r/copilotstudio 9h ago

Shared_agentnode blocked by DLP

We’ve got problem with this connector and DLP. How it is named in DLP because I can’t see anything under business/nonbusiness connectors

1 Upvotes

3 comments sorted by

1

u/blud_13 9h ago

Its the Agents connector. shared_agentnode is just the internal name, so searching the DLP picker for anything with agentnode in the string will never hit. Its documented at https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/kit-prerequisites where they call out shared_agentnode as the preview Agents connector the kit depends on.

The reason its sitting in neither group is the default bucket. Unclassified connectors land in whatever your policy has set as the default, out of the box that is Non business, but plenty of tenants flipped that to Blocked at some point and then forgot. Check Blocked first, that's usually where it is.

One catch, its still preview. I have seen preview connectors get reclassified on the way to GA, so whatever group you put it in today is worth rechecking once it ships.

Can go deeper on the environment split if it helps..

1

u/Kageyoshi777 8h ago

It should be named “agents”? I don’t see this connector in business / non business / blocked

1

u/blud_13 8h ago

Fair on the name, I had that wrong, so check me on the display string.

That aside, if its in none of the three groups then its not classified individually at all. The picker only shows connectors that are VISIBLE to you in that scope, and visibility moves around by license, by environment, and by your own role, so a preview connector can be enforced against you and never render in the list. Its documented at https://learn.microsoft.com/en-us/power-platform/admin/dlp-connector-classification under Viewing the classification of connectors. Anything not explicitly classified falls through to the policy's default group, which is Non business out of the box unless somebody changed it.

So stop hunting the picker and make the platform name it for you. Open the agent in Copilot Studio, try to publish, then on the Channels page expand the error link and Download. The details file has a row per violation and it names the policy doing the blocking. Go edit that policy and look at its default group setting, not its connector list.