Hello @Yatipa Chaleenutthawut ,
Welcome to Microsoft Q&A .Thank you for reaching out to us.
Thank you for sharing the implementation details and error information. After reviewing the reported behavior, two separate issues have been identified. The first relates to streaming event handling when using the Azure AI Projects OpenAI-compatible client, and the second relates to authorization requirements for Agent operations. Since these issues are independent, resolving both areas should help unblock the multi-agent workflow implementation
- Import Error: ResponseStreamEventType Observed Error - cannot import name 'ResponseStreamEventType' from 'azure.ai.projects.models' Analysis : The implementation is using
openai_client.conversations.create()
openai_client.responses.create(stream=True)
through an OpenAI-compatible client obtained from:
project_client.get_openai_client()
Current Azure AI Projects SDK guidance indicates that Responses and Conversations operations are handled through this OpenAI-compatible client surface. Additionally, SDK engineering guidance indicates that classes related to OpenAI client calls are not exposed through the azure-ai-projects model package. Therefore, importing:
from azure.ai.projects.models import ResponseStreamEventType
is not a supported pattern. Please check if the following helps- Verify installed package versions:
pip show azure-ai-projects
pip show azure-ai-agents
pip show openai
pip show azure-identity
- Review the implementation against the latest SDK samples and Responses API documentation, as older samples may reference components that are no longer available.
- Remove the unsupported import and use the streaming events returned by the Responses API directly.
- Avoid importing from internal modules such as:
azure.ai.projects._models
since these are not part of the supported public SDK surface and may change between releases.
- If package alignment is required, update to the latest supported releases:
pip install --upgrade azure-ai-projects azure-ai-agents openai azure-identity
Please note that streaming event structures can vary depending on the installed OpenAI SDK version. The event example below should be treated as illustrative and validated against the SDK version currently installed. for event in stream: print(event.type)
- Permission Error: Microsoft.MachineLearningServices/workspaces/agents/action Observed Error -
Identity(object id:) does not have permissions for Microsoft.MachineLearningServices/workspaces/agents/action Analysis This error is separate from the SDK import issue. The authentication process is succeeding, but the identity executing the Agent operation does not currently have the permissions required to perform that action. Azure AI Foundry permissions are divided into two areas: Control-plane permissions Used for Azure resource management activities, including roles such as:
Data-plane permissions Used for:
- Agent creation
- Agent execution
- Agent interaction
- Inference operations
Current Foundry documentation states that control-plane permissions alone do not automatically grant the data-plane permissions required for Agent operations. Appropriate Foundry roles are required for Agent-related activities. An additional consideration is the identity being used during execution. When DefaultAzureCredential() is configured, authentication may occur through:
- Azure CLI credentials
- Managed Identity
- Service Principal
- Environment credentials
For this reason, the Object ID returned in the error should be validated before making RBAC changes
Please check if the following steps help-
- Confirming the runtime identity Verify that the executing identity matches with Azure Entra ID Object ID (GUID) For Azure CLI authentication:
az account show
To validate the signed-in identity:
az ad signed-in-user show
- Reviewing role assignments Run:
az role assignment list \
--assignee d32d8048-dccd-4e16-8ffb-fe14bdc4f634 \
--all
Verify that the identity has the appropriate role assignment at the relevant Foundry project or resource scope.
- Validating Foundry permissions Review whether an appropriate Foundry role has been assigned, such as:
- Foundry User
- Foundry Project Manager
- Foundry Owner
For custom roles, verify that the permissions include the Agent actions required by the workload. Please note that current Foundry documentation specifically notes that Azure AI Developer is not intended for Foundry Agent scenarios and should not be relied upon as the primary role for Agent operations. Instead, validate that an appropriate Foundry role is assigned
- Refreshing authentication After any role assignment changes:
az logout
az login
Allow time for RBAC propagation and retry the workflow execution.
The ResponseStreamEventType error is caused by using an unsupported import while working with the OpenAI-compatible Responses API surface. Aligning the implementation with the current SDK guidance should resolve that issue.
Separately, the Microsoft.MachineLearningServices/workspaces/agents/action error indicates that the identity executing the Agent operation does not currently have the required data-plane permissions. Validating the runtime identity and its Foundry role assignments should help resolve the remaining authorization blocker.
The following references might be helpful , please check them out
Thank you
Please "Accept" the answer with an "Upvote" if the response was helpful. This will be benefitting other community members who face the same issue.