Add cloud-aware endpoints and harden GCC blueprint setup - #478
Merged
Rick Brighenti (rbrighenti) merged 14 commits intoSep 28, 2026
Merged
Conversation
Normalize cloud keys for environment overrides and route consent/token/Graph URL generation through cloud-aware helpers so arbitrary cloud names can be configured without code changes Make client-credential token authority cloud-aware
Rick Brighenti (rbrighenti)
force-pushed
the
feature/cloud-agnostic-endpoints
branch
from
July 24, 2026 16:09
84723d1 to
c0d736c
Compare
This comment has been minimized.
This comment has been minimized.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- InteractiveGraphAuthService: append /v1.0 to the cloud-specific Graph BaseUrl so overriding RequestAdapter.BaseUrl doesn't drop the API version segment and 404 every request; add regression test. - BootstrapConfigResolver: pass the caller's CancellationToken into the 'az cloud show' invocation so bootstrap can be cancelled. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Rick Brighenti (rbrighenti)
September 9, 2026 13:30
View session
Preserve cloud-aware routing alongside the BYO MCP device-code flow. Partition Graph token caches by authority and validate blueprint lookup rows without losing the stored blueprint. Add regression coverage and clarify explicit GCC endpoint configuration. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Rick Brighenti (rbrighenti)
September 25, 2026 14:46
View session
Apply the discovery HTTPS URL contract to explicit create/delete overrides before token acquisition, preserving valid custom paths and independent override precedence. Add regression tests for unsafe URL components and normalization. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Rick Brighenti (rbrighenti)
requested review from
Copilot and
jaganp (jaganp-microsoft)
September 25, 2026 15:02
Copilot started reviewing on behalf of
Rick Brighenti (rbrighenti)
September 25, 2026 15:02
View session
Preserve the requested display-name-first single-result recovery behavior. Warn with stored and selected object IDs before setup persists the replacement; keep ambiguous and malformed lookups fail-closed. Document the requirement and cover mismatch, matching/no stored ID, and ambiguous results. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Rick Brighenti (rbrighenti)
September 25, 2026 15:18
View session
Resolve the Observability resource inside existing cloud validation so AzureUSGovernment returns false with actionable guidance before Graph configuration or state writes. Cover all, identity and licenses runner modes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Rick Brighenti (rbrighenti)
September 25, 2026 15:51
View session
Krishnadheeraj (DheerajPannala)
approved these changes
Sep 28, 2026
dbezic (dbezic)
approved these changes
Sep 28, 2026
Rick Brighenti (rbrighenti)
deleted the
feature/cloud-agnostic-endpoints
branch
September 28, 2026 15:50
Krishnadheeraj (DheerajPannala)
added a commit
that referenced
this pull request
Sep 28, 2026
…y-permissions Conflict resolutions: - GetFixedApiPermissionSpecs / admin-consent URL builders take both the cloud environment (#478) and includeObservability (#501); the skipped Observability spec, URL, and combined-URL scope stay omitted in every cloud. - Portal walkthrough filter and ClearSkippedObservabilityConsentUrl match any cloud's Observability app ID (ConfigConstants.IsObservabilityApiAppId). - S2S PowerShell keeps the spec-driven per-target block (resource IDs come from the cloud-aware specs); delegated Observability block keeps the skip gate and uses #478's cloud resource ID and Graph base URL. - Registration failure keeps RecordRegistrationFailure (a superset of #478's --agent-registration-only error); #478's registration-only test now accepts the longer message, and #501's duplicate registration-only test is removed. - CHANGELOG: kept all #478 entries, dropped the "full setup continues to treat registration as best-effort" clause that #501 changes for blueprint agents, and pointed Option B at the Observability app ID for the user's cloud. - Tests: GCC cases pin the cross-cloud skip filter and consent-URL clear. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12
Krishnadheeraj (DheerajPannala)
added a commit
that referenced
this pull request
Sep 28, 2026
After merging #478, sovereign clouds use their own Observability app IDs, so the README's opt-back-in command no longer hard-codes the commercial ID. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12
This was referenced Sep 28, 2026
Krishnadheeraj (DheerajPannala)
added a commit
that referenced
this pull request
Oct 1, 2026
… default (#501) * Add --skip-observability-permissions to setup all Blueprint agents that export telemetry through the app-only S2S endpoint (microsoft/Agent365-nodejs#290, microsoft/Agent365-Samples#339) are authorized by their agent registration, so the Observability API OtelWrite permission, and the admin consent it needs, is unnecessary for them. - New opt-in `setup all --skip-observability-permissions` omits Observability API from the permission specs (inheritable permissions, app role grants, batch consent) and from the per-resource and combined admin consent URLs. Defaults are unchanged: the published SDKs still export to the non-S2S endpoint by default. - The flag fails fast for AI Teammate agents and with authMode s2s/both, since OtelWrite is the only app role those modes grant. A contradicting --authmode flag is rejected before bootstrap signs in. - With the flag, a failed agent registration is an error (exit 1), because registration is then the agent's only Observability authorization. - Fix: `setup all --agent-registration-only` exited 0 when registration failed. - Dry run plan, setup summary, CHANGELOG, and docs updated. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Make skipping Observability permissions the default for blueprint agents Per 3P Dev Scale scrum feedback, the no-consent flow becomes the main path instead of an opt-in flag. - Remove --skip-observability-permissions. Blueprint agents in the default (obo) auth mode no longer request Observability API permissions; registered agents export telemetry with an app-only token over the S2S endpoint. - authMode s2s/both keep requesting OtelWrite, the only app role those modes grant; `both` also covers agents whose SDK still exports through the delegated (OBO) route. - AI Teammate setup is unchanged until instance creation can be validated end to end. - Registration failure stays an error on the default path. - Tests: the default plan omits Observability; s2s/both (flag or config) keep it; AI Teammate keeps it. Mutation-checked. Validated live: a roleless app-only token for a registered agent identity exports 200 on S2S; an unregistered identity gets 403 insufficient_scope. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Stop requesting Observability permissions in every blueprint auth mode The S2S endpoint authorizes registered agents without OtelWrite whatever the auth mode, so s2s/both no longer request it either. They still grant any other app-role specs (e.g. Defender once #485 lands). Agents whose SDK still exports through the delegated route grant OtelWrite manually, as the CHANGELOG upgrade note describes. AI Teammate setup is unchanged. Tests encode the changed requirement for s2s/both (flag or config) and are mutation-checked. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Address #501 review: registration and consent edge cases - When registration is required (--agent-registration-only, or Observability permissions not requested), an inconclusive registration check now fails setup instead of passing. The stored ID is kept and no duplicate registration is created. The optional path still retains the stored ID. - When Observability is not included, drop an Observability consent entry saved by an earlier run so the admin is not asked for it. - Keep Observability for an AI Teammate config retained for a dry run (skip only for an effective blueprint selection). - Scope the guided-setup OtelWrite grant steps to AI Teammates and SDKs that still export through the delegated route; fix two stale doc comments. Regression tests cover each case and are mutation-checked. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Condense #501 changelog entries and refresh stale test wording Make the upgrade note one consumer-facing sentence, and update the Fixed entry: setup exits 1 when registration fails or cannot be verified for blueprint agents as well as with --agent-registration-only. Replace "without the flag" in a registration test, since the flag was removed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Scope the Observability upgrade note to delegated-route agents The upgrade note opened by saying every existing agent needs the Observability permissions, which contradicted the S2S exception. Scope the heading and requirement to agents that export through the delegated (OBO) route. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Address #501 review: s2s/both summary and failed app-role hand-off - Setup summary: blueprint agents no longer request any app role (OtelWrite was the only one), so an s2s or both run has no S2S grant. The Blueprint Permission Grants row now says so instead of reporting a delegated grant, or a PENDING with no action item for non-admin s2s runs: "not required (no S2S app roles to grant)" for s2s, and the delegated status plus "no S2S app roles to grant" for both. - The S2S PowerShell hand-off lists the app roles that were actually not assigned, recorded per blueprint and agent identity, instead of hardcoding Observability OtelWrite. AI Teammates still get the OtelWrite step because they still request it. - A stale Observability consent URL is also cleared on admin runs, and only the URL is cleared: ConsentGranted and the inheritable-permission state are kept, since re-running setup does not revoke. - Document why registration is always required in real runs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Align #501 docs with the s2s/both summary - CHANGELOG upgrade note: the setup summary prints the OtelWrite PowerShell steps only for AI Teammates now, so point blueprint agents on the delegated route to Option A. - Setup README: s2s and both have no app role to assign for blueprint agents, and the summary reports the S2S grant as not required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * List a hand-off per failed S2S target in the setup summary When the blueprint and agent-identity app-role grants both fail in one run, the summary printed only the agent identity's roles and dropped the blueprint's. It now prints one hand-off per failed target, each listing that target's pending roles and principal. A single failed target prints as before. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Qualify the s2s/both README note and de-duplicate pending roles - README: s2s and both have nothing to assign for blueprint agents only when no other permission adds an app role. - Setup summary: a role recorded twice for the same target is listed once. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Address observability S2S review feedback Align guided setup docs with the app-only S2S telemetry model, fail setup when a missing blueprint secret blocks required registration, and update dry-run/help/summary remediation for skipped OtelWrite. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Clarify delegated-route upgrade note Point new blueprint agents that still use the delegated Observability route to the custom permissions command that stamps inheritable permissions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Keep the setup admin removal note and fix the missing-secret retry advice - CHANGELOG upgrade note: keep stating that `a365 setup admin` was removed in this release, next to the new `setup permissions custom` route. - Missing blueprint secret: the error now says to re-run `a365 setup blueprint` and then `a365 setup all`. `--agent-registration-only` skips identity creation, so it can't recover a run that never created the agent identity. The test pins this. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Point the Observability opt-back-in command at the cloud's app ID After merging #478, sovereign clouds use their own Observability app IDs, so the README's opt-back-in command no longer hard-codes the commercial ID. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Address observability opt-back-in review Separate default Observability omission from effective requested permissions when custom Observability permissions are configured, and update dry-run/help/docs for cloud-aware S2S guidance. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Tighten observability opt-back-in handling Require custom Observability opt-back-in to target the configured cloud and OtelWrite, track identity and registration failure severity explicitly, and clarify delegated-route documentation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Record the auth mode before the agent identity step EffectiveAuthMode and NoS2SAppRolesToGrant were set only after an agent identity existed, so when identity creation failed an s2s/both run with no app roles to grant could be summarized as a pending or delegated grant instead of "no S2S app roles to grant". Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 --------- Co-authored-by: Krishnadheeraj <12496535+DheerajPannala@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds cloud-aware Microsoft Graph, OAuth authority, and Agent 365 Tools routing, with GCC Moderate validation for ordinary blueprint agents. Commercial endpoints remain the defaults; configurable endpoints and resource mappings do not imply certification of every government cloud.
main, including the BYO MCP device-code improvements, without rewriting branch history.Configuration
For the GCC Moderate scenario exercised here:
GCC Moderate uses the default Graph and authority hosts. The environment name alone does not switch Agent 365 discovery away from the commercial service. Other environments can supply
graphBaseUrl/authorityHostin config or higher-precedenceA365_GRAPH_BASE_URL_{ENV}/A365_AUTHORITY_HOST_{ENV}variables. Graph/authority overrides must be HTTPS origins; environment suffixes are normalized, e.g.gcc-highbecomesGCC_HIGH.The CLI architecture documentation and Unreleased notes describe the behavior.
Validation evidence
Live results below were obtained on
a18beb7de6before this PR refresh. They are not a claim that the newly merged revision has already completed its live retest.ListSampleProducts, returningPhone, Tablet, LaptopwithisError:false.main; assertions were not weakened. Local execution uses .NET 10 roll-forward for net8 targets, not native .NET 8 coverage.