Microsoft Foundry: Unable to Access Agents in a Managed Application Deployment — Tenant Mismatch and Permissions Issues

Erkki Holttinen 0 Reputation points
2026-09-30T10:53:06.45+00:00

Problem description

I am unable to access the Agents section in Microsoft Foundry for a deployment created through Azure Managed Applications. Despite some portal areas being accessible, the Agents area does not load as expected, showing errors about insufficient permissions or workspace not found.

Environment

The issue involves Microsoft Foundry deployed via Azure Managed Applications into a managed resource group with deny rules, in a scenario involving different Microsoft Entra tenants between publisher and customer.

What I've already tried

I have reviewed the browser network trace, observed the tenant mismatch error (in request query?getAgentsResolver), and confirmed that publisher-side accounts can partially access the portal but cannot load the Agents section. No additional troubleshooting steps or configuration checks are documented.

Current status

I am seeking clarification on whether Azure AI Foundry supports publisher-managed access in this deployment pattern, and guidance on how to properly set up access without exposing underlying assets, as current workarounds do not meet our security and operational requirements.

Microsoft Foundry
Microsoft Foundry

A unified Azure platform for creating and managing AI models, agents, and applications with built‑in enterprise security, monitoring, and governance


1 answer

Sort by: Newest
  1. Jubin Soni 0 Reputation points
    2026-10-01T01:46:26.05+00:00

    Hi Erkki, thank you for your questions. A few additions to the answer above.

    1. Send telemetry to your own tenant. Enable tracing into Application Insights and route diagnostic settings to a Log Analytics workspace you control. Cross-tenant delivery usually needs Azure Lighthouse or customer approval, but it covers most support needs like latency, errors, and token usage without any portal access.
    2. Don't count on Lighthouse fixing the Agents blade. Lighthouse delegates control plane RBAC, but the Agents experience checks the tenant that owns the resource. Test this in a sandbox early.
    3. Use a multi-tenant app registration for programmatic access. Have the customer consent so a service principal exists in their tenant, then assign it a narrow Foundry role at the project scope. Pin the tenant explicitly in your credential.
    4. Consider a thin publisher-owned admin API. If neither side should see the underlying assets, a small service that calls Foundry with a scoped identity is easier to secure and audit than opening up the portal.
    5. Review the deny assignment settings. Check whether data actions are denied along with control plane actions, since that may explain the "workspace not found" error.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.