Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

First identify which Microsoft surface is failing: a Microsoft 365 Copilot plugin that connects to an MCP server or API, an MCP app in Microsoft 365 Copilot, or Copilot Studio’s MCP integration. Their settings and known issues differ, so a plugin-manifest fix may not apply to a Copilot Studio connection. Then locate the failure stage—endpoint, authentication, tool discovery, or invocation—before changing configuration.

This guide follows Microsoft Learn’s troubleshooting documentation checked on September 29, 2026. The Copilot Studio MCP troubleshooting page was last updated August 19, 2026; Microsoft’s plugin authentication troubleshooting and MCP app troubleshooting pages show July 16, 2026 updates.

Identify the Copilot surface and failure stage

“Microsoft Copilot API MCP Server” can describe different integration paths. Confirm the host and integration type in your setup before applying a fix:

  • Microsoft 365 Copilot plugin or MCP app: Use Microsoft’s plugin authentication or MCP app troubleshooting guidance. Plugin authentication may involve a manifest and an authentication configuration stored in the Microsoft Enterprise token store.
  • Copilot Studio MCP integration: Use the Copilot Studio troubleshooting path. It documents transport and tool-schema compatibility issues that are distinct from plugin authentication settings.

Classify the failure by its observable symptom: endpoint or network error, sign-in or token exchange error, empty tool list, tool that does not trigger, or sign-in popup that remains open. Microsoft’s troubleshooting pages use labels such as “No tools listed,” “Users can’t sign in or token exchange fails,” “Sign in popup opens but gets stuck or never closes,” and “Tools not triggering from Copilot chat.” These are documentation headings, not prevalence statistics.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For Microsoft 365 Copilot, begin by exposing the actual error rather than guessing. Microsoft’s instruction is: “To see authentication errors in agent responses, enable developer mode.” Inspect the debug information card and the Actions section, which shows MCP tools available to an agent. Microsoft’s authentication troubleshooting guide and MCP apps troubleshooting guide provide the corresponding paths.

Fix a server that is reachable but lists no tools

An empty Actions list can result from endpoint or authentication trouble, discovery configuration, or runtime validation. Check them in that order.

  1. Verify the MCP endpoint. Confirm the server is running and that the plugin manifest points to the intended MCP endpoint. Check the URL against the server configuration, including the relevant host and path.
  2. Check authentication before discovery. Some servers return no tools until a user signs in. Resolve any authentication error first, then inspect the tool list again.
  3. Test discovery. Confirm the server’s tools/list response contains the expected tools. If the server does not return them, investigate its MCP implementation or configuration rather than changing Copilot’s invocation settings.
  4. Check dynamic discovery settings. For dynamic discovery, Microsoft documents run_for_functions: ["*"] with an empty top-level functions array. Also check whether runtime validation has withheld a tool.
  5. Check pinned tool declarations. If tools are declared in the manifest, verify the functions entries, descriptions, and run_for_functions tool names agree with the tools the server provides.

Microsoft’s MCP apps troubleshooting page documents these discovery checks. A server that returns tools but still shows none in Copilot points toward manifest configuration or runtime validation; a server that returns none points toward endpoint, authentication, or server-side discovery.

Repair plugin sign-in and OAuth configuration

For a Microsoft 365 Copilot plugin, compare the OAuth provider, authentication configuration, and plugin manifest as a set. Microsoft identifies mismatches among these locations as a common source of sign-in failure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Match the base URL. The authentication configuration’s Base URL must match the MCP server url in the manifest. For an API plugin, compare it with the applicable OpenAPI server URL instead.
  2. Register the exact redirect URI. In the OAuth provider, register https://teams.microsoft.com/api/platform/v1.0/oAuthRedirect.
  3. Match the reference ID. The runtime’s auth.reference_id must match the ID of the authentication configuration in the Teams developer portal.
  4. Verify app and tenant access. Check whether app-level and organization-level usage restrictions allow the application and the tenant using it.
  5. Check the App ID. If the error identifies an App ID mismatch, compare the plugin App ID with the OAuth or SSO registration rather than changing unrelated URL settings.

Authentication options depend on the plugin type. Microsoft documents Entra SSO, OAuth 2.0, and anonymous authentication for both MCP and API plugins; dynamic client registration (DCR) for MCP plugins only; and API keys for API plugins only. API-key support differs between MCP and API plugins. Agent connector authorization is a separate configuration surface, so do not assume plugin settings control it. See Microsoft’s authentication configuration overview.

Interpret token and authorization errors

Observed error or behavior What to check Action
HTTP 307 from the OAuth token endpoint The token endpoint is redirecting. Microsoft documents HTTP 307 Temporary Redirect from a token endpoint as unsupported in the Microsoft 365 Copilot plugin flow. Configure a direct token endpoint instead of relying on that redirect.
App ID mismatch Plugin App ID versus OAuth or SSO registration. Make the registered IDs consistent.
Base URL mismatch Manifest MCP server URL or API server URL versus authentication-config Base URL. Make the relevant URLs match.
Missing or incorrect reference_id Runtime reference versus authentication-config ID in the Teams developer portal. Set the runtime reference to the correct authentication-config ID.
Organization access restriction Tenant or organization policy. Ask the organization administrator to review whether the app is permitted.

For an on-behalf-of flow that needs user consent to another API, Microsoft says to return 401 Unauthorized to prompt the user to sign in and grant consent. Do not treat that response as interchangeable with a generic server failure: in this flow it is part of the consent path. The precise correction depends on the error shown in the debug information card. See Microsoft’s plugin authentication troubleshooting guidance.

Resolve consent, SSO, and repeated sign-in problems

Clear stored OAuth credentials

To clear stored OAuth credentials for the Microsoft 365 Copilot experience, sign out through Chat settings > Agents, then authenticate again. This is useful when a saved credential or prior consent state is interfering with the current sign-in.

Check Entra SSO configuration

For Entra SSO, verify the app’s Application ID URI, the consent redirect URI, and the Microsoft Enterprise token store client against Microsoft’s documented configuration. A mismatch in one can prevent token acquisition even when the MCP endpoint is available.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When SSO tokens persist

Signing out does not necessarily force Entra SSO to reauthenticate: token persistence can depend on caching or tenant and client settings. Microsoft points to removing consent or revoking sessions when forced reauthentication is needed. Coordinate those actions with the relevant administrator because they affect the user’s authorization state beyond a single tool call. Follow the exact flow-specific details in Microsoft’s troubleshooting page.

Fix a sign-in popup that authenticates but will not close

If authentication appears successful but the popup remains open, Microsoft identifies a destroyed window.opener reference as a likely cause. The redirect chain may sever the link the popup needs to notify its opener that sign-in is complete.

  1. Open the popup’s developer tools and inspect window.opener through the redirect sequence.
  2. Use the Network tab to examine responses in the redirect chain and identify a Cross-Origin-Opener-Policy: same-origin header.
  3. Review navigation for rel="noopener", which can also remove the opener reference.
  4. Correct the response or navigation behavior that severs the reference, then retry the sign-in flow.

Do not diagnose this as an OAuth credential mismatch solely because the popup fails to close; first determine whether the authentication completed and the opener was lost. Microsoft describes this case in its authentication troubleshooting guide.

Check Copilot Studio MCP transport and schema constraints

These checks apply to Copilot Studio’s MCP integration, not automatically to Microsoft 365 Copilot plugins. Its troubleshooting page identifies several known compatibility issues:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Open SSE connection endpoint: The endpoint returned by the Open SSE connection call must be a full URI. An incomplete endpoint can prevent the connection from being established.
  • exclusiveMinimum schema value: It must be Boolean. A different value can make the schema incompatible.
  • type field: It should contain only one type value.
  • Reference-type inputs or outputs: These are unsupported and are filtered.
  • Enum inputs: Copilot Studio interprets enum inputs as strings.

Microsoft labels these as known issues; its page does not provide a workaround for every item. If a tool is filtered or its input is represented differently, compare its schema with these constraints before treating the symptom as a network outage. See Microsoft’s Copilot Studio MCP troubleshooting page, last updated August 19, 2026.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If you are diagnosing a page visually as part of your integration workflow, ScreenshotNeo can return a screenshot or PDF with one request. For example:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for request options. Cookie and consent banners are accepted or removed before capture, along with known newsletter popups and chat widgets; each step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and the response reports the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info, and capture_pdf for AI agents. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 shots.

Sign up for ScreenshotNeo’s free plan to get 1,000 screenshots a month with no card.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prevent repeat failures with a staged check

When the connection breaks again, use the same checkpoints in sequence instead of changing several settings at once:

  1. Identify the host surface: Microsoft 365 Copilot plugin or MCP app, versus Copilot Studio.
  2. Expose the diagnostic response or error, then classify it as endpoint, authentication, discovery, invocation, or schema behavior.
  3. For plugin sign-in, compare the OAuth provider, authentication configuration, and manifest values; for missing tools, inspect authentication, tools/list, runtime validation, and manifest declarations.
  4. For Copilot Studio, verify the full URI returned by Open SSE and check the documented schema constraints.
  5. Change only the setting implicated by the observed error and retest the affected stage.

Microsoft’s troubleshooting pages do not publish connection failure rates or resolution-rate statistics, so a generic “connection failed” message cannot establish a single most likely cause. The host, stage, and concrete error are the useful diagnostic evidence.

Frequently Asked Questions

Does every Copilot MCP connection use a plugin manifest?

No. Microsoft 365 Copilot plugins and Copilot Studio MCP integration are distinct surfaces; confirm which one you configured before changing manifest or connector settings.

Does Microsoft publish a rate for how often these connection failures occur?

The cited Microsoft troubleshooting pages do not publish a prevalence or resolution-rate statistic.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.