Blog/Microsoft 365 Copilot Federated Connectors: What IT Admins Need to Lock Down
Microsoft 365CopilotIT GovernanceData Security

Microsoft 365 Copilot Federated Connectors: What IT Admins Need to Lock Down

July 30, 20267 min readBy Brad McCorkle, Founder & CEO, Lesos AI

Microsoft 365 Copilot federated connectors let Copilot pull live data from third-party apps like HubSpot, Notion, and Google Calendar the moment a user asks a question, using the Model Context Protocol instead of Microsoft's normal indexing pipeline. Microsoft ships the first wave of these connectors on by default for every tenant, so your users can already query outside systems through Copilot whether or not IT approved it. If you run a Microsoft 365 tenant, the connector list is worth checking this week.

This is not a hypothetical rollout still stuck in a preview ring somewhere.

Microsoft began the public preview in November 2025 and pushed federated connectors to general availability worldwide between April and May 2026. Every tenant with Microsoft 365 Copilot licensing got this feature on the same default-on terms, regardless of company size or industry.

What Are Microsoft 365 Copilot Federated Connectors?

A federated connector works differently from the Graph connectors most IT teams already know, which crawl and index content into Microsoft's search index ahead of time. Federated connectors skip indexing entirely. When a user asks Copilot something that touches a connected app, Copilot calls out to that app in real time over the Model Context Protocol, pulls back only the records the user's own account can already see there, and does not retain the response afterward. Nothing from HubSpot or Notion gets copied into your Microsoft 365 environment.

  • Canva
  • HubSpot
  • Notion
  • Linear
  • Intercom
  • Google Contacts
  • Google Calendar

That list is the starting point, not the ceiling. Microsoft adds new default connectors under the same tenant-wide toggle on an ongoing basis, so the set of external apps Copilot can query grows without a separate rollout announcement for each one.

Why Are These Connectors Turned On by Default in Every Tenant?

The default posture ships opt-out, not opt-in. Microsoft-published connectors go live for a tenant the day Microsoft ships them unless an admin has already flipped the tenant-wide toggle to off. That is a deliberate adoption choice on Microsoft's part, not an oversight, and it means the connector list in your tenant can grow without a single change request crossing an IT desk.

Before any user connects Copilot to HubSpot, Google Calendar, or another external service, check that service's data residency terms and your existing contract with that vendor. A federated connector does not renegotiate your agreement with HubSpot. It just gives Copilot a new path to query the data that agreement already covers.

What Can Copilot Actually See Through a Federated Connector?

  • Read-only by design: a connector can retrieve data from the connected app but cannot write back to it.
  • Runs on the user's own credentials, so Copilot can only see what that specific user is already authorized to see in the source app.
  • Nothing is copied into Microsoft Graph or indexed for search. Each query is a live round trip that ends when the answer is returned.
  • Every connector call is logged and auditable through Microsoft Purview.
  • The Connector Usage Report in the Microsoft 365 admin center shows which connectors are active and which Copilot agents reference them.

That is a reasonable security model on paper. It still depends entirely on your users' existing permissions in those third-party apps being correct, and in the access reviews I have run, they rarely are.

How Do You Govern Federated Connectors as an IT Admin?

Admins manage federated connectors from the Microsoft 365 admin center under Copilot connectors > Your connections, where each connector can be reviewed and toggled individually, alongside a single tenant-wide switch that disables every default connector at once.

  • Open the Microsoft 365 admin center and go to Copilot connectors > Your connections to see everything currently enabled in your tenant today.
  • Decide your default posture (allow all, allow-list, or block all) before users start asking why Copilot cannot see their HubSpot pipeline.
  • Use the tenant-wide toggle to lock in that posture. It applies automatically to new default connectors Microsoft releases later, so the decision does not need to be remade every quarter.
  • Pull the Connector Usage Report monthly and check it against your change log. This is the fastest way to catch a connector someone enabled through a departmental license outside IT's normal approval path.
  • Fold connector approvals into the same access review your SSO and MFA policies already go through instead of treating Copilot as a separate system.
Governance PostureWhat HappensBest Fit
Allow all (Microsoft default)Every Microsoft-published connector goes live automatically as Microsoft ships itTenants with mature data classification and low third-party licensing risk
Allow-listOnly connectors IT has reviewed stay on; everything else waits for approvalMost mid-market IT teams balancing user demand against audit requirements
Block allTenant-wide toggle disabled; Copilot answers only from content indexed the normal wayRegulated environments where third-party data residency terms are unclear

Where This Fits Your Broader AI Governance Program

The pattern here is not unique to Copilot. Every SaaS vendor is shipping some version of an agent that reaches into other tenants' data by default, and the vendor's incentive is adoption, not your audit trail. We built the same tiered review process into the SSO and MFA reset security model we deploy with clients, and the same model applies to any connector a vendor turns on without asking first.

If your team does not already have a standing process for reviewing default-on AI features before they reach users, that gap is worth closing before the next connector ships. That review process is exactly what our AI strategy engagements are built to set up: a repeatable checklist your team runs every time a vendor flips a new AI feature on, instead of reacting one connector at a time.

Frequently Asked Questions

Are Microsoft 365 Copilot federated connectors on by default?

Yes. Microsoft-published federated connectors are enabled by default for every tenant with Microsoft 365 Copilot licensing unless an admin has already disabled the tenant-wide toggle. New default connectors Microsoft releases later inherit whatever posture that toggle is set to.

How do I turn off federated Copilot connectors for my whole tenant?

Go to the Microsoft 365 admin center, open Copilot connectors > Your connections, and use the tenant-wide toggle to disable all default federated connectors in one operation, or disable individual connectors one at a time from the same screen.

Do federated connectors store third-party data inside Microsoft 365?

No. Federated connectors query the external app in real time using the Model Context Protocol and return an answer without indexing or storing the source data in Microsoft Graph. Each query is a live round trip tied to the requesting user's own permissions in that app.

Is this a security risk for a mid-market company?

The risk is proportional to how clean your access permissions already are inside the connected third-party apps, since Copilot inherits whatever a user can already see there. A company with stale HubSpot or Notion permissions inherits that same exposure through Copilot, which is why the admin center toggle and the Connector Usage Report matter more than the connector feature itself.

Which apps can Microsoft 365 Copilot connect to right now?

As of mid-2026, Microsoft's default federated connectors cover Canva, HubSpot, Notion, Linear, Intercom, Google Contacts, and Google Calendar, with Microsoft adding more apps to the default list on an ongoing basis under the same tenant-wide toggle.

Don't Let Default-On AI Features Outrun Your Governance

Support Team ships with the same tiered access controls, audit trail, and change log your security team already expects for ServiceNow and Microsoft 365 automation, so a new AI feature does not have to mean a new blind spot. Bring your current connector list and we will show you the gaps.

See How It Works

How AI-ready is your organization?

Free 2-minute assessment. Get an industry-specific score and action plan — no call required.

Get My Readiness Score