mcp-gateway

Azure Entra ID Application Roles Setup

Follow these steps to enable application roles, assign them to identities, and pass the role value into adapter/tool definitions for authorization.

1. Enable and Configure Roles on the App Registration

2. Assign Roles to Identities

3. Provide the Role Value When Creating Adapters or Tools

4. Built-in Agent Tools Are Disabled (bash, read_file, write_file)

Built-in tools are disabled for every caller, including mcp.admin, agent creators, and callers with previously configured built-in roles such as mcp.builtin.

Remove built-in references when updating agents. Authorization for registered MCP tools, subagents, adapters, and workload identity is unchanged.

5. Authorize Workload Identity on Adapters and Tools (useWorkloadIdentity)

Setting useWorkloadIdentity: true binds the deployed pod to the cluster’s shared federated identity (the workload-sa service account annotated with azure.workload.identity/client-id). Any container in that pod can then mint Entra ID access tokens for that identity and reach whatever Azure resources it is granted. Because the identity is shared by every workload in the namespace and is not owned by the requester, this is gated on the caller’s role at create and update time, with no creator bypass.