We appreciate the current support for Microsoft Entra ID v2 authentication using Client ID and Client Secret, as outlined in the [authentication documentation] (https://github.com/microsoft/Power-CAT-Copilot-Studio-Kit). However, some customers have strict security policies that prohibit the use of client secrets for authentication.
To accommodate these scenarios, we would like to request support for Client Certificate authentication as an alternative mechanism. This would enhance the flexibility and enterprise readiness of the Copilot Studio Kit, especially for customers operating in highly regulated environments.
Request Summary:
Add support for Client Certificate authentication in addition to Client ID/Secret.
Provide documentation and configuration guidance for certificate-based setup.
Clarify if this feature is on the roadmap or under consideration.
Thank you for considering this enhancement. It would significantly improve adoption and compliance for a broader range of enterprise customers.