Share via

What is the access right required to configure a tool on Microsoft Foundry?

Kenny Wong (HK) 140 Reputation points
2026-02-10T02:19:21.3033333+00:00

When I try to configure a tool on Microsoft Foundry, some fields got blank out and I am unable to fill in anything (for example, the Remote MCP Server endpoint).

May I know what access right is required to configure the tool? I have already got the Azure AI User right

Azure AI services
Azure AI services

A group of Azure services, SDKs, and APIs designed to make apps more intelligent, engaging, and discoverable.

{count} votes

1 answer

Sort by: Most helpful
  1. SRILAKSHMI C 14,815 Reputation points Microsoft External Staff Moderator
    2026-02-10T05:55:40.3+00:00

    Hello Kenny Wong (HK),

    Welcome to Microsoft Q&A and Thank you for reaching out.

    I understand that you’re encountering this issue because your current permissions don’t allow tool configuration in Microsoft Foundry. When a user lacks the required access rights, the Foundry UI intentionally greys out or leaves blank certain configuration fields (such as the Remote MCP Server endpoint) to prevent edits. The Azure AI User role you currently have only allows you to run and use existing tools and agents, but it does not permit configuring or modifying them.

    To configure or edit tools in Microsoft Foundry, you must be assigned a higher-privilege role at the AI Project scope (or higher, such as Resource Group or Subscription). Roles such as Azure AI Project Contributor, Azure AI Project Manager, Azure AI Developer, or Owner allow both tool usage and configuration. In addition, if the tool interacts with Azure OpenAI or reasoning models, you must also have the Cognitive Services OpenAI Contributor role assigned. This role is required even if you already hold elevated Azure permissions, such as Service Administrator.

    In terms of role capabilities, the Azure AI User role allows you to use tools but not configure them, whereas Azure AI Developer, Azure AI Project Contributor, Azure AI Project Manager, and Owner roles all allow both using and configuring tools, including editing endpoints, authentication settings, and Remote MCP server details.

    To resolve the issue, go to the Azure Portal, navigate to your Azure AI Foundry / AI Project, and open Access control (IAM). Use Check access to verify your current role assignments. If the required roles are missing, request assignment of Azure AI Project Contributor (recommended minimum) and, if applicable, Cognitive Services OpenAI Contributor from your subscription administrator. After any role changes, allow 5–10 minutes for permissions to propagate, then refresh the Foundry UI and try again.

    Finally, if the tool depends on other Azure resources—such as Fabric, Storage, Key Vault, or external APIs make sure you also have the necessary permissions on those resources. Missing access to a dependent resource can also cause configuration fields to remain disabled.

    The behaviour you’re seeing is expected when only the Azure AI User role is assigned. Tool configuration in Microsoft Foundry requires Contributor-, Developer-, or Manager-level access, and in some scenarios, the Cognitive Services OpenAI Contributor role as well. Once the correct permissions are in place and fully propagated, the configuration fields will become editable.

    Please refer this

    I Hope this helps. Do let me know if you have any further queries.

    Thank you!

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.