Foundry Basic Agent cannot resolve private Azure AI Search MCP endpoint through VNet injection

Leo Tam (IT, Contractor) 20 Reputation points
2026-09-28T09:05:56.29+00:00

I have a Microsoft Foundry Basic Agent project using BYO VNet injection. The agent is a brand-new agent with only a connected knowledge base. The knowledge base is created by the Knowledge tab in Foundry IQ, connecting to the AI search service with managed identity. The agent fails during MCP tool enumeration with:

Name or service not known. The host name could not be resolved from the selected network path.

The failing endpoint is:

https://testaisearch.search.windows.net/knowledgebases/knowledgebase545/mcp

I have validated the customer-managed network path:

  • The Foundry account network injection points to RAG-VNET/agent-subnet.
  • The VNet RAG-VNET 10.0.0.0/24 has two subnets default 10.0.0.0/27 and agent-subnet 10.0.0.128/27
  • The agent subnet is delegated to Microsoft.App/environments.
  • The Azure AI Search private endpoint is Approved and Succeeded.
  • The private endpoint targets the searchService subresource and has private IP 10.0.0.4.
  • privatelink.search.windows.net contains the correct A record and is linked to RAG-VNET.
  • The VNet uses Azure-provided DNS and has no custom DNS servers.
  • From a Linux VM inside RAG-VNET, the Search hostname resolves to 10.0.0.4.
  • From the same VM, HTTPS/TLS to the exact MCP endpoint succeeds and returns HTTP 401, as expected without authentication.
  • Recreating the knowledge base and RemoteTool connection did not resolve the issue.
  • Enabling Azure AI Search public network access did not change the agent runtime error.

Thanks for helping

Foundry Agent Service
Foundry Agent Service

A fully managed platform in Microsoft Foundry for hosting, scaling, and securing AI agents built with any supported framework or model

0 comments No comments

Answer accepted by question author
Allan Solomon Mejia 10,225 Reputation points
2026-09-28T16:03:50.2666667+00:00

Hello @Leo Tam (IT, Contractor)

The DNS configuration appears correct for resources inside RAG-VNET, but the key issue is the Basic Agent setup.

The Basic Agent deployments don’t support private Azure AI Search resources. Access to Azure AI Search through a private endpoint requires a Standard Agent setup with virtual network injection.

The successful test from the Linux VM proves that the private endpoint and private DNS zone work from RAG-VNET. It doesn’t prove that the Basic Agent runtime uses that network path. The Basic Agent runtime isn’t deployed into the delegated subnet in the supported private-network architecture.

The supported resolution is:

  1. Create a Standard Agent setup.
  2. Supply the required bring-your-own Azure Storage, Azure Cosmos DB, and Azure AI Search resources.
  3. Configure VNet injection during creation, using the subnet delegated to Microsoft.App/environments.
  4. Create private endpoints for the three dependent resources; Foundry doesn’t create them automatically.
  5. Use the project managed identity for the Azure AI Search connection and grant it the required Search data-plane role.
  6. Recreate the Foundry IQ RemoteTool connection and agent in the Standard project.

These requirements are documented in the private-network setup instructions.

The knowledge-base connection should continue using the Azure AI Search service endpoint: https://testaisearch.search.windows.net and the project connection should use the RemoteTool category with ProjectManagedIdentity authentication.

Adding network injection to an existing agent setup isn’t supported in every scenario, and secured Standard capability settings require all three BYO resources. Creating a new Standard project is therefore the cleanest supported path.

References:

Set up private networking for Foundry Agent Service

Azure AI Search tool networking limitations

Connect agents to Foundry IQ knowledge bases


Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.