Microsoft

Dynamics 365/ Dataverse

Included as an environment-scoped business-data and application-platform surface whose GA MCP server can search records and metadata, run supported read-only SQL, mutate records and schemas, manage skills, and transfer files under Dataverse security and Power Platform administration.

CRM, revenue & customerSystem of recordBYO-UI-ready platform
An illustration of access surfaces surrounding a governed system.
System roleSystem of record
Access maturityBYO-UI-ready platform
MCP supportOfficial MCP server
Reference updatedNot stated by publisher
BYO-UI reviewedJul 22, 2026

Concrete capability record

Data, retrieval, actions, identity, and operating limits

A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.

01 · Records and state owned

Dataverse environments; tables, schemas, columns, and rows; business skills or playbooks; apps; structured and unstructured search results; supported SQL SELECT queries; upload/download files and SAS URLs; allowed MCP clients; Entra app registrations; and Copilot Credit usage.

02 · Data you can retrieve

Use `search_data` for structured or unstructured Dataverse data, `search` for table schemas and business skills, `describe` for details about tables, records, schemas, skills, and apps, `read_query` for supported SQL SELECT, and `file_download` to generate a download URL.

03 · Actions and write paths

Create, update, or delete rows; create, modify, or delete table schema; add or update and delete skills or playbooks; and initialize and commit file uploads. Microsoft marks record and table deletion as requiring explicit user approval.

04 · Authentication and permissions

Each Dataverse environment has its own MCP endpoint and enabled-client list. Direct non-Microsoft clients require a registered Microsoft Entra app with the Dynamics CRM `mcp.tools` permission; the local proxy requires tenant admin consent and client allowlisting. Data access continues to enforce Dataverse security roles and row-level security.

05 · Monitoring, approval, and recovery

Power Platform administrators can enable or disable the server and individual allowed clients per environment. Client policies must be reviewed after tool-name changes. Record and table deletion carry an explicit approval requirement; preview tools use a separately enabled endpoint.

06 · Limits and caveats

`read_query` supports SQL SELECT rather than general SQL. The data-search tool depends on Dataverse search. External agents can incur Copilot Credits unless qualifying licenses apply. Advanced connector policies require a Managed Environment; preview tools may change without notice and are not covered by support agreements.

Agent access

MCP support

Official MCP serverPer-environment Dataverse GA data MCP with optional local proxy and preview endpoint; separate Power Apps agent-feed MCP remains previewDataverse `/api/mcp` GA tools plus optional unsupported preview tools; separate Power Apps MCP Server is English-only preview

Support: Official MCP server

Read scope: Authorize retrieval per environment and Dataverse actor: record/data search, metadata and skill search, result description, supported SQL SELECT, and file-download URL generation. Do not treat the renamed metadata `search` tool as the prior data-search operation.

Write scope: The GA server exposes row create/update/delete, table-schema create/update/delete, skill upsert/delete, and file-upload initiation/commit. These are Dataverse actions under the signed-in actor’s security; the separate Power Apps preview server’s supervised data-entry flow is not the same tool set.

Authentication: Microsoft Entra-backed user authentication to an environment endpoint. Non-Microsoft clients use either Microsoft’s local proxy after tenant admin consent or a custom Entra app for direct remote access; direct apps request the Dynamics CRM `mcp.tools` permission and must be allowlisted in Power Platform.

Approval boundary: Always show environment, table, row or schema target, logical names, changed fields, and tool name before a mutation. Enforce Microsoft’s explicit confirmation on `delete_record` and `delete_table`; also require review for schema changes, skill replacement or deletion, and file commits because they alter shared platform state.

Protocol does not erase product boundaries.

Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.

Editorial assessment

Access-maturity dimensions

A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.

Data access4
Action access4
Event access4
Identity4
Governance4
Agent access3
UI extensibility3
Portability4
Observability3
Documentation5

Proposed customer-shaped experiences

What customers could create on top.

The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that Microsoft ships them.

Single-platform patterns

  • Role-specific CRM and customer-operations workspace
  • Account journey room
  • Pipeline-quality debugger
  • Customer expansion cockpit
Use in the brief builder →

Multi-platform compositions

  • Dynamics 365 / Dataverse + marketing or intent platform: account journey room
  • Dynamics 365 / Dataverse + conversation or support system + analytics or warehouse: cross-system decision workspace
Explore composition recipes →

Evidence and dates

First-party references, with publisher and review dates separated

“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.

5 recorded sources
MCPRepresentative source
https://learn.microsoft.com/en-us/power-apps/maker/data-platform/data-platform-mcp ↗

Official Microsoft documentation confirms a per-environment endpoint, row-level and role-based security, external-agent billing, and a separate preview-tool surface. Distinguish Dataverse data MCP from Power Apps…

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 12, 2026

Targeted first-party MCP/agent-role review; broader API inventory retained

HomepageSource inventory
https://www.microsoft.com/en-us/dynamics-365 ↗

First-party product homepage used to confirm product identity and current positioning.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Verified fact

Tied to cited first-party evidence reviewed for this profile.

Source inventory

Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.

Editorial assessment

System role, maturity interpretation, and architectural boundary.

Proposed design

Interface patterns and compositions—not vendor product claims.