Foundry agent: OBO auth error with API key persists after re-attaching knowledge base with Custom Keys connection

Krzysztof Zając 0 Reputation points
2026-10-01T13:52:17.78+00:00

Hi,

We have a prompt agent in Microsoft Foundry (new portal) that uses a Foundry IQ knowledge base (Azure AI Search). We call the agent from .NET and PowerShell via the Responses API, authenticating with the Foundry project API key. This setup worked without any changes from July until the morning of October 1, 2026. Since then, every API call fails with: 400 Bad Request: Tools configured with OBO auth are not supported with API key authentication. Please use a different authentication method. Testing in the portal playground (signed in with Entra ID) still works. Removing the knowledge base from the agent makes API key calls succeed again.

What we've checked:

  • The knowledge base has a single knowledge source over an Azure AI Search index. No remote SharePoint, Work IQ or other federated sources, no permission trimming.
  • We created a new project connection to the knowledge base MCP endpoint (https://<search>.search.windows.net/knowledgebases/<kb>/mcp?api-version=2026-08-01-preview): category RemoteTool, authentication Custom Keys, header api-key with the search admin key.
  • The agent definition references this connection (project_connection_id). The tool entry contains only type, server_label, server_url, require_approval and project_connection_id. No headers, no structured inputs.
  • The error is identical. After adding it as a custom MCP tool, the portal shows it under Knowledge rather than Tools.
  • We can't use project managed identity at the moment (no permission to assign roles on the search service).
  • As a temporary workaround we attached the same index via the classic Azure AI Search tool; API key calls no longer fail.

This looks like the same issue as https://learn.microsoft.com/en-us/answers/questions/5856997/how-to-chat-using-the-api-key-with-azure-foundry-p
The suggested fix there (detach the tool and re-attach it with API key authentication) does not resolve it in our case: we re-attached the knowledge base through a project connection with Custom Keys authentication (api-key header), and the error is unchanged.

Questions:

  1. Was there a recent service-side change that enforces OBO for knowledge base tools, regardless of the connection's authentication type?
  2. What is the supported way to use a Foundry IQ knowledge base tool when calling the agent with an API key? Is a key-based (Custom Keys) connection supposed to work, or is project managed identity the only option?

Thanks!

Foundry Tools
Foundry Tools

Formerly known as Azure AI Services or Azure Cognitive Services is a unified collection of prebuilt AI capabilities within the Microsoft Foundry platform

0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.