microsoft / microsoft/sre-agent

[Issue] Users with SRE Agent Administrator role seeing authorization error for DataConnectors/ListSecrets

Open
#249 1 comment 0 reactions 0 assignees View on GitHub
question
Dominant language
PowerShell
Stars
160
Forks
97
Avg merge
2d 5h
Merged PRs (30d)
12

Description

Issue Description
I deployed an Azure SRE Agent in my tenant and configured several connectors, including Teams, Log Analytics and Application Insights and MCP servers. Subsequently, I granted another user SRE Administrator role over my newly created agent. When viewing connectors, the SRE Administrator user that I added consistently sees a red banner on the Connectors screen of the agent, indicating an authorization failure on Microsoft.App/agents/{agent name}/DataConnectors/ListSecrets. It's unclear if there's any impact to this error, agent chat seems to behave normally and can access connectors.

Additionally, one of my customers has experienced this behavior.

Image

Thread ID
N/A

Steps to Reproduce
1. Create new SRE Agent
2. Configure 1 or more connectors (App Insights, Log Analytics, MCP, etc)
3. Grant a second user SRE Agent Administrator over the RG that contains the agent/managed identity
4. Access new SRE agent as second user
5. Navigate to Connectors screen
6. Observe red banner at top of screen indicating user does not have authorization to perform ListSecrets on the DataConnectors child resource

The above steps produced identical results in Chrome and Edge.

Agent resource ID: subscriptions/8bd05b2f-62c5-4def-9869-f0617ebb3970/resourceGroups/RG-PDP-SRE/providers/Microsoft.App/agents/sre-pdp

Expected Behavior
Since SRE Agent Administrator has full control over the agent resource, I would not expect to see this error.

Actual Behavior
I did see the authorization error described above. Agent behavior seems unimpacted, chat behaves normally.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start at the agent's Connectors screen and reproduce the issue using the listed role, resource, and connector steps. Inspect the DataConnectors/ListSecrets authorization request and compare the behavior for the agent owner and SRE Agent Administrator. Done means the administrator can open Connectors without the authorization banner while connector access and chat remain functional.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
authorization
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.