Foundry Agent cannot resolve Azure AI Search MCP endpoint ("Name or service not known")

70351079 0 Reputation points
2026-09-08T15:07:54.8266667+00:00

Environment:

  • Microsoft Foundry (New Foundry experience)
  • Azure AI Search Knowledge Base
  • MCP endpoint generated by Foundry IQ

Error:

Error encountered while enumerating tools from remote server.

Endpoint:

https://ai-search-cooh-ts-brd-mvc.search.windows.net/knowledgebases/historical-loe-v2/mcp

Message:

Name or service not known.

The host name could not be resolved from the selected network path.

Screenshot 2026-09-08 103424

Foundry Agent Service
Foundry Agent Service

A fully managed platform in Microsoft Foundry for hosting, scaling, and securing AI agents built with any supported framework or model


4 answers

Sort by: Most helpful
  1. Alex Burlachenko 25,290 Reputation points MVP Volunteer Moderator
    2026-09-14T07:17:39.5266667+00:00

    Hi my digital friend 70351079 & thx for join me at Q&A platform,

    this is a DNS/network-path failure, not an MCP authentication or knowledge-base configuration problem. The error occurs while the agent is enumerating MCP tools, before it can actually call the knowledge base. The key part is Name or service not known for <search-service>.search.windows.net. Foundry's documentation for private agentic retrieval requires the Foundry-to-Azure AI Search path to have working private connectivity, and Azure AI Search uses the privatelink.search.windows.net private DNS zone.

    If the Search service has public access disabled or restricted, make sure it has an approved private endpoint reachable from the network used by the Foundry Agent runtime, and that privatelink.search.windows.net is correctly linked/resolvable from that network. Testing DNS from your workstation alone isn't sufficient because the Agent runtime, not your browser, is making this MCP request. Microsoft also notes that private endpoints for Azure AI Search aren't automatically created when configuring Foundry private networking.

    I would first verify how the Search resource's Networking is configured. If it's private, this error is very consistent with a missing private endpoint/DNS link or an incorrectly configured Foundry VNet path. Microsoft specifically recommends validating that <search-service>.search.windows.net resolves to the private IP from the intended VNet and that TCP 443 is reachable. If those checks are correct but the Agent runtime still reports that the hostname can't be resolved, I'd open a Foundry support case with the project ID, Search resource ID, MCP endpoint, timestamp and trace/run ID. At that point Microsoft needs to inspect the network/DNS context actually being used by the Agent runtime.

    rgds,

    Alex

    Was this answer helpful?


  2. 70351079 0 Reputation points
    2026-09-09T13:55:14.77+00:00

    Hi Team, 

    I am requesting assistance with private network connectivity between Azure AI Search and the GPT-4o deployment used by a Foundry IQ knowledge base. 

    The historical LOE knowledge source and knowledge base were created successfully and both show as Active. However, retrieval fails when Azure AI Search attempts to invoke the GPT-4o model. 

    Confirmed backend error 

    POST /knowledgebases/historical-loe-v2/retrieve  HTTP 403 Forbidden    Could not complete model action. The model endpoint returned status code '403' (Forbidden). Public access is disabled. Please configure private endpoint. 

    Relevant resources 

    Azure AI Search service: ai-search-cooh-ts-brd-mvc 

    Knowledge base: historical-loe-v2 

    Foundry/OpenAI resource: ai-foundry-resource-cooh-ts 

    Model deployment: gpt-4o 

    Model endpoint: ai-foundry-resource-cooh-ts.openai.azure.com 

    Foundry private endpoint: pe-foundry-cooh-ts 

    OpenAI private endpoint IP shown in DNS configuration: 10.19.200.125 

    Configuration already verified 

    Public network access on the Foundry resource is disabled, as required by IQVIA policy. 

    The policy prevents enabling public access for testing: Cognitive Services accounts should disable public network access. 

    The Foundry private endpoint connection is Approved. 

    Private endpoint DNS entries exist for the Foundry Cognitive Services, OpenAI, and services.ai endpoints. 

    The Azure AI Search knowledge source and knowledge base are Active. 

    The failure occurs specifically when Azure AI Search invokes the GPT-4o model during knowledge retrieval. 

    Request 

    Could you please review and configure the supported private network path from Azure AI Search to the Foundry/OpenAI model endpoint? Specifically, please verify: 

    DNS resolution from the Azure AI Search agentic-retrieval runtime to ai-foundry-resource-cooh-ts.openai.azure.com resolves through the appropriate private DNS configuration. 

    1. Network connectivity from the Azure AI Search retrieval runtime to the Foundry/OpenAI private endpoint on TCP 443. Hi Team,  I am requesting assistance with private network connectivity between Azure AI Search and the GPT-4o deployment used by a Foundry IQ knowledge base.  The historical LOE knowledge source and knowledge base were created successfully and both show as Active. However, retrieval fails when Azure AI Search attempts to invoke the GPT-4o model.  Confirmed backend error  POST /knowledgebases/historical-loe-v2/retrieve HTTP 403 Forbidden  Could not complete model action. The model endpoint returned status code '403' (Forbidden). Public access is disabled. Please configure private endpoint.  Relevant resources 
      • Azure AI Search service: ai-search-cooh-ts-brd-mvc 
      • Knowledge base: historical-loe-v2 
      • Foundry/OpenAI resource: ai-foundry-resource-cooh-ts 
      • Model deployment: gpt-4o 
      • Model endpoint: ai-foundry-resource-cooh-ts.openai.azure.com 
      • Foundry private endpoint: pe-foundry-cooh-ts 
      • OpenAI private endpoint IP shown in DNS configuration: 10.19.200.125 
      Configuration already verified 
      • Public network access on the Foundry resource is disabled, as required by IQVIA policy. 
      • The policy prevents enabling public access for testing: Cognitive Services accounts should disable public network access. 
      • The Foundry private endpoint connection is Approved. 
      • Private endpoint DNS entries exist for the Foundry Cognitive Services, OpenAI, and services.ai endpoints. 
      • The Azure AI Search knowledge source and knowledge base are Active. 
      • The failure occurs specifically when Azure AI Search invokes the GPT-4o model during knowledge retrieval. 
      Request  Could you please review and configure the supported private network path from Azure AI Search to the Foundry/OpenAI model endpoint? Specifically, please verify: 
      1. DNS resolution from the Azure AI Search agentic-retrieval runtime to ai-foundry-resource-cooh-ts.openai.azure.com resolves through the appropriate private DNS configuration. 
      2. Network connectivity from the Azure AI Search retrieval runtime to the Foundry/OpenAI private endpoint on TCP 443. 

    Was this answer helpful?

    0 comments No comments

  3. Karnam Venkata Rajeswari 5,340 Reputation points Microsoft External Staff Moderator
    2026-09-08T16:59:38.5833333+00:00

    Hello @70351079 ,

    Welcome to Microsoft Q&A .Thank you for reaching out to us.

    The MCP endpoint structure appears consistent with the expected Foundry IQ Knowledge Base endpoint format. However, the Knowledge Base name and API version should also be confirmed against the generated endpoint.

    The message "Name or service not known" indicates that the Agent runtime cannot resolve the Azure AI Search hostname through the selected network path. This occurs before MCP tool enumeration, authentication, Knowledge Base retrieval, or GPT-4o invocation begins.

    Please check if the following steps help-

    1. Confirming the Agent networking setup
      1. Please confirm whether Standard Agent Setup with private networking is configured.
      2. Private MCP connectivity requires a supported private networking configuration.
      3. If Basic Agent Setup is configured, the private MCP endpoint may not be reachable through the intended private path.
    2. Validating Azure AI Search networking
      1. Start by reviewing the Public Network Access setting.
      2. Confirm that a Private Endpoint exists when private-only access is required.
      3. Verify that the Private Endpoint connection status is Approved.
      4. Confirm that the Agent runtime network and Search Private Endpoint network have the required connectivity.
    3. Validating Private DNS
      1. Confirm that the private DNS zone privatelink.search.windows.net exists.
      2. Confirm that the Search service record points to the expected private IP address.
      3. Verify that the zone is linked to the VNet associated with the Agent runtime.
      4. If custom DNS, Azure Firewall DNS Proxy, VPN, ExpressRoute, or corporate DNS forwarding is configured, confirm that private Search DNS queries are forwarded correctly.
    4. Testing DNS and HTTPS connectivity From a resource using the closest available DNS and network path, run: Resolve-DnsName ai-search-cooh-ts-brd-mvc.search.windows.net or nslookup ai-search-cooh-ts-brd-mvc.search.windows.net For a private endpoint configuration, the hostname should resolve to the expected private IP address. After successful resolution, test TCP port 443: Test-NetConnection ai-search-cooh-ts-brd-mvc.search.windows.net -Port 443 If DNS succeeds but port 443 fails, review VNet peering, NSGs, firewalls, routing, and Private Endpoint configuration.
    5. Validating the Capability Host
      1. Confirm that the required Capability Host configuration is provisioned and healthy for both the Foundry account and project.
      2. This should be treated as a secondary runtime-networking validation rather than a confirmed root cause.
    6. Performing an optional isolation test If security policy permits, temporarily allow public network access on Azure AI Search and retry the Agent request. A successful result would strongly indicate an issue with private DNS, Private Endpoint configuration, routing, or the Agent private networking path. The original security configuration should be restored after testing. If the behavior changes to an HTTP 401 or 403 error after DNS connectivity is restored, the next step would be to review the project managed identity configuration and Azure AI Search data-plane permissions.

    The following references might be helpful , please check them out

    Please let us know if the response was helpful

     

    Thank you

     

    Was this answer helpful?

    0 comments No comments

  4. AI answer

    2026-09-08T15:08:17.63+00:00

    This error indicates a DNS/network path problem to the Azure AI Search knowledge base MCP endpoint, not a tool-schema issue.

    Use this checklist:

    1. Verify the MCP endpoint format
      • The search service endpoint must be the Azure AI Search service URL.
      • The knowledge base name must exactly match the knowledge base created in Azure AI Search.
      • For the knowledge base MCP endpoint, use API version 2026-08-01-preview.
    2. Check whether the endpoint is private or depends on private DNS
      • If the Azure AI Search service or MCP path is reachable only through a private endpoint, Foundry agent connectivity depends on the selected network path, DNS, firewall rules, and private endpoint configuration.
      • Ensure private endpoints exist for all Azure services the MCP tools access.
      • Verify firewall rules permit agent-to-service traffic.
    3. Validate DNS resolution from the Foundry network path
      • The error text explicitly says the host name could not be resolved from the selected network path.
      • If the search service was previously or is currently configured with a private endpoint, DNS can resolve the service to a private IP that the agent path cannot reach.
      • In that case, review private endpoint connections and private DNS configuration for Azure AI Search.
    4. Check authorization after DNS is fixed
      • If the next error becomes 401 or 403, confirm the project managed identity has Search Index Data Reader on the search service.
      • If the connection writes to indexes, also assign Search Index Data Contributor.
      • If creating or deleting the project connection fails with 403 from Azure Resource Manager, confirm the user or service principal has permissions on the Microsoft Foundry resource and project.
      • If using keyless authentication, confirm sign-in is to the correct tenant and subscription.
    5. Confirm the agent is configured to use the knowledge base tool
      • Ensure the MCP tool is configured.
      • Ensure allowed_tools includes knowledge_base_retrieve.
    6. If using private MCP generally in Foundry Agent Service
      • Private MCP connectivity requires Standard Agent Setup with private networking.
      • Basic agent setup does not support private MCP endpoints.

    A practical interpretation for this specific error:

    • Name or service not known means Foundry is failing before authentication, during hostname resolution.
    • Focus first on Azure AI Search endpoint correctness, private endpoint/private DNS state, and whether the selected Foundry network path can resolve and reach the search service hostname.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.