Unable to connect Azure AI Foundry to Azure AI Search knowledge base (403 error / DNS resolution issue)

Swapnil Wani (Tata Consultancy Services Limited) 25 Reputation points Microsoft External Staff
2026-04-20T06:58:57.7133333+00:00

We are attempting to connect Azure AI Foundry (agentic retrieval to Foundry agent) with an Azure AI Search knowledge base, but encountering the following errors.

Initially, we received the following error:

Error: Access denied when connecting to the MCP server at https://<search-service-endpoint>/knowledgebases/<knowledgebase-name>/mcp while trying to list tools (HTTP 403 Forbidden). Please check: (1) your credentials have the required permissions for this server, (2) any IP allowlists or network policies allow requests from this service, and (3) the server’s access control settings permit the requested operation.

After adding a Private Endpoint, the error changed to:

Error encountered while enumerating tools from remote server: https://<search-service-endpoint>/knowledgebases/<knowledgebase-name>/mcp. Details: Name or service not known.


Tried Approaches

  • Configured Managed Virtual Network in Azure AI Foundry and ensured both services are deployed in the same region.
  • Added a Private Endpoint (PE) to the Azure AI Search service.
  • Enabled “Allow Azure services on the trusted services list” in the Search service networking settings.

Still facing the same issue.

Azure OpenAI in Foundry Models

Answer accepted by question author
Manas R Mohanty 17,270 Reputation points Moderator
2026-05-26T17:05:17.2366667+00:00

Hi @Swapnil Wani (Tata Consultancy Services Limited)

Answer was hinted in above comment and shared with you internally earlier for reference.

Re-emphasizing again for users restricted to use managed identity only.

As AI search is supported through private endpoint only. Using Public IPs won't work even with managed VNET.

We should create AI search resource in same region as of foundry and VNET and connect them through private endpoints.

Once they are secured with VNET, you can use a VM's Bastion browser (internal subscription has restriction)/VPN Gateway (p2s works/s2s is also supported) in same VNET.

  1. Please leverage Template 19 to create Foundry and AI search resource for Own VNET and tools in VNET scenario https://github.com/microsoft-foundry/foundry-samples/tree/main/infrastructure/infrastructure-setup-bicep/19-private-network-agent-toolsWorked for one of my recent interactions and saves manual network configuration. Please check out P2S/S2S documentation with networking team to configure if accessing with Bastion browser does not work
  2. Please leverage Template 18 for managed VNET (Bug fixed on using own vnet recently)

(Bring your own VNET scenario/ Managed VNET along own VNET)

Thank you for understanding our constraints on helping on networking part.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Oldest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.