Almanac
Microsoft/d365salesDynamics 365

Consultant-focused KB for Microsoft Dynamics 365 Sales: implementation notes, gotchas, and configuration decisions beyond the official docs — across pipeline management, opportunities, forecasting, sequences, sales accelerator, Copilot, integrations, administration, and licensing.

feature-copilot-enablement-and-access-control.mdv1 · history
CurrentApplies to AllUpdated 6 days agoSource Microsoft Learn

What it does

Copilot in Dynamics 365 Sales is turned on and off through a stack of four separate switches — tenant-level Power Platform settings, an Entra group allow list, and a per-app toggle inside Sales Hub. All of them default to on, which means most orgs get Copilot whether they planned for it or not, and the work on a project is usually deciding who should not have it.

Key facts

  • Copilot is on by default for organisations in a region with an Azure OpenAI Service endpoint, and for those that consented to cross-region data movement and put the sales app on the monthly release channel. Everyone else needs an admin to consent to data movement in the Power Platform admin center, then switch Copilot on in Sales Hub. If someone previously turned it off, it stays off.
  • The four levels: tenant-level Chat agent in Model-Driven Apps (preview) under Copilot > Settings > Power Apps; the tenant-level Dynamics 365 Sales Copilot setting; the "Control who can use AI features in model-driven apps" Entra group restriction; and the app-level toggle in Sales Hub. A user has to clear all four.
  • The Sales Hub setting lives under Change area > App Settings > General Settings > Copilot. All apps takes Default, On or Off, and Individual apps overrides it per app — so you can run Copilot in Sales Hub only.
  • "Sales app" means any app containing the lead and opportunity tables that isn't on the exclusion list — Field Service and its mobile app, Resource Scheduling, the App for Outlook module, Customer Service Hub, Copilot Service Workspace, Omnichannel Engagement Hub and Project Service.
  • Turn audit on sits on the same page and switches audit history on for lead, opportunity and account. Copilot needs it to show recent changes; without it the Recent changes tab isn't available.
  • Bing search is a separate tenant consent affecting account news only. Turning it off kills the "Get latest news for accounts" prompt and nothing else.
  • A hidden app called Copilot in Dynamics 365 Sales is installed in every Sales environment whether Copilot is on or not, plus a matching Azure app registration for auth. It self-updates and self-renews. Don't delete either.
  • Microsoft's position is that the Sales agent in Microsoft 365 Copilot will become the preferred route to Copilot assistance in Sales. When it's enabled, the experiences split under one icon: Chat for the Sales agent, App Skills for Copilot in Dynamics 365 Sales. Using Microsoft 365 Copilot inside Dynamics 365 Sales is still documented as preview.
  • Azure OpenAI resources behind Copilot are opted out of abuse monitoring and human review, and no customer data is kept in a new data store. That's the line that gets you through most security reviews.

When to use / skip

There's no real "skip" here — it's on unless you turn it off, so treat this as a governance exercise rather than a feature decision. The orgs that genuinely need to intervene are the regulated ones, the ones outside an Azure OpenAI region who haven't consented to data movement, and the ones running a phased rollout where only a pilot team should see Copilot. Everyone else should spend their effort on summary field configuration and adoption instead of the on/off switch.

If your client is public sector or financial services with a nervous DPO, budget a session on the data flow and the cross-region consent early. That conversation blocks go-live more often than any technical task.

Configuration decisions

  • Whether to consent to cross-region data movement. Microsoft recommends it even with a local Azure OpenAI endpoint, so Copilot survives a regional outage. Some clients won't accept that, and it's a genuine trade-off.
  • Whether Copilot is on for all sales apps or only named ones. If you're piloting, set All apps to Off and switch on the single app.
  • Whether to restrict access by Entra group. It's the only user-level control; no security role grants or removes Copilot in Sales.
  • Whether to consent to Bing search. It buys account news and nothing else, and it sends the account name to Bing.
  • Whether to turn auditing on for lead, opportunity and account, accepting the storage cost on high-volume tables.
  • Whether to enable the Sales agent in Microsoft 365 Copilot alongside, and so which experience sellers are trained on.

Gotchas

  • Turning off the tenant-level control makes the Sales Hub Copilot settings page disappear entirely. Admins report "the settings have gone" and the trail goes cold unless you know to look in the Power Platform admin center.
  • DLP is the most common silent failure. Block the connectors Copilot needs — Microsoft Copilot Studio, Dataverse, the knowledge-source connectors — and Copilot loads, then refuses to answer with a generic "unable to connect".
  • The other common first-run failure is the Copilot in Dynamics 365 Sales agent failing to publish in Copilot Studio when first created. Republishing once fixes it permanently.
  • Enabling the Sales agent in Microsoft 365 Copilot changes who generates the summary banner for accounts and opportunities. Your carefully configured summary fields stop being used until you reconfigure them on the agent side.
  • Auditing switched on to support recent changes doesn't switch itself off. Remove summary fields from related tables later and you have to turn audit history off for those tables by hand.
  • Some agent capabilities consume Copilot Studio capacity and are billed by consumption; the billing setup article itself is still marked preview. Base Copilot chat and summaries aren't what burns credits — the agents are.

Consultant notes

  • Do the data residency conversation in discovery, not in UAT. Ask where the tenant sits, whether there's a local Azure OpenAI endpoint, and get the cross-region consent signed off by whoever owns data protection.
  • Before you demo anything, check DLP. A blocked connector makes Copilot look broken and you'll spend the demo apologising.
  • Push back on "turn it on for everyone on day one". Entra group restriction plus a single app toggle gives you a clean pilot, and adoption is better when the first cohort has been shown what the summaries are built from.
  • Check the audit decision with whoever owns environment capacity. Turning auditing on across lead, opportunity and account in a large org isn't free.
  • Tell the client plainly that Microsoft is steering towards the Sales agent in Microsoft 365 Copilot. If they're buying Microsoft 365 Copilot anyway, plan training around that rather than the App Skills pane.

Worth another look once the Sales agent in Microsoft 365 Copilot comes out of preview inside Dynamics 365 Sales, since the enablement path changes then.

Was this accurate?