setup blueprint: identifierUris set to api://<appId> instead of api://botid-<appId>, breaking Teams message delivery
Maintainer thường phản hồi trong vòng 5 ngày
@ajmfehr đang làm issue này rồi.
Từ ngày 1/8/2026.
Đánh giá
Issue này chưa được đánh giá.
Mô tả
Description
a365 setup blueprint / a365 setup all stamps the blueprint Entra app's identifierUris as api://<appId>. Teams requires the botid- prefix (api://botid-<appId>) for Activity Protocol routing and token exchange. Without it, messages sent to an agent instance are silently never delivered to the configured Notification URL — no error surfaces anywhere.
The offending line is BlueprintSubcommand.cs#L1260:
var identifierUri = $"api://{appId}";
applied at L1264 via PATCH /v1.0/applications/{objectId}.
The CLI's own dry-run output disagrees with what it does. Three places print the prefixed form:
PublishCommand.cs#L318—webApplicationInfo.resource -> api://botid-{ClientAppId}, but L353 writeswebInfo["resource"] = $"api://{blueprintId}"NonDwSetupOrchestrator.cs#L61, L95, L96— printsapi://botid-<appId>, but that method is a stub (LogWarningat L50: "not yet fully implemented")
Possible provenance: #191 specified $IdentifierUri = "api://<blueprint-id>" in its repro script, and that appears to have been implemented literally. The botid- text in NonDwSetupOrchestrator looks like a holdover from the classic Azure Bot / App Registration flow, which did apply the prefix — which is why developers who onboarded via the older path never hit this.
Behavior is identical across --authmode obo|s2s|both, --m365, --aiteammate, and standalone setup blueprint.
Expected behavior
identifierUris is set to api://botid-<appId>, matching the CLI's dry-run output, and messages sent to an agent instance reach the configured Notification URL.
SDK Version
1.1.214
Language/Runtime
.NET 8 (a365 CLI global tool); agent runtime Node.js 20 / TypeScript Teams SDK
OS
macOS 14
How to Reproduce
a365 setup all --agent-name <name> --m365- Start a Teams SDK app on a public HTTPS endpoint; set that endpoint as the blueprint's Notification URL (Agent Type: API Based) in Developer Portal
- Publish + activate the generated package via M365 Admin Center
- Create an agent instance from the Teams Store
- Send the instance a chat message
The app receives nothing. No error in the app, in Developer Portal, or from the CLI.
Output
$ az ad app show --id <blueprint-id> --query identifierUris -o json
[
"api://<blueprint-id>"
]
After manually applying the prefix, messages are delivered immediately on the next send:
$ az ad app update --id <blueprint-id> --identifier-uris "api://botid-<blueprint-id>"
Note that once messages do flow, a separate missing-grant problem surfaces as AADSTS65001 naming the instance app rather than the blueprint — which sends you looking at instance consent instead of blueprint inheritance. Filing that separately.
Screenshots
N/A
Code of Conduct
- I agree to follow the Microsoft Open Source Code of Conduct.
- Ngôn ngữ chính
- C#
- Star
- 61
- Fork
- 35
- Merge trung bình
- 5 ngày 22 giờ
- Pull request đã merge (30 ngày)
- 4
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của microsoft/Agent365-devTools
-
Two hardening notes from a blind pre-registered read at ea1579f: AgenticUserId skips ValidateGuid before an az shell-out; config secret has no file-mode hardening on macOS/LinuxCó thể làm lại được @ajmfehr đã nhận 33 ngày trước và không có pull request nào đang mở. Đang mởenhancement escalated feature P1 security
microsoft/Agent365-devTools#493 · 3 bình luận · 1 người được giao ·
Maintainer thường phản hồi trong vòng 5 ngày
-
setup permissions custom uses User.Read token for OAuth2 grant operationCó thể làm lại được @ajmfehr đã nhận 61 ngày trước và không có pull request nào đang mở. Đang mởbug escalated P1 security
microsoft/Agent365-devTools#486 · 3 bình luận · 1 người được giao ·
Maintainer thường phản hồi trong vòng 5 ngày
Tất cả issue của microsoft/Agent365-devTools
Issue tương tự
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
Esri/calcite-dotnet-toolkit#30 · 1 reaction ·
-
VideoViewer: rotated (portrait phone) videos shown sideways when system decimal separator is a commaĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Volodymyr-Petrunin/Bankomaten#45 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
thekid/inotify-win#45 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
AvaloniaUI/Avalonia#22420 ·
Maintainer thường phản hồi trong vòng 1 ngày