Connect Microsoft 365 Copilot to StackJack
Microsoft 365 Copilot can reach StackJack as an organization-wide Copilot connector (MCP is the Model Context Protocol, the open standard AI tools use to call external tools). A Microsoft 365 admin…
Written By Christopher Scaminaci
Last updated 6 days ago
Microsoft 365 Copilot can reach StackJack as an organization-wide Copilot connector (MCP is the Model Context Protocol, the open standard AI tools use to call external tools). A Microsoft 365 admin adds the connector once, rolls it out, and everyday Copilot chat can then look up your MSP data — each user signs in with their own StackJack account, so everyone gets exactly the tools and connector access they hold.
Connector or agent — two different ways to use StackJack from Copilot
Microsoft designs Copilot connectors as a retrieval surface — search-and-fetch style, read-only tools. For workflows that change data, build a Copilot Studio agent or use another connected AI tool.
Prerequisites
- A Global Administrator or AI Administrator role in the Microsoft 365 admin center.
- A StackJack workspace. Every person who will use the connector must be a member of it — the connector signs each user in as themselves, and a non-member's sign-in is refused.
- Know your StackJack region (US or EU) — it decides which Base URL and registration ID you enter. Your region is shown at Settings → Region; see Data residency.
There is no catalog setting to turn on first. The connector's Base URL is StackJack's compact endpoint, and that address always serves its small, searchable catalog — see Catalog modes.
Add StackJack as a connector
Sign in to the Microsoft 365 admin center.
In the left pane, select Copilot → Connectors.
Select the Gallery tab.
Under Created by your org, on the Create a new connector tile, select Add.
On the Custom connector page, under Connect to MCP server, select Add.
Enter the connector details:
Select Save.
The published registration IDs
These IDs are public identifiers, not secrets — they point Microsoft at StackJack's published OAuth registration so your users' sign-ins go to the right place. Use the ID that matches your StackJack region, together with that region's Base URL.
Roll out and enable
After you save, the connector appears under Your Connections:
- To test with a small group first, select the connector → Staged rollout, and add test users or groups.
- When ready, select Deploy to all users.
- Use Enable / Disable on the connector to control availability without deleting its configuration.
Changes can take up to 15 minutes to reach Copilot.
How users sign in
The first time Copilot needs StackJack in a chat, it prompts the user to connect. The user opens the connection manager, selects Connect, and signs in with their normal StackJack account — the same sign-in as the portal.
The connection is per user:
- Tool access follows the signing-in member — their tool roles and allowed tools, not an org-wide credential.
- Connector credentials resolve per user the same way sign-in connections always do — see Shared vs per-user credentials.
- Activity is attributed to that user in usage logs.
- Removing the member from your team cuts their connector access on the next request.
Signing in again. A StackJack sign-in in Copilot does not last forever. When it ends, Copilot shows the same connect prompt the next time a chat needs StackJack. Select Connect and sign in the same way as the first time. Your tool access and your connectors stay as they were, so nothing else needs to be set up again.
Using StackJack in a Copilot chat
Ask Copilot for MSP data the way you would ask a colleague: "what tickets are open for Contoso in StackJack", "use StackJack to find which of Contoso's machines missed last night's patch run". Copilot searches StackJack for a tool that fits the question, reads what that tool does, and runs it under your own sign-in. Tool limits below covers which tools everyday Copilot chat reaches.
Three things make an answer better:
- Say "StackJack" in your first prompt. A request that names the source is the clearest way to ask for it. The first prompt that needs StackJack is also the one that shows the sign-in prompt, if you have not connected yet.
- Name the customer. One StackJack connector covers every customer in that system, so "Contoso" narrows the search in a way "our client" cannot.
- Name the system when you know it. "in HaloPSA" or "in NinjaOne" points Copilot at the right connector on the first try.
Check that it worked. Every tool call a Copilot chat makes is recorded against the person who asked. Open Audit Logs in the portal and look for entries under your own name with a recent time. An entry there means the connector reached StackJack and signed in as you, even when Copilot's own answer is vague. No entry means Copilot answered without calling StackJack — ask again and name StackJack in the prompt. See Audit logs.
Tool limits
StackJack can expose hundreds of tools depending on your connectors and plan — far more than a chat surface wants to load. The connector's Base URL is therefore the compact endpoint: a small catalog where the AI searches for what it needs (stackjack_search_tools), reads a tool's details, and runs read-only tools on demand, with every permission and subscription check still enforced.
That address always serves the compact list — for an organization that turned catalog modes on, one that turned them off, and one that has never touched the setting. The Enable catalog modes for this organization setting on the Settings page decides what your standard endpoint serves, so turn it on when you want your other AI tools to get a shorter list too; it changes nothing about this connector.
If you point a Copilot connector at the standard endpoint instead, StackJack recognizes it there too — by how the connection signs in rather than by the tool's name — so it is served the compact list once your organization has enabled catalog modes, or, while your organization has never chosen either way, once your tool list is large enough to need it. An organization that turned catalog modes off keeps the full list on the standard endpoint, which is the case the compact Base URL above avoids entirely. See Catalog modes.
Because Copilot connectors are a retrieval surface, write and destructive tools stay out of everyday Copilot chat; the compact catalog's read-only search, describe, and run-read-only tools are the working set.
Troubleshooting
- The connector saved, but chats don't use StackJack as a source. Allow up to 15 minutes after any change. Check the staged-rollout audience includes you and the connector is Enabled. Also check the Base URL matches your region's registration ID (a US ID with an EU URL fails to authenticate).
- Copilot asks you to sign in to StackJack again. This is expected when your sign-in has ended. Select Connect and sign in; the chat continues as before. If it asks again straight after a sign-in that succeeded, contact StackJack support.
- Sign-in succeeds, but no data comes back. Confirm your user is an active member of the StackJack workspace and holds tools for the connectors you are asking about.
- Everything else: Connection troubleshooting.