Update Azure Connector for AI security features
Important information
Third-party documentation is subject to change. Updates might not be reflected in BeyondTrust documentation.
-
Log into Insights and navigate to the connector creation screen for a new Microsoft Azure Connector.
Follow steps 2 to 4 only.
You’ll need to rerun the setup script to add custom permissions for the BT-SP-Connector Service Principal. -
Register the connector as an admin management application. View Microsoft documentation.
- Requires PowerShell for Power Platform Administrators module
- Use the client ID of your configured BT-SP-Connector in Azure as the $appId in the script.
- Use the tenant ID of your Azure environment as the $tenantId in the script
-
From the Azure portal, launch Power Platform
-
Navigate to Manage > Environments
-
For each environment:
-
Select the environment
-
If Dataverse has not been enabled in your environment, select Add Dataverse
-
Elevate your user account to the System Administrator role. View Microsoft documentation.
-
Navigate to Security Roles > + New Role and configure:
-
Role Name:
BT-Read-Only
-
Business Unit: Select the current environment’s business unit
-
Uncheck Include App Opener privileges for running Model‑Driven apps
-
Select Save
-
Select Organization for Read column for the following rows:
Table Name Copilot bot Copilot component botcomponent Process workflow
-
-
From the current environment main page, navigate to S2S apps > + New app user
-
Add BT-SP-Connector as an app user, and assign it BT-Read-Only role
-
Updated about 1 hour ago