All skills
microsoft avatar

/microsoft-foundry

@04110d9
by microsoftmicrosoft/skills3.1k stars
351

Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end. USE FOR: foundry, azd ai agent, azd provision/deploy, hosted agent scaffold/develop/run/deploy/troubleshoot, prompt agent create, create agent, update agent, add tool to agent, invoke agent, agent.yaml, agent insights, pull agent insights, evaluate agent, batch eval, continuous eval, continuous monitoring, agent CI/CD, optimize prompt, improve prompt, prompt optimizer, optimize agent instructions, Agent Optimizer scaffold, dataset curation from traces, deploy model, model fine-tuning (SFT/DPO/RFT), Foundry project, RBAC, role assignment, permissions, quota, capacity, region, deployment failure, AI Services, create Foundry resource, knowledge index, customize deployment, onboard, availability, training-data, grader, distillation, large file upload. DO NOT USE FOR: Azure Functions, App Service, general Azure deploy (use azure-deploy), general Azure prep (use azure-prepare).

Use this Skill: https://skilld.dev/gh/microsoft/skills/microsoft-foundry

This session only. Nothing lands on disk.

foundry-agenttoolboxreferencestool-mcp-user-entra-token.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Tool — Remote MCP server, user Entra token (type: mcp, auth UserEntraToken)

Attach a remote MCP server that authenticates with the caller's own Entra identity — the platform forwards the signed-in user's Entra token to the MCP server (auth type UserEntraToken), so the server sees the end user, not a shared credential. No BYO app registration, client secret, or OAuth consent flow. Needs a connection (--kind remote-tool --auth-type user-entra-token) scoped to the upstream resource via --audience; the toolbox references it by name and the created tool carries a populated project_connection_id.

Use this when the MCP server enforces per-user permissions off the caller's Entra identity (e.g. Microsoft 365 / Graph-backed services). Work IQ is a concrete, preview instance of this pattern.

🚦 Before creating a toolbox/connection either way, read create-hosted.md → Toolbox creation boundary.


Getting the catalog inputs

Only the MCP tiles this query returns support user-entra-token. Run the discovery script with --user-entra-token — it lists exactly the tiles you can attach with this reference, each with the audience its connection needs:

../scripts/get-catalog-inputs.sh --user-entra-token      # bash
pwsh ../scripts/get-catalog-inputs.ps1 -UserEntraToken   # PowerShell

If the tile is not in this list, user-entra-token does not apply to it — it uses a different auth mode.


A. Imperative CLI

Steps 1–3 of toolbox.md § The flow. Write the toolbox spec to a file — azd ai toolbox create --from-file takes a path (stdin - is not supported).

# 0. Install the CLI extension (once)
azd extension install azure.ai.toolboxes

# 1. Create the user-entra-token MCP connection (no secret; audience scopes the forwarded token)
azd ai connection create entra-mcp-conn \
  --kind remote-tool --target https://<mcp-host>/mcp \
  --auth-type user-entra-token \
  --audience <upstream-resource-uri-or-app-id> \
  --project-endpoint "$FOUNDRY_PROJECT_ENDPOINT"

# Write the toolbox spec to a file
cat > entra-mcp.yaml <<'EOF'
description: user-entra-token mcp toolbox
connections:
  - name: entra-mcp-conn
EOF

Create a new toolbox (first version auto-promoted):

azd ai toolbox create agent-tools --from-file entra-mcp.yaml --project-endpoint "$FOUNDRY_PROJECT_ENDPOINT"

azd ai toolbox create / delete require an azd environment (run inside an azd init'd directory), unlike connection create / toolbox show which work with just --project-endpoint.

Add to an existing toolbox (new version — then promote):

azd ai toolbox connection add agent-tools entra-mcp-conn --project-endpoint "$FOUNDRY_PROJECT_ENDPOINT"
azd ai toolbox publish agent-tools <new-version> --project-endpoint "$FOUNDRY_PROJECT_ENDPOINT"

connection add creates a new immutable version but leaves the default unchanged until you publish it.

--from-file entry:

connections:
  - name: entra-mcp-conn       # RemoteTool (UserEntraToken); the audience lives on the connection

B. Declarative azure.yaml

Declare the toolbox as a host: azure.ai.toolbox service; azd deploy upserts it (and auto-promotes the new version). Create the user-entra-token connection first (section A, step 1), then reference it under tools: by its name via project_connection_id.

name: my-agent-project
services:
  agent-tools:
    host: azure.ai.toolbox
    tools:
      - type: mcp
        server_label: entra
        project_connection_id: entra-mcp-conn   # the connection name from section A
        require_approval: never

  # A hosted agent in the same project consumes the toolbox by name
  my-agent:
    host: azure.ai.agent
    uses:
      - agent-tools          # depend on the toolbox service
    environmentVariables:
      - name: TOOLBOX_NAME
        value: agent-tools    # agent resolves the MCP endpoint at runtime
azd deploy agent-tools

Set FOUNDRY_PROJECT_ENDPOINT and AZURE_SUBSCRIPTION_ID in the azd env (after it's created) before azd deploy, or it errors infrastructure has not been provisioned. No azd provision / infra: block is needed.


Verify & deploy

After creating the toolbox either way, verify its MCP endpoint end-to-end (bearer token + raw tools/list / tools/call) — see test-endpoint.md.

The MCP server resolves data as the calling user's Entra identity — there is no separate consent step; the toolbox bearer token's identity is forwarded directly. Locally that's your az login identity; through a deployed agent it's the invoking user, so results differ by caller. A caller who lacks access to the upstream resource gets an empty or unauthorized result from that server, not a toolbox error.


References

Source: SKILL.md on GitHub

2 warnings3d4 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill provides a comprehensive environment for managing the end-to-end lifecycle of AI agents, models, and infrastructure on Microsoft Foundry. It includes sub-skills for deployment, evaluation, fine-tuning, and troubleshooting. The skill utilizes dynamic code execution and shell command wrappers, which are used within the context of local development and cloud orchestration. All external resources and dependencies originate from trusted organizations and well-known services.

  • Socket3d

    2 alerts: gptSecurity, gptAnomaly

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    36/36 files flagged

Signed by skilld at 04110d9. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
metadata
{
  "author": "Microsoft",
  "version": "1.2.26"
}

README badge

README badge for microsoft/skills/microsoft-foundry