Skip to content

Integrations / Copilot

Give your Copilot agentsa source worth citing.

We run a public read-only MCP server, so a Copilot agent can answer questions about 99 Data Rooms from our own content rather than from a summary of a summary. It needs no sign-in and no key. Reading your own rooms is a separate capability on Business and Enterprise.

Public server
Read only
Sign-in
Not needed
Your rooms
Business up
Protocol
MCP over HTTP

First, which Copilot

One name, several products.

This matters before any instruction does. Microsoft applies the Copilot name across a family of products whose extensibility differs, and following the wrong set of steps ends with somebody concluding our server is down when it is simply not the surface they are standing in.

Per Microsoft's current documentation as at 1 September 2026, the two places most people succeed are Copilot Studio, where a custom agent can be given tools from a remote MCP server, and GitHub Copilot in an editor such as Visual Studio Code, where MCP servers are configured for a workspace and used by its agent mode. For the broader Microsoft 365 Copilot experiences, whether an arbitrary external MCP server can be added is a question for your tenant's configuration and Microsoft's current guidance, not something we can answer for you.

Setup

One URL, wherever you are adding it.

The server speaks Model Context Protocol over streamable HTTP and takes no credentials, because nothing private sits behind it:

https://mcp.99datarooms.com/mcp
  1. In the Copilot surface you are building in, add a remote MCP server pointing at the URL above. In Copilot Studio this is done when adding tools to an agent; in GitHub Copilot it is the workspace MCP configuration your editor reads.
  2. Leave authentication unset. This server is unauthenticated by design, so a client that insists on a key or a secret has been configured for the wrong endpoint.
  3. Clear whatever approval your organisation requires before an agent may call an external tool. In a managed tenant that gate is real and it is your administrator's to open.
  4. Test it with something checkable, such as what the free plan includes, and compare the answer against our pricing page.

We describe the capability rather than a precise menu path, because these interfaces are Microsoft's to move and a step written to today's labels misleads tomorrow. Look for whatever adds a remote MCP server by URL, and take Microsoft's documentation over ours where the two differ.

Why bother

Procurement can check us itself.

If you are the person who has to justify a data room choice to a committee, the awkward part is rarely the demo. It is the written claims: hosting and residency, what the audit trail records, which certifications belong to the vendor and which belong to the infrastructure it rents. A connected agent can put those questions to our published content directly and quote what it finds, which is a much shorter path than a questionnaire and a fortnight of email. Our position on provider certifications is stated plainly on trust rather than implied, so the answer you get back is the same answer we would give in a call.

The other half

Reaching your own rooms.

Answering questions about the product is not the same as reading your confidential material, and the two run on different endpoints on purpose. Assistant access to the rooms you own is a Business and Enterprise capability, off by default on every room, with a company-wide switch an organisation owner can use to forbid it outright. Once enabled, an assistant can list the rooms chosen at connection time, read and search the documents inside them, read the Q&A raised through your share links and see how much of each document has genuinely been read.

The published tool list, the two scopes, the actions deliberately left out and the four gates a connection must clear live on the AI assistants page. Plans are on pricing.

AI assistant access is rolling out to Business and Enterprise accounts. If the connection step does not find the server yet, it has not reached your account.

The honest boundary

No write actions, at all, ever.

The public server is read-only and will stay that way. It holds no tool that creates, edits, uploads, renames or deletes anything, so an agent instructed to change something finds nothing to call. A server open to anyone on the internet without a sign-in should not be able to act, and this one cannot. It equally cannot see customer content: the material it serves is what we already publish on this website. Work inside your rooms belongs to the authenticated route above, on a paid plan, with your consent recorded at each step. See security for how we approach the rest.

Copilot, Copilot Studio, GitHub Copilot, Microsoft 365 and Visual Studio Code are products of Microsoft Corporation. 99 Data Rooms is a product of 99 Developers Ltd and is not affiliated with, endorsed by or sponsored by Microsoft. Setup guidance describes Microsoft's software as documented on 1 September 2026 and may change without notice to us.

Questions

The ones people actually ask.

Which Copilot are we talking about?

Microsoft uses the name across several products, and their extensibility stories differ. Agents built in Copilot Studio and the developer-facing GitHub Copilot both have documented ways to use tools from a remote MCP server. Whether a given Microsoft 365 Copilot experience can reach an arbitrary external MCP server depends on the product and on your tenant's policy, so check Microsoft's documentation for the surface you are actually using.

Is this an official Microsoft integration?

No. We publish an open Model Context Protocol server; Copilot is one of several clients able to consume one. There is no private arrangement between the two companies, and nothing about our server is bespoke to Microsoft.

Will our tenant administrator have to approve anything?

Very likely, and that is normal. In managed Microsoft environments the ability to add external tools to an agent is usually governed centrally. That gate belongs to your organisation, not to us, and we cannot grant or bypass it.

What does the public server actually expose?

Published reference content only: our documentation, the glossary, pricing and the use-cases. No account data, no customer documents and nothing behind a sign-in is reachable through it. It is the material you could read in a browser, arranged so a model can quote it accurately.

Can Copilot read the documents in our rooms?

Only through a separate authenticated route on Business or Enterprise, which you enable room by room and approve on a consent screen. It is a different endpoint with a different permission model, and the public server has no path to it. The full contract is on our AI assistants page.