Entra admin consent checklist (read-only)
Verified as of 2026-09-18
Steps
- In Entra ID, register an application (single-tenant) for Meridian.
- Add a client secret (or certificate). Note tenant ID, client ID, and secret.
- Grant Power Platform API access with licensing read permissions only (e.g. Licensing.Allocations.Read, Licensing.BillingPolicies.Read). Do not grant allocation write.
- Have a Power Platform Administrator or Global Administrator admin-consent the app for the tenant.
- Confirm token audience/scope is https://api.powerplatform.com/.default.
- Provide tenant ID, client ID, and client secret to Meridian Vendors → Microsoft Copilot Studio (Zero-Access engagements: stop here and use the consumption export artifact instead).
What you should have
App registration IDs + admin-consent confirmation (no secrets in email).
Gotchas
- Meridian never allocates Copilot Credits — read-only scopes only.
- Interactive user tokens are not used in production; service principal custody is server-side.