LowCodeStacks
Sign in

Copilot Studio knowledge: limits, sign-in rules and why the agent finds nothing

Every knowledge-source limit in one place (websites, SharePoint, files, Dataverse), the sign-in setting each channel needs, and a checklist for when an agent answers 'I don't know' or won't publish.

Copilot StudioLook it up · Quick reference6 min read

Checked against Microsoft Learn · 9 sourcesHow we write guides

An agent that can't find an answer it should know is rarely broken. Usually a limit was reached quietly, a file is too big to read, or the agent's sign-in setting doesn't fit the source or channel. This page puts those rules side by side.

Note

Checked against Microsoft Learn on 6 October 2026. Copilot Studio changes often, so check the Sources list for Microsoft's current figures.

Knowledge sources at a glance

How many sources an agent can search at once depends on its orchestration mode, set in the agent's settings: generative or classic. A Create generative answers node inside a topic always uses the classic limits.

SourceGenerative orchestrationClassic orchestrationWho it searches as
Public websites (searched with Bing)254Nobody: public content only
SharePoint (site URLs)254 per generative answers nodeThe person chatting
Uploaded filesAll files (not counted in the 25)Limited by Dataverse file storageNobody: stored with the agent
DataverseNo fixed limit2 sources, up to 15 tables eachThe person chatting
Enterprise data through connectorsNo fixed limit2 per agentThe person chatting

Across the whole agent:

  • up to 500 knowledge sources of all types;
  • up to 500 uploaded files, each up to 512 MB;
  • up to 1,000 topics and 200 trigger phrases per topic;
  • instructions for a Microsoft 365 Copilot agent up to 8,000 characters.

Warning

A Create generative answers node in a topic always works the classic way, even when the agent uses generative orchestration. So its public-website limit is 4, not 25. More than 4 makes publishing fail with TooManyPublicSiteSearchSources.

SharePoint specifics

  • File size depends on licensing:

    • without a Microsoft 365 Copilot licence in the same tenant, generative answers read SharePoint files up to 7 MB;
    • with that licence and tenant graph grounding with semantic search turned on, up to 200 MB.

    Bigger files can still appear in search results, but their contents aren't used for answers.

  • Pages: only modern SharePoint pages are read. Classic ASPX pages, and modern pages that contain SPFx components, are ignored.

  • File types: Word, PowerPoint and PDF files on a site can be used.

  • Links aren't followed. The agent reads the files and pages you add, not the pages they link to. Add a linked site as its own source if you need it.

  • Protected content is skipped. Files labelled Confidential or Highly confidential, and password-protected files, can't be indexed. They may still show as Ready but never contribute to answers.

  • Uploading a SharePoint folder (the "Upload files → SharePoint" route) syncs up to 1,000 files, 50 folders and 10 levels of subfolders per source, every 4–6 hours.

The sign-in setting must fit the channel and the source

In Settings → Security → Authentication, choose one of three options:

OptionWorks inCan use SharePoint and Dataverse knowledge?Notes
No authenticationWebsites and any public channelNo: only public sites and uploaded filesAnyone with the link can chat. Tools that need the user's own credentials won't work
Authenticate with Microsoft (default for new agents)Teams, Microsoft 365 Copilot, Power AppsYes, as the person chattingThe only option the Teams and Microsoft 365 channel accepts. Users aren't asked to sign in again
Authenticate manuallyWebsites, apps and other channelsYes, with extra set-up (below)Needed when you publish outside Microsoft's own apps but still want sign-in

Things that catch people out:

  • Teams group chats and channels can't use knowledge that needs the user's own sign-in, such as SharePoint. That works in one-to-one chats only, by design.
  • Manual authentication with SharePoint needs an Entra ID app registration with the delegated Sites.Read.All and Files.Read.All permissions, consent granted, and those two scopes added next to profile openid in the agent's authentication settings. If anything is missing, the agent doesn't error: it simply finds nothing. Generic OAuth isn't supported for SharePoint knowledge.
  • Your admin can override you. Admins can set per-environment rules, such as "Require Microsoft authentication". An agent whose setting no longer fits is blocked from publishing and stops answering until it's changed.

"The agent says it doesn't know": a checklist

Work down the list; most cases end in the first four.

  1. Is the source status Ready? Right after you add files, the status can briefly say Ready, switch to In progress, then Ready again. Wait for the second Ready.
  2. Can the person chatting see that content? SharePoint, Dataverse and connector sources answer as the user. If they can't open the file in SharePoint, the agent can't use it for them. Test with their account, not yours.
  3. Is the file small enough? Check the 7 MB / 200 MB SharePoint rule above. For a large reference document, upload it to the agent instead (up to 512 MB).
  4. Is the content readable? Look for sensitivity labels, password protection, a classic SharePoint page, or text that's only inside images. Images are only read inside PDF files.
  5. Is it the right channel? In a Teams group chat or channel, SharePoint knowledge won't work, so test in a one-to-one chat.
  6. Is SharePoint search restricted? If your tenant turned on Restricted SharePoint Search, SharePoint knowledge is blocked unless the site is on the allowed list. Ask your SharePoint admin.
  7. Too many sources? With more than 25 sources, generative orchestration picks which ones to search by their descriptions. Give every source a short, specific description of what it contains.
  8. Did you publish after changing it? Edits only reach users after Publish. In Teams, an existing conversation can keep the old version. Type "start over" to refresh it.

"It won't publish": a checklist

  • Open the Review panel. Blocking issues stop publishing; warnings don't. Typical blockers: a data policy blocks a tool or knowledge source, the authentication setting conflicts with a policy, or no channel is set up.
  • Too many public sites in a generative answers node shows as TooManyPublicSiteSearchSources. Keep each node to 4.
  • Check everything the agent depends on. Flows, connectors and knowledge sources must all exist and be connected in this environment, especially after importing a solution.

Users can't reach it in Teams

  • "You don't have access to talk to this bot": the agent can be installed, but the user isn't allowed to use it. In the Teams admin center, check the org-wide custom app settings, and that the Shared Power Apps app is allowed. Then check the agent is shared with that user.
  • Rate limits: Teams limits how fast agents can send messages, so keep replies concise.
  • No sign-out: users of an authenticated agent can't sign out explicitly. That's fine for use inside your organization, but it fails Teams Store certification if you plan to list the agent publicly.

Sources