Skip to content

Control 2.17: Cross-Tenant Agent Federation (MCP and Entra Agent ID)

Control ID: 2.17 Pillar: Security & Protection Regulatory Reference: GLBA §501(b), SEC Reg S-P (248.30), FFIEC IT Handbook (Information Security Booklet), OCC Bulletin 2023-17 (Third-Party Relationships: Risk Management), FINRA Rule 3110 (supervisory systems and WSPs) Last Verified: 2026-06-12 Governance Levels: Baseline / Recommended / Regulated


Scope boundary: FSI-CopilotGov vs FSI-AgentGov

This control governs the Microsoft 365 Copilot surface only — tenant-level configuration, data-source posture, audit/eDiscovery, and admin-managed extensibility. Governance of the agents themselves (Copilot Studio agents, declarative agents, Agent Builder, custom pro-code agents) — including agent registration, risk tiering, environment zoning, model-card review, and lifecycle promotion — lives in the companion FSI-AgentGov framework. See Relationship to FSI-AgentGov for the full boundary map.

Consume-and-cross-link control

Identity-plane and MCP-server-trust governance for cross-tenant agents is authoritative in FSI-AgentGov, not here. This control is intentionally thin: it covers only the Microsoft 365 Copilot consumption side — the firm's decision to permit or block cross-tenant published agents that surface in the Copilot experience, and the inventory awareness needed to make that decision. For the underlying controls, use:

Objective

Govern, from the Microsoft 365 Copilot side, the decision to permit or block agents that cross an organizational tenant boundary and surface in the Copilot experience — including cross-tenant Microsoft Entra Agent ID-backed agents, Model Context Protocol (MCP) federated servers, and externally published Copilot Studio agents. This control helps support GLBA §501(b) safeguard requirements, SEC Reg S-P (248.30) customer-information protection, FFIEC third-party access expectations, OCC Bulletin 2023-17 third-party lifecycle risk management, and FINRA Rule 3110 supervisory systems and WSPs.

The authoritative agent-identity, Conditional Access, MCP-server-trust, and agent-lifecycle controls live in FSI-AgentGov (see the callout above). This control adds the Copilot-surface guardrail and cross-references those controls rather than re-specifying them. It complements Control 2.16 — Federated Connector and MCP Governance (single-tenant connector/MCP enablement) and Control 1.10 — Vendor Risk Management (authoring intake).

Why This Matters for FSI

  • GLBA §501(b) — when a cross-tenant agent surfaced in Copilot can retrieve or return customer non-public personal information (NPI), the safeguard boundary extends to an external tenant the firm does not directly administer.
  • SEC Reg S-P (248.30) — cross-tenant agent invocation can move customer data outside the firm's tenant boundary through an external endpoint.
  • FFIEC IT Examination Handbook (Information Security Booklet) — identity federation and external connections are expected to be governed; permitting an external agent into the Copilot experience is such a connection.
  • OCC Bulletin 2023-17 — each external tenant whose agent is consumed is effectively a third-party data processor subject to lifecycle risk management.
  • FINRA Rule 3110 (supervisory systems and WSPs) — written supervisory procedures should identify cross-tenant agents surfaced in Copilot as a supervised technology surface.

No single control satisfies these obligations. Apply this control together with the authoritative FSI-AgentGov controls and the firm's third-party risk program.

Control Description

Authoritative governance is in FSI-AgentGov. The agent identity, Conditional Access, MCP-server-trust, attestation, and decommissioning mechanics referenced below are specified in FSI-AgentGov Controls 2.26, 2.17, and 2.25. This control does not restate them; it governs the Copilot-surface admit/deny decision and the cross-references that keep the two frameworks aligned.

Copilot-Side Scope (what this control governs)

In scope here (Copilot consumption side) Authoritative elsewhere (FSI-AgentGov)
Decision to permit or block externally published Copilot Studio agents that appear in the Microsoft 365 Copilot experience, via M365 admin center > Integrated apps / Agents (Agent registry) Agent identity lifecycle, Conditional Access for agent identities, attestation, and decommissioning — AgentGov 2.26
Inventory awareness of cross-tenant agents and MCP servers that reach the firm's Copilot users, for supervisory and examination readiness MCP server registration, signed attestation, and cross-tenant trust — AgentGov 2.17 + MCP Server Governance playbook
Requiring admin approval before users install externally published agents into Copilot; blocking end-user self-install Agent 365 registry, registry sync, and control-plane policy — AgentGov 2.25

Three Cross-Tenant Patterns (reference)

The three cross-tenant patterns — (1) cross-tenant Entra Agent ID-backed agents, (2) MCP federated server trust, and (3) Copilot Studio multi-tenant publishing — are described in full in the FSI-AgentGov controls referenced above. From the Copilot side, all three reduce to the same question: should this externally originated agent be allowed to surface for the firm's Copilot users, and is it inventoried for supervision?

Risk Profile for FSI

Cross-tenant agents surfaced in Copilot introduce opaque provenance, supervisory gaps, third-party lifecycle gaps, and data-residency exposure. The mitigations (signed attestation, Conditional Access for agent identities, cryptographic provenance verification) are governed by FSI-AgentGov; the Copilot-side mitigation is to block by default and admit only inventoried, approved external agents.

Copilot Surface Coverage

M365 Application Cross-Tenant Agent Exposure Notes
Microsoft 365 Copilot Chat Yes Primary surface for externally published Copilot Studio agents
Microsoft 365 Copilot Agents (declarative) Yes May reference cross-tenant MCP endpoints; governed for trust in AgentGov
Teams (custom agents) Yes External agents installed by users surface here
Word, Excel, PowerPoint, Outlook Indirect Inherit any cross-tenant agent the user has installed
Microsoft Purview (audit) Yes Cross-tenant invocations should appear in the unified audit log (Control 3.1)

Governance Levels

Baseline

  • Maintain Copilot-side awareness of which cross-tenant / externally published agents can surface for the firm's users, sourced from the M365 admin center Agent registry and Integrated apps.
  • Block externally published agents by default; admit only those recorded in the firm's approved list.
  • Defer agent-identity, Conditional Access, and MCP-trust configuration to FSI-AgentGov Controls 2.26 and 2.17.
  • Require documented admin approval before an externally published agent is made available to Copilot users; block end-user self-installation.
  • Reconcile the Copilot-side approved list with the FSI-AgentGov cross-tenant agent inventory and attestation records on a semi-annual basis.
  • Confirm that cross-tenant agent activity surfaced in Copilot is captured by existing Purview audit and supervision tooling (Controls 3.1, 3.6).

Regulated

  • Reconcile the Copilot-side approved list with FSI-AgentGov attestation and third-party review records quarterly; suspend Copilot availability of any agent whose AgentGov attestation has lapsed.
  • Include the Copilot-side approved list and the cross-references to FSI-AgentGov evidence in examination packages.
  • When a counterparty relationship terminates, confirm — as part of the FSI-AgentGov decommissioning runbook — that the external agent no longer surfaces for Copilot users.

Setup & Configuration

Step 1: Identify Externally Published Agents Reaching Copilot

Portal: Microsoft 365 admin center > Integrated apps and Microsoft 365 admin center > Agents (Agent registry).

Review which externally published agents and connectors can surface for the firm's Copilot users. Record each one in the firm's Copilot-side approved list with owner, counterparty, and approval status. Deep identity and MCP-server attributes are maintained in the FSI-AgentGov inventory — reference, do not duplicate, that record.

Step 2: Apply the Admit/Deny Decision in the Copilot Surface

Block externally published agents by default. Admit only agents that appear in the firm's approved list and have a current FSI-AgentGov attestation/identity record. Require admin approval before an external agent is made available; block end-user self-installation.

Step 3: Configure Identity, Conditional Access, and MCP Trust in FSI-AgentGov

Use FSI-AgentGov Control 2.26 for Entra Agent ID and Conditional Access for agent identities, and FSI-AgentGov Control 2.17 plus the MCP Server Governance playbook for MCP server registration and attestation. Record the cross-reference so examiners can trace the Copilot-side decision to the authoritative control.

Licensing note (verify in FSI-AgentGov): Conditional Access for agent identities and Agent 365 licensing prerequisites are documented in FSI-AgentGov and at Conditional Access for agents. Verify current requirements before deploying in production.

Step 4: Audit and Supervision Coverage

Confirm that cross-tenant agent activity surfaced in Copilot is captured by the unified audit log (Control 3.1) and supervision tooling (Control 3.6). Forward anomalies to the SIEM (Control 4.11). Full cross-tenant invocation telemetry and detection content are governed in FSI-AgentGov.

Financial Sector Considerations

  • OCC Bulletin 2023-17 lifecycle alignment: The Copilot-side approved list should reference the FSI-AgentGov third-party lifecycle record for each counterparty rather than maintaining a parallel one.
  • FINRA Rule 3110 supervisory systems and WSPs: Identify cross-tenant agents surfaced in Copilot as a supervised technology surface; point supervisors to the FSI-AgentGov inventory and attestation evidence.
  • MNPI and customer NPI handling: Where Copilot may include customer NPI or MNPI in prompts to a cross-tenant agent, exclude those data classes via DLP and prompt scoping (Controls 2.1, 2.5) until the counterparty's handling controls are confirmed in FSI-AgentGov.
  • Information barrier scope: Confirm cross-tenant agents surfaced in Copilot respect information barriers (Control 2.4).
  • Data residency posture: Cross-tenant agents may process data outside approved residency boundaries (Control 2.7); the residency assessment is recorded in FSI-AgentGov.

Verification Criteria

# Verification Step Expected Outcome Tier
1 Review the Copilot-side approved list of externally published agents Every externally published agent that can surface for Copilot users is listed with owner, counterparty, and approval status Baseline
2 Confirm default-block posture in the Copilot surface Externally published agents are blocked by default; only approved-list agents are admitted Baseline
3 Confirm cross-reference to FSI-AgentGov Each approved agent references a current FSI-AgentGov identity/attestation record (Controls 2.26 / 2.17) Recommended
4 Confirm admin-approval gate External agents require admin approval before Copilot availability; end-user self-install is blocked Recommended
5 Confirm audit/supervision coverage Cross-tenant agent activity surfaced in Copilot appears in the unified audit log and supervision tooling Recommended
6 Confirm quarterly reconciliation (Regulated) The Copilot-side approved list is reconciled with FSI-AgentGov attestation/third-party records each quarter; lapsed attestations trigger Copilot suspension Regulated
7 Confirm decommissioning linkage (Regulated) On counterparty termination, the external agent no longer surfaces for Copilot users, evidenced against the FSI-AgentGov decommissioning runbook Regulated

Additional Resources


FSI Copilot Governance Framework v1.8.0 - July 2026