Skip to content

azure-ai-agents: MCP usage errors with Azure AI Foundry #42428

Description

  • Packages:
    • azure-ai-projects: 1.0.0b10
    • azure-ai-agents: 1.2.0b1
  • Operating System: macOS Sequoia 15.5
  • Python Version: 3.11.8

Describe the bug
I've been having issues using the MCP integrations with Azure AI Foundry agents. Specifically, there are two things:

  1. An AssertionError is frequently occurring. It's happened for both GitMCP and Tavily's MCP servers. I have yet to try more MCP servers, but I suspect I'll continue to see these errors coming up. See the error below.
  2. I'm seeing repeated failures to invoke the tools provided to the agent for these MCP servers, resulting in unsatisfactory answers. See below for the error.
    • Perhaps I need to provide more specific instructions to the agent to guide it towards invoking the tools provided? I would think the agent would be smart enough to know as is without more specific prompting.

Error to problem 1

The result with the error:

{
  "data": {
    "response": "I encountered an issue while trying to get the current weather information for Seattle. You can check a reliable weather website or app for real-time updates. Alternatively, if you need general information about Seattle's climate or typical weather patterns, feel free to ask!"
  },
  "meta": {
    "run_steps": [
      {
        "id": "step_hgixrj0R0tORvoMZpTkf14cN",
        "object": "thread.run.step",
        "created_at": 1754658900,
        "run_id": "run_cT1NcPI13R3b88JJA9oDq179",
        "assistant_id": "asst_GyjPbDs3XfMbSrv0VehZmcFv",
        "thread_id": "thread_jlp4vdxxi3HlI7F5E67A6jEC",
        "type": "message_creation",
        "status": "completed",
        "cancelled_at": null,
        "completed_at": 1754658901,
        "expires_at": null,
        "failed_at": null,
        "last_error": null,
        "step_details": {
          "type": "message_creation",
          "message_creation": {
            "message_id": "msg_q8TpSGSexr47v7Pb0nImYnbc"
          }
        },
        "usage": {
          "prompt_tokens": 152,
          "completion_tokens": 52,
          "total_tokens": 204,
          "prompt_token_details": {
            "cached_tokens": 0
          }
        }
      },
      {
        "id": "step_ovu486RNvTcTKZ0zIBUmEB72",
        "object": "thread.run.step",
        "created_at": 1754658900,
        "run_id": "run_cT1NcPI13R3b88JJA9oDq179",
        "assistant_id": "asst_GyjPbDs3XfMbSrv0VehZmcFv",
        "thread_id": "thread_jlp4vdxxi3HlI7F5E67A6jEC",
        "type": "tool_calls",
        "status": "completed",
        "cancelled_at": null,
        "completed_at": 1754658900,
        "expires_at": null,
        "failed_at": null,
        "last_error": null,
        "step_details": {
          "type": "tool_calls",
          "tool_calls": [
            {
              "id": "call_UWl9nlG2w8akjCWKLMpgdeKi",
              "type": "mcp",
              "arguments": "{\"location\":\"Seattle, WA\"}",
              "name": "weather",
              "server_label": "tavily",
              "output": "content_type='system_error' name='AssertionError' text=\"Encountered exception: <class 'AssertionError'>.\""
            }
          ]
        },
        "usage": {
          "prompt_tokens": 106,
          "completion_tokens": 19,
          "total_tokens": 125,
          "prompt_token_details": {
            "cached_tokens": 0
          }
        }
      }
    ]
  }
}

Error to problem 2

{
  "data": {
    "response": "I currently don't have real-time capabilities to check the latest weather. However, you can easily find the current weather in Seattle by checking a weather website or app like Weather.com, the Weather Channel, or a local news website. Alternatively, you can use a digital assistant on your phone or smart device to get the latest weather update."
  },
  "meta": {
    "run_steps": [
      {
        "id": "step_47k5HIxdJe4D1T02IvGfzqZ5",
        "object": "thread.run.step",
        "created_at": 1754659678,
        "run_id": "run_HF0DgO0m9n8PhVZyYqMKz7JL",
        "assistant_id": "asst_xOCNz0JcZ2yMbzbDDZ96FIee",
        "thread_id": "thread_uKI5zjsP5xAIhXfJ9rEO0x43",
        "type": "message_creation",
        "status": "completed",
        "cancelled_at": null,
        "completed_at": 1754659679,
        "expires_at": null,
        "failed_at": null,
        "last_error": null,
        "step_details": {
          "type": "message_creation",
          "message_creation": {
            "message_id": "msg_ThsZroUC9qje77hFJuPTuSR8"
          }
        },
        "usage": {
          "prompt_tokens": 106,
          "completion_tokens": 68,
          "total_tokens": 174,
          "prompt_token_details": {
            "cached_tokens": 0
          }
        }
      }
    ]
  }
}

To Reproduce
Steps to reproduce the behavior:

  1. Create a Foundry agent integrated with the Tavily MCP server:
  2. Ask the agent something like "What is the weather in Seattle today?"
  3. Repeat the above two steps a handful of times to see both problems outlined above.

Expected behavior
I would expect two things:

  1. No assertion errors when the tavily-search tool is invoked.
  2. The tool always being invoked (although I understand there's a level of non-determinism to agents).

Screenshots
N/A

Additional context

  • The agent is using model gpt-4o with a provided temperature of 0.7.
  • The agent's instructions are very basic: You are a helpful assistant. When appropriate, use the available tools to help answer the user's query..

Activity

  1. added
    customer-reportedIssues that are reported by GitHub users external to the Azure organization.
    needs-triageWorkflow: This is a new issue that needs to be triaged to the appropriate team.
    questionThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
    on Aug 8, 2025
  2. jacobreesmontgomery commented on Aug 8, 2025

    @jacobreesmontgomery
    Author

    Also, when the tool is successfully invoked, accomplished after changing the prompt to be more enforcing, I am still seeing a failure result:

      "detail": "An unexpected error occurred: Failed to process query: Agent run failed: server_error - Sorry, something went wrong.",
    

    This is the only context I receive in the logs which isn't particularly insightful. I can remote debug into your SDK, although more insightful logging would be ideal.

  3. added
    Service AttentionWorkflow: This issue is responsible by Azure service team.
    and removed
    needs-triageWorkflow: This is a new issue that needs to be triaged to the appropriate team.
    on Aug 8, 2025
  4. github-actions commented on Aug 8, 2025

    @github-actions
    Contributor
  5. glharper commented on Aug 8, 2025

    @glharper
    Member

    reesmonty (@jacobreesmontgomery) We are aware of multiple issues involving MCP tool usage in Agents and are triaging them now.

    Alex Pryiomka (@apryiomka) FYI

  6. abhilashknair commented on Aug 10, 2025

    @abhilashknair

    I’m facing the same issue. Is there any update or workaround available?

  7. 32 remaining items

  8. jacobreesmontgomery commented on Aug 20, 2025

    @jacobreesmontgomery
    Author

    ith npx: npx @modelcontextprotocol/inspec

    What are the exact steps you follow to get this working? I could not figure it out.

  9. jacobreesmontgomery commented on Aug 20, 2025

    @jacobreesmontgomery
    Author

    @jacobreesmontgomery Does submitting an approval not work, or does disabling approval - setting require_approval to never - not work? Can you share your SDK example?

    Setting require_approval to never does not work, seemingly.

    I shared the example above. Not sure what you mean.

  10. apryiomka commented on Aug 20, 2025

    @apryiomka

    reesmonty (@jacobreesmontgomery) can you please share your Python code snippet that doesn't work?

  11. jacobreesmontgomery commented on Aug 21, 2025

    @jacobreesmontgomery
    Author

    Alex Pryiomka (@apryiomka) , I'd be happy to hop on a call to briefly show you, but I'm not comfortable disclosing that here since this is FedEx-internal code.

  12. glharper commented on Aug 21, 2025

    @glharper
    Member

    @apryiomka , I'd be happy to hop on a call to briefly show you, but I'm not comfortable disclosing that here since this is FedEx-internal code.

    I can take a look with you, reesmonty (@jacobreesmontgomery). My email is <my_gh_username>(at)microsoft(dot)com

  13. ITWApple commented on Aug 25, 2025

    @ITWApple

    I have the same issue. I can see that although listcall works, call_tool fails since it terminates the session before the tool_Call. I ran wireshark to analyze the packets and I see DELETE being called before calling the tool. I have tested the MCP server using FastMCP client and MS Copilot Studio- and in both situations, my MCP server works fine. Azure AI Agent SDK however fails.

    Python:
    Name: azure-ai-agents
    Version: 1.2.0b3

    Below is my code that I am using.

    `import os, time
    #import gradio as gr
    from dotenv import load_dotenv
    import asyncio

    Azure AI Agent SDK

    from azure.ai.projects.aio import AIProjectClient
    from azure.identity.aio import DefaultAzureCredential
    from azure.ai.agents.models import (
    ListSortOrder,
    McpTool,
    RequiredMcpToolCall,
    RunStepActivityDetails,
    SubmitToolApprovalAction,
    ToolApproval,
    )

    Load environment variables

    load_dotenv()

    Azure Agent + OpenAI configuration

    endpoint = os.getenv("AZ_PROJ_ENDPNT") # Azure project endpoint (Agent Service)
    api_key = os.getenv("AZ_OPENAPI") # Your Azure OpenAI / Agent key
    deployment = os.getenv("AZ_MODEL") # Model deployment name
    mcp_server_url = os.getenv("MCP_SERVER_URL")
    mcp_server_label = os.getenv("MCP_SERVER_LABEL")
    agent_id = os.getenv("AZ_AGENT_ID")

    async def main() -> None:

    project_client = AIProjectClient(
        endpoint=endpoint,
        credential=DefaultAzureCredential(),
    )
    
    # Initialize agent MCP tool
    mcp_tool = McpTool(
        server_label=mcp_server_label,
        server_url=mcp_server_url,
        #allowed_tools=[],  # Optional: specify allowed tools
    )
    mcp_tool.set_approval_mode("never")  # Uncomment to disable approval requirement
    async with project_client:
        agents_client = project_client.agents
        agent = await agents_client.get_agent(agent_id=agent_id)
        
        # print(f"Created agent, ID: {agent.id}")
        # print(f"MCP Server: {mcp_tool.server_label} at {mcp_tool.server_url}")
    
        #Create thread for communication
        thread = await agents_client.threads.create()
        print(f"Created thread, ID: {thread.id}")
    
        # Create message to thread
        message = await agents_client.messages.create(
            thread_id=thread.id,
            role="user",
            content="Please list all the devices under company Example",
        )
        print(f"Created message, ID: {message.id}")
    
        #Create and process agent run in thread with MCP tools
        #mcp_tool.update_headers("SuperSecret", "123456")
    
        run = await agents_client.runs.create(thread_id=thread.id, agent_id=agent.id, tool_resources=mcp_tool.resources)
        print(f"Created run, ID: {run.id}")
    
        while run.status in ["queued", "in_progress", "requires_action"]:
            await asyncio.sleep(1)
            run = await agents_client.runs.get(thread_id=thread.id, run_id=run.id)
    
            if run.status == "requires_action" and isinstance(run.required_action, SubmitToolApprovalAction):
                tool_calls = run.required_action.submit_tool_approval.tool_calls
                if not tool_calls:
                    print("No tool calls provided - cancelling run")
                    await agents_client.runs.cancel(thread_id=thread.id, run_id=run.id)
                    break
    
                tool_approvals = []
                for tool_call in tool_calls:
                    if isinstance(tool_call, RequiredMcpToolCall):
                        try:
                            print(f"Approving tool call: {tool_call}")
                            tool_approvals.append(
                                ToolApproval(
                                    tool_call_id=tool_call.id,
                                    approve=True,
                                    headers=mcp_tool.headers,
                                )
                            )
                        except Exception as e:
                            print(f"Error approving tool_call {tool_call.id}: {e}")
    
                print(f"tool_approvals: {tool_approvals}")
                if tool_approvals:
                    await agents_client.runs.submit_tool_outputs(
                        thread_id=thread.id, run_id=run.id, tool_approvals=tool_approvals
                    )
    
            print(f"Current run status: {run.status}")
    
        print(f"Run completed with status: {run.status}")
        if run.status == "failed":
            print(f"Run failed: {run.last_error}")
    
        # Display run steps and tool calls
        run_steps = agents_client.run_steps.list(thread_id=thread.id, run_id=run.id)
    
        # Loop through each step
        async for step in run_steps:
            print(f"Step {step['id']} status: {step['status']}")
    
            # Check if there are tool calls in the step details
            step_details = step.get("step_details", {})
            tool_calls = step_details.get("tool_calls", [])
    
            if tool_calls:
                print("  MCP Tool calls:")
                for call in tool_calls:
                    print(f"    Tool Call ID: {call.get('id')}")
                    print(f"    Type: {call.get('type')}")
    
            if isinstance(step_details, RunStepActivityDetails):
                for activity in step_details.activities:
                    for function_name, function_definition in activity.tools.items():
                        print(
                            f'  The function {function_name} with description "{function_definition.description}" will be called.:'
                        )
                        if len(function_definition.parameters) > 0:
                            print("  Function parameters:")
                            for argument, func_argument in function_definition.parameters.properties.items():
                                print(f"      {argument}")
                                print(f"      Type: {func_argument.type}")
                                print(f"      Description: {func_argument.description}")
                        else:
                            print("This function has no parameters")
    
            print()  # add an extra newline between steps
    
        # Fetch and log all messages
        messages = agents_client.messages.list(thread_id=thread.id, order=ListSortOrder.ASCENDING)
        print("\nConversation:")
        print("-" * 50)
        async for msg in messages:
            if msg.text_messages:
                last_text = msg.text_messages[-1]
                print(f"{msg.role.upper()}: {last_text.text.value}")
                print("-" * 50)
    
        # Example of dynamic tool management
        # print(f"\nDemonstrating dynamic tool management:")
        # print(f"Current allowed tools: {mcp_tool.allowed_tools}")
    
    
        # Clean-up and delete the agent once the run is finished.
        # NOTE: Comment out this line if you plan to reuse the agent later.
        # await agents_client.delete_agent(agent.id)
        # print("Deleted agent")
    

    if name == "main":
    asyncio.run(main())`

    Screenshots:

    1. DELETE:
    Image
    1. Tool Call (after DELETE)
    Image
    1. Failed 404:
    Image

    Notes:
    My MCP server is accessible online but access is restricted only from MS published IP list. Therefore not accessible to general public to test with.
    I have tested the tool calling with RestAPI and its the same result.

  14. apryiomka commented on Aug 25, 2025

    @apryiomka

    @apryiomka , I'd be happy to hop on a call to briefly show you, but I'm not comfortable disclosing that here since this is FedEx-internal code.

    reesmonty (@jacobreesmontgomery) could you please email to oai-assistants@microsoft.com, we will tirage on our end. We can continue the conversation over the email.

  15. apryiomka commented on Aug 25, 2025

    @apryiomka

    reesmonty (@jacobreesmontgomery) please also note that the tool resource / approval has to match on the server_label property.

  16. ITWApple commented on Aug 25, 2025

    @ITWApple

    @apryiomka , I'd be happy to hop on a call to briefly show you, but I'm not comfortable disclosing that here since this is FedEx-internal code.

    @jacobreesmontgomery could you please email to oai-assistants@microsoft.com, we will tirage on our end. We can continue the conversation over the email.

    Alex Pryiomka (@apryiomka) sorry for my case,
    but would this addressed as part of a bug or would you want me to open a new case. I believe its the same issue. I have posted my findings above

  17. removed
    needs-team-attentionWorkflow: This issue needs attention from Azure service team or SDK team
    on Sep 3, 2025
  18. github-actions commented on Sep 3, 2025

    @github-actions
    Contributor

    Hi reesmonty (@jacobreesmontgomery). Thank you for opening this issue and giving us the opportunity to assist. We believe that this has been addressed. If you feel that further discussion is needed, please add a comment with the text "/unresolve" to remove the "issue-addressed" label and continue the conversation.

  19. github-actions commented on Sep 10, 2025

    @github-actions
    Contributor

    Hi reesmonty (@jacobreesmontgomery), since you haven’t asked that we /unresolve the issue, we’ll close this out. If you believe further discussion is needed, please add a comment /unresolve to reopen the issue.

  20. locked and limited conversation to collaborators on Dec 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

AIAI AgentsService AttentionWorkflow: This issue is responsible by Azure service team.customer-reportedIssues that are reported by GitHub users external to the Azure organization.issue-addressedWorkflow: The Azure SDK team believes it to be addressed and ready to close.questionThe issue doesn't require a change to the product in order to be resolved. Most issues start as that

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions