How to Add Multiple Tools to a Toolbox and Assign it to an Agent in Azure AI Foundry (HTTP 403 Forbidden via MCP)

KANGSEOP Jung 0 평판 포인트
2026-06-08T00:38:09.3666667+00:00

Hello,

I am currently configuring a workflow in the Azure AI Foundry web portal. My goal is to add multiple tools to a Toolbox and then enable an Agent to utilize that Toolbox.

Since there currently seems to be no direct way to attach a Toolbox to an Agent in the UI, I attempted a workaround: I registered the Toolbox itself as an MCP (Model Context Protocol) Tool and then assigned that MCP Tool to the Agent. However, when testing the Agent in the Playground, I encountered the following error:

Error: Access denied when connecting to the MCP server at https://{Project}.ai.azure.com:443/api/projects/{Project}/toolboxes/{Tool}/mcp while enumerating tools (HTTP 403 Forbidden). Please verify: (1) your credentials have the necessary permissions to access this server, (2) any IP allowlists or network policies permit requests from this service, and (3) the server's access control configuration allows the requested operation.

Current Configuration Details:

  • Endpoint: Copied and pasted the direct endpoint of the Toolbox into the MCP Tool configuration.
  • Authentication: Microsoft Entra ID
  • Identity Type: Project Managed Identity
  • Audience: https://ai.azure.com
    Note: I have already verified that each of the individual tools registered inside the Toolbox works perfectly fine when executed independently.

While troubleshooting, I found a note stating that requests to the Toolbox endpoint require a specific header: Foundry-Features: Toolboxes=V1Preview. I suspect that the lack of this header during the Agent-to-MCP communication might be causing the HTTP 403 Forbidden error.

Questions

What is the standard/recommended way to make an Agent use a Toolbox?

Desired Setup: Add Tool A and Tool B to a Toolbox $\rightarrow$ Assign this Toolbox to an Agent $\rightarrow$ The Agent automatically discovers and utilizes Tool A and Tool B.

Is my current approach (registering a Toolbox as an MCP Tool) architecturally supported, or is it an invalid approach?

If this approach is supported, what am I misconfiguring in my setup? (e.g., missing Managed Identity permissions, network policies, or the required preview headers?)

Is this integration currently unsupported simply because the Toolbox feature is in Public/Private Preview?

Thank you in advance for your guidance and support!

Foundry Tools
Foundry Tools

이전 명칭은 Azure AI Services 또는 Azure Cognitive Services였으며, Microsoft Foundry 플랫폼 내의 사전 구축된 AI 기능을 통합한 컬렉션입니다


답변 1개

정렬 기준: 가장 유용함
  1. Karnam Venkata Rajeswari 5,340 평판 포인트 Microsoft 외부 직원 중재자
    2026-06-24T12:07:39.27+00:00

    Hello KANGSEOP Jung,

    Welcome to Microsoft Q&A .Thank you for reaching out to us.

     The current issue appears during the Agent-to-Toolbox MCP discovery process, where the Agent attempts to enumerate the tools exposed by the Toolbox MCP endpoint and receives an HTTP 403 Forbidden response.

    Troubleshooting HTTP 403 Forbidden during Toolbox discovery

    Because the failure occurs while enumerating tools, the following validation steps are suggested in priority order.

    1. Validating the Toolbox preview header Toolbox MCP endpoint requests require the following preview feature header: Foundry-Features: Toolboxes=V1Preview Since the error occurs during tool discovery, confirming whether this header is included in requests sent through the Agent-to-MCP path should be the first investigation step. If the request reaches the Toolbox endpoint without the required header, the discovery operation may be rejected
    2. Validating Azure AI Foundry project permissions and RBAC Please review whether:
      • The developer identity has appropriate permissions to manage Toolbox resources within the Azure AI Foundry project.
      • The Project Managed Identity used by the Agent has permission to access and use Toolbox resources at runtime.
      • Any downstream Azure resources used by Toolbox tools grant the necessary permissions to the runtime identity.
      A common scenario is that Toolbox creation succeeds, but the runtime identity used by the Agent does not have sufficient permissions during tool discovery or execution.
    3. Validating authentication and project connections Please confirm:
      • Microsoft Entra ID authentication is configured successfully.
      • The configured audience is https://ai.azure.com
      • Any project connections used by Toolbox tools exist within the same Azure AI Foundry project.
      • The runtime identity is authorized to use those connections.
    4. Reviewing networking and access restrictions If networking controls are configured, validate:
      • Private endpoint configuration.
      • Firewall rules.
      • Selected network access settings.
      • IP allowlists.
      Ensure connectivity exists between:
      • The Agent runtime and the Toolbox MCP endpoint.
      • The Toolbox and any dependent services used by its tools.
    5. Validating Toolbox configuration When adding multiple tools to a Toolbox:
      • Provide clear descriptions for each tool.
      • Confirm connection-based tools reference valid project connections.
      • If multiple instances of the same tool type are configured, verify whether unique tool names are required by the Toolbox configuration.
      Issues related to duplicate or invalid tool definitions typically result in Toolbox validation errors and are generally separate from the HTTP 403 discovery behavior currently being observed

    Regarding if preview status contribute to this scenario - Toolbox functionality is currently available as a preview capability and may have additional requirements or limitations compared to generally available features.However, the information available does not indicate that Toolbox usage with Agents is unsupported.

    Please check if the following steps help-

    1. Test the Toolbox MCP endpoint directly outside the Agent flow using:
      • A valid Microsoft Entra token.
      • The required header:Foundry-Features: Toolboxes=V1Preview
    2. Confirming whether the behavior occurs:
      1. Only in Agent Playground.
      2. Or also through SDK/API-based invocation.
    3. Reviewing permissions for:
      1. Developer identity.
      2. Agent Project Managed Identity.
    4. Validate project connections and downstream resource permissions.
    5. Review:
      • Firewall settings.
      • Virtual Network configuration.
      • Private endpoint configuration.

    The following references might be helpful , please check them out

    Thank you

     

    Please "Accept" the answer with an "Upvote" if the response was helpful. This will be benefitting other community members who face the same issue.

     

    이 대답이 도움이 되었나요?

    댓글 0개 설명 없음

답변

질문 작성자는 답변을 '승인됨'으로 표시하고, 중재자는 답변을 '추천됨'으로 표시할 수 있습니다. 이를 통해 사용자는 해당 답변이 작성자의 문제를 해결했다는 것을 알 수 있습니다.