Adding MCP servers to Copilot Studio in regulated environments
Five architecture decisions the wizard quietly assumes you've made — identity (API key vs. OBO), DLP zone, generative orchestration, Streamable transport, tenant scoping — plus the threat model that isn't in the docs.