Intermittent failure when invoking MCP tools through A2A in Microsoft Foundry

Girija Sravya Peesapati (US) 0 Reputation points
2026-10-07T10:06:03.1566667+00:00

Currently evaluating an Agent-to-Agent (A2A) integration pattern in Microsoft Foundry involving multiple agents and MCP-based tool integrations.
The setup consists of two Foundry agents:

  • One agent connected to ROVO MCP for Jira-related operations
  • A second agent connected to GitHub MCP for repository and code analysis

Both MCP integrations work successfully when tested independently, and direct A2A communication between the two agents is also working. However, I’m encountering an issue when the target agent attempts to invoke its GitHub MCP tools as part of an A2A-delegated request.
This makes the flow fail specifically at:

Agent 1 → A2A → Agent 2 → GitHub MCP
A simple A2A response works, and GitHub MCP works directly from Agent 2, but delegated requests that require Agent 2 to use GitHub MCP sometimes return a generic Foundry runtime error with a request ID.

I would like to understand whether there are any known limitations around A2A agents invoking their own MCP tools, particularly when conversation context is also being passed between agents, and what the recommended architecture is for this pattern.

Any guidance on configuration or troubleshooting would be appreciated.
User's image

Foundry Agent Service
Foundry Agent Service

A fully managed platform in Microsoft Foundry for hosting, scaling, and securing AI agents built with any supported framework or model

0 comments No comments

1 answer

Sort by: Newest
  1. Rukshan edirisinghe 1,400 Reputation points
    2026-10-07T12:35:02.74+00:00

    Hi @Girija Sravya Peesapati (US)

    One thing worth checking first is the approval setting on Agent 2's GitHub MCP tool. In Foundry, require_approval defaults to always, so every MCP call returns an mcp_approval_request that the caller has to answer. When you test Agent 2 directly you can approve it, but when Agent 1 delegates over A2A there's no one to send that approval back, and the run can end in a generic error.

    Here's what I'd try:

    1. On Agent 2, set the GitHub MCP tool to require_approval: {"never": ["<tool_name>", ...]} for the read-only tools it needs during delegated requests (or never while you test).
    2. Keep each GitHub MCP call small, like one repo or one path at a time. Non-streaming MCP calls time out after 100 seconds, and passing a long conversation context through A2A makes slow calls more likely.
    3. Run the same delegated prompt a few times. If it still fails sometimes, open an Azure support request with the request IDs from the error, since only Microsoft can trace those runs.

    Does it fail on every delegated request that needs GitHub MCP, or only on the bigger ones, like a full repo analysis?

    If this resolved your issue, please consider accepting it as the answer. If the error keeps showing up, let me know and I'll be happy to keep helping.

    Reference:

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.