I am troubleshooting an Azure AI Foundry Toolbox integration issue and would like to understand whether I am missing a configuration or permission.
I have two separate Azure AI Foundry projects:
Project B
In both projects, I am trying to connect an Azure AI Foundry Agent to a Toolbox using the Toolbox MCP endpoint through the Foundry UI.
In Project A, the Agent can successfully connect to the Toolbox using Microsoft Entra ID with Agent Identity authentication. The Toolbox is published and the tools are discovered correctly.
However, in Project B, I receive a 403 Forbidden error when attempting the same configuration.
This suggests that connecting an Agent to a Toolbox via the MCP endpoint is supported, as the same setup is working successfully in Project A.
Configuration tested in Project B
I have:
Published the Toolbox and confirmed that it contains active tools.
Granted the relevant managed identity the Azure AI Developer role.
Allowed time for RBAC changes to propagate.
Confirmed that the MCP endpoint is reachable.
Tested both:
Agent Identity
**Project Managed Identity**
Tested the following audience values:
`https://ai.azure.com`
`https://ai.azure.com/.default`
The error I receive is:
Access denied when connecting to the MCP server at https://<foundry-resource>.services.ai.azure.com/api/projects/<project>/toolboxes/<toolbox>/versions/<version>/mcp while enumerating tools (HTTP 403 Forbidden).
Please verify:
The configured credential, connection, or selected identity has the downstream permission, RBAC role, workspace or resource access, or access policy required by this server.
If the endpoint is behind private networking or IP allowlists, requests from the selected network path are permitted.
The server's access control configuration allows this operation for the configured authentication mode.
Comparison with Project A
Interestingly, I initially experienced a similar issue in Project A. I made several changes to the role assignments and configuration, but the error did not appear to resolve immediately.
However, when I tested the Agent again yesterday, it was working successfully. I had not made any further changes immediately before the successful test.
This makes me wonder whether there is a specific role assignment that is required, or whether there can be a delay before the relevant permissions become effective.
I have replicated the role assignments that I could identify from Project A in Project B, but the 403 error in Project B is still occurring.
What I am trying to understand
Could anyone clarify the following?
What are the exact steps in the Foundry UI to connect an Agent to a Toolbox using the Toolbox MCP endpoint?
What RBAC roles/permissions are required for the Agent Identity or Project Managed Identity to access the Toolbox?
Does the Foundry resource, project, Toolbox, or Agent require any specific role assignment?
Are there any additional access policies, authentication settings, audience values, or networking configuration required?
Is there a known RBAC propagation delay for this integration?
Is there a difference in the permissions required when using Agent Identity vs Project Managed Identity?
I would particularly appreciate an example of the minimum required RBAC configuration, as I can compare this against the two projects.
The main reason I am asking is that the exact same type of MCP Toolbox integration is working in Project A, but returns a 403 in Project B, so I am trying to identify what configuration or permission differs between the two.I am troubleshooting an Azure AI Foundry Toolbox integration issue and would like to understand whether I am missing a configuration or permission.
I have two separate Azure AI Foundry projects:
Project A
Project B
In both projects, I am trying to connect an Azure AI Foundry Agent to a Toolbox using the Toolbox MCP endpoint through the Foundry UI.
In Project A, the Agent can successfully connect to the Toolbox using Microsoft Entra ID with Agent Identity authentication. The Toolbox is published and the tools are discovered correctly.
However, in Project B, I receive a 403 Forbidden error when attempting the same configuration.
This suggests that connecting an Agent to a Toolbox via the MCP endpoint is supported, as the same setup is working successfully in Project A.
Configuration tested in Project B
I have:
Published the Toolbox and confirmed that it contains active tools.
Granted the relevant managed identity the Azure AI Developer role.
Allowed time for RBAC changes to propagate.
Confirmed that the MCP endpoint is reachable.
Tested both:
Agent Identity
**Project Managed Identity**
Tested the following audience values:
`https://ai.azure.com`
`https://ai.azure.com/.default`
The error I receive is:
Access denied when connecting to the MCP server at
https://<foundry-resource>.services.ai.azure.com/api/projects/<project>/toolboxes/<toolbox>/versions/<version>/mcp
while enumerating tools (HTTP 403 Forbidden).
Please verify:
The configured credential, connection, or selected identity has the downstream permission, RBAC role, workspace or resource access, or access policy required by this server.
If the endpoint is behind private networking or IP allowlists, requests from the selected network path are permitted.
The server's access control configuration allows this operation for the configured authentication mode.
Comparison with Project A
Interestingly, I initially experienced a similar issue in Project A. I made several changes to the role assignments and configuration, but the error did not appear to resolve immediately.
However, when I tested the Agent again yesterday, it was working successfully. I had not made any further changes immediately before the successful test.
This makes me wonder whether there is a specific role assignment that is required, or whether there can be a delay before the relevant permissions become effective.
I have replicated the role assignments that I could identify from Project A in Project B, but the 403 error in Project B is still occurring.
What I am trying to understand
Could anyone clarify the following?
What are the exact steps in the Foundry UI to connect an Agent to a Toolbox using the Toolbox MCP endpoint?
What RBAC roles/permissions are required for the Agent Identity or Project Managed Identity to access the Toolbox?
Does the Foundry resource, project, Toolbox, or Agent require any specific role assignment?
Are there any additional access policies, authentication settings, audience values, or networking configuration required?
Is there a known RBAC propagation delay for this integration?
Is there a difference in the permissions required when using Agent Identity vs Project Managed Identity?
I would particularly appreciate an example of the minimum required RBAC configuration, as I can compare this against the two projects.
The main reason I am asking is that the exact same type of MCP Toolbox integration is working in Project A, but returns a 403 in Project B, so I am trying to identify what configuration or permission differs between the two.