You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于Bot Framework多租户应用弃用对现有C#/Python定制化聊天机器人影响的技术问询

关于Bot Framework多租户应用弃用对现有C#/Python定制化聊天机器人影响的技术问询

Hey there, let's break down your concerns step by step to clear up the confusion and mitigate the risks you're facing with the upcoming Bot Framework multi-tenant deprecation.

1. 明确多租户弃用的具体范围

First, let's demystify Microsoft's official notice:

Microsoft docs for new update - Multi-tenant (Deprecated – ends July 31, 2025)
"Incoming webhooks are also deprecated by the end of 2025"

This does not mean all incoming requests to your bots will stop working after 2025. Here's what it actually means:

  • After July 31, 2025, you won't be able to use a multi-tenant Azure AD app registration for your bot's authentication with Bot Framework services. Any new or reconfigured auth flows relying on multi-tenant setups will fail.
  • The incoming webhooks deprecation refers specifically to multi-tenant-enabled webhook endpoints tied to those legacy app registrations—existing bot traffic won't immediately drop off, but you must migrate your bot's identity before the deadline to avoid long-term service disruptions.
  • You will need to switch your bot's identity to either a single-tenant Azure AD app registration or a user-assigned managed identity before the deprecation date.

2. 解决单租户/用户分配托管标识的配置困惑

I totally get why the Azure portal UI is throwing you off—right now, Bot Framework integration isn't clearly highlighted in single-tenant app registration screens, and user-assigned identities are still tied to multi-tenant sections in some views. This is just a temporary UI gap as Microsoft aligns the portal with the deprecation timeline. Here's the clear truth:

  • Single-tenant app registrations do work with Bot Framework: You can manually configure this by:
    • Creating a single-tenant Azure AD app registration
    • Generating a client secret or certificate for authentication
    • Manually entering the app's client ID and your tenant ID in your Azure Bot resource's Authentication settings (even if the UI doesn't auto-populate these fields)
  • User-assigned managed identities are fully supported: These are standalone identity resources that you can attach to your bot, independent of multi-tenant app registrations. The portal will likely update soon to make this configuration more intuitive, but for now, you can assign a user-assigned identity directly to your Azure Bot resource via the "Identity" tab in the portal.

3. 单租户模式下的认证顾虑及替代方案

Your worry about authentication failing in single-tenant mode is completely valid—historically, Bot Framework relied on multi-tenant setups to handle cross-tenant user requests, and that's even been confirmed by Microsoft employees in forums. But there are now supported workarounds to keep cross-tenant auth working without multi-tenant app registrations:

  • Tenant Allowlisting: If you know all the specific tenants your bot needs to serve, add those tenant IDs to your single-tenant app's "Allowed tenants" list in Azure AD. This lets your bot authenticate users from approved external tenants without multi-tenant auth.
  • User-Assigned Managed Identity with Cross-Tenant Access Policies: For scenarios where you need to support unforeseen tenants, you can use a user-assigned managed identity and configure cross-tenant access policies in Azure AD to let external tenants trust your bot's identity. This maintains cross-tenant auth capabilities without relying on multi-tenant app registrations.
  • 关键提醒:For your complex bot with adaptive dialogs, RAG integrations, and business API calls, none of your core conversational logic will break when switching identities. You'll only need to update the auth configuration in your bot's startup code:
    • In C#: Update MicrosoftAppCredentials to use your single-tenant app's details or user-assigned managed identity ID
    • In Python: Adjust settings in the azure.identity provider to use the new identity
      All your dialog flows, RAG logic, and API integrations will remain fully functional as long as the auth layer is configured correctly.

4. 无法迁移到Copilot/Agent SDK的替代路径

I understand that migrating to the Microsoft 365 Copilot/Agent SDK isn't an option right now—adaptive dialog support is critical to your implementation, and it's frustrating that the new SDK doesn't cover that yet. Here's what you can do instead:

  1. Test the new identity setup with a staging bot first: Replicate your core dialog flows and auth logic in a non-production environment to validate that cross-tenant auth works as expected before touching your production bots.
  2. Open a dedicated support case with Microsoft: Since your bot is business-critical with complex custom logic, you can request personalized support to get guidance tailored to your specific scenario (especially if you need to support a large number of external tenants).
  3. Monitor Bot Framework documentation updates: Microsoft is actively adding more clarity on single-tenant and managed identity configurations for complex bots, including adaptive dialog support. The core Bot Framework v4 runtime (which your bot uses) will continue to be supported post-2025 as long as you're using a supported identity model.

Final Key Takeaways

You don't need to rebuild your bot from scratch to comply with the deprecation. The only mandatory change is migrating your bot's identity to a single-tenant app or user-assigned managed identity before July 31, 2025. Your adaptive dialogs, RAG integrations, and business API logic will remain intact—you just need to update the auth configuration layer.

内容来源于stack exchange

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.08 07:39:34