Edit

Manage AI experience access to Business Applications in Work IQ (preview)

Business Applications in Work IQ is in public preview. Preview features aren't meant for production use and might have restricted functionality. Microsoft makes these features available before an official release so that customers can get early access and provide feedback.

Connection controls are administrative settings that determine which AI experiences and applications can connect to business applications data. These controls let administrators manage availability through Microsoft 365 Copilot, allow or block access to the Work IQ MCP server, and use App Access to control which applications can access data in an environment.

This article covers connection controls. For environment features and data participation, see Manage participation in Business Applications in Work IQ. For the underlying data permissions, see Review user, agent, and application access for Business Applications in Work IQ.

Before you begin

You need to have the appropriate roles to manage AI experience access:

  • AI Administrator role to work with settings in the Microsoft 365 admin center.
  • Power Platform Administrator role to work with application-access settings in the Power Platform admin center.

Copilot access control

The Microsoft 365 admin center provides a setting that determines who can access business applications through Microsoft 365 Copilot. For most customers, availability is on for all users by default.

The audience setting determines who can use the connection. Existing business-data permissions determine which data each person can access. Administrators can choose from these audience options:

  1. All users: Make the connection available across your organization.
  2. Specific groups: Make the connection available to selected groups.
  3. No users: Turn off this connection for users in your organization.

To review or change this setting:

  1. Sign in to the Microsoft 365 admin center.
  2. Select Copilot > Settings.
  3. Open the setting for business applications availability in Microsoft 365 Copilot.
  4. Choose the audience.
  5. Select Save if you made changes.

Work IQ MCP server access control

The Work IQ MCP server has its own availability control for connected AI experiences and coding agents. This control applies to the entire Work IQ MCP server, separate from Copilot audience settings or App Access.

To review current availability:

  1. Sign in to the Microsoft 365 admin center.
  2. Select Agents > Tools.
  3. Select Work IQ MCP.
  4. Review its current availability.

To block access to the server, select Block.

Application access control (App Access)

App Access is the mechanism used to choose which applications, including agentic applications such as Copilot Cowork, are allowed to access data in a particular environment. Some Microsoft applications have preauthorized access to data in Dataverse, which you can control through App Access. App Access addresses application access to the underlying environment data. Work IQ participation settings serve a different purpose and don't prevent agentic access.

Third-party applications never have preauthorized access to Dataverse data.

Configuring application access

  1. Sign in to the Power Platform admin center.
  2. Select Security > Identity & access.
  3. Select App Access Control.
  4. Select the environment in which you want to enable app access.
  5. Select Enable, and then select Save.
  6. Return to the environment and select the applications you want to block from accessing the environment.

Verifying and restoring access

After a change takes effect, test a request from an application covered by the configuration and verify the expected access result.

To restore access to a blocked application, update its App Access configuration for the same environment and test the connection again.