1
00:00:00,000 --> 00:00:03,480
Welcome to another episode of Microsoft Knowledge Nuggets here on M365.

2
00:00:03,480 --> 00:00:05,440
FM, I'm your host, Mirko Peters.

3
00:00:05,440 --> 00:00:06,680
So here's a question for you.

4
00:00:06,680 --> 00:00:09,440
What if Copilot could search across your entire company?

5
00:00:09,440 --> 00:00:11,480
Not just emails and files in SharePoint,

6
00:00:11,480 --> 00:00:14,720
but also your CRM, your ticketing system, your HR database,

7
00:00:14,720 --> 00:00:15,720
your project Wiki?

8
00:00:15,720 --> 00:00:20,160
What if you could ask one question and get an answer that pulls from all of those systems at once

9
00:00:20,160 --> 00:00:22,240
without ever leaving Microsoft 365?

10
00:00:22,240 --> 00:00:24,000
That's the promise, but here's the reality.

11
00:00:24,000 --> 00:00:29,960
Microsoft 365 Copilot out of the box only looks at content stored in SharePoint Online and OneDrive.

12
00:00:29,960 --> 00:00:33,800
That's it, your emails, your team's messages, your documents, those are all fair game.

13
00:00:33,800 --> 00:00:37,720
But the vast majority of your company's important business data lives somewhere else.

14
00:00:37,720 --> 00:00:40,920
Think about your CRM like Salesforce, your ticketing system like ServiceNow,

15
00:00:40,920 --> 00:00:44,520
your Wiki, like Confluence, maybe even a Google Drive you haven't migrated yet.

16
00:00:44,520 --> 00:00:46,680
Copilot can't see any of that, not by default.

17
00:00:46,680 --> 00:00:50,200
That's a huge blind spot, and it's exactly what Copilot connectors are designed to solve.

18
00:00:50,200 --> 00:00:53,320
So by the end of this episode, you'll understand what Graph Connectors are.

19
00:00:53,320 --> 00:00:55,720
They're now called Copilot Connectors, by the way.

20
00:00:55,720 --> 00:00:57,160
The two very different types.

21
00:00:57,160 --> 00:01:00,040
And which one you should use depending on your situation.

22
00:01:00,040 --> 00:01:02,200
Grab your coffee and let's dive in.

23
00:01:02,200 --> 00:01:04,360
The problem, your data is everywhere.

24
00:01:04,360 --> 00:01:08,760
Here's the thing, most companies don't store everything inside Microsoft 365.

25
00:01:08,760 --> 00:01:11,880
You might have a CRM like Salesforce for your customer data,

26
00:01:11,880 --> 00:01:14,600
a ticketing system like ServiceNow for IT support,

27
00:01:14,600 --> 00:01:17,160
a Wiki like Confluence for Documentation,

28
00:01:17,160 --> 00:01:21,080
or even a Google Drive or Dropbox that team started using before

29
00:01:21,080 --> 00:01:23,640
your company standardized on Microsoft.

30
00:01:23,640 --> 00:01:27,320
So when you ask Copilot a question like, "What's the status of the Contoso deal?"

31
00:01:27,320 --> 00:01:30,280
or, "Show me the latest support ticket from that customer."

32
00:01:30,280 --> 00:01:31,640
Copilot draws a blank.

33
00:01:31,640 --> 00:01:32,760
It can't see that data.

34
00:01:32,760 --> 00:01:36,600
It's like having a library card that only works for one shelf in a building with 50 rooms.

35
00:01:36,600 --> 00:01:38,440
You can access the books right in front of you,

36
00:01:38,440 --> 00:01:40,200
but everything else might as well not exist.

37
00:01:40,200 --> 00:01:42,360
Without Copilot, you'd have to contact Switch.

38
00:01:42,360 --> 00:01:45,880
Imagine searching for the customer in Salesforce, copying the account details.

39
00:01:45,880 --> 00:01:49,000
Next, your Open Service Now, search for the ticket, copy that too.

40
00:01:49,000 --> 00:01:51,880
After that, you go to Confluence to find the project notes.

41
00:01:51,880 --> 00:01:54,680
Finally, you paste it all into an email or a team's message.

42
00:01:54,680 --> 00:01:56,840
You're jumping between five different browser tabs,

43
00:01:56,840 --> 00:02:00,520
logging into each system separately and manually stitching the information together.

44
00:02:00,520 --> 00:02:03,720
That waste time breaks your flow and it's exactly the kind of busy work

45
00:02:03,720 --> 00:02:05,320
that Copilot was supposed to eliminate.

46
00:02:05,320 --> 00:02:07,080
But the real cost isn't just wasted time.

47
00:02:07,080 --> 00:02:09,960
When Copilot can't connect the dots across all your data,

48
00:02:09,960 --> 00:02:11,560
you get incomplete answers.

49
00:02:11,560 --> 00:02:14,360
You might make a decision based on the information you have in front of you,

50
00:02:14,360 --> 00:02:18,680
not realizing that the critical piece of data lives in a system Copilot can't see.

51
00:02:18,680 --> 00:02:21,480
That missed insight could be a customer complaint logged in your CRM,

52
00:02:21,480 --> 00:02:25,880
but never surfaced in your email or a contract renewal date sitting in your ERP system,

53
00:02:25,880 --> 00:02:27,080
but not in your calendar.

54
00:02:27,080 --> 00:02:29,960
These gaps add up and they can lead to real consequences.

55
00:02:29,960 --> 00:02:31,320
So Microsoft built a bridge.

56
00:02:31,320 --> 00:02:32,840
Let's look at what that bridge actually is.

57
00:02:32,840 --> 00:02:35,080
What is a Graph connector?

58
00:02:35,080 --> 00:02:39,480
A Graph connector is a piece of software that brings external data into the Microsoft Graph.

59
00:02:39,480 --> 00:02:43,000
Now, the Microsoft Graph is the same index that powers Microsoft Search,

60
00:02:43,000 --> 00:02:45,080
SharePoint Search, and now Copilot.

61
00:02:45,080 --> 00:02:47,960
Think of it as the central nervous system of Microsoft 365.

62
00:02:47,960 --> 00:02:50,520
It's the place where all your data lives and gets connected.

63
00:02:50,520 --> 00:02:52,920
So a Graph connector works like a conveyor belt.

64
00:02:52,920 --> 00:02:58,120
You load data from your external system onto the belt and it gets delivered into the Microsoft 365 index.

65
00:02:58,120 --> 00:02:59,320
Once the data is in there,

66
00:02:59,320 --> 00:03:02,520
Copilot can search it, summarize it, and answer questions about it,

67
00:03:02,520 --> 00:03:04,520
just like it does with your emails and files.

68
00:03:04,520 --> 00:03:07,160
That Salesforce account record, now Copilot can find it,

69
00:03:07,160 --> 00:03:09,720
that service no ticket, Copilot can summarize it,

70
00:03:09,720 --> 00:03:12,920
that confluence wiki page, Copilot can answer questions about it.

71
00:03:12,920 --> 00:03:14,520
Here's something that might surprise you.

72
00:03:14,520 --> 00:03:15,880
Graph connectors are not new.

73
00:03:15,880 --> 00:03:18,280
They've existed for years, powering SharePoint Search.

74
00:03:18,280 --> 00:03:20,440
You might have been using them without even knowing it.

75
00:03:20,440 --> 00:03:25,240
If you've ever searched in SharePoint and seen results from an external system appear in a separate vertical

76
00:03:25,240 --> 00:03:27,160
that was a Graph connector at work,

77
00:03:27,160 --> 00:03:29,400
what's new is that Copilot now uses them,

78
00:03:29,400 --> 00:03:32,040
and that changes everything because Copilot doesn't just find the data.

79
00:03:32,040 --> 00:03:33,800
It reasons over it, summarizes it,

80
00:03:33,800 --> 00:03:36,040
and answers questions about it in natural language.

81
00:03:36,040 --> 00:03:36,840
But there's a catch.

82
00:03:36,840 --> 00:03:39,880
Microsoft actually offers two very different types of connectors.

83
00:03:39,880 --> 00:03:41,560
They work in fundamentally different ways.

84
00:03:41,560 --> 00:03:42,920
Let me explain the difference.

85
00:03:42,920 --> 00:03:45,080
The two models synced versus federated.

86
00:03:45,080 --> 00:03:46,520
So here's where it gets interesting.

87
00:03:46,520 --> 00:03:48,760
Microsoft gives you two completely different ways

88
00:03:48,760 --> 00:03:51,000
to bring external data into Copilot.

89
00:03:51,000 --> 00:03:53,560
The choice between them comes down to one basic question.

90
00:03:53,560 --> 00:03:56,760
Do you want to copy the data or do you want to ask for it live?

91
00:03:56,760 --> 00:03:59,160
The first model is called a Syncid connector.

92
00:03:59,160 --> 00:04:02,840
With this approach, you copy the data from the external system into the Microsoft Graph.

93
00:04:02,840 --> 00:04:05,800
It gets indexed, stored, and semantically processed.

94
00:04:05,800 --> 00:04:09,400
Think of it like moving your filing cabinet into the same building as your desk.

95
00:04:09,400 --> 00:04:12,040
Instead of walking to another room every time you need a file,

96
00:04:12,040 --> 00:04:13,880
that cabinet is right there, organized,

97
00:04:13,880 --> 00:04:15,640
searchable, ready to use.

98
00:04:15,640 --> 00:04:19,640
The data becomes a permanent resident of your Microsoft 365 tenant.

99
00:04:19,640 --> 00:04:21,720
The second model is called a federated connector.

100
00:04:21,720 --> 00:04:22,920
It works completely differently.

101
00:04:22,920 --> 00:04:23,800
You don't copy anything.

102
00:04:23,800 --> 00:04:25,240
When a user asks a question,

103
00:04:25,240 --> 00:04:28,360
Copilot reaches out to the external system in real time,

104
00:04:28,360 --> 00:04:31,320
asks it for relevant information and brings back the answer.

105
00:04:31,320 --> 00:04:33,480
No data is stored in Microsoft 365.

106
00:04:33,480 --> 00:04:36,680
It's like asking a librarian in another building to look something up for you.

107
00:04:36,680 --> 00:04:38,920
They go find the book, read you the answer,

108
00:04:38,920 --> 00:04:40,600
and the book stays on their shelf.

109
00:04:40,600 --> 00:04:41,800
You never take possession of it.

110
00:04:41,800 --> 00:04:43,640
Why does Microsoft offer two models?

111
00:04:43,640 --> 00:04:45,800
Because different data has different needs.

112
00:04:45,800 --> 00:04:47,240
Some data changes rarely.

113
00:04:47,240 --> 00:04:49,880
Think HR policies, project wikis, archive contracts.

114
00:04:49,880 --> 00:04:51,400
That kind of data is fine to copy.

115
00:04:51,400 --> 00:04:54,280
You index it once, maybe refresh it daily, and you're good.

116
00:04:54,280 --> 00:04:55,640
But other data is live.

117
00:04:55,640 --> 00:04:58,680
Inventory levels, current support ticket status, real time pricing.

118
00:04:58,680 --> 00:05:00,520
If you copy that data, it's stale.

119
00:05:00,520 --> 00:05:03,960
The moment it arrives, you need the freshest answer every single time.

120
00:05:03,960 --> 00:05:05,400
There's another key difference.

121
00:05:05,400 --> 00:05:08,760
Sync connectors are set up by an admin for the whole organization.

122
00:05:08,760 --> 00:05:10,520
One person configures the connection

123
00:05:10,520 --> 00:05:12,840
and everyone who has permission can use it.

124
00:05:12,840 --> 00:05:16,280
Federated connectors require each user to authenticate individually.

125
00:05:16,280 --> 00:05:18,120
So if you're connecting to Salesforce,

126
00:05:18,120 --> 00:05:21,080
every person who wants to ask co-pilot about Salesforce data

127
00:05:21,080 --> 00:05:23,160
needs to log into Salesforce themselves.

128
00:05:23,160 --> 00:05:25,160
That's more set up per user, but it also means

129
00:05:25,160 --> 00:05:27,160
each person only sees what they're allowed to see.

130
00:05:27,160 --> 00:05:28,520
Let's dive deeper into each model

131
00:05:28,520 --> 00:05:30,760
so you know which one fits your situation.

132
00:05:30,760 --> 00:05:33,000
Sync connectors, the deep dive.

133
00:05:33,000 --> 00:05:34,280
Let's start with sync connectors

134
00:05:34,280 --> 00:05:36,120
because they're the more established model

135
00:05:36,120 --> 00:05:38,680
and the one you're most likely to encounter first.

136
00:05:38,680 --> 00:05:39,720
Here's how it works.

137
00:05:39,720 --> 00:05:42,920
An admin goes to the Microsoft 365 admin center,

138
00:05:42,920 --> 00:05:44,760
navigates to search and intelligence

139
00:05:44,760 --> 00:05:46,680
and opens the data sources section.

140
00:05:46,680 --> 00:05:49,480
You'll see a gallery of over a hundred pre-built connectors.

141
00:05:49,480 --> 00:05:51,720
You pick the one you need, say service now,

142
00:05:51,720 --> 00:05:53,160
JIRA or confluence,

143
00:05:53,160 --> 00:05:55,560
and authenticate using OOOH 2.0,

144
00:05:55,560 --> 00:05:58,200
which means no passwords are stored in plain text.

145
00:05:58,200 --> 00:05:59,720
Then you configure what data to pull,

146
00:05:59,720 --> 00:06:01,720
how often to sync in which fields to map.

147
00:06:01,720 --> 00:06:04,200
Once that's done, the connector starts pulling data

148
00:06:04,200 --> 00:06:05,480
into the Microsoft graph

149
00:06:05,480 --> 00:06:07,640
and here's what makes co-pilot powerful.

150
00:06:07,640 --> 00:06:09,640
The data gets a semantic index

151
00:06:09,640 --> 00:06:12,040
that means co-pilot doesn't just match keywords.

152
00:06:12,040 --> 00:06:14,520
It understands the meaning behind your question.

153
00:06:14,520 --> 00:06:16,120
So if you search for Q3 budget,

154
00:06:16,120 --> 00:06:19,800
co-pilot can find a document title 2025 financial review

155
00:06:19,800 --> 00:06:22,440
because it understands the relationship between the concepts.

156
00:06:22,440 --> 00:06:24,600
That's a big leap forward from traditional search

157
00:06:24,600 --> 00:06:27,080
where you'd need the exact title or keyword.

158
00:06:27,080 --> 00:06:29,560
Now security is baked into this model from the ground up.

159
00:06:29,560 --> 00:06:32,520
Every indexed item includes an access control list

160
00:06:32,520 --> 00:06:35,720
or ACL which tells Microsoft 365 who can see it.

161
00:06:35,720 --> 00:06:38,040
If a user doesn't have permission in the source system,

162
00:06:38,040 --> 00:06:39,720
they won't see it in co-pilot either.

163
00:06:39,720 --> 00:06:41,160
The permissions follow the data.

164
00:06:41,160 --> 00:06:43,880
So if your Salesforce account only allows your sales team

165
00:06:43,880 --> 00:06:45,160
to see certain records,

166
00:06:45,160 --> 00:06:48,040
those same restrictions apply inside co-pilot.

167
00:06:48,040 --> 00:06:49,960
There are some limitations worth knowing about.

168
00:06:49,960 --> 00:06:51,960
Each item can be up to four megabytes

169
00:06:51,960 --> 00:06:54,840
and the connector can handle up to 25 concurrent operations

170
00:06:54,840 --> 00:06:55,960
on a single connection.

171
00:06:55,960 --> 00:06:57,800
And if your data lives on premises

172
00:06:57,800 --> 00:07:00,280
like on a local file server or a SQL database

173
00:07:00,280 --> 00:07:01,480
in your own data center,

174
00:07:01,480 --> 00:07:04,360
you need to install the Microsoft Graph Connector agent.

175
00:07:04,360 --> 00:07:06,040
That agent reads your local data

176
00:07:06,040 --> 00:07:08,600
and sends only the text and metadata to the cloud

177
00:07:08,600 --> 00:07:10,920
while your actual files stay on your premises.

178
00:07:10,920 --> 00:07:14,600
But the good news is you don't have to build any of this from scratch.

179
00:07:14,600 --> 00:07:17,480
Microsoft and its partners offer over 100 pre-built connectors

180
00:07:17,480 --> 00:07:20,280
for Salesforce, ServiceNow, Jura, Confluence, Google Drive,

181
00:07:20,280 --> 00:07:22,280
GitHub, Box, Dropbox and many more.

182
00:07:22,280 --> 00:07:24,600
If your company uses a popular business application,

183
00:07:24,600 --> 00:07:26,280
there's probably already a connector for it

184
00:07:26,280 --> 00:07:28,120
but what if you need real-time data?

185
00:07:28,120 --> 00:07:30,040
That's where the second model comes in.

186
00:07:30,040 --> 00:07:32,360
Federated connectors, the deep dive.

187
00:07:32,360 --> 00:07:33,800
Now let's talk about the second model

188
00:07:33,800 --> 00:07:34,760
because it's the newer one

189
00:07:34,760 --> 00:07:36,440
and it works completely differently.

190
00:07:36,440 --> 00:07:38,360
With a federated connector, no data gets stored

191
00:07:38,360 --> 00:07:40,280
in Microsoft 365 at all.

192
00:07:40,280 --> 00:07:42,120
When a user asks co-pilot a question,

193
00:07:42,120 --> 00:07:44,280
co-pilot sends a request to the external system

194
00:07:44,280 --> 00:07:46,920
using the model context protocol or MCP.

195
00:07:46,920 --> 00:07:49,080
Think of it as a standard way for co-pilot to say,

196
00:07:49,080 --> 00:07:51,240
"Hey, I need information about this topic

197
00:07:51,240 --> 00:07:54,120
and for the external system to respond with what it's got."

198
00:07:54,120 --> 00:07:55,880
The external system does the searching,

199
00:07:55,880 --> 00:07:57,800
finds the relevant results and sends them back

200
00:07:57,800 --> 00:08:00,120
and co-pilot presents that answer to the user.

201
00:08:00,120 --> 00:08:02,120
The original data never leaves the source system.

202
00:08:02,120 --> 00:08:03,960
This model is great for live data.

203
00:08:03,960 --> 00:08:06,920
I'm talking about inventory levels that change by the minute.

204
00:08:06,920 --> 00:08:10,520
Support ticket status that updates every time an agent touches a case

205
00:08:10,520 --> 00:08:12,520
or real-time pricing that fluctuates.

206
00:08:12,520 --> 00:08:13,880
If you sync that kind of data,

207
00:08:13,880 --> 00:08:15,400
it's stale by the time it hits the index.

208
00:08:15,400 --> 00:08:16,920
But with a federated connector,

209
00:08:16,920 --> 00:08:18,600
you always get the freshest answer

210
00:08:18,600 --> 00:08:20,840
because every single query goes straight to the source.

211
00:08:20,840 --> 00:08:21,960
There's a trade-off though.

212
00:08:21,960 --> 00:08:24,120
User authentication works differently here.

213
00:08:24,120 --> 00:08:25,160
With a sync connector,

214
00:08:25,160 --> 00:08:27,400
an admin sets it up once and everyone can use it.

215
00:08:27,400 --> 00:08:28,760
With a federated connector,

216
00:08:28,760 --> 00:08:31,720
each person must log into the external service themselves.

217
00:08:31,720 --> 00:08:34,120
So if you want to ask co-pilot about a Salesforce record,

218
00:08:34,120 --> 00:08:36,280
you need to authenticate with Salesforce first.

219
00:08:36,280 --> 00:08:39,160
Co-pilot then respects whatever permissions you have in that system.

220
00:08:39,160 --> 00:08:41,320
If you can only see your own accounts in Salesforce,

221
00:08:41,320 --> 00:08:43,880
co-pilot will only return results for those accounts.

222
00:08:43,880 --> 00:08:45,480
It's per user and per session.

223
00:08:45,480 --> 00:08:47,640
Now, federated connectors are still rolling out.

224
00:08:47,640 --> 00:08:50,040
Right now, they're limited to the researcher experience

225
00:08:50,040 --> 00:08:51,160
in co-pilot chat,

226
00:08:51,160 --> 00:08:54,120
where you can ask deep research-oriented questions

227
00:08:54,120 --> 00:08:57,400
and co-pilot goes out to find answers across multiple sources.

228
00:08:57,400 --> 00:08:59,320
It's not yet available everywhere in co-pilot,

229
00:08:59,320 --> 00:09:02,200
not in Teams, not in Outlook, not in the side panel of Word or Excel,

230
00:09:02,200 --> 00:09:03,480
but Microsoft is expanding.

231
00:09:03,480 --> 00:09:04,840
The connector catalog is growing,

232
00:09:04,840 --> 00:09:06,840
and the expectation is that federated connectors

233
00:09:06,840 --> 00:09:09,720
will become available in more co-pilot experiences over time.

234
00:09:09,720 --> 00:09:10,920
One more thing to know.

235
00:09:10,920 --> 00:09:13,160
Federated connectors are read only by default.

236
00:09:13,160 --> 00:09:14,840
Co-pilot can search and fetch data,

237
00:09:14,840 --> 00:09:17,160
but it cannot write back to the external system.

238
00:09:17,160 --> 00:09:19,080
It can't create a new ticket in service now

239
00:09:19,080 --> 00:09:21,160
or update a contact record in Salesforce.

240
00:09:21,160 --> 00:09:23,000
That's by design to keep things safe.

241
00:09:23,000 --> 00:09:24,600
If you need co-pilot to take actions,

242
00:09:24,600 --> 00:09:27,000
that's a different extensibility model called plugins.

243
00:09:27,000 --> 00:09:30,680
But for search and retrieval, federated connectors do exactly what you need,

244
00:09:30,680 --> 00:09:32,040
so which one should you use?

245
00:09:32,040 --> 00:09:33,800
It depends on your scenario, sir.

246
00:09:33,800 --> 00:09:35,880
Which connector model should you use?

247
00:09:35,880 --> 00:09:37,880
So which connector model should you use?

248
00:09:37,880 --> 00:09:39,080
Let's make it practical.

249
00:09:39,080 --> 00:09:42,040
You want a synced connector when the data doesn't change often.

250
00:09:42,040 --> 00:09:44,600
Think HR policies that get updated once a quarter,

251
00:09:44,600 --> 00:09:47,160
or project weekies where the content is mostly stable,

252
00:09:47,160 --> 00:09:50,440
or archived contracts you need to reference but rarely modify.

253
00:09:50,440 --> 00:09:52,600
Synced connectors give you semantic search.

254
00:09:52,600 --> 00:09:54,600
Co-pilot understands the meaning of your question,

255
00:09:54,600 --> 00:09:55,800
not just the keywords.

256
00:09:55,800 --> 00:09:58,840
And the data becomes available everywhere in Microsoft 365,

257
00:09:58,840 --> 00:10:01,240
search co-pilot SharePoint, the whole platform,

258
00:10:01,240 --> 00:10:03,640
you index it once and it's there for everyone.

259
00:10:03,640 --> 00:10:07,080
Use a federated connector when the data changes constantly

260
00:10:07,080 --> 00:10:09,720
and you need the latest answer every single time.

261
00:10:09,720 --> 00:10:12,040
Live support tickets where the status might change

262
00:10:12,040 --> 00:10:13,720
while you're asking the question,

263
00:10:13,720 --> 00:10:16,040
inventory levels that fluctuate throughout the day,

264
00:10:16,040 --> 00:10:19,080
current project status that gets updated in real time.

265
00:10:19,080 --> 00:10:21,400
With federated connectors, you don't store a copy,

266
00:10:21,400 --> 00:10:23,400
so you never have to worry about stale data.

267
00:10:23,400 --> 00:10:25,960
You get the freshest answer straight from the source,

268
00:10:25,960 --> 00:10:28,520
but here's the thing, you don't have to pick just one.

269
00:10:28,520 --> 00:10:29,880
Many organizations use both.

270
00:10:29,880 --> 00:10:32,520
They use synced connectors for their static knowledge base,

271
00:10:32,520 --> 00:10:35,320
HR policies, onboarding docs, reference materials,

272
00:10:35,320 --> 00:10:38,680
and they use federated connectors for their dynamic operational data.

273
00:10:38,680 --> 00:10:42,040
Live tickets, current inventory, real time project status.

274
00:10:42,040 --> 00:10:44,440
It's not an either/or decision, it's a both in strategy.

275
00:10:44,440 --> 00:10:45,720
Now let's talk about cost.

276
00:10:45,720 --> 00:10:49,480
Synced connectors use storage and compute inside Microsoft 365.

277
00:10:49,480 --> 00:10:52,040
Every item you index takes up space and gets processed

278
00:10:52,040 --> 00:10:53,320
by the semantic index.

279
00:10:53,320 --> 00:10:54,760
That's included in your licensing,

280
00:10:54,760 --> 00:10:56,840
but there are limits depending on your plan.

281
00:10:56,840 --> 00:11:00,280
Federated connectors don't store data in Microsoft 365,

282
00:11:00,280 --> 00:11:01,960
so they don't consume that storage,

283
00:11:01,960 --> 00:11:03,960
but they do require the external system

284
00:11:03,960 --> 00:11:05,720
to handle every query in real time.

285
00:11:05,720 --> 00:11:08,680
If your salesforce instance is already struggling with performance,

286
00:11:08,680 --> 00:11:12,040
adding hundreds of co-pilot queries on top of that could cause issues,

287
00:11:12,040 --> 00:11:13,960
so keep that in mind when you're planning.

288
00:11:13,960 --> 00:11:15,640
Security and compliance.

289
00:11:15,640 --> 00:11:17,080
Before you set anything up,

290
00:11:17,080 --> 00:11:19,240
there's one thing you absolutely must get right,

291
00:11:19,240 --> 00:11:20,440
and that's security.

292
00:11:20,440 --> 00:11:24,200
Every single item that goes through a connector needs an access control list attached to it.

293
00:11:24,200 --> 00:11:24,920
That's an ACL.

294
00:11:24,920 --> 00:11:28,200
It tells Microsoft 365 who can see that piece of data.

295
00:11:28,200 --> 00:11:30,120
Forget to include one, and two things can happen.

296
00:11:30,120 --> 00:11:33,160
The data might become visible to everyone in your organization,

297
00:11:33,160 --> 00:11:34,920
or it might become invisible to everyone.

298
00:11:34,920 --> 00:11:37,480
Neither is good, so when you're configuring a connector,

299
00:11:37,480 --> 00:11:41,160
pay close attention to how permissions are mapped from the source system.

300
00:11:41,160 --> 00:11:43,960
All connectors use OAuth 2.0 for authentication.

301
00:11:43,960 --> 00:11:45,000
That's the modern standard.

302
00:11:45,000 --> 00:11:47,000
No passwords stored in plain text,

303
00:11:47,000 --> 00:11:49,400
no shared service accounts with weak credentials.

304
00:11:49,400 --> 00:11:52,280
It's the same protocol you use when you log into a website

305
00:11:52,280 --> 00:11:54,120
with your Google or Microsoft account.

306
00:11:54,120 --> 00:11:55,560
The connector authenticates securely,

307
00:11:55,560 --> 00:11:58,200
and then it pulls data based on the permissions you've granted.

308
00:11:58,200 --> 00:11:59,800
Data and transit is encrypted.

309
00:11:59,800 --> 00:12:03,640
When your connector moves data from Salesforce or Service now into Microsoft 365,

310
00:12:03,640 --> 00:12:05,080
that traffic is protected.

311
00:12:05,080 --> 00:12:06,280
For Syncad Connectors,

312
00:12:06,280 --> 00:12:09,320
data address is also encrypted inside Microsoft 365,

313
00:12:09,320 --> 00:12:11,880
so even if someone somehow accessed the storage layer,

314
00:12:11,880 --> 00:12:14,600
they couldn't read the data without the encryption keys.

315
00:12:14,600 --> 00:12:16,280
Now, what about data that lives on premises?

316
00:12:16,280 --> 00:12:21,000
Maybe you have a file server in your office or a SQL database running in your own data center?

317
00:12:21,000 --> 00:12:22,920
You don't want to move that data to the cloud,

318
00:12:22,920 --> 00:12:23,800
and you don't have to.

319
00:12:23,800 --> 00:12:27,640
You install the Microsoft Graph Connector agent on a machine inside your network.

320
00:12:27,640 --> 00:12:29,320
That agent reads your local data,

321
00:12:29,320 --> 00:12:31,800
and sends only the text and metadata to the cloud.

322
00:12:31,800 --> 00:12:34,120
Your actual data files stay on your premises.

323
00:12:34,120 --> 00:12:38,120
The only thing that travels over the internet is the content that needs to be indexed.

324
00:12:38,120 --> 00:12:39,880
Not the original files themselves.

325
00:12:39,880 --> 00:12:42,520
And here's something that matters if you're in a regulated industry.

326
00:12:42,520 --> 00:12:45,880
Microsoft Graph Connectors inherit Microsoft 365's compliance

327
00:12:45,880 --> 00:12:50,680
certifications ISO 27001, SOC2, HEAPA, FedRAMP.

328
00:12:50,680 --> 00:12:55,240
If your organization already uses Microsoft 365 for compliant workloads,

329
00:12:55,240 --> 00:12:58,840
the same certifications apply to the data you bring in through connectors.

330
00:12:58,840 --> 00:13:03,400
You don't need separate audits or additional certifications for the connector layer.

331
00:13:03,400 --> 00:13:04,520
Ready to try it?

332
00:13:04,520 --> 00:13:06,120
Here's how to get started.

333
00:13:06,120 --> 00:13:07,160
Getting started.

334
00:13:07,160 --> 00:13:08,600
So where do you actually start?

335
00:13:08,600 --> 00:13:11,400
The first place is the Microsoft 365 Admin Center,

336
00:13:11,400 --> 00:13:14,040
head over to search in Intelligence, then open data sources.

337
00:13:14,040 --> 00:13:16,280
That's where you'll find the connector gallery.

338
00:13:16,280 --> 00:13:19,000
It's a list of over 100 pre-built connectors ready to go.

339
00:13:19,000 --> 00:13:19,720
Pick one.

340
00:13:19,720 --> 00:13:20,920
Let's say ServiceNow.

341
00:13:20,920 --> 00:13:24,040
Click on it, and the setup wizard walks you through the whole thing.

342
00:13:24,040 --> 00:13:26,920
You authenticate to ServiceNow using OAuth 2.0,

343
00:13:26,920 --> 00:13:28,600
then you choose what data to sync,

344
00:13:28,600 --> 00:13:31,800
maybe just incidents and knowledge articles instead of the whole database.

345
00:13:31,800 --> 00:13:35,080
You map the fields from ServiceNow to the Microsoft Graph schema.

346
00:13:35,080 --> 00:13:37,960
And you configure the ACL's permissions carry over correctly.

347
00:13:37,960 --> 00:13:41,240
For a straightforward setup, the whole process takes maybe 30 minutes.

348
00:13:41,240 --> 00:13:43,720
Now, what if your data source doesn't have a pre-built connector?

349
00:13:43,720 --> 00:13:44,760
You can build your own.

350
00:13:44,760 --> 00:13:49,480
Use the Microsoft Graph Connectors API or the Microsoft 365 Agents Toolkit.

351
00:13:49,480 --> 00:13:50,920
You'll need to create three things.

352
00:13:50,920 --> 00:13:54,600
First, a connection that tells Microsoft 365 where the data lives.

353
00:13:54,600 --> 00:13:58,360
Second, a schema that defines what fields exist and how they map.

354
00:13:58,360 --> 00:14:01,400
Third, a way to manage the external items.

355
00:14:01,400 --> 00:14:05,320
Adding them, updating them, deleting them when they change in the source system.

356
00:14:05,320 --> 00:14:09,000
It's more work, but it gives you complete control over what gets indexed and how.

357
00:14:09,000 --> 00:14:12,040
Once your connector is set up, test it, ask co-pilot a question

358
00:14:12,040 --> 00:14:13,960
that should pull from your new data source.

359
00:14:13,960 --> 00:14:16,680
Something like, show me open incidents from ServiceNow

360
00:14:16,680 --> 00:14:19,320
or what's the latest contract in Salesforce.

361
00:14:19,320 --> 00:14:20,680
Check that the results appear.

362
00:14:20,680 --> 00:14:23,560
Then check that only authorized users see the right results.

363
00:14:23,560 --> 00:14:27,000
If someone in marketing asks about a sales-only account, they shouldn't see it.

364
00:14:27,000 --> 00:14:28,920
If they do, your ACLs need work.

365
00:14:28,920 --> 00:14:30,920
Let's wrap up with the big picture.

366
00:14:30,920 --> 00:14:32,760
So now you know what Graph Connectors are.

367
00:14:32,760 --> 00:14:35,960
They let you bring external data into Microsoft 365.

368
00:14:35,960 --> 00:14:38,280
Data that co-pilot can't see on its own.

369
00:14:38,280 --> 00:14:39,800
You have two models to choose from.

370
00:14:39,800 --> 00:14:42,120
Sync-it-connectors, copy, and index the data,

371
00:14:42,120 --> 00:14:44,600
giving you semantic search and broader availability.

372
00:14:44,600 --> 00:14:47,560
Federated connectors query the source in real-time,

373
00:14:47,560 --> 00:14:50,200
giving you fresh answers without storing a copy.

374
00:14:50,200 --> 00:14:51,160
Here's why this matters.

375
00:14:51,160 --> 00:14:54,520
Co-pilot becomes truly useful when it can see all your company data.

376
00:14:54,520 --> 00:14:56,760
Not just what's sitting in SharePoint in one drive.

377
00:14:56,760 --> 00:15:00,440
A co-pilot that only knows about your emails and documents is a limited assistant.

378
00:15:00,440 --> 00:15:02,920
A co-pilot that also knows about your CRM,

379
00:15:02,920 --> 00:15:06,040
your ticketing system, your HR database, your project wiki.

380
00:15:06,040 --> 00:15:09,320
That's a co-pilot that can actually transform how you work.

381
00:15:09,320 --> 00:15:10,440
Your next step is simple.

382
00:15:10,440 --> 00:15:13,400
Pick one external system that holds critical data for your team.

383
00:15:13,400 --> 00:15:14,840
Set up a connector for it this week.

384
00:15:14,840 --> 00:15:16,680
See how it changes your co-pilot experience.

385
00:15:16,680 --> 00:15:19,320
You might be surprised at how much more useful co-pilot becomes

386
00:15:19,320 --> 00:15:22,360
when it has access to the data that actually runs your business.

387
00:15:22,360 --> 00:15:26,280
This has been another episode of Microsoft Knowledge Nuggets here on M365.

388
00:15:26,280 --> 00:15:28,200
FM, I'm your host, Mirko Peters.

389
00:15:28,200 --> 00:15:30,680
If this helped you understand Graph Connectors a little better,

390
00:15:30,680 --> 00:15:32,840
subscribe on your favorite podcast platform.

391
00:15:32,840 --> 00:15:38,280
And share this episode with a colleague who's been wondering why co-pilot can't seem to find their salesforce data.

392
00:15:38,280 --> 00:15:39,240
Until next time.

