You have a Microsoft Foundry project that contains an incident triage agent.
You have a Model Context Protocol (MCP) server registered in the organizational tool catalog. The MCP server exposes two tools named docs_search and deployment_delete.
You need to ensure that the agent can only invoke docs_search.
What should you configure?
The restriction belongs in the agent's MCP tool configuration because Microsoft Foundry supports an `allowed_tools` allowlist that controls which tools discovered from an MCP server are exposed to the agent. Configuring the allowlist to include only `docs_search` makes `deployment_delete` unavailable for model selection. This is stronger than adding a sentence to the agent instructions because instructions influence behavior but do not remove a dangerous tool from the callable surface. Project details describe resources rather than per-agent tool exposure, and a transient run setting is not the appropriate persistent configuration boundary for the registered MCP integration. Therefore C, the agent tool configuration, is the correct answer. Least privilege remains the governing principle: grant only the identity, data, tool, or deployment access required for the specific operation. The selected answer preserves that boundary while still allowing the workflow to satisfy its functional requirement. From a security and governance perspective, the control should be enforced at the narrowest platform boundary that can deterministically block or constrain the action. Relying only on prompt text is weaker because the model can still be induced to behave unexpectedly.
Official Microsoft reference: Microsoft Foundry agents - Model Context Protocol tools
Currently there are no comments in this discussion, be the first to comment!