Environment
OS: Windows
GitHub Copilot app: v1.1.26
MCP server type: HTTP / Remote MCP
MCP server URL: https://mcp.dev.azure.com/RB-Group
Azure DevOps organization: RB-Group
Description
Azure DevOps Remote MCP authentication stopped working unexpectedly. It previously worked, but since October 5/6, 2026 the GitHub Copilot app fails when clicking Sign in for the MCP server.
The browser does not open and authentication fails with:
Authentication failed
azure-devops: RPC error -32603: Request session.mcp.oauth.login failed with message:
Failed to fetch MCP OAuth protected-resource metadata from
https://mcp.dev.azure.com/.well-known/oauth-protected-resource/RB-Group
Previously the same MCP configuration worked without changes to the server URL or configuration.
MCP configuration
{
"servers": {
"azure-devops": {
"type": "http",
"url": "https://mcp.dev.azure.com/RB-Group"
}
}
}
Reproduction
- Open GitHub Copilot app on Windows.
- Add/configure the Azure DevOps Remote MCP server: https://mcp.dev.azure.com/RB-Group
- Open MCP settings.
- Click Sign in.
- Authentication fails before the browser authentication flow starts.
Important diagnostics
The affected Windows machine can successfully access the exact protected-resource metadata URL using curl.exe.
Request:
curl.exe -i --connect-timeout 10 "https://mcp.dev.azure.com/.well-known/oauth-protected-resource/RB-Group"
Result:
HTTP/1.1 200 OK
Content-Type: application/json; charset=utf-8
Response:
{
"resource": "https://mcp.dev.azure.com/RB-Group",
"authorization_servers": [
"https://login.microsoftonline.com/95e66ecc-f2c2-464b-84d9-8fda407bc923/v2.0"
],
"bearer_methods_supported": [
"header"
],
"scopes_supported": [
"https://mcp.dev.azure.com/.default"
]
}
The MCP endpoint itself is also reachable:
curl.exe -i --connect-timeout 10 "https://mcp.dev.azure.com/RB-Group"
Result:
HTTP/1.1 405 Method Not Allowed
Allow: POST
This appears expected for an unauthenticated GET against the MCP endpoint and confirms that the endpoint is reachable.
The Microsoft Entra OpenID configuration endpoint advertised by the MCP metadata is also reachable:
curl.exe -i --connect-timeout 10 "https://login.microsoftonline.com/95e66ecc-f2c2-464b-84d9-8fda407bc923/v2.0/.well-known/openid-configuration"
Result:
HTTP/1.1 200 OK
The response contains the expected authorization and token endpoints.
Additional observations
The failure therefore appears to be specific to the OAuth/MCP implementation inside the GitHub Copilot app rather than network connectivity or Azure DevOps availability.
The browser is not launched before the failure occurs.
The local MCP OAuth token directory contains two token files created during the failed authentication attempts:
~/.copilot/mcp-oauth-config/
2bc11faa0a8f244b0e89fc36f4b782a959ab5fe29124767fa92fe79e719467df.tokens.json
bebc44e5d28335b71f85c9c23bba136226562901e81757961dc79685bd084018.tokens.json
The token metadata includes:
{
"scope": "https://mcp.dev.azure.com/.default",
"requestedScope": "https://mcp.dev.azure.com/.default"
}
No credentials or token values are included in this report.
Windows also has the following TCP excluded port range:
Start Port End Port
50000 50059
However, there is currently no evidence that the failure is caused by the local OAuth callback port.
Expected behavior
Copilot should successfully retrieve the protected-resource metadata, discover the Microsoft Entra authorization server, and proceed with the OAuth login flow.
Actual behavior
Copilot reports:
Failed to fetch MCP OAuth protected-resource metadata
even though the same metadata URL returns HTTP 200 with valid JSON when accessed from the same Windows machine using curl.exe.
Environment
OS: Windows
GitHub Copilot app: v1.1.26
MCP server type: HTTP / Remote MCP
MCP server URL: https://mcp.dev.azure.com/RB-Group
Azure DevOps organization: RB-Group
Description
Azure DevOps Remote MCP authentication stopped working unexpectedly. It previously worked, but since October 5/6, 2026 the GitHub Copilot app fails when clicking Sign in for the MCP server.
The browser does not open and authentication fails with:
Authentication failed
azure-devops: RPC error -32603: Request session.mcp.oauth.login failed with message:
Failed to fetch MCP OAuth protected-resource metadata from
https://mcp.dev.azure.com/.well-known/oauth-protected-resource/RB-Group
Previously the same MCP configuration worked without changes to the server URL or configuration.
MCP configuration
{
"servers": {
"azure-devops": {
"type": "http",
"url": "https://mcp.dev.azure.com/RB-Group"
}
}
}
Reproduction
Important diagnostics
The affected Windows machine can successfully access the exact protected-resource metadata URL using curl.exe.
Request:
curl.exe -i --connect-timeout 10 "https://mcp.dev.azure.com/.well-known/oauth-protected-resource/RB-Group"
Result:
HTTP/1.1 200 OK
Content-Type: application/json; charset=utf-8
Response:
{
"resource": "https://mcp.dev.azure.com/RB-Group",
"authorization_servers": [
"https://login.microsoftonline.com/95e66ecc-f2c2-464b-84d9-8fda407bc923/v2.0"
],
"bearer_methods_supported": [
"header"
],
"scopes_supported": [
"https://mcp.dev.azure.com/.default"
]
}
The MCP endpoint itself is also reachable:
curl.exe -i --connect-timeout 10 "https://mcp.dev.azure.com/RB-Group"
Result:
HTTP/1.1 405 Method Not Allowed
Allow: POST
This appears expected for an unauthenticated GET against the MCP endpoint and confirms that the endpoint is reachable.
The Microsoft Entra OpenID configuration endpoint advertised by the MCP metadata is also reachable:
curl.exe -i --connect-timeout 10 "https://login.microsoftonline.com/95e66ecc-f2c2-464b-84d9-8fda407bc923/v2.0/.well-known/openid-configuration"
Result:
HTTP/1.1 200 OK
The response contains the expected authorization and token endpoints.
Additional observations
The failure therefore appears to be specific to the OAuth/MCP implementation inside the GitHub Copilot app rather than network connectivity or Azure DevOps availability.
The browser is not launched before the failure occurs.
The local MCP OAuth token directory contains two token files created during the failed authentication attempts:
~/.copilot/mcp-oauth-config/
2bc11faa0a8f244b0e89fc36f4b782a959ab5fe29124767fa92fe79e719467df.tokens.json
bebc44e5d28335b71f85c9c23bba136226562901e81757961dc79685bd084018.tokens.json
The token metadata includes:
{
"scope": "https://mcp.dev.azure.com/.default",
"requestedScope": "https://mcp.dev.azure.com/.default"
}
No credentials or token values are included in this report.
Windows also has the following TCP excluded port range:
Start Port End Port
50000 50059
However, there is currently no evidence that the failure is caused by the local OAuth callback port.
Expected behavior
Copilot should successfully retrieve the protected-resource metadata, discover the Microsoft Entra authorization server, and proceed with the OAuth login flow.
Actual behavior
Copilot reports:
Failed to fetch MCP OAuth protected-resource metadata
even though the same metadata URL returns HTTP 200 with valid JSON when accessed from the same Windows machine using curl.exe.