Building and customizing solutions using Microsoft 365 Copilot APIs and tools
When an agent works in Azure AI Foundry but fails in Microsoft Teams or Microsoft 365 Copilot, the most common causes are missing permissions on the published agent identity, Bot Service issues, or publishing/approval problems.
Use the following checks and fixes:
- Reassign permissions to the published agent identity
- Publishing creates an Agent Application with its own Entra agent identity, separate from the Foundry project identity. Permissions assigned to the project identity do not carry over.
- If tools or Azure resources are accessed using agent identity, they will fail after publishing unless roles are reassigned.
- In Azure portal, locate the resources your agent calls (for example, storage accounts, APIs, other Azure services) and assign the required roles (for example,
Reader, custom roles, or app-specific roles) to the Agent Application’s identity, not the project identity. - This specifically addresses the scenario where the agent “works in Foundry but fails after publishing.”
- Verify the Agent Application and Bot Service are healthy
- In the Foundry portal, open the agent and confirm it shows as Published and note the Application ID and Tenant ID.
- In Azure portal, confirm the Azure Bot Service resource created during publishing exists and is running.
- If the agent doesn’t respond in Teams, check Bot Service logs for errors and restart the resource if needed.
- Check Microsoft 365 / Teams approval and scope
- For organization-scope agents, verify an admin has approved the app in the Microsoft 365 admin center. If approval is pending or blocked by app policies, users will not be able to use the agent.
- If users can’t find the agent in the store, confirm the correct scope (Individual vs Organization) and, for Individual scope, share the direct link.
- Validate the publishing package in Teams
- Download the publishing package (.zip) from the Foundry publishing UI.
- In Teams: Apps → Manage your apps → Upload an app → Upload a custom app and select the .zip.
- Open the agent in Teams and send a test message. Confirm:
- The agent responds.
- Tools work as expected.
- The published agent identity has access to required Azure resources.
- If package upload fails, re-download the package and ensure all required metadata is present.
- Check for known limitations and channel-specific behavior
- Agents published to Microsoft 365 Copilot do not support file uploads, image generation, streaming responses, or citations. These limitations can affect perceived behavior but should not cause total failure.
- In Microsoft 365 Copilot, some media types and message types are not supported; URLs may be removed or transformed for security.
- If Teams is using a stale configuration
- If errors appear only after republishing or updating the agent, Teams may still be using an older configuration. A known workaround is:
- In the Teams admin center, disable the agent app, wait a few seconds, then re-enable it.
- Turn off the Teams channel for the agent in the authoring tool, save, then turn it back on.
- Republish the agent so Teams picks up the latest configuration.
- If errors appear only after republishing or updating the agent, Teams may still be using an older configuration. A known workaround is:
If, after these steps, the agent still fails only in Teams or Microsoft 365 Copilot, collect the Conversation ID, Agent ID, and timestamp of a failing run and open a support case so logs can be reviewed at the service level.
References: