How to allow users to use Power Automate Flows and Power Apps but not Copilot Studio?

Edward 66 Reputation points
2026-07-25T00:57:44.1433333+00:00

Hello, is this possible to be accomplished?

  1. In M365 Admin Center -> Billing -> Licenses -> M365 Copilot, we unchcked 'Copilot Studio in Copilot for M365'.

Based on my testing, it looks like 'Environment Maker' role for the user in that environment (Power Platform Admin Center) is overwriting it and allowing users to still access Copilot Studio.

Is there a way to allow users to create personal flows in Power Automate and/or Power Apps (in default environment) without granting them access to Copilot Studio?

Microsoft 365 and Office | Development | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Teddie-D 19,760 Reputation points Microsoft External Staff Moderator
    2026-07-27T04:18:34.2233333+00:00

    Hi @Edward

    Based on the current product design, this scenario isn't supported.

    The Copilot Studio in Copilot for M365 option in the Microsoft 365 Admin Center controls the user's entitlement to the Copilot Studio capability, but authoring permissions are also governed by Power Platform environment security roles.

    According to Secure your Copilot Studio projects - Microsoft Copilot Studio, users who need to author agents should be assigned the Environment Maker security role. If a user is granted the Environment Maker role in the Default environment so they can create Power Apps and personal Power Automate flows, they also receive the environment-level authoring permissions that Copilot Studio relies on.

    I have not found Microsoft documentation describing a supported configuration that allows users to retain Environment Maker capabilities for Power Apps and Power Automate while preventing Copilot Studio authoring within the same environment. The documented governance approach is to manage access through environment permissions, security roles, and environment design.

    If your goal is to prevent specific users from creating Copilot Studio agents, the supported approach is to manage environment access and security roles accordingly and consider using separate environments for users who need agent authoring capabilities. Microsoft documentation on environment strategy and governance recommends using environment separation and role-based access controls to manage different workloads and maker scenarios.

    You can read more at:

    I hope this helps clarify the current behavior.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".   

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.  

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.