Share via

Unable to create agents in Azure AI Foundry portal - 403 Forbidden on Microsoft.MachineLearningServices/workspaces/agents/actionSubject: Unable to create agents in Azure AI Foundry portal - 403 Forbidden on Microsoft.MachineLearningServices/workspaces/age

Max den Hoed 0 Reputation points
2026-03-25T13:21:42.06+00:00

Hi

I am unable to create agents via the Azure AI Foundry portal (ai.azure.com)

or via the Foundry Agents API. I receive a 403 Forbidden error.

ERROR MESSAGE:

"Identity(object id: : [OBJECT ID REMOVED]) does not have

permissions for Microsoft.MachineLearningServices/workspaces/agents/action

actions."

ENVIRONMENT:

  • Foundry Resource: entra-foundry-eur (Microsoft.CognitiveServices/accounts)
  • Foundry Project: entra-foundry-eur-project
  • Resource Group: entra-llm-resource
  • Location: germanywestcentral
  • User: [EMAIL REMOVED]
  • Object ID: : [OBJECT ID REMOVED]

INVESTIGATION FINDINGS:

  1. There is NO Microsoft.MachineLearningServices/workspaces resource in the subscription. The Foundry resource is type Microsoft.CognitiveServices/accounts.
  2. The Agents API internally routes to a virtual ML workspace path: Microsoft.MachineLearningServices/workspaces/entra-foundry-eur@entra-foundry-eur-project@AML This virtual workspace does not exist as a real ARM resource.
  3. Creating assistants via the OpenAI-compatible API (entra-foundry-eur.openai.azure.com/openai/assistants) SUCCEEDS, confirming RBAC on Cognitive Services is correct.
  4. Creating agents via the Foundry API (entra-foundry-eur.services.ai.azure.com/api/projects/.../agents) with api-version=2025-05-15-preview FAILS with 403.

ROLES ASSIGNED TO USER (all confirmed):

  • Owner (subscription level)
  • Contributor (subscription + resource group)
  • Azure AI Developer (hub + project + resource group)
  • Azure AI User (resource group)
  • AzureML Data Scientist (resource group)
  • Cognitive Services OpenAI Contributor (hub + project)
  • Cognitive Services Contributor (hub + project)
  • Cognitive Services OpenAI User (hub + project)
  • Cognitive Services User (hub)
  • Storage Blob Data Contributor (storage account)
  • Search Index Data Contributor (search service)
  • Search Service Contributor (search service)

CORRELATION IDs:

  • Trace ID: [TRACE ID REMOVED]
  • APIM request ID: [REQUEST ID REMOVED]
  • Operation: [OPERATION ID REMOVED]

REQUEST:

Please advise which specific role or configuration is needed to grant

Microsoft.MachineLearningServices/workspaces/agents/action permission

on a CognitiveServices-based Foundry resource with no ML workspace.

Microsoft.MachineLearningServices provider is registered.

Foundry Tools
Foundry Tools

Formerly known as Azure AI Services or Azure Cognitive Services is a unified collection of prebuilt AI capabilities within the Microsoft Foundry platform


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.