An Azure service that provides an integrated environment for bot development.
Teams Bot calling Foundry Prompt agent with user credentials
We have a custom Microsoft Teams bot that calls a Microsoft Foundry prompt agent through the Responses API (agent_reference). The agent has an MCP tool that uses OAuth identity passthrough with a custom OAuth connection.
Today the bot calls Foundry with its own service principal. In our tests, the MCP OAuth login was stored under the bot, so all Teams users shared the first user's login. Sending x-ms-user-identity didn't change this for the prompt agent.
We need each Teams user to have their own MCP OAuth login.
Is it supported for the bot to call the prompt agent with each user's delegated Entra token for https://ai.azure.com?
If so, does Foundry then store the MCP OAuth login separately for each of those users?
If not, what is the supported way for a custom bot to get per-user MCP OAuth tokens with a prompt agent?