Azure Foundry : Unable to use Oauth Connection or Delete Oauth Connection

Fabien COLOIGNIER 0 Points de réputation
2026-06-03T17:14:08.7+00:00

Hello there,

I'm currently using Azure Foundry (new interface).
I wanted to connect one of my agent to my custom mcp (built with Function App) using Oauth.
I've successfully using the Azure Portal UI and I have one agent that ask for consent and afterward is able to call the MCP Tool.

So the next time is trying to script the creation of the connection to avoid doing it manually.
I've choose to use the "az" commands so i've run this query :

az rest --method put --url https://management.azure.com/subscriptions/<tenantid>/resourceGroups/<resourceGroupName>/providers/Microsoft.CognitiveServices/accounts/<FoundryName>/projects/<project-name>/connections/connection-jiramcp-oauth-new?api-version=2026-03-01

with this body

{
  "properties": {
    "category": "RemoteTool",
    "authType": "OAuth2",
    "isDefault": false,
    "target": "https://xxxxx.azurewebsites.net/runtime/webhooks/mcp?code=xxxx",
    "isSharedToAll": true,
    "credentials": {
      "clientId": "client-id",
      "clientSecret": "client-secret"
    },
    "authorizationUrl": "https://login.microsoftonline.com/<tenantId>/oauth2/v2.0/authorize",
    "refreshUrl": "https://login.microsoftonline.com/<tenantId>/oauth2/v2.0/token",
    "tokenUrl": "https://login.microsoftonline.com/<tenantId>/oauth2/v2.0/token",
    "scopes": [
      "api://final-client-id/user_impersonation",
      "offline_access",
      "openid",
      "profile"
    ],
    "metadata": {
      "type": "custom_MCP"
    }
  }
}

The creation of the connexion is succesfull and when i check the JSON of the created connection with the command line it's exactly the same as the one created with the portal.

Unfortunately, when change the "project_connection_id" from the connection created using the portal to the one created by script it doesn't work anymore (i've also tried to create a new agent, it doesn't work either)

Error[Failed Dependency] while enumerating tools, the dependency call to the MCP server: https://xxxx.azurewebsites.net:443/runtime/webhooks/mcp failed with status code 500, and error message: Failed to retrieve ConnectorGateway connection. Status: 500, Details: {"error":{"code":"InternalServerError","message":"Encountered internal server error. The tracking Id is '60c45d82-67b6-4f75-8a31-bd4c30fa88da'."}} This indicates a server-side or upstream gateway issue. Please ensure the MCP server is reachable, healthy, and correctly configured. If it appears healthy, check any network, APIM, firewall, or proxy settings that could be blocking or interrupting the request.

Moreover, I'm not able to delete the Oauth connection created by script

InternalServerError({"error":{"code":"ServiceError","severity":null,"message":"InternalServerError","messageFormat":null,"messageParameters":null,"referenceCode":null,"detailsUri":null,"target":null,"details":[],"innerError":null,"debugInfo":null,"additionalInfo":null},"correlation":{"operation":"50a50d8f194f1fd8c5f11bd4f0bb69c4","request":"2a4d0171e43251b0"},"environment":"francecentral","location":"francecentral","time":"2026-06-03T17:07:14.6662425+00:00","componentName":"account-rp","statusCode":500})

This problem occurs only with "Oauth connections", i've managed to create, update delete other connection, like keyvault connection, application insights connection, azure ai search connection, mcp connection

I would love to have some help on this !

Foundry Tools
Foundry Tools

Anciennement appelé Azure AI Services ou Azure Cognitive Services, il s’agit d’une collection unifiée de fonctionnalités d’IA prédéfinies au sein de la plateforme Microsoft Foundry


1 réponse

  1. Karnam Venkata Rajeswari 5,340 Points de réputation Personnel externe Microsoft Modérateur
    2026-06-19T19:18:19.4066667+00:00

    Hello Fabien COLOIGNIER,

    Welcome to Microsoft Q&A .Thank you for reaching out to us.

    Thank you for sharing the detailed investigation results, request payload and error messages.

    After reviewing the scenario, the key observation is that the same MCP endpoint and OAuth configuration work successfully when the connection is created through Azure AI Foundry, but fail when the connection is created programmatically and then associated with an agent.

    The OAuth connection created through the API is successfully created and can be retrieved through management APIs, indicating that the initial creation request is accepted.

    However, when the agent attempts to use that connection, Azure AI Foundry returns the following error during tool enumeration Failed to retrieve ConnectorGateway connection

    Since the portal-created connection works while the API-created connection does not, the current evidence does not indicate an issue with the MCP endpoint, OAuth application registration, configured scopes or consent flow itself.

    Instead, the behavior suggests there may be a difference between the provisioning workflow used by the AI Foundry portal and the direct API creation path for OAuth connections.

    A second important observation is that the same connection also fails to delete and returns a server-side 500 InternalServerError.

    When both of the following occur:

    • Runtime usage of the connection fails
    • Deletion of the connection fails

    it suggests that the issue may extend beyond the OAuth configuration itself. This behavior warrants further investigation into the connection's backend state and lifecycle processing.

    To help isolate the issue, the following checks can be helpful

    1. Comparing the complete connection definitions
      1. Export the full GET response for the working portal-created connection.
      2. Export the full GET response for the failing API-created connection.
      3. Compare all returned properties, including authentication metadata, connection state information, provider settings, secret references, and system-generated fields.
    2. Reproducing using a clean test
      1. Create a new OAuth connection with a unique name.
      2. Create a new agent.
      3. Configure the same MCP endpoint and OAuth application.
      4. Verify whether the behavior reproduces consistently.
    3. Validating the API workflow
      1. Confirm whether the portal is using the same API version (2026-03-01) and request sequence as the scripted implementation.
      2. Review any differences between the portal workflow and direct REST calls.

    The following references might be helpful , please check them out

    Thank you

     

    Please "Accept" the answer with an "Upvote" if the response was helpful. This will be benefitting other community members who face the same issue.

    Cette réponse a-t-elle été utile ?

    0 commentaires Aucun commentaire

Votre réponse

Les réponses peuvent être marquées comme « Acceptées » par l’auteur de la question et « Recommandées » par les modérateurs, ce qui aide les utilisateurs à savoir que la réponse a résolu le problème de l’auteur.