Skip to content
5 changes: 4 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,9 @@ Blueprint agents that export telemetry through the app-only S2S endpoint don't n
- `--secret-lifetime-months <N>` option (and matching `secretLifetimeMonths` field in the `--input-file` JSON) on `develop-mcp register-external-mcp-server` — controls the lifetime of the client secrets created on the A365Proxy and RemoteProxy Entra apps. Valid range `1-24`; omit to use the Graph default (~2 years). Calendar-aware (uses `DateTimeOffset.AddMonths`, so Jan 31 + 1 month → Feb 28/29). Added so tenants with an `appManagementPolicies` cap on client-secret lifetime — previously a hard failure inside `CreateEntraAppsAsync` with a generic "Failed to create secret" message — can fit registration inside their tenant's policy. When Graph rejects the requested (or default) lifetime with a tenant-policy error, the CLI now emits an actionable error naming the flag and the attempted value (e.g. `Tenant Entra ID policy rejected the requested 12-month lifetime ... Pass --secret-lifetime-months N with a smaller value (e.g. --secret-lifetime-months 3) that fits inside your tenant's appManagementPolicies cap.`) instead of the previous generic failure.
- `--publisher-name` / `-p` option on `develop-mcp publish` — sets the publisher name written into the published MCP server's package metadata. Required for custom (user-created) MCP servers; ignored for 1p Microsoft-owned servers (e.g. `msdyn_DataverseMCPServer`), which always publish as "Microsoft". Prompted interactively when omitted.
- `--yes` / `-y` option on `develop-mcp publish` — skips the interactive "Proceed with publish? (y/N)" confirmation.
- `a365 develop-mcp publish` now provisions an A365 proxy Entra app for custom (non-Dataverse) MCP servers and forwards its credentials so the Power Platform connector is created at publish time; first-party Dataverse servers skip it (#499).
- `--service-tree-id` option on `a365 develop-mcp publish` — stamps the ServiceTree ID on the Entra apps publish creates, required in Microsoft corporate tenants (#499).
- `--secret-lifetime-months <N>` / `-l` option on `a365 develop-mcp publish` — caps the A365 proxy app's client-secret lifetime (1-24 months) for tenants with an `appManagementPolicies` cap (#499).
- `a365 develop get-token --device-code` — forces device code auth for Microsoft Graph scopes the Windows WAM broker rejects (e.g. Exchange `MailboxSettings.ReadWrite`, `ExchangeMessageTrace.Read.All`).

### Fixed
Expand Down Expand Up @@ -168,7 +171,7 @@ Blueprint agents that export telemetry through the app-only S2S endpoint don't n
- **`a365 config permissions` removed** — replace with `a365 setup permissions custom --resource-app-id <guid> --scopes <scopes>`.
- **`--config`/`-c` option removed from all commands** — config file is now always resolved from the current directory (`a365.config.json`). Scripts passing `--config <path>` will receive a parse error; change directory before running the CLI instead.
- **`--tenant-id` / `-t` removed from `a365 develop-mcp register-external-mcp-server`** — the tenant is now auto-detected from the current `az login` session. Scripts passing `-t <id>` / `--tenant-id <id>` will receive a System.CommandLine parse error; run `az login --tenant <id>` (or `az account set --subscription <id>`) to target a specific tenant instead.
- **`a365 develop-mcp publish` now creates a `<server-name>-PublicClients` Entra app registration in your tenant** — the publish orchestration runs CLI-side, so after each publish you will see a new app registration named `<server-name>-PublicClients` in your tenant's Entra ID. These are created by the CLI; clean them up with the same name if you unpublish.
- **`a365 develop-mcp publish` now creates Entra app registrations in your tenant** — every publish creates a `<server-name>-PublicClients` app, and publishing a custom (non-Dataverse) server also creates a `<server-name>-A365Proxy` app (first-party Dataverse servers skip the proxy app). These are created by the CLI; clean them up with the same names if you unpublish (#499).
- **`a365 develop-mcp publish` now requires the `Application.ReadWrite.All` Microsoft Graph permission** — needed to create the Entra app registration above. Running publish with only read-only Graph permissions will fail. Grant `Application.ReadWrite.All` to the account (or app) running the CLI before publishing.
- **`--agent-instance-only` renamed to `--agent-registration-only`** on `a365 setup all` — update any scripts using the old flag name.
- **`setup permissions custom --resource-app-id --scopes` applies permissions directly to Entra ID** — unlike the former `a365 config permissions` which only wrote to `a365.config.json`, this inline mode immediately mutates the live blueprint in Entra and cannot be undone by editing a config file.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -392,6 +392,12 @@ private static Command CreatePublishSubcommand(
description: "Publisher name for the MCP Server. Required for custom (user-created) MCP servers; ignored for 1p Microsoft-owned servers (e.g. msdyn_DataverseMCPServer) which always publish as 'Microsoft'.");
command.AddOption(publisherNameOption);

var serviceTreeIdOption = new Option<string?>("--service-tree-id", description: "ServiceTree ID for Entra app registration (required in Microsoft corporate tenants)");
command.AddOption(serviceTreeIdOption);

var secretLifetimeMonthsOption = new Option<int?>(["--secret-lifetime-months", "-l"], description: "Lifetime in months (1-24) for the generated client secret on the A365 proxy Entra app. Default is 2 years. Set a value smaller than the appManagementPolicies cap in your tenant.");
command.AddOption(secretLifetimeMonthsOption);
Comment thread
deepaligargms marked this conversation as resolved.
Comment thread
deepaligargms marked this conversation as resolved.

var yesOption = new Option<bool>(
["--yes", "-y"],
description: "Skip the interactive 'Proceed with publish? (y/N)' confirmation.");
Expand All @@ -412,7 +418,9 @@ private static Command CreatePublishSubcommand(
DisplayName: context.ParseResult.GetValueForOption(displayNameOption),
PublisherName: context.ParseResult.GetValueForOption(publisherNameOption),
Yes: context.ParseResult.GetValueForOption(yesOption),
DryRun: context.ParseResult.GetValueForOption(dryRunOption));
DryRun: context.ParseResult.GetValueForOption(dryRunOption),
ServiceTreeId: context.ParseResult.GetValueForOption(serviceTreeIdOption),
SecretLifetimeMonths: context.ParseResult.GetValueForOption(secretLifetimeMonthsOption));

var executor = new PublishCommandExecutor(logger, toolingService, graphApiService);
var success = await executor.ExecuteAsync(args, context.GetCancellationToken());
Expand Down
Loading
Loading