Build Identity-Aware Agents With Azure AI Foundry and Descope

Build Identity-Aware Agents With Azure AI Foundry and Descope

Introduction

Azure AI Foundry is Microsoft's managed platform for building and operating agents, with a session-isolated runtime and publishing to Teams and Microsoft 365 Copilot. Microsoft Entra Agent ID gives every Foundry agent a first-class identity in your directory, automatically registered, governed by Conditional Access, and extendable to third-party agents through federation. It's the strongest native agent identity story of any cloud.

What Descope adds to Azure AI Foundry

The Descope Agentic Identity Hub provides several capabilities (Policies, Connections, cloud-neutral agent directory) that address specific gaps in AI Foundry’s native identity capabilities.

Cloud-neutral agent directory

Entra Agent ID has a powerful directory: every Foundry and Copilot Studio agent registers automatically, Conditional Access applies to agents like people, and third-party agents can federate in. What the directory entry carries is the question. An Entra entry governs directory standing and granted access: whether the agent may sign in, what it's been consented or assigned.

The Descope Agentic Identity Hub is a single directory for every agent in your fleet: the Foundry agent, the Bedrock AgentCore agent, the Vertex AI agent, the LangGraph prototype. Each entry carries issuance-time policy and a credential vault, and the integration point with any runtime is standard OAuth.

One credential manager

Descope Connections vaults OAuth tokens for third-party services and static API keys for internal systems. The Entra Agent ID integration gets your agent Entra tokens for Microsoft Graph and Entra-registered APIs. Connections does this, for any agent in the fleet, through the same token exchange and governed by the same policy. The agent retrieves a scoped credential at call time.

Resource authorization beyond Entra External ID

Your MCP servers and backend APIs need an authorization server. Descope MCP Auth implements the MCP authorization spec with OAuth 2.1, including DCR and Client ID Metadata Documents (CIMD), which allows off-the-shelf clients like Claude Desktop to register themselves.

Why use both Entra Agent ID and Descope

Descope augments the Microsoft stack by adding per-request authorization, fleet-wide credential management, and resource auth that External ID doesn't cover. In a model using both Descope and Entra, Entra Agent ID is the directory of what your agents are and what they've been granted in the Microsoft world. Descope is the directory of what your agents may do per request, decided at issuance.

Integrating Descope and Azure AI Foundry

The full flow has three phases: the user authenticates and consents in the browser, the app invokes the agent and forwards the resulting token to the agent's tools, and the tools fetch scoped credentials as they work.

Getting started

  1. Create a Descope project. Sign up and copy your Project ID from Settings > Project.
  2. Connect Microsoft Entra as your IdP. In the console, select your tenant under Tenants, then navigate to the SSO Setup Suite Configurations and generate a link for the SSO Setup Suite.
  3. Create an Agentic Client. Go to Clients, click + Add Client, and name it.
  4. Define your Resources. Go to Resources, click + Resource, and choose API or MCP Server.
  5. Configure Connections for third-party and internal services. Go to Connections, click + Connections, and pick from the library.
  6. Front your MCP servers with Descope MCP Auth and connect them to your Foundry agent as MCP tools.
  7. Forward the user's Descope access token on each agent run as the MCP tool's Authorization header.

User authentication and agent invocation

Your app runs a standard OIDC authorization code flow with Descope as the provider. The user authenticates and consents in the browser before invocation. The Foundry-specific part is what you do with the resulting access token.

Fetching credentials inside tools

Inside agent tools, credential retrieval depends on the target. For Descope-protected resources, the agent performs OAuth Token Exchange. Policies checks the user, agent, and requested scope; a refused scope never becomes a token.

DESCOPE_TOKEN_URL = "https://api.descope.com/oauth2/v1/apps/token"

def exchange_for_resource_token(user_access_token: str, resource: str, scopes: list[str]) -> str:
    # Implementation

Gating sensitive actions with CIBA

For sensitive actions, CIBA provides out-of-band human approval. This runs inside the tool: when the agent decides an elevated operation is needed, the tool blocks until a human approves.

def request_step_up(login_hint: str, binding_message: str) -> dict:
    # Implementation

Start building with Descope and Azure AI Foundry

Foundry gives your agents a production runtime and a home in Teams. Entra Agent ID gives them a directory identity and a path to Microsoft resources. Descope gives them one identity layer across every cloud they touch, with policy evaluated at token issuance.

FAQs about Azure AI Foundry and Descope