permissions
      Application Users
      .
    5. Create a new Application User.
    6. Map this user to the Service Principal that you created in the previous section.
    7. For Copilor Studio integrations:
      1. Assign the roles that you want to have access to Dataverse (ex. System Administrator).
      2. PowerShell Authorization: Open PowerShell and run this command to grant the application user access to the agent's custom connectors. This step is required to connect the Service Principal and the PowerApps database.
      3. # First, connect to your Power Platform accountAdd-PowerAppsAccount # Define variables$connectorName = "%2Fproviders%2FMicrosoft.PowerApps%2Fapis%2Fshared_staffing-20change-20job-5f37e4e62c5a1b3800-5f947f09f4586dacb3"$environmentId = "ad3c7726-1a23-e541-a1d1-0b4b68e34c1d"$userObjectId = "305cfb44-9301-4fed-8d9f-0b45a861dd6e" # Assign permissionsSet-AdminPowerAppConnectorRoleAssignment -ConnectorName $connectorName -EnvironmentName $environmentId -RoleName CanView -PrincipalType User -PrincipalObjectId $userObjectId
      4. For Azure Foundry Integration: Access
        Foundry portal
        Project
        Project Details
        Parent Resource
        Users
        Add User
        .
    8. Copy these identifiers to your clipboard for the Workday configuration:
      Azure Portal:
      • Tenant ID: Search for
        Microsoft Entra ID
        Overview
        Tenant ID
        .
      Power Platform Admin Center (For Copilot Studio Integration):
      • Environment URL and Environment ID: Click
        Manage
        Environment
        .
      Azure Foundry Platform (for Foundry integration):
      • For each project, click
        Foundry portal
        Project
        Project Details
        to retrieve each endpoint.
  2. Configure sync in Workday:
    1. Access the
      Create Microsoft Agent Sync Configuration
      task in Workday.
    2. For Foundry integration, create new Azure group resources and enter:
      • Microsoft Azure Group Name
      • Microsoft Azure Group URL: Foundry Project Endpoint
    3. For Copilot Studio project groups, enter:
      • Environment Name
      • Environment URL
      • Environment ID
    4. Create new External Client CredStore for Sync:
      • Auth Scheme for External Client
        : OAuth 2.0 Client Credential.
      • Client ID:
        Service Principle Client ID.
      • Client Secret:
        Service Principle Client Secret.
      • Token Endpoint:
        https://login.microsoftonline.com/<TenantID>/oauth2/v2.0/token
    5. Click
      OK
      and start the sync.
  3. Verify agent sync:
    1. Access Agent Management Hub.
    2. In Microsoft:
      • For Copilot Studio: Edit the security settings of your Custom Connector and enter the Workday ASU credentials.
      • Use the Copilot agent playground to invoke the agent and confirm it can successfully call Workday.