Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
20 commits
Select commit Hold shift + click to select a range
b50eef4
Add develop-mcp commands to list and grant MCP server permissions
rancelammers Sep 21, 2026
9f1a56d
Report sign-in failure distinctly from a missing BYO application
rancelammers Sep 21, 2026
1e81288
Add blueprint discovery and make device code sign-in usable
rancelammers Sep 21, 2026
9c40f0f
Surface blueprint IDs in help and errors instead of a command
rancelammers Sep 21, 2026
662abe4
Name the MCP server and scope explicitly in list-agent-instances output
rancelammers Sep 21, 2026
ed9f685
Fix defects found in end-to-end review
rancelammers Sep 22, 2026
323e373
Rename list-agent-instances to grant-agent-mcpserver-permissions
rancelammers Sep 22, 2026
78ce0f3
Fold single-identity grant into grant-agent-mcpserver-permissions
rancelammers Sep 22, 2026
c510ff3
Take only a blueprint and grant through interactive selection
rancelammers Sep 22, 2026
24160fc
Rename the subcommand to grant-agents-access
rancelammers Sep 22, 2026
df496df
Address PR review feedback on grant-agents-access
rancelammers Sep 22, 2026
cb5a1a9
Fix identity, client, and consent-type gaps found in PR review
rancelammers Sep 22, 2026
6244f3d
Reference PR #500 in the changelog entries for this change
rancelammers Sep 22, 2026
b470e13
Address review findings on grant-agents-access
rancelammers Sep 22, 2026
b5d8780
Reject empty selection tokens and strengthen resolve-failure tests
rancelammers Sep 23, 2026
d304aee
Scope grant-agents-access changes to the new command only
rancelammers Sep 23, 2026
b033d2a
Correct CHANGELOG for the scoped consent-type and device-code changes
rancelammers Sep 23, 2026
a389d29
Return every matching application and let the user choose
rancelammers Sep 23, 2026
f85290f
Honor --device-code on the fallback token path and abort on unreadabl…
rancelammers Sep 23, 2026
ca26cca
Route device-code Graph tokens through the cache-aware credential
rancelammers Sep 23, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,11 @@ Agents provisioned before this release need `Agent365.Observability.OtelWrite` g
**Option B — CLI** (`a365 setup admin`) has been removed in this release. Use Option A above, or copy the PowerShell instructions printed in the `a365 setup all` summary output.

### Added
- `a365 develop-mcp grant-agents-access --agent-blueprint-id <GUID> --mcp-server-name <NAME>` reports which agent instances of a blueprint are missing the permission to call a BYO MCP server, and prompts you to select which ones to grant it to (#500).
- When more than one Entra application shares the MCP server's name, `a365 develop-mcp grant-agents-access` now lists them all and asks which one to use instead of failing (#500).
- `a365 develop-mcp grant-agents-access --help` now lists Microsoft's first-party agent blueprint names and IDs, and the same list is printed when `--agent-blueprint-id` is missing or not a GUID, so you can find the ID without looking it up elsewhere (#500).
- `--device-code` option on `a365 develop-mcp grant-agents-access` — signs in with a device code instead of the browser or Windows sign-in dialog, for embedded and remote terminals (#500).
- `--dry-run` option on `a365 develop-mcp grant-agents-access` — lists the agent instances that are missing the permission without granting it (#500).
- Setup and bootstrap now use Microsoft's first-party Agent 365 CLI application when it is present in your tenant, validating it without changing Microsoft's app registration, and fall back to a tenant-owned "Agent 365 CLI" app when it is not (#489).
- Log separator written at the start of each CLI invocation now redacts values for secret-bearing options (e.g. `--idp-client-secret`) so they are not written to the log file in plain text.
- Authentication context (tenant and user) is now logged at the `Information` level whenever the resolved sign-in identity changes, giving operators a clear audit trail in the log file of who the CLI is acting as, without exposing credentials.
Expand Down Expand Up @@ -59,6 +64,7 @@ Agents provisioned before this release need `Agent365.Observability.OtelWrite` g
- `a365 develop get-token --device-code` — forces device code auth for Microsoft Graph scopes the Windows WAM broker rejects (e.g. Exchange `MailboxSettings.ReadWrite`, `ExchangeMessageTrace.Read.All`).

### Fixed
- `a365 develop-mcp grant-agents-access --device-code` no longer prompts repeatedly within a single command, and no longer fails in embedded or remote terminals where the sign-in prompt could not be displayed (#500).
- Setup no longer fails to detect the Agent 365 CLI application in tenants where it is not yet provisioned, and reports lookup errors instead of silently switching your configured client app (#489).
- The first-party Agent 365 CLI app now uses device code authentication when Windows Account Manager is unavailable, avoiding unsupported browser-response errors in WSL, macOS, and Linux (#489).
- `setup all --authmode s2s` no longer prints spurious "Action Required" PowerShell steps when the agent identity already inherits its app roles from the blueprint, and now retries the grant automatically before falling back to manual steps (#460).
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,8 @@ public static Command CreateCommand(
ILogger logger,
IAgent365ToolingService toolingService,
IEvaluationPipelineService? evaluationPipelineService = null,
GraphApiService? graphApiService = null)
GraphApiService? graphApiService = null,
McpServerPermissionService? mcpServerPermissionService = null)
{
var developMcpCommand = new Command("develop-mcp", "Manage MCP servers in Dataverse environments");

Expand All @@ -40,6 +41,11 @@ public static Command CreateCommand(
developMcpCommand.AddCommand(CreateUnpublishSubcommand(logger, toolingService));
developMcpCommand.AddCommand(CreateRegisterExternalMcpServerSubcommand(logger, toolingService, graphApiService));

if (mcpServerPermissionService is not null)
{
developMcpCommand.AddCommand(McpServerPermissionsSubcommands.CreateGrantAgentsAccessSubcommand(logger, mcpServerPermissionService));
}

if (evaluationPipelineService is not null)
{
developMcpCommand.AddCommand(CreateEvaluateSubcommand(logger, evaluationPipelineService));
Expand Down
Loading
Loading