Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
By default, the Agent 365 CLI targets the Microsoft commercial cloud. It authenticates by using https://login.microsoftonline.com, calls Microsoft Graph at https://graph.microsoft.com, and calls Agent 365 services at https://agent365.svc.cloud.microsoft. The Microsoft 365 US Government clouds are Government Community Cloud (GCC), GCC High, and Department of Defense (DoD). To use the CLI in one of these clouds, select the cloud environment and configure the endpoints for that cloud.
This article explains how the CLI resolves cloud settings and how to configure them in your a365.config.json file or with environment variables.
Note
Cloud-aware endpoint resolution is available in recent versions of the Agent 365 CLI. Update to the latest version before you configure a US Government cloud. For update instructions, see Update the Agent 365 CLI.
Important
Configurable endpoints don't guarantee that every Agent 365 service or feature is available in every cloud. Some services and features that are available in the commercial cloud might not yet be available in GCC, GCC High, or DoD. Confirm service availability for your cloud before you run setup. For Agent 365 feature availability in GCC, see the Microsoft Agent 365 service description.
Supported cloud environments
The environment name tells the CLI which cloud you target. Set it explicitly for every US Government cloud.
| Cloud | environment value |
Environment variable suffix (<ENV>) |
|---|---|---|
| Commercial (default) | prod |
PROD |
| GCC | gcc |
GCC |
| GCC High | gcc-high |
GCC_HIGH |
| DoD | dod |
DOD |
The environment name controls two behaviors:
- The CLI reads the environment-scoped variables that match the environment name. For example, with
gcc-high, the CLI readsA365_GRAPH_BASE_URL_GCC_HIGH. - Setup grants permissions on the Agent 365 Observability resource for the selected cloud. For more information, see Observability permissions.
The environment name doesn't change the authority host, Microsoft Graph base URL, or Agent 365 service endpoints on its own. Configure those endpoints for your cloud as described in Configure GCC and Configure GCC High or DoD.
Important
Don't use the Azure CLI cloud name AzureUSGovernment as the environment. That name doesn't distinguish between GCC, GCC High, and DoD, so the CLI reports a configuration error when it needs cloud-specific settings. Use gcc, gcc-high, or dod instead.
How the CLI resolves cloud settings
The CLI resolves the environment name first, and then uses it to resolve each endpoint.
Environment name
The CLI uses the first value it finds:
- The
environmentfield ina365.config.json. - The
A365_ENVIRONMENTenvironment variable. - For setup commands that run without an
a365.config.jsonfile, the name of the active Azure CLI cloud (az cloud show). If the Azure CLI cloud isAzureUSGovernment, setup stops and asks you to setA365_ENVIRONMENTtogcc,gcc-high, ordod. - The default,
prod.
When setup generates an a365.config.json file, it records the resolved environment, authorityHost, and graphBaseUrl values so later commands target the same cloud.
The develop list-available command doesn't read a365.config.json. It always reads the environment from A365_ENVIRONMENT, so set that variable when you use the command in a US Government cloud.
Authority host and Microsoft Graph base URL
For each endpoint, the CLI uses the first value it finds:
- The environment-scoped environment variable (
A365_AUTHORITY_HOST_<ENV>orA365_GRAPH_BASE_URL_<ENV>). - The matching field in
a365.config.json(authorityHostorgraphBaseUrl). - The commercial-cloud default (
https://login.microsoftonline.comorhttps://graph.microsoft.com).
The CLI doesn't read these settings from unsuffixed variables such as A365_GRAPH_BASE_URL.
Each resolved value must be an HTTPS origin: a scheme, host, and optional port only. Don't include a path, query string, fragment, or user information. For example, the CLI accepts https://login.microsoftonline.us but rejects https://login.microsoftonline.us/common. If a value fails validation, the CLI stops with an error.
The CLI applies the resolved authority host and Graph base URL consistently across setup, consent, authentication, Microsoft Entra ID query, cleanup, and create-instance flows. It caches tokens separately for each authority host, so switching clouds doesn't reuse tokens from another cloud.
Important
Pair the authority host and the Graph base URL for the same cloud. If you override one, override the other so authentication and Graph data-plane calls target the same environment.
Agent 365 service endpoints
The CLI calls Agent 365 services to discover Model Context Protocol (MCP) servers, manage MCP servers, and register the agent's messaging endpoint. Configure these service endpoints with environment variables only. These endpoints don't have a365.config.json fields.
| Variable | Description |
|---|---|
A365_DISCOVER_ENDPOINT_<ENV> |
The full URL of the Agent 365 Tools discovery endpoint. The CLI calls this URL to discover MCP servers. It also uses the URL's origin for related Agent 365 service calls, including MCP server management and messaging endpoint registration. The default value is https://agent365.svc.cloud.microsoft/agents/v2/discoverMCPServers. |
A365_CREATE_ENDPOINT_<ENV> |
The full URL that the CLI calls to register the agent's messaging endpoint. This value takes precedence over the origin of A365_DISCOVER_ENDPOINT_<ENV>. |
A365_DELETE_ENDPOINT_<ENV> |
The full URL that the CLI calls to remove the agent's messaging endpoint registration. This value takes precedence over the origin of A365_DISCOVER_ENDPOINT_<ENV>. |
Each value must be an absolute HTTPS URL. Include a path if the endpoint needs one, but don't include a query string, fragment, or user information.
Important
Setting the environment name alone doesn't switch Agent 365 service calls away from the commercial service. If you don't set A365_DISCOVER_ENDPOINT_<ENV>, the CLI calls the commercial Agent 365 service, even in a US Government cloud.
Configure GCC
GCC uses the commercial authority host and Microsoft Graph base URL, so you don't need to override them. For more information, see Microsoft Graph national cloud deployments. Set the environment to gcc and point Agent 365 service calls at the GCC service.
In a365.config.json, set the environment field:
{
"tenantId": "YOUR_TENANT_ID",
"environment": "gcc",
"messagingEndpoint": "https://your-app.azurewebsites.net/api/messages",
"deploymentProjectPath": "."
}
Then set the environment variables. Setting A365_ENVIRONMENT also covers commands that don't read a365.config.json, such as develop list-available. In Bash, run the following commands:
export A365_ENVIRONMENT="gcc"
export A365_DISCOVER_ENDPOINT_GCC="https://gcc.agent365.svc.cloud.microsoft/agents/v2/discoverMCPServers"
In Windows PowerShell, run the following commands:
$env:A365_ENVIRONMENT = "gcc"
$env:A365_DISCOVER_ENDPOINT_GCC = "https://gcc.agent365.svc.cloud.microsoft/agents/v2/discoverMCPServers"
Configure GCC High or DoD
GCC High and DoD use their own authority host and Microsoft Graph base URL:
| Cloud | environment value |
Authority host (authorityHost) |
Microsoft Graph base URL (graphBaseUrl) |
|---|---|---|---|
| GCC High | gcc-high |
https://login.microsoftonline.us |
https://graph.microsoft.us |
| DoD | dod |
https://login.microsoftonline.us |
https://dod-graph.microsoft.us |
These values come from the following articles. Check them for the current endpoints:
- Microsoft Entra authentication endpoints for national clouds
- Microsoft Graph national cloud deployments
GCC High and DoD tenants use Azure Government. The Agent 365 CLI uses the Azure CLI for some operations, such as detecting your tenant, so sign in to the Azure CLI in Azure Government. For instructions, see Connect to Azure Government with Azure CLI. Azure services in Azure Government also use different domain names than global Azure. For example, if you host your agent in Azure App Service, your messaging endpoint uses an Azure Government domain. For the endpoint mapping, see Compare Azure Government and global Azure.
Set these values in a365.config.json or with environment variables. Environment-scoped variables take precedence over the matching a365.config.json fields, so use them to override a checked-in configuration per machine or per pipeline.
Configure in a365.config.json
The following example targets GCC High:
{
"tenantId": "YOUR_TENANT_ID",
"environment": "gcc-high",
"authorityHost": "https://login.microsoftonline.us",
"graphBaseUrl": "https://graph.microsoft.us",
"messagingEndpoint": "https://your-app.azurewebsites.us/api/messages",
"deploymentProjectPath": "."
}
Configure with environment variables
The following Bash example targets GCC High:
export A365_ENVIRONMENT="gcc-high"
export A365_AUTHORITY_HOST_GCC_HIGH="https://login.microsoftonline.us"
export A365_GRAPH_BASE_URL_GCC_HIGH="https://graph.microsoft.us"
The following Windows PowerShell example targets GCC High:
$env:A365_ENVIRONMENT = "gcc-high"
$env:A365_AUTHORITY_HOST_GCC_HIGH = "https://login.microsoftonline.us"
$env:A365_GRAPH_BASE_URL_GCC_HIGH = "https://graph.microsoft.us"
For DoD, set the environment to dod, use the DOD suffix, and use the DoD Microsoft Graph base URL.
If Agent 365 services are available in your cloud, also set A365_DISCOVER_ENDPOINT_<ENV> to the discovery endpoint for that cloud. Otherwise, the CLI calls the commercial Agent 365 service. For more information, see Agent 365 service endpoints.
Configuration reference
This section lists the a365.config.json properties and environment variables that control cloud settings.
a365.config.json properties
| Property | Description | Required | Default |
|---|---|---|---|
environment |
The cloud environment name. Use prod, gcc, gcc-high, or dod. This value determines which environment-scoped variables the CLI reads and which Observability resource setup uses. |
No | prod |
authorityHost |
The OAuth authority host for the selected cloud. The value must be an HTTPS origin. | No | https://login.microsoftonline.com |
graphBaseUrl |
The Microsoft Graph base URL for the selected cloud. The value must be an HTTPS origin. | No | https://graph.microsoft.com |
Environment variables
| Variable | Description |
|---|---|
A365_ENVIRONMENT |
The cloud environment name. The CLI uses this value when a365.config.json doesn't set environment, and for commands that don't read a365.config.json. The default value is prod. |
A365_AUTHORITY_HOST_<ENV> |
The OAuth authority host. This value takes precedence over authorityHost in a365.config.json. |
A365_GRAPH_BASE_URL_<ENV> |
The Microsoft Graph base URL. This value takes precedence over graphBaseUrl in a365.config.json. |
A365_DISCOVER_ENDPOINT_<ENV> |
The Agent 365 Tools discovery endpoint. The CLI also uses its origin for related Agent 365 service calls. |
A365_CREATE_ENDPOINT_<ENV> |
The messaging endpoint registration URL. |
A365_DELETE_ENDPOINT_<ENV> |
The messaging endpoint removal URL. |
A365_MCP_APP_ID_<ENV> |
The Agent 365 Tools resource application ID that the CLI uses to acquire tokens for tool servers. Most developers don't need to set this variable. |
How the environment suffix is derived
The CLI derives the <ENV> suffix on each environment-scoped variable from your environment name. The CLI trims the name, replaces every character that isn't a letter or digit with an underscore (_), and converts it to uppercase. An empty name becomes PROD.
| Environment name | Normalized suffix | Example variable |
|---|---|---|
gcc |
GCC |
A365_DISCOVER_ENDPOINT_GCC |
gcc-high |
GCC_HIGH |
A365_GRAPH_BASE_URL_GCC_HIGH |
dod |
DOD |
A365_AUTHORITY_HOST_DOD |
The environment name and the suffix on the variable must resolve to the same normalized value. For example, A365_ENVIRONMENT=gcc-high pairs with A365_AUTHORITY_HOST_GCC_HIGH.
Observability permissions
During setup, the CLI grants the agent blueprint the Agent365.Observability.OtelWrite permission on the Agent 365 Observability resource for the selected cloud:
| Cloud | Observability resource application ID |
|---|---|
| Commercial | 9b975845-388f-4429-889e-eab1ef63949c |
| GCC | 2c672ad5-b104-44ed-8069-bb68dd138546 |
| GCC High | 009c6bd0-82e4-4466-95b3-4c996521f3d7 |
| DoD | a9e04047-c6a7-430b-a7ae-faf8f8eed1b7 |
Earlier versions of the CLI always granted the permission on the commercial Observability resource. If you set up an agent in a US Government cloud with an earlier version, set the environment for your cloud and rerun a365 setup all so the CLI grants the permission on your cloud's Observability resource.
Verify your configuration
After you configure a cloud, run a read-only command and confirm the CLI uses the expected endpoints. For example:
- Run the
develop list-availablecommand. The output shows the environment and the discovery endpoint URL that the CLI calls. - Acquire a token by using the
develop get-tokencommand.
Troubleshoot cloud configuration
The following table lists common cloud configuration errors and how to resolve them.
| Symptom | Cause | Resolution |
|---|---|---|
Authority host must be an HTTPS origin without a path, query, fragment, or user info. (or the same error for the Graph base URL) |
The authority host or Graph base URL includes a path, query string, or fragment. | Use a bare HTTPS origin. For example, use https://login.microsoftonline.us rather than https://login.microsoftonline.us/common/oauth2/v2.0/authorize. |
An error says that AzureUSGovernment or the Azure CLI cloud doesn't distinguish GCC Moderate (GCC), GCC High, and DoD. |
The environment is AzureUSGovernment, or setup detected that cloud from the Azure CLI. |
Set the environment to gcc, gcc-high, or dod. |
| The CLI calls the commercial Agent 365 service in a US Government cloud. | A365_DISCOVER_ENDPOINT_<ENV> isn't set, or its suffix doesn't match the environment name. |
Set A365_DISCOVER_ENDPOINT_<ENV> with the suffix for your environment. |
| Setup grants permissions on the commercial Observability resource. | The environment isn't set, so the CLI uses prod. |
Set the environment for your cloud and rerun setup. |
PowerShell fallback is available only for commercial Graph and authority endpoints. |
Microsoft Graph sign-in failed, and the CLI can't fall back to PowerShell Connect-MgGraph when you use custom endpoints. |
Resolve the sign-in failure. For example, confirm that you registered your client app in your cloud and that you sign in with an account in your cloud's tenant. |
Related content
- Agent 365 CLI
- Agent 365 CLI reference
- Microsoft Entra authentication and national clouds
- Microsoft Graph national cloud deployments
- Compare Azure Government and global Azure
- Connect to Azure Government with Azure CLI
- Microsoft 365 U.S. Government GCC High endpoints
- Microsoft 365 U.S. Government DoD endpoints
- Microsoft Agent 365 service description