Building custom solutions that extend, automate, and integrate Microsoft 365 apps.
Hi @Edward
Based on the current product design, this scenario isn't supported.
The Copilot Studio in Copilot for M365 option in the Microsoft 365 Admin Center controls the user's entitlement to the Copilot Studio capability, but authoring permissions are also governed by Power Platform environment security roles.
According to Secure your Copilot Studio projects - Microsoft Copilot Studio, users who need to author agents should be assigned the Environment Maker security role. If a user is granted the Environment Maker role in the Default environment so they can create Power Apps and personal Power Automate flows, they also receive the environment-level authoring permissions that Copilot Studio relies on.
I have not found Microsoft documentation describing a supported configuration that allows users to retain Environment Maker capabilities for Power Apps and Power Automate while preventing Copilot Studio authoring within the same environment. The documented governance approach is to manage access through environment permissions, security roles, and environment design.
If your goal is to prevent specific users from creating Copilot Studio agents, the supported approach is to manage environment access and security roles accordingly and consider using separate environments for users who need agent authoring capabilities. Microsoft documentation on environment strategy and governance recommends using environment separation and role-based access controls to manage different workloads and maker scenarios.
You can read more at:
- Work with Power Platform environments - Microsoft Copilot Studio | Microsoft Learn
- Develop a tenant environment strategy to adopt Power Platform at scale - Power Platform | Microsoft…
I hope this helps clarify the current behavior.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.