Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

setup blueprint: identifierUris set to api://<appId> instead of api://botid-<appId>, breaking Teams message delivery

Aperta
#482 3 commenti 0 reazioni 1 assegnatario Vedi su GitHub

@ajmfehr ci sta già lavorando.

Dal 1/8/2026.

Valutazione

Questa issue non è ancora stata valutata.

Descrizione

bug escalated P1 security
Description

a365 setup blueprint / a365 setup all stamps the blueprint Entra app's identifierUris as api://<appId>. Teams requires the botid- prefix (api://botid-<appId>) for Activity Protocol routing and token exchange. Without it, messages sent to an agent instance are silently never delivered to the configured Notification URL — no error surfaces anywhere.

The offending line is BlueprintSubcommand.cs#L1260:

var identifierUri = $"api://{appId}";

applied at L1264 via PATCH /v1.0/applications/{objectId}.

The CLI's own dry-run output disagrees with what it does. Three places print the prefixed form:

Possible provenance: #191 specified $IdentifierUri = "api://<blueprint-id>" in its repro script, and that appears to have been implemented literally. The botid- text in NonDwSetupOrchestrator looks like a holdover from the classic Azure Bot / App Registration flow, which did apply the prefix — which is why developers who onboarded via the older path never hit this.

Behavior is identical across --authmode obo|s2s|both, --m365, --aiteammate, and standalone setup blueprint.

Expected behavior

identifierUris is set to api://botid-<appId>, matching the CLI's dry-run output, and messages sent to an agent instance reach the configured Notification URL.

SDK Version

1.1.214

Language/Runtime

.NET 8 (a365 CLI global tool); agent runtime Node.js 20 / TypeScript Teams SDK

OS

macOS 14

How to Reproduce
  1. a365 setup all --agent-name <name> --m365
  2. Start a Teams SDK app on a public HTTPS endpoint; set that endpoint as the blueprint's Notification URL (Agent Type: API Based) in Developer Portal
  3. Publish + activate the generated package via M365 Admin Center
  4. Create an agent instance from the Teams Store
  5. Send the instance a chat message

The app receives nothing. No error in the app, in Developer Portal, or from the CLI.

Output
$ az ad app show --id <blueprint-id> --query identifierUris -o json
[
  "api://<blueprint-id>"
]

After manually applying the prefix, messages are delivered immediately on the next send:

$ az ad app update --id <blueprint-id> --identifier-uris "api://botid-<blueprint-id>"

Note that once messages do flow, a separate missing-grant problem surfaces as AADSTS65001 naming the instance app rather than the blueprint — which sends you looking at instance consent instead of blueprint inheritance. Filing that separately.

Screenshots

N/A

Code of Conduct
Lingua principale
C#
Stelle
60
Fork
34
Merge medio
8g 8h
PR unite (30g)
1

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di microsoft/Agent365-devTools

Tutte le issue di microsoft/Agent365-devTools

Issue simili

Altre issue su C#

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.