Control 2.17: Cross-Tenant Agent Federation (MCP and Entra Agent ID)
Control ID: 2.17 Pillar: Security & Protection Regulatory Reference: GLBA §501(b), SEC Reg S-P (248.30), FFIEC IT Handbook (Information Security Booklet), OCC Bulletin 2023-17 (Third-Party Relationships: Risk Management), FINRA Rule 3110 (supervisory systems and WSPs) Last Verified: 2026-06-12 Governance Levels: Baseline / Recommended / Regulated
Scope boundary: FSI-CopilotGov vs FSI-AgentGov
This control governs the Microsoft 365 Copilot surface only — tenant-level configuration, data-source posture, audit/eDiscovery, and admin-managed extensibility. Governance of the agents themselves (Copilot Studio agents, declarative agents, Agent Builder, custom pro-code agents) — including agent registration, risk tiering, environment zoning, model-card review, and lifecycle promotion — lives in the companion FSI-AgentGov framework. See Relationship to FSI-AgentGov for the full boundary map.
Consume-and-cross-link control
Identity-plane and MCP-server-trust governance for cross-tenant agents is authoritative in FSI-AgentGov, not here. This control is intentionally thin: it covers only the Microsoft 365 Copilot consumption side — the firm's decision to permit or block cross-tenant published agents that surface in the Copilot experience, and the inventory awareness needed to make that decision. For the underlying controls, use:
- FSI-AgentGov Control 2.26 — Entra Agent ID Identity Governance — agent identities, Conditional Access for agent identities, sign-in/audit, attestation, decommissioning.
- FSI-AgentGov Control 2.17 — Multi-Agent Orchestration Limits and the MCP Server Governance playbook — MCP server registration, signed attestation, and cross-tenant trust.
- FSI-AgentGov Control 2.25 — Agent 365 Admin Center Governance Console — Agent 365 registry, registry sync, and control-plane governance.
Objective
Govern, from the Microsoft 365 Copilot side, the decision to permit or block agents that cross an organizational tenant boundary and surface in the Copilot experience — including cross-tenant Microsoft Entra Agent ID-backed agents, Model Context Protocol (MCP) federated servers, and externally published Copilot Studio agents. This control helps support GLBA §501(b) safeguard requirements, SEC Reg S-P (248.30) customer-information protection, FFIEC third-party access expectations, OCC Bulletin 2023-17 third-party lifecycle risk management, and FINRA Rule 3110 supervisory systems and WSPs.
The authoritative agent-identity, Conditional Access, MCP-server-trust, and agent-lifecycle controls live in FSI-AgentGov (see the callout above). This control adds the Copilot-surface guardrail and cross-references those controls rather than re-specifying them. It complements Control 2.16 — Federated Connector and MCP Governance (single-tenant connector/MCP enablement) and Control 1.10 — Vendor Risk Management (authoring intake).
Why This Matters for FSI
- GLBA §501(b) — when a cross-tenant agent surfaced in Copilot can retrieve or return customer non-public personal information (NPI), the safeguard boundary extends to an external tenant the firm does not directly administer.
- SEC Reg S-P (248.30) — cross-tenant agent invocation can move customer data outside the firm's tenant boundary through an external endpoint.
- FFIEC IT Examination Handbook (Information Security Booklet) — identity federation and external connections are expected to be governed; permitting an external agent into the Copilot experience is such a connection.
- OCC Bulletin 2023-17 — each external tenant whose agent is consumed is effectively a third-party data processor subject to lifecycle risk management.
- FINRA Rule 3110 (supervisory systems and WSPs) — written supervisory procedures should identify cross-tenant agents surfaced in Copilot as a supervised technology surface.
No single control satisfies these obligations. Apply this control together with the authoritative FSI-AgentGov controls and the firm's third-party risk program.
Control Description
Authoritative governance is in FSI-AgentGov. The agent identity, Conditional Access, MCP-server-trust, attestation, and decommissioning mechanics referenced below are specified in FSI-AgentGov Controls 2.26, 2.17, and 2.25. This control does not restate them; it governs the Copilot-surface admit/deny decision and the cross-references that keep the two frameworks aligned.
Copilot-Side Scope (what this control governs)
| In scope here (Copilot consumption side) | Authoritative elsewhere (FSI-AgentGov) |
|---|---|
| Decision to permit or block externally published Copilot Studio agents that appear in the Microsoft 365 Copilot experience, via M365 admin center > Integrated apps / Agents (Agent registry) | Agent identity lifecycle, Conditional Access for agent identities, attestation, and decommissioning — AgentGov 2.26 |
| Inventory awareness of cross-tenant agents and MCP servers that reach the firm's Copilot users, for supervisory and examination readiness | MCP server registration, signed attestation, and cross-tenant trust — AgentGov 2.17 + MCP Server Governance playbook |
| Requiring admin approval before users install externally published agents into Copilot; blocking end-user self-install | Agent 365 registry, registry sync, and control-plane policy — AgentGov 2.25 |
Three Cross-Tenant Patterns (reference)
The three cross-tenant patterns — (1) cross-tenant Entra Agent ID-backed agents, (2) MCP federated server trust, and (3) Copilot Studio multi-tenant publishing — are described in full in the FSI-AgentGov controls referenced above. From the Copilot side, all three reduce to the same question: should this externally originated agent be allowed to surface for the firm's Copilot users, and is it inventoried for supervision?
Risk Profile for FSI
Cross-tenant agents surfaced in Copilot introduce opaque provenance, supervisory gaps, third-party lifecycle gaps, and data-residency exposure. The mitigations (signed attestation, Conditional Access for agent identities, cryptographic provenance verification) are governed by FSI-AgentGov; the Copilot-side mitigation is to block by default and admit only inventoried, approved external agents.
Copilot Surface Coverage
| M365 Application | Cross-Tenant Agent Exposure | Notes |
|---|---|---|
| Microsoft 365 Copilot Chat | Yes | Primary surface for externally published Copilot Studio agents |
| Microsoft 365 Copilot Agents (declarative) | Yes | May reference cross-tenant MCP endpoints; governed for trust in AgentGov |
| Teams (custom agents) | Yes | External agents installed by users surface here |
| Word, Excel, PowerPoint, Outlook | Indirect | Inherit any cross-tenant agent the user has installed |
| Microsoft Purview (audit) | Yes | Cross-tenant invocations should appear in the unified audit log (Control 3.1) |
Governance Levels
Baseline
- Maintain Copilot-side awareness of which cross-tenant / externally published agents can surface for the firm's users, sourced from the M365 admin center Agent registry and Integrated apps.
- Block externally published agents by default; admit only those recorded in the firm's approved list.
- Defer agent-identity, Conditional Access, and MCP-trust configuration to FSI-AgentGov Controls 2.26 and 2.17.
Recommended
- Require documented admin approval before an externally published agent is made available to Copilot users; block end-user self-installation.
- Reconcile the Copilot-side approved list with the FSI-AgentGov cross-tenant agent inventory and attestation records on a semi-annual basis.
- Confirm that cross-tenant agent activity surfaced in Copilot is captured by existing Purview audit and supervision tooling (Controls 3.1, 3.6).
Regulated
- Reconcile the Copilot-side approved list with FSI-AgentGov attestation and third-party review records quarterly; suspend Copilot availability of any agent whose AgentGov attestation has lapsed.
- Include the Copilot-side approved list and the cross-references to FSI-AgentGov evidence in examination packages.
- When a counterparty relationship terminates, confirm — as part of the FSI-AgentGov decommissioning runbook — that the external agent no longer surfaces for Copilot users.
Setup & Configuration
Step 1: Identify Externally Published Agents Reaching Copilot
Portal: Microsoft 365 admin center > Integrated apps and Microsoft 365 admin center > Agents (Agent registry).
Review which externally published agents and connectors can surface for the firm's Copilot users. Record each one in the firm's Copilot-side approved list with owner, counterparty, and approval status. Deep identity and MCP-server attributes are maintained in the FSI-AgentGov inventory — reference, do not duplicate, that record.
Step 2: Apply the Admit/Deny Decision in the Copilot Surface
Block externally published agents by default. Admit only agents that appear in the firm's approved list and have a current FSI-AgentGov attestation/identity record. Require admin approval before an external agent is made available; block end-user self-installation.
Step 3: Configure Identity, Conditional Access, and MCP Trust in FSI-AgentGov
Use FSI-AgentGov Control 2.26 for Entra Agent ID and Conditional Access for agent identities, and FSI-AgentGov Control 2.17 plus the MCP Server Governance playbook for MCP server registration and attestation. Record the cross-reference so examiners can trace the Copilot-side decision to the authoritative control.
Licensing note (verify in FSI-AgentGov): Conditional Access for agent identities and Agent 365 licensing prerequisites are documented in FSI-AgentGov and at Conditional Access for agents. Verify current requirements before deploying in production.
Step 4: Audit and Supervision Coverage
Confirm that cross-tenant agent activity surfaced in Copilot is captured by the unified audit log (Control 3.1) and supervision tooling (Control 3.6). Forward anomalies to the SIEM (Control 4.11). Full cross-tenant invocation telemetry and detection content are governed in FSI-AgentGov.
Financial Sector Considerations
- OCC Bulletin 2023-17 lifecycle alignment: The Copilot-side approved list should reference the FSI-AgentGov third-party lifecycle record for each counterparty rather than maintaining a parallel one.
- FINRA Rule 3110 supervisory systems and WSPs: Identify cross-tenant agents surfaced in Copilot as a supervised technology surface; point supervisors to the FSI-AgentGov inventory and attestation evidence.
- MNPI and customer NPI handling: Where Copilot may include customer NPI or MNPI in prompts to a cross-tenant agent, exclude those data classes via DLP and prompt scoping (Controls 2.1, 2.5) until the counterparty's handling controls are confirmed in FSI-AgentGov.
- Information barrier scope: Confirm cross-tenant agents surfaced in Copilot respect information barriers (Control 2.4).
- Data residency posture: Cross-tenant agents may process data outside approved residency boundaries (Control 2.7); the residency assessment is recorded in FSI-AgentGov.
Verification Criteria
| # | Verification Step | Expected Outcome | Tier |
|---|---|---|---|
| 1 | Review the Copilot-side approved list of externally published agents | Every externally published agent that can surface for Copilot users is listed with owner, counterparty, and approval status | Baseline |
| 2 | Confirm default-block posture in the Copilot surface | Externally published agents are blocked by default; only approved-list agents are admitted | Baseline |
| 3 | Confirm cross-reference to FSI-AgentGov | Each approved agent references a current FSI-AgentGov identity/attestation record (Controls 2.26 / 2.17) | Recommended |
| 4 | Confirm admin-approval gate | External agents require admin approval before Copilot availability; end-user self-install is blocked | Recommended |
| 5 | Confirm audit/supervision coverage | Cross-tenant agent activity surfaced in Copilot appears in the unified audit log and supervision tooling | Recommended |
| 6 | Confirm quarterly reconciliation (Regulated) | The Copilot-side approved list is reconciled with FSI-AgentGov attestation/third-party records each quarter; lapsed attestations trigger Copilot suspension | Regulated |
| 7 | Confirm decommissioning linkage (Regulated) | On counterparty termination, the external agent no longer surfaces for Copilot users, evidenced against the FSI-AgentGov decommissioning runbook | Regulated |
Additional Resources
- FSI-AgentGov Control 2.26 — Entra Agent ID Identity Governance
- FSI-AgentGov Control 2.17 — Multi-Agent Orchestration Limits
- FSI-AgentGov Control 2.25 — Agent 365 Admin Center Governance Console
- FSI-AgentGov — MCP Server Governance playbook
- Microsoft Entra Agent ID
- Conditional Access for agent identities
- Manage agents in the Microsoft 365 admin center
- Model Context Protocol (MCP) Specification
- OCC Bulletin 2023-17 — Third-Party Relationships: Risk Management
- FINRA Rule 3110 — Supervision
- Sister Solution: Solution 21 — Cross-Tenant Agent Federation Auditor (operational counterpart that performs inventory, attestation validation, and review workflows in coordination with FSI-AgentGov)
- Related Controls: 1.10 Vendor Risk Management, 2.4 Information Barriers, 2.7 Data Residency, 2.16 Federated Connector and MCP Governance, 3.8 Model Risk Management, 4.13 Extensibility Governance
FSI Copilot Governance Framework v1.8.0 - July 2026