Follow these steps to enable application roles, assign them to identities, and pass the role value into adapter/tool definitions for authorization.
McpGateway).Adapter Reader).Users/Groups for people or Applications for service principals.mcp.engineer).mcp.engineer, mcp.scientist).mcp.admin. This value is used by the gateway to grant elevated write access beyond the resource creator.requiredRoles collection with the exact Value strings created above.{
"name": "sample-adapter",
// ...
"requiredRoles": ["mcp.engineer", "mcp.scientist"]
}
SimplePermissionProvider grants:
mcp.admin, or matches one of the requiredRoles entries.mcp.admin.If no
requiredRolesis configured, it by default ALLOW ALL READ access.
bash, read_file, write_file)Built-in tools are disabled for every caller, including mcp.admin, agent creators, and callers with previously configured built-in roles such as mcp.builtin.
builtin: references return 400 Bad Request.BuiltinToolSettings:RequiredRoles is retained for configuration compatibility only; neither it nor additional role assignments can enable built-in execution.Remove built-in references when updating agents. Authorization for registered MCP tools, subagents, adapters, and workload identity is unchanged.
useWorkloadIdentity)Setting useWorkloadIdentity: true binds the deployed pod to the cluster’s shared federated identity (the workload-sa service account annotated with azure.workload.identity/client-id). Any container in that pod can then mint Entra ID access tokens for that identity and reach whatever Azure resources it is granted. Because the identity is shared by every workload in the namespace and is not owned by the requester, this is gated on the caller’s role at create and update time, with no creator bypass.
mcp.admin may set useWorkloadIdentity: true. Other callers receive 403 Forbidden; adapters and tools that do not request workload identity are unaffected.To grant this without full admin, create a dedicated app role (e.g. mcp.workload), assign it (Section 2), then configure it on the gateway:
// appsettings.json
{
"WorkloadIdentitySettings": {
"RequiredRoles": [ "mcp.workload" ]
}
}
The same setting via environment variables (e.g. in the pod spec) uses the array index form:
WorkloadIdentitySettings__RequiredRoles__0=mcp.workload
mcp.admin is always permitted in addition to any configured roles. Leaving RequiredRoles empty keeps workload identity admin-only.