Foundry ADO MCP tools connection (with Custom OAuth identity).

Rajender Akula 55 Reputation points Microsoft Employee
2026-05-21T20:55:06.9766667+00:00

Hi Team,

User's image

I am wondering if this "Custom" option is available today in foundry to connect to ADO MCP. Because, when I give the details and save the connection for "Custom". It just defaults to the "Managed" option back.

Can someone let me know if this is something intended for future usage or some known issue with foundry?

Thanks,
Rajender

Foundry Tools
Foundry Tools

Formerly known as Azure AI Services or Azure Cognitive Services is a unified collection of prebuilt AI capabilities within the Microsoft Foundry platform


Answer accepted by question author
Anshika Varshney 15,625 Reputation points Microsoft External Staff Moderator
2026-06-01T16:25:24.2733333+00:00

Hello @Rajender Akula

You're very welcome! I'm glad the information was helpful. Thank you for the update and for reaching out to the ADO MCP team.

Aspect Current Status Upcoming Feature
Authentication Method Limited to Custom OAuth identity today Project Managed Identity will be available
-------- -------- --------
Authentication Method Limited to Custom OAuth identity today Project Managed Identity will be available
Availability Currently restricted Expected next week in Foundry UI
Location Foundry UI Project Managed Identity option in Foundry UI

You'll soon be able to connect Foundry ADO MCP tools using Managed Identity instead of Custom OAuth identity passthrough, which is:

  • More secure (no need to manage OAuth credentials)
  • Simpler to configure
  • Native Azure integration

Helpful Documentation:

The documentation you shared is indeed valuable for understanding authentication mechanisms: MCP server authentication - Azure AI Foundry[learn.microsoft]

Since you now have confirmation from the ADO MCP team and know the feature is coming next week, please consider marking this question as answered/resolved by accepting this answer. This will help others facing the same issue find the solution faster.

If you encounter any issues when the Project Managed Identity option becomes available next week, feel free to comment here and I'll be happy to help further.

Thank you for following up with the team and sharing this update it's very helpful for the community!

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Newest
  1. AI answer

    2026-05-21T20:55:27.3033333+00:00

    The Custom OAuth option is supported for MCP tools in Microsoft Foundry, including when connecting MCP servers with OAuth identity passthrough. Custom OAuth is used when bringing an app registration instead of relying on a Microsoft-managed OAuth app.

    For MCP tools in general, the documented flow is:

    1. In Foundry, go to Tools and connect the MCP server.
    2. Choose OAuth identity passthrough for Authentication.
    3. Select Custom OAuth and provide:
      • Client ID (app registration ID)
      • Client secret (if required)
      • Authorization URL
      • Token URL
      • Refresh URL (or reuse the token URL)
      • Scopes
    4. Save the connection; Foundry then returns a redirect URL that must be added to the Microsoft Entra app registration.

    This pattern is explicitly supported for:

    • Microsoft MCP Server for Enterprise, where the guidance is to select Custom as the OAuth provider and supply the app registration details.
    • Custom MCP servers, where OAuth identity passthrough (OBO) with custom OAuth parameters is the documented option.

    If the UI reverts from Custom back to Managed after saving, that behavior is not described as expected in the documentation and is likely a product issue rather than by design. Given that Custom OAuth is a supported configuration path, the connection should persist as Custom once all required fields are valid.

    Recommended next steps:

    1. Verify all required Custom OAuth fields are populated exactly as required (Client ID, Token URL, Auth URL, Refresh URL, and any required scopes). Incomplete or invalid values can prevent saving.
    2. If the configuration is valid but the selection still flips back to Managed, treat this as a Foundry UI or service bug and raise a support ticket so the product group can investigate.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.