This article covers the Brightflag MCP connector in Microsoft Copilot. The first part is for Microsoft 365 administrators setting up the connector for the first time. The second part is for individual users connecting their own accounts. Administrators must complete their setup before users can connect.
This feature is currently in beta.
Part 1: Administrator setup
Before you start
You will need:
• The Global Administrator or AI Administrator role in the Microsoft 365 admin center.
• Access to the Teams Developer Portal.
• The MCP URL, client ID, and client secret provided to you by your Brightflag account team. If you do not have these, contact your Brightflag account team before proceeding.
• A Brightflag login. Step 2 signs in as a Brightflag user, so if you do not have one, ask a colleague who does to complete that step.
Every user who connects needs a paid Microsoft 365 Copilot license. Users on the free Copilot Chat (Basic) tier should not expect the connector to be available.
You will also enter these details in Step 1:
• Scopes: mcp:matter:read and mcp:invoice:read (your Brightflag account team will confirm)
• Authorization URL: https://auth.brightflag.com/oauth2/authorize
• Token URL: https://auth.brightflag.com/oauth2/token
• Client authentication method: Request body parameters (default). HTTP Basic authentication is also supported.
Step 1: Register the OAuth client
This step stores Brightflag’s sign-in details so that Copilot can connect users to Brightflag. It produces a registration ID that you will need in Step 2.
1. Go to the Teams Developer Portal (dev.teams.microsoft.com) and sign in with your admin account.
2. Select Tools, then OAuth client registration.
3. Select Register client.
4. Complete the form:
– Name the registration "Brightflag MCP" or another appropriate name.
– Enter the Base URL provided by your Brightflag account team.
– Leave Restrict usage by organization set to My organization only.
– Under Restrict usage by Teams app, select Any Teams app (for testing and store validation only).
– Enter the client ID and client secret provided by Brightflag.
– Enter the authorization URL and token URL listed above. If a refresh URL is requested, use the token URL.
– Enter the scopes provided by Brightflag.
– Leave Client password authentication method as Request body parameters (default).
– If the form offers PKCE, turn it on.
– Select Save.
5. Copy the registration ID that is generated.
Done. Keep the registration ID to hand and continue to Step 2.
Step 2: Create the connector
This step registers Brightflag as a connector in your organization, making it available to Copilot.
1. Go to the Microsoft 365 admin center (admin.microsoft.com).
2. Select Copilot, then Connectors.
3. Open the Gallery tab. Under Created by your org, select Add on Create a new connector.
4. Under Connect to MCP server, select Add.
5. Complete the form:
– Name it "Brightflag MCP".
– Use the MCP URL provided to you by Brightflag.
– Set the authentication type to OAuth 2.0 and enter the registration ID from Step 1.
– Add the developer name, website, privacy policy, and terms of use details requested.
6. Select Authorize. Sign in to Brightflag and select Allow Access.
7. Confirm you see the Success message.
Done. Brightflag now appears in your connections. Continue to Step 3.
Step 3: Roll out the connector to users
This step makes the connector available to your users. You can start with a pilot group and widen access later.
1. Go to Copilot, then Connectors, then the Your Connections tab, and select Brightflag.
2. Confirm the status shows Ready.
3. Under staged rollout, choose who can see the connector: everyone, or a pilot group first.
4. Confirm the option to allow information from this connection to appear in Copilot is switched On.
5. Assign a Microsoft 365 Copilot license to each user. Go to Users, then Active users, select the user, then Licenses and apps.
6. Allow up to 15 minutes for changes to take effect.
Done. Let your users know they can now connect their own accounts.
Part 2: Connect to Brightflag (users)
This part is for individual users connecting to Brightflag in Copilot for the first time. Your administrator must complete Part 1 first, and you need a Microsoft 365 Copilot license, before this option is available to you.
1. Open Microsoft 365 Copilot Chat (copilot.cloud.microsoft) and sign in with your work account.
2. Select the ellipsis (...) menu, then Settings.
3. Select Sources in the left pane.
4. Under Browse sources, search for Brightflag and select Connect.
5. Review the connection message, then select Continue.
6. You will be redirected to the Brightflag sign-in page. Sign in with your Brightflag credentials.
7. You will be asked to allow access to Brightflag by the MCP integration. Select Allow Access.
8. Return to Copilot and confirm Brightflag appears in your sources and a message says it is now connected.
You are all set and ready to start using the integration.
Tip. When you ask a question, mention Brightflag, for example "In Brightflag, show me all pending invoices from this month." Copilot decides for itself whether to use a connected source, and naming Brightflag makes it much more likely to do so.
Troubleshooting
Brightflag does not appear under Sources. Your administrator may not have rolled it out to you yet, or you may not have a Copilot license. Allow up to 15 minutes after any change, then refresh. Contact your administrator before raising a support request.
Sign-in fails after you enter your Brightflag credentials. Ask your administrator to check the client ID, client secret, and scopes, and that the Microsoft redirect URI is allowed on your Brightflag client. Share the timestamp and request ID from the error with your Brightflag account team.
Copilot answers without using Brightflag. Name Brightflag in your question, confirm the source is switched on, and start a new chat after connecting.
A question returns nothing. Ask "What vendors do we have?" to check the name matches what is in Brightflag. You can only see data that your own Brightflag permissions allow.
The connection stops working after a while. Go to Settings, then Sources, disconnect Brightflag, reconnect it, and sign in again.
