Azure AI Foundry Agent receives 403 Forbidden when connecting to Toolbox MCP endpoint, but same configuration works in another Foundry project

Mayank Pant 0 Reputation points
2026-09-18T09:14:25.7366667+00:00

I am troubleshooting an Azure AI Foundry Toolbox integration issue and would like to understand whether I am missing a configuration or permission.

I have two separate Azure AI Foundry projects:

  • Project A

Project B

In both projects, I am trying to connect an Azure AI Foundry Agent to a Toolbox using the Toolbox MCP endpoint through the Foundry UI.

In Project A, the Agent can successfully connect to the Toolbox using Microsoft Entra ID with Agent Identity authentication. The Toolbox is published and the tools are discovered correctly.

However, in Project B, I receive a 403 Forbidden error when attempting the same configuration.

This suggests that connecting an Agent to a Toolbox via the MCP endpoint is supported, as the same setup is working successfully in Project A.

Configuration tested in Project B

I have:

Published the Toolbox and confirmed that it contains active tools.

Granted the relevant managed identity the Azure AI Developer role.

Allowed time for RBAC changes to propagate.

Confirmed that the MCP endpoint is reachable.

Tested both:

Agent Identity

  **Project Managed Identity**
  
  Tested the following audience values:
  
     `https://ai.azure.com`
     
        `https://ai.azure.com/.default`
        

The error I receive is:

Access denied when connecting to the MCP server at https://<foundry-resource>.services.ai.azure.com/api/projects/<project>/toolboxes/<toolbox>/versions/<version>/mcp while enumerating tools (HTTP 403 Forbidden). Please verify: The configured credential, connection, or selected identity has the downstream permission, RBAC role, workspace or resource access, or access policy required by this server. If the endpoint is behind private networking or IP allowlists, requests from the selected network path are permitted. The server's access control configuration allows this operation for the configured authentication mode.

Comparison with Project A

Interestingly, I initially experienced a similar issue in Project A. I made several changes to the role assignments and configuration, but the error did not appear to resolve immediately.

However, when I tested the Agent again yesterday, it was working successfully. I had not made any further changes immediately before the successful test.

This makes me wonder whether there is a specific role assignment that is required, or whether there can be a delay before the relevant permissions become effective.

I have replicated the role assignments that I could identify from Project A in Project B, but the 403 error in Project B is still occurring.

What I am trying to understand

Could anyone clarify the following?

What are the exact steps in the Foundry UI to connect an Agent to a Toolbox using the Toolbox MCP endpoint?

What RBAC roles/permissions are required for the Agent Identity or Project Managed Identity to access the Toolbox?

Does the Foundry resource, project, Toolbox, or Agent require any specific role assignment?

Are there any additional access policies, authentication settings, audience values, or networking configuration required?

Is there a known RBAC propagation delay for this integration?

Is there a difference in the permissions required when using Agent Identity vs Project Managed Identity?

I would particularly appreciate an example of the minimum required RBAC configuration, as I can compare this against the two projects.

The main reason I am asking is that the exact same type of MCP Toolbox integration is working in Project A, but returns a 403 in Project B, so I am trying to identify what configuration or permission differs between the two.I am troubleshooting an Azure AI Foundry Toolbox integration issue and would like to understand whether I am missing a configuration or permission.

I have two separate Azure AI Foundry projects:

Project A

Project B

In both projects, I am trying to connect an Azure AI Foundry Agent to a Toolbox using the Toolbox MCP endpoint through the Foundry UI.

In Project A, the Agent can successfully connect to the Toolbox using Microsoft Entra ID with Agent Identity authentication. The Toolbox is published and the tools are discovered correctly.

However, in Project B, I receive a 403 Forbidden error when attempting the same configuration.

This suggests that connecting an Agent to a Toolbox via the MCP endpoint is supported, as the same setup is working successfully in Project A.

Configuration tested in Project B

I have:

Published the Toolbox and confirmed that it contains active tools.

Granted the relevant managed identity the Azure AI Developer role.

Allowed time for RBAC changes to propagate.

Confirmed that the MCP endpoint is reachable.

Tested both:

Agent Identity

  **Project Managed Identity**
  
  Tested the following audience values:
  
     `https://ai.azure.com`
     
        `https://ai.azure.com/.default`
        

The error I receive is:

Access denied when connecting to the MCP server at
https://<foundry-resource>.services.ai.azure.com/api/projects/<project>/toolboxes/<toolbox>/versions/<version>/mcp
while enumerating tools (HTTP 403 Forbidden). Please verify: The configured credential, connection, or selected identity has the downstream permission, RBAC role, workspace or resource access, or access policy required by this server. If the endpoint is behind private networking or IP allowlists, requests from the selected network path are permitted. The server's access control configuration allows this operation for the configured authentication mode.

Comparison with Project A

Interestingly, I initially experienced a similar issue in Project A. I made several changes to the role assignments and configuration, but the error did not appear to resolve immediately.

However, when I tested the Agent again yesterday, it was working successfully. I had not made any further changes immediately before the successful test.

This makes me wonder whether there is a specific role assignment that is required, or whether there can be a delay before the relevant permissions become effective.

I have replicated the role assignments that I could identify from Project A in Project B, but the 403 error in Project B is still occurring.

What I am trying to understand

Could anyone clarify the following?

What are the exact steps in the Foundry UI to connect an Agent to a Toolbox using the Toolbox MCP endpoint?

What RBAC roles/permissions are required for the Agent Identity or Project Managed Identity to access the Toolbox?

Does the Foundry resource, project, Toolbox, or Agent require any specific role assignment?

Are there any additional access policies, authentication settings, audience values, or networking configuration required?

Is there a known RBAC propagation delay for this integration?

Is there a difference in the permissions required when using Agent Identity vs Project Managed Identity?

I would particularly appreciate an example of the minimum required RBAC configuration, as I can compare this against the two projects.

The main reason I am asking is that the exact same type of MCP Toolbox integration is working in Project A, but returns a 403 in Project B, so I am trying to identify what configuration or permission differs between the two.

Foundry Tools
Foundry Tools

Formerly known as Azure AI Services or Azure Cognitive Services is a unified collection of prebuilt AI capabilities within the Microsoft Foundry platform


1 answer

Sort by: Most helpful
  1. Walker Pollitt 80 Reputation points
    2026-09-19T22:12:44.6566667+00:00

    Since the same Toolbox/MCP configuration works from another Foundry project, I would treat the working project as the control and compare the two projects' identities and authorization rather than changing the MCP server first.

    A "403 Forbidden" is especially significant here because Foundry Toolbox has two separate authorization boundaries:

    1. Agent → Toolbox
    2. Toolbox/tool → downstream service

    So successful creation of the Toolbox connection does not necessarily prove that the runtime agent identity is authorized to invoke it.

    For a Prompt Agent, first identify the managed identity actually being used by the failing agent. Microsoft documents that the agent identity requires the Foundry User role on the Foundry project in this scenario.

    Compare that assignment between the working and failing projects.

    In the failing project, check:

    Foundry project → Access control (IAM)

    and verify that the agent's managed identity has the required project access.

    Also compare the identity used by the working agent against the failing agent rather than comparing only your own user account. Your interactive Azure permissions and the runtime agent's permissions are not necessarily the same thing.

    Next, inspect the Toolbox's downstream authentication.

    If the tool uses Microsoft Entra authentication, verify:

    • whether it uses Agent Identity or Project Managed Identity;
    • the Entra audience configured for the connection;
    • the RBAC assignments on the underlying service;
    • that the role assignment is granted to the identity from the failing project, not only the identity from the working project.

    This distinction matters because Microsoft documents agent-to-Toolbox identity and downstream authentication as separate authorization boundaries. A tool returning "401" or "403" can therefore indicate that the agent reached the Toolbox but authorization failed farther downstream.

    If this is an MCP connection using Entra authentication, also compare the configured Audience between the two projects. The audience must correspond to the Application ID URI expected by the MCP server.

    I would troubleshoot it as an A/B comparison:

    1. Identify the runtime agent identity in Project A (working).
    2. Identify the runtime agent identity in Project B (403).
    3. Compare Foundry project RBAC assignments.
    4. Compare Toolbox/project connection authentication types.
    5. Compare the configured Entra audience.
    6. Compare downstream-service RBAC for both identities.
    7. Check whether either project uses Project Managed Identity while the other uses Agent Identity.
    8. After correcting RBAC, allow time for the role assignment to propagate before testing again.

    If "tools/list" succeeds but the actual tool invocation returns 403, that is another useful boundary test. It suggests the agent can reach/discover the Toolbox but authorization is failing during tool execution or against the downstream resource.

    If even Toolbox discovery fails with 403, concentrate first on the agent → Foundry project/Toolbox authorization path.

    Because one Foundry project already works, I would not rebuild the MCP server until these identity differences have been ruled out. The working project gives you a very useful known-good configuration to compare against.

    Microsoft Learn references:

    Use a Toolbox with a hosted agent:

    https://learn.microsoft.com/en-us/azure/foundry/agents/how-to/tools/use-toolbox-hosted-agent?wt.mc_id=studentamb_521824

    Create and manage a Toolbox:

    https://learn.microsoft.com/en-us/azure/foundry/agents/how-to/tools/toolbox?wt.mc_id=studentamb_521824

    MCP authentication:

    https://learn.microsoft.com/en-us/azure/foundry/agents/how-to/mcp-authentication?wt.mc_id=studentamb_521824

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.