Azure / Azure/azure-dev

[Issue] adding to azd ai agent doctor - permissions check between Foundry project and Storage account

Open
#8,665 0 comments 0 reactions 0 assignees View on GitHub
area/security customer-reported enhancement ext-agents
Dominant language
Go
Stars
569
Forks
364
Avg merge
2d 19h
Merged PRs (30d)
136

Description

Suggest to add to "azd ai agent doctor" an additional permissions check between Foundry project and Storage account RBAC.
It should have Storage Blob Data Contributor role. This is must for Hosted Agents on Foundry.
Especially when running "azd ai agent optimize" command.
It mentioned in docs but not tested by "doctor" command.
"Confirm that the project managed identity (not the resource identity) has the Storage Blob Data Contributor role on the storage account."
Ref:
https://learn.microsoft.com/en-us/azure/foundry/how-to/bring-your-own-azure-storage-foundry#permission-errors-when-accessing-storage

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.