Configure Microsoft Agent Sync
- Identify your Microsoft Global Administrators. Microsoft agent sync uses application permissions that require admin consent in Microsoft Entra. Only Global Administrators can grant admin consent for your organization. Ensure a Microsoft Global Administrator is available so that they can grant admin consent during the course of the set up.
Security: These domains in the Agent System of Record functional area:
- Agent Compliance
- Agent Management Hub
- Manage: Agents
- Reports: Agent Reporting
- Setup: Agents
These domains in the System functional area:
- Reports: AI Agent Security
- Security Configuration
This guide describes how to set up the one-time administrative bootstrap required to synchronize agents from Microsoft Copilot Studio (CPS) and Azure AI Foundry into the Workday Agent System of Record (ASOR).
- Configure Microsoft access:
- Access the Microsoft Entra admin center:
- Register a newService Principal(App Registration) to represent the Workday Agent Sync integration.
- Generate and save the Client ID and Client Secret to your clipboard for later use in Workday.
- Access the Power Platform Admin Center:
- Navigate to .
- Create a new Application User.
- Map this user to the Service Principal that you created in the previous section.
- For Copilor Studio integrations:
- Assign the roles that you want to have access to Dataverse (ex. System Administrator).
- PowerShell Authorization: Open PowerShell and run this command to grant the application user access to the agent's custom connectors. This step is required to connect the Service Principal and the PowerApps database.
- # First, connect to your Power Platform accountAdd-PowerAppsAccount # Define variables$connectorName = "%2Fproviders%2FMicrosoft.PowerApps%2Fapis%2Fshared_staffing-20change-20job-5f37e4e62c5a1b3800-5f947f09f4586dacb3"$environmentId = "ad3c7726-1a23-e541-a1d1-0b4b68e34c1d"$userObjectId = "305cfb44-9301-4fed-8d9f-0b45a861dd6e" # Assign permissionsSet-AdminPowerAppConnectorRoleAssignment -ConnectorName $connectorName -EnvironmentName $environmentId -RoleName CanView -PrincipalType User -PrincipalObjectId $userObjectId
- For Azure Foundry Integration: Access .
- Copy these identifiers to your clipboard for the Workday configuration:Azure Portal:
- Tenant ID: Search for .
Power Platform Admin Center (For Copilot Studio Integration):- Environment URL and Environment ID: Click .
Azure Foundry Platform (for Foundry integration):- For each project, click to retrieve each endpoint.
- Configure sync in Workday:
- Access theCreate Microsoft Agent Sync Configurationtask in Workday.
- For Foundry integration, create new Azure group resources and enter:
- Microsoft Azure Group Name
- Microsoft Azure Group URL: Foundry Project Endpoint
- For Copilot Studio project groups, enter:
- Environment Name
- Environment URL
- Environment ID
- Create new External Client CredStore for Sync:
- Auth Scheme for External Client: OAuth 2.0 Client Credential.
- Client ID:Service Principle Client ID.
- Client Secret:Service Principle Client Secret.
- Token Endpoint:https://login.microsoftonline.com/<TenantID>/oauth2/v2.0/token
- ClickOKand start the sync.
- Verify agent sync:
- Access Agent Management Hub.
- In Microsoft:
- For Copilot Studio: Edit the security settings of your Custom Connector and enter the Workday ASU credentials.
- Use the Copilot agent playground to invoke the agent and confirm it can successfully call Workday.