MoneyFlock may earn a commission if you subscribe to a Lovable Business plan through links in this article, at no extra cost to you. TJ Alam is a certified Lovable Expert.
Lovable Microsoft 365 support now covers three separate things: eight Microsoft 365 connectors available on every plan, Microsoft sign-in for the apps you build, and Copilot Managed Runtime, which publishes your app into your company's own Microsoft Entra tenant. Copilot Managed Runtime is limited to the Business and Enterprise plans and is rolling out in public preview.
On 28 September 2026, Lovable and Microsoft announced that apps built with Lovable can run inside a company's own Microsoft tenant. For a finance team, that is the difference between a visitor badge and a staff badge. The expense tool somebody built in an afternoon stops being a link passed around in chat and becomes an application IT can see, govern and switch off, sitting in the same inventory as everything else the company runs.
This guide is written for the person who has to approve that. It covers what each plan actually unlocks, what your tenant admin is consenting to, the three finance workflows that fit the model today, the limits nobody puts in the announcement, and the honest case for using Power Apps instead. Every figure below was checked on the vendor's own pages on 29 September 2026.
The plan gate in Lovable's own documentation, captured 29 September 2026.
What Lovable Microsoft 365 Includes on Each Plan
The announcement bundles three capabilities that are gated very differently. Reading them as one feature is the most common mistake, and it is an expensive one, because two of them cost nothing and the third starts at 50 dollars a month.
Microsoft 365 connectors are the eight product connectors in the catalogue: Outlook, Teams, OneDrive, SharePoint, Word, Excel, PowerPoint and OneNote. Each signs in with a Microsoft account and calls Microsoft Graph through Lovable's connector gateway, with token refresh handled for you. App and chat connectors are available by default on Free, Pro and Business plans.
On Enterprise plans they start switched off. The setting that controls who can create connections defaults to No one, so the connector stays disabled until a workspace admin changes it. That is the opposite of what most buyers assume about the most expensive tier.
Microsoft sign-in for your app lets the people using what you built log in with their Microsoft account, and that is available on every plan too. Workspace sign-in with Microsoft Entra ID, meaning single sign-on into Lovable itself, is a Business and Enterprise feature.
Copilot Managed Runtime is the new capability and the only one behind a paywall. It is available on Business and Enterprise plans. On Business the connector defaults to Admins. On Enterprise it defaults to No one until an admin turns it on.
Lovable Microsoft 365 capabilities by plan, checked 29 September 2026
| Capability | Free | Pro | Business | Enterprise |
|---|---|---|---|---|
| Microsoft 365 connectors, eight products | Yes | Yes | Yes | Off by default |
| Microsoft sign-in for apps you build | Yes | Yes | Yes | Yes |
| Microsoft Fabric connector | Yes | Yes | Yes | Off by default |
| Workspace SSO with Entra ID | No | No | Yes | Yes |
| Copilot Managed Runtime | No | No | Yes, admins by default | Yes, off by default |
| Directory sync, SCIM | No | No | No | Yes |
| Audit logs | No | No | No | Yes |
That last pair deserves a pause, because the vendor contradicts itself. The 28 September announcement says Business and Enterprise plans include SSO, SCIM, security scanning and audit logs. The SCIM documentation says plainly that it is available on the Enterprise plan, and the pricing page lists Directory sync and Audit logs under Enterprise. Two of the three live pages agree, so treat SCIM and audit logs as Enterprise features, and get it in writing before you commit on the strength of the blog post.
50 dollars a month is the real entry price for Copilot Managed Runtime, because it starts on the Business plan. The same 100 monthly credits on Pro cost 25 dollars.
Credits are a separate axis from features. Business runs from 100 credits at 50 dollars a month up to 10,000 credits at 4,300 dollars a month, with volume discounts beginning at the 1,200-credit rung. The full ladder and how credits get consumed sit in our breakdown of Lovable pricing.
Why Running Inside the Tenant Matters for Finance
Finance teams generate more internal tools than any department outside engineering, and almost none of them survive contact with a security review. The reconciliation sheet that became a web app, the approval tracker built for one quarter, the dashboard that reads the team inbox: each works, and each is a separate login, a separate copy of the data, and a separate thing nobody has inventoried.
Publishing into the tenant changes three things at once. The app requires a Microsoft work sign-in, so there is no second credential to manage or offboard. Your existing data loss prevention and connector policies are enforced at runtime, so the app cannot quietly reach a source your policies forbid. And app activity flows into your Microsoft audit logs, which is usually the question that stalls these projects.
The line that matters most to a reviewer: end users' runtime activity in published apps stays in your Microsoft estate and does not flow back to Lovable. The app reaches data through Microsoft connectors under each user's own sign-in. Lovable keeps the project itself, meaning the source code and the chat history, governed by your Lovable workspace settings.
If your review also covers the platform rather than only the runtime, our assessment of whether Lovable is safe for financial data handles the workspace-level controls separately, and the team workspace guide covers roles and per-member limits.
How to Publish a Finance App Into Your Tenant
Five steps, split between an IT admin and the person building. Lovable estimates the admin half at about 20 minutes, and it is a one-time job for the whole tenant.
Step 1: Grant admin consent in Microsoft Entra
A tenant admin adds Lovable as an enterprise application. The fastest route is the admin consent URL, which takes your tenant ID and the client ID 2679639a-43b1-48b5-add7-85cedd49f1fc. The application is listed as Lovable managed apps in Microsoft Entra and can also be added from the gallery. Skip this step and every builder's Microsoft sign-in fails at the first attempt, which is the single most common support ticket at rollout.
Step 2: Allow external artifact deployment
Lovable compiles apps outside Microsoft's platform, so your environments need one policy change to accept them. In the Power Platform admin center, open Manage, then Environment groups, then Rules for the group your builders use, find the Allow external artifact deployment rule and enable it. Repeat for every environment group where people build.
Step 3: Decide where apps get created
By default Microsoft creates one environment per builder on first publish and reuses it afterwards. Those environments are created without Dataverse. If you would rather every app landed somewhere you control, create or pick an environment and give builders its ID to paste into the Environment ID field when they set up the connection.
Step 4: Enable the connector in Lovable
A Lovable workspace admin opens Connectors, then Admin settings, then App and chat connectors, and picks who can create Copilot Managed Runtime connections: No one, Admins, or Editors and admins. That setting doubles as the availability switch. Business defaults to Admins, Enterprise defaults to No one.
Step 5: Build, preview and publish
The builder describes the app in the project chat and names Copilot Managed Runtime as where it runs. Lovable asks one question before it writes any files: a website it hosts, or an app in your Microsoft tenant. The preview runs inside the Copilot Managed Runtime host, so Microsoft asks for a sign-in the first time it loads. On publish, the dialog shows the environment your app deploys to, then an App URL to share.
The consent screen your tenant admin is actually approving, captured 29 September 2026.
Zero admin permissions. Lovable's Entra application holds no application-level permissions and no admin access to your tenant, and it can never do more than the signed-in user is already allowed to do under your policies.
One network detail quietly breaks first attempts. The in-editor preview runs as an embedded frame, so proxies that inspect TLS traffic and browser policies that strip third-party embedded content break it silently, with no error worth reading. The domains to allow are lovable.dev and its subdomains, login.microsoftonline.com, and the powerapps.com, managedapps.cloud.microsoft, lovable.app and lovableproject.com wildcards. Test with one builder on the normal corporate network before you roll this out to a department.
Three Finance Workflows That Fit Today
Expense approvals that post to a Teams channel
The app takes a request, applies your approval thresholds, stores the receipt in SharePoint or OneDrive, and posts the outcome to the finance channel through the Teams connector. Approvers never leave Microsoft 365, and the audit trail belongs to the tenant rather than to a spreadsheet. This is the strongest first build, because the threshold logic is exactly the part a generic tool always gets wrong.
A tracker on top of a live Excel workbook
The Excel connector reads and writes workbooks stored in OneDrive or SharePoint, so the workbook stays the system of record and the app becomes the interface over it. Nobody has to migrate anything, which is usually what kills these proposals before they start. That is a different job from a one-off conversion, which our guide to turning a finance spreadsheet into an app covers on its own.
A read-only dashboard on Microsoft Fabric
The Fabric connector puts a single GraphQL endpoint in front of Lakehouses, Warehouses, Fabric SQL databases and mirrored databases. For a finance dashboard that is usually enough, because you are reading. The writes are the part to check carefully before you promise anything.
100,000 rows is the ceiling on one Fabric query across all pages, alongside 100 items per request by default, a 64 MB response cap, a 100-second timeout and 10 levels of nesting.
Writes work on SQL stores only. Fabric Warehouses, Fabric SQL databases and Azure SQL databases accept create, update, delete and stored procedure calls. Lakehouses and every mirrored source are exposed through SQL analytics endpoints and stay read-only. A Warehouse table also needs a defined primary key before Fabric generates write fields for it, so a table without one appears read-only and the cause is not visible from inside the app.
If you are still mapping which connectors your stack needs, our rundown of the Lovable connectors for a finance stack is the wider view.
What Copilot Managed Runtime Cannot Do
Four limits, and the second one quietly rewrites most architectures.
No public access. Apps in Copilot Managed Runtime are internal by design. Everyone who opens one signs in with a Microsoft work account from your tenant. A client portal, or anything customer-facing, needs regular Lovable publishing instead.
No Lovable Cloud. Apps in Copilot Managed Runtime do not use Lovable Cloud. No database, no secrets, no backend functions. The app works with data through Microsoft connectors, and that is the whole list. If your design assumed a table for application state, move it to Dataverse or SQL before anyone starts building.
Publishing is tied to one identity. It always runs under the Microsoft work account that created the project's connection. Colleagues can collaborate on the project when the connection is shared with them, but publishing their own projects means connecting their own accounts. Plan the handover before that person changes role.
Removal happens in Microsoft, not in Lovable. Taking a published app down is a job for your Microsoft admin tools, and Lovable cannot remove an app from your tenant. Revoking consent in Entra blocks new access immediately, and access already granted expires within about an hour.
Where your app runs: the two publishing paths, 29 September 2026
| Question | Regular Lovable publishing | Copilot Managed Runtime |
|---|---|---|
| Who can open it | Anyone with the link | Your tenant only, work sign-in required |
| Database and secrets | Lovable Cloud available | Not available, connectors only |
| Sign-in | Whatever you build | Microsoft Entra, always |
| Shows in the IT app inventory | No | Yes |
| Removed by | You, inside Lovable | Your Microsoft admin |
| Minimum plan | Free | Business |
SCIM and audit logs sit under Enterprise on the pricing page, not Business, captured 29 September 2026.
Common Mistakes
Treating the announcement as one feature
Connectors, app sign-in and Copilot Managed Runtime are three products with three different gates. Teams pay for Business expecting connectors they already had on Free, or build a proof of concept on Free and discover at publish time that the runtime needs Business. Decide which of the three you actually need before anyone picks a plan.
Assuming the Enterprise plan turns everything on
It does the opposite. On Enterprise, the setting for who can create connections defaults to No one, which disables both the Microsoft 365 connectors and Copilot Managed Runtime until a workspace admin changes it. If your pilot is on Enterprise and the connector is missing from the catalogue, that setting is almost always why.
Designing around a database you will not get
This is the costly one. Apps in Copilot Managed Runtime have no Lovable Cloud database, no secrets store and no backend functions. A design that assumed any of those has to be reworked around Microsoft connectors, and it is far cheaper to discover that in the planning meeting than three days into the build.
Budgeting the Lovable plan and forgetting the Microsoft licensing
Your Lovable plan covers building the app. Running the published app uses your organization's Microsoft licensing, and the licensing for Copilot Managed Runtime is set by Microsoft rather than by Lovable. Confirm what the people opening your app will need before you present a number to anyone who signs off budgets.
When to Use Power Apps Instead
The honest answer is: quite often.
If the app is a form over a Dataverse table, if your team already has Power Platform skills and a deployment process, if you need managed environments and solution-based release management, or if the app has to work offline on a phone, Power Apps is the better fit and has been for years. Copilot Managed Runtime is a hosting model, not a replacement for that platform.
The case for building with Lovable is speed on the first version, and the fact that what comes out is real code your engineers can pick up. If nobody on your team will ever open that code, the advantage is thinner than it looks. It is also worth weighing that Copilot Managed Runtime is in public preview, which makes it the wrong choice for anything with a hard deadline and no fallback plan.
What to Watch Next
- Does Copilot Managed Runtime leave public preview, and does the plan gate move when it does?
- Do SCIM and audit logs stay on Enterprise, or does the pricing page move them to Business to match the September announcement?
- Does Lovable Cloud ever reach apps running in the tenant, or do Microsoft connectors stay the only data path?
- Does publishing stay tied to a single Microsoft identity, or does workspace-level publishing arrive?
- Does the Fabric connector gain the REST API and OneLake file access it currently lacks?
Frequently Asked Questions
What does Lovable integrate with?
Lovable ships a connector catalogue covering Microsoft 365, Microsoft Fabric, Dataverse, Dynamics, SQL, Power BI, the major cloud providers and a long list of business tools. For Microsoft specifically there are eight product connectors plus Azure Graph and Entra API for directory-level access without a signed-in user. Apps can also connect to any API you point them at.
What are the available integrations for Microsoft Office 365?
Eight, each with its own connector: Outlook for mail and calendar, Teams for channels and messages, OneDrive for files, SharePoint for sites and lists, Word, Excel, PowerPoint and OneNote. They all use the same Microsoft sign-in and Microsoft Graph pattern, so one setup process covers all of them, and you can create several connections per product for different accounts or environments.
Does Microsoft Entra ID support SSO?
Yes, and Lovable supports it at two levels that are easy to confuse. Workspace SSO signs your team into Lovable itself and is a Business and Enterprise feature. Microsoft sign-in for the apps you build is separate, available on every plan, and is what your app's users see. Apps published through Copilot Managed Runtime always require a Microsoft work sign-in, with no option to turn it off.
Is Copilot run by Microsoft?
Yes. Copilot Managed Runtime is Microsoft's host, configured by your IT team in the Power Platform admin center, and Microsoft runs the app once Lovable packages it with the Copilot Managed Runtime SDK. Lovable builds and deploys it, Microsoft hosts it, and your tenant policies govern it at runtime.
Is Lovable hosted on AWS?
Lovable does not name its own cloud provider on the Microsoft integration pages, so treat any third-party claim about it with caution. What the documentation does state is more useful for a review: an app published through Copilot Managed Runtime runs inside your Microsoft Entra tenant, its data stays there, and end-user runtime activity does not flow back to Lovable. An app published the regular way is hosted by Lovable instead, which is the distinction that matters for a data-residency question.
Key Takeaways
- Three capabilities, three gates: Microsoft 365 connectors and app sign-in are on every plan, workspace SSO with Entra ID is Business and up, and Copilot Managed Runtime is Business and Enterprise only.
- Business starts at 50 dollars a month for 100 credits, which is the real entry price for running apps in your tenant. The same credits on Pro cost 25 dollars.
- The announcement and the documentation disagree on SCIM and audit logs. The documentation and the pricing page both put them on Enterprise, so plan for that.
- Apps in the tenant get no Lovable Cloud: no database, no secrets, no backend functions. Data comes through Microsoft connectors only.
- Tenant setup is a one-time admin job of roughly 20 minutes, and Lovable receives no admin access to your tenant at any point.
- Fabric reads are generous, Fabric writes are not. Only SQL stores accept writes, and Warehouse tables need a primary key first.
- Copilot Managed Runtime is in public preview, so keep a fallback for anything with a fixed deadline.
Back to the badge. The reason this matters is not that Lovable got faster, it is that the app finally arrives at the door with the same credentials as everything else in the building. If your finance team has a folder of tools nobody will approve, that is the constraint this removes, and the plan you need to remove it is Business.
If you are weighing the platform as a whole rather than this one feature, our full Lovable review is the place to start. If you want the tenant setup handled rather than explained, TJ takes this work through the Lovable Expert directory profile, and you can start a Lovable Business plan here.
References
- Lovable documentation, Build and publish apps to Microsoft Copilot Managed Runtime, read 29 September 2026.
- Lovable documentation, Set up your Microsoft tenant for Copilot Managed Runtime, read 29 September 2026.
- Lovable documentation, Connect your app to Microsoft 365 and Connect your app to Microsoft Fabric, read 29 September 2026.
- Lovable blog, Lovable and Microsoft: run the apps you build inside your company's Microsoft tenant, published 28 September 2026.
- Microsoft Copilot blog, Build where you want, run with confidence, read 29 September 2026.
- Lovable pricing page and SCIM documentation, plan tiers and credit ladder checked in the browser 29 September 2026.
Verified in the browser on 29 September 2026: the Copilot Managed Runtime, tenant setup, Microsoft 365, Microsoft Fabric and SCIM documentation pages, the 28 September announcement, and the live pricing table including the Business credit ladder.
About the author
TJ Alam is a certified Lovable Expert (Website Builder track), founder of Digi Flock Enterprises, and built tjalam.com and cyberdance.in on Lovable. He works with teams putting finance and operations tools into production and can be reached through his Lovable Expert directory profile.
MoneyFlock may earn a commission if you subscribe to a Lovable Business plan through links in this article, at no extra cost to you. TJ Alam is a certified Lovable Expert.