microsoft / microsoft/sre-agent
[Issue] Users with SRE Agent Administrator role seeing authorization error for DataConnectors/ListSecrets
- Dominant language
- PowerShell
- Stars
- 160
- Forks
- 97
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 12
Description
Issue Description
I deployed an Azure SRE Agent in my tenant and configured several connectors, including Teams, Log Analytics and Application Insights and MCP servers. Subsequently, I granted another user SRE Administrator role over my newly created agent. When viewing connectors, the SRE Administrator user that I added consistently sees a red banner on the Connectors screen of the agent, indicating an authorization failure on Microsoft.App/agents/{agent name}/DataConnectors/ListSecrets. It's unclear if there's any impact to this error, agent chat seems to behave normally and can access connectors.
Additionally, one of my customers has experienced this behavior.
Thread ID
N/A
Steps to Reproduce
1. Create new SRE Agent
2. Configure 1 or more connectors (App Insights, Log Analytics, MCP, etc)
3. Grant a second user SRE Agent Administrator over the RG that contains the agent/managed identity
4. Access new SRE agent as second user
5. Navigate to Connectors screen
6. Observe red banner at top of screen indicating user does not have authorization to perform ListSecrets on the DataConnectors child resource
The above steps produced identical results in Chrome and Edge.
Agent resource ID: subscriptions/8bd05b2f-62c5-4def-9869-f0617ebb3970/resourceGroups/RG-PDP-SRE/providers/Microsoft.App/agents/sre-pdp
Expected Behavior
Since SRE Agent Administrator has full control over the agent resource, I would not expect to see this error.
Actual Behavior
I did see the authorization error described above. Agent behavior seems unimpacted, chat behaves normally.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start at the agent's Connectors screen and reproduce the issue using the listed role, resource, and connector steps. Inspect the DataConnectors/ListSecrets authorization request and compare the behavior for the agent owner and SRE Agent Administrator. Done means the administrator can open Connectors without the authorization banner while connector access and chat remain functional.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure
- Domain
- authorization
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100