Per-user OAuth identity for MCP calls from a Teams bot

Teodora 0 Reputation points
2026-10-03T10:28:46.2966667+00:00

Context: A custom Teams bot (Bot Framework, Python) calls a Foundry prompt agent via the Responses API (agent_reference + conversations). The agent uses a remote MCP tool with OAuth identity passthrough against Keycloak. The MCP server enforces per-user document permissions, so each Teams user must use their own MCP OAuth credentials.

Problem: The bot authenticates to Foundry with its own service principal (ClientSecretCredential). Foundry therefore stores one MCP OAuth login under the bot's identity, and every Teams user silently reuses whoever consented last.

What we tested:

  • Users calling Foundry directly with their own Entra token each got a separate oauth_consent_request and separate MCP login — per-user isolation works when the caller's token represents the user.
  • Adding x-ms-user-identity: <user object ID> on a prompt agent call from the bot's service principal did not isolate the MCP login; credentials were still stored under the bot's identity.

Questions

  1. Can a custom confidential client (the bot's app registration) get a delegated token for https://ai.azure.com on behalf of a Teams user (via auth code flow / Teams SSO + OBO) and call the Foundry Responses API with it? Is Azure Machine Learning Services (18a66f5f-…) → delegated user_impersonation, requested as https://ai.azure.com/.default, the correct permission/scope?
  2. What is Microsoft's recommended architecture for a custom Teams bot + Foundry agent + per-user OAuth MCP server, where Foundry (not the bot) calls the MCP server?
Azure AI Bot Service
Azure AI Bot Service

An Azure service that provides an integrated environment for bot development.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.