Beyond the first agent
Having built a basic agent, you now move to the capabilities that make one production-ready: high-quality generative answers from custom knowledge, secure authentication, integration with Power Automate, real logic with variables and Power Fx, and a disciplined approach to deployment across environments.
The gap between a demo agent and a deployed one is rarely the conversation design. It is authentication, governance, and lifecycle management. This unit concentrates on exactly those areas.
By the end of this unit- Configure custom knowledge sources and tune generative answers for accuracy and grounding.
- Use variables, conditions, and Power Fx to add real logic, and integrate Power Automate flows.
- Apply user authentication and an application lifecycle management (ALM) approach across environments.
What changes at production scale
- Answers from a single public site
- Anonymous or no authentication
- Built and edited directly in one environment
- Tested by the author only
- Answers grounded in governed, permission-aware sources
- Authenticated users with appropriate access
- Promoted through dev, test, and production environments
- Monitored, versioned, and supportable
- Custom knowledge configuration and answer grounding
- User authentication and connection security
- Solution-based ALM with environment promotion
- Logic via variables, conditions, and Power Fx
Generative answers and knowledge
Generative answers let the agent respond to questions you have not explicitly authored, drawing on connected knowledge. Their quality depends on the sources you connect and how you configure grounding. A confident, fluent, wrong answer is the failure mode to design against.
1. Connect custom knowledge sources
Beyond a single public site, connect SharePoint sites and documents, Dataverse tables, file uploads, and — for richer scenarios — custom data via connectors. Choose authoritative, maintained sources and scope each to what the agent genuinely needs. Breadth without relevance degrades answer quality.
2. Ground answers and keep them in scope
Configure the agent to answer from its connected knowledge rather than general model knowledge where accuracy matters. Grounding ties responses to your content and provides citations, so users can verify. Constrain the agent so it declines gracefully when the answer is not in its sources, rather than improvising.
3. Test against real questions and edge cases
Evaluate answers with the genuine questions users will ask, including ambiguous and out-of-scope ones. Check the citations point to the right content, and confirm the agent says "I don't have that information" when it should. This is where you catch confident hallucination before users do.
When generative answers honour source permissions, an authenticated user only sees content they are entitled to. This makes user authentication a prerequisite for safe knowledge grounding — not an optional add-on. Pair the two deliberately.
An agent gives a fluent, confident answer about a policy that does not actually exist in its connected sources. What is the most likely configuration issue?
Variables, conditions, and Power Fx
Real agents make decisions. Variables hold state across a conversation, conditions branch on that state, and Power Fx expressions compute and transform values. Together they turn a linear script into responsive logic.
How the pieces fit
Variables — holding state across the conversation
Conditions — branching on what you know
Power Fx — expressions for computation
Power Automate — extending what the agent can do
Think of a conversation where your agent currently asks the same thing twice, or asks something it could infer. Which variable would let it remember, and which condition would let it skip the redundant question? Small logic improvements like these are what make an agent feel competent rather than robotic.
Authentication, flows, and ALM
Enterprise deployment rests on two foundations: authenticating users so the agent acts within their permissions, and managing the agent's lifecycle so changes move safely from development to production.
Authentication
Configure user authentication so the agent knows who it is talking to. With Microsoft Entra ID authentication, the agent can respect each user's permissions, personalise responses, and pass identity into actions and grounded knowledge. For internal agents this is typically integrated authentication via Teams; for external or web agents you configure it explicitly. Authentication is what makes permission-aware knowledge and secure actions possible.
Application lifecycle management
1. Build inside a solution
Author the agent within a Power Platform solution so it, its flows, connections, and dependencies are packaged together. A solution is the unit you export and import — building outside one makes promotion painful later.
2. Separate dev, test, and production environments
Develop in one environment, validate in another, and run live in a third. This isolates work in progress from what users depend on, and gives you a place to test changes against representative data before they reach anyone.
3. Promote with managed solutions and pipelines
Export the agent as a managed solution and import it into the next environment, or use Power Platform pipelines to automate promotion. Reconfigure connection references and environment variables per environment so secrets and endpoints stay environment-specific. Version deliberately and keep release notes.
Deepen these skills with the official content:
Build copilots with Microsoft Copilot Studio ↗
End of Unit 7
You should now be able to:
- Configure custom knowledge and ground generative answers so the agent declines rather than improvises.
- Use variables, conditions, and Power Fx for logic, and call Power Automate flows as actions.
- Apply user authentication and a solution-based ALM approach across dev, test, and production.
Unit review
Why is grounding generative answers to connected sources important?
What is the difference between a topic variable and a global variable?
Why should you build a production agent inside a Power Platform solution?
Why is user authentication a prerequisite for permission-aware knowledge?
End of module
You have completed Course 07: Building Custom Copilots. Next: Extending Copilot With Plugins — declarative and custom agents, message extensions, API plugins, and Graph connectors.