
Explanation:
Set tool_choice to: required
Configure the tool to authenticate by: Using a distinct agent identity bound to the client application Set tool_choice to required because the compliance workflow must deterministically include a tool-based retrieval step before the agent generates a response. Microsoft Foundry Agent Service guidance states that tool_choice provides the most deterministic control over tool use: auto lets the model decide, none prevents tool calls, and required forces the model to call one or more tools. This directly corrects the current nondeterministic behavior where the model decides whether to call tools.
For authentication, use a distinct agent identity bound to the client application . Microsoft Foundry creates a shared identity for unpublished or in-development agents, but publishing an agent automatically creates a dedicated agent identity blueprint and agent identity associated with the agent application resource. Published agents authenticate tool calls by using that unique agent identity, and RBAC permissions must be assigned to the new identity. This provides isolation from the broader shared project identity and supports independent audit trails for compliance workflows.
Storing API keys in prompts violates security guidance and prevents robust audit attribution. The shared project agent identity is easier for development, but it has a broader blast radius and does not meet the isolation requirement. Reference topics: Foundry Agent Service tool choice, tool authentication, published agent identities, RBAC, and auditability.