Microsoft Foundry: hello-world autopilot microsoft365/publish returns 502 upstream_dependency_failed

Panu Hällfors 0 Reputation points
2026-10-11T09:57:08.15+00:00

Publishing the official hello-world autopilot sample to Microsoft 365, samples/python/autopilot-agents/hello-world seems to fail – any idea of what to look at?

What happens:

azd deploy succeeds. Publishing then fails.

azd ai agent publish stops with:

publish_teams_app: HTTP request failed: context deadline exceeded

Calling the API directly with curl --max-time 600 returns HTTP 502:

POST {projectEndpoint}/agents/hello-world-autopilot/microsoft365/publish?api-version=2025-11-15-preview

{

"error": {

*"code": "upstream_dependency_failed",*

*"message": "An error occurred while processing your request. You can retry your request, or contact us if the error persists. Please include the request ID 7f715b8302179e291627d107f7f90e3d in your message."*

}

}

Request ID: 7f715b8302179e291627d107f7f90e3d

x-ms-region: East US

server: istio-envoy

The body uses the sample metadata with publishAsAutopilot=true, publishScope=Tenant, and useAgenticUserTemplate=true. The same azd timeout happens for this sample also in Sweden Central region. Public network access is enabled (this is one mentioned cause for the upstream error, but not in this case).

azd is 1.34.2 and azure.ai.agents is 1.0.0-beta.17.

Already tried:

  • Registered Microsoft.BotService and waited until it was Registered. No bot resource appears, and the 502 stays.
  • West Europe refuses a new Foundry account in this subscription. East US accepts it, and publish still returns 502.
  • The tenant has Business Premium, Copilot Business, and Agent 365. It has no E7 license. Copilot Frontier is on for all users.
  • After deploy, the agent shows in the Microsoft 365 admin center Registry as Available. It has no Agent instances tab and does not show in Teams under Agents for the team.

One possible caveat, that should not be the issue though:

I have never seen the Microsoft Admin Agents > Overview "Try now" banner that's described in instructions - I've found no way to get it shown. I've added the licenses mentioned above, and everything in the Agents > Overview page is enabled and show correctly though. Consequently, I don't have "Microsoft 365 Frontier for AI Teammates" product, but AFAIK the other licenses I have should be enough for this use case. In any case, the documentation suggests that if this was the issue, I should get 4xx reply, not a 502.

Any idea how to get past the upstream error?

A big thanks in advance!

Foundry Agent Service
Foundry Agent Service

A fully managed platform in Microsoft Foundry for hosting, scaling, and securing AI agents built with any supported framework or model

0 comments No comments

1 answer

Sort by: Most helpful
  1. Allan Solomon Mejia 10,385 Reputation points
    2026-10-11T19:30:28.44+00:00

    Hello @Panu Hällfors

    Thanks for providing the detailed troubleshooting results, particularly the direct API response and request ID.

    Since azd deploy completes successfully, but both azd ai agent publish and the direct REST API call fail, focus on the Microsoft 365 autopilot publishing process and its upstream dependencies, rather than the agent deployment itself.

    The 502 upstream_dependency_failed response indicates that the publishing request encountered an upstream dependency failure. However, it doesn't identify which dependency failed, so we shouldn't assume this is an Azure Bot Service or regional issue without further evidence.

    1. Verify Agent 365 Frontier enrollment

    One detail worth investigating is your tenant's Frontier enrollment. Creating a Foundry autopilot with an agent user account requires Frontier enrollment, acceptance of the Microsoft Agent 365 terms of service, and the applicable licensing prerequisites.

    You mentioned that the Try now banner is missing and that you don't have the Microsoft Agent 365 Frontier subscription.

    Although you have Business Premium, Copilot Business, and Agent 365 licenses, verify whether the tenant has completed the specific Agent 365 Frontier onboarding process.

    There's an E7 requirement for access to Agent 365 preview features. Your existing licenses shouldn't be assumed to satisfy that requirement without confirmation.

    1. Validate the autopilot publishing metadata

    The following are the required publishing properties:

    • publishAsAutopilot: true
    • publishScope: Tenant
    • useAgenticUserTemplate: true
    • agenticUserTemplate: Required when useAgenticUserTemplate is enabled

    Since you're using the official sample, don't immediately change these settings. However, it's worth confirming that the generated request contains the complete agenticUserTemplate object, including the correct AgentIdentityBlueprintId.

    1. Distinguish registration from successful publishing

    You mentioned that the agent already appears as Available in the Microsoft 365 admin center Registry.

    The Foundry agents can be synchronized into the Agent 365 registry independently of the autopilot publishing workflow.

    Therefore, its presence in the registry doesn't necessarily confirm that the autopilot blueprint was successfully published, approved, or made available for creating instances.

    1. Escalate the upstream failure with the request ID

    Since the same failure occurs through the CLI and direct API, and you've reproduced the behavior in East US and Sweden Central, I recommend opening a Microsoft Azure support request.

    Provide the following information:

    • Error: 502 upstream_dependency_failed
    • Request ID: 7f715b8302179e291627d107f7f90e3d
    • Regions tested: East US and Sweden Central
    • API version: 2025-11-15-preview
    • Azure Developer CLI version: 1.34.2
    • UTC timestamps of the failed requests
    • Tenant Frontier enrollment and licensing status

    Ask Microsoft Support to identify the failing upstream dependency and verify whether tenant eligibility or a service-side publishing issue is responsible.

    Additional clarification, could you confirm two things?

    • Has your tenant explicitly accepted the Microsoft Agent 365 Frontier terms of service, or have you only enabled Frontier access for users?
    • Does the publishing request contain the complete agenticUserTemplate object, including AgentIdentityBlueprintId?

    These details would help distinguish a missing prerequisite from a potential service-side failure.

    At this point, there's no documentation establishing that this specific 502 error is caused by licensing, Azure Bot Service registration, or a known regional outage. The request ID should help Microsoft investigate the underlying failure.

    Hope this helps narrow down the issue.

    Reference:

    Preview Agent 365 features through the Frontier program

    Quickstart: Build your first autopilot

    Microsoft Agent 365 integration with Foundry


    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.