diff --git a/litellm/proxy/guardrails/guardrail_hooks/agent_365/agent_365.py b/litellm/proxy/guardrails/guardrail_hooks/agent_365/agent_365.py index 9ffd1111d62..6e5849a92a4 100644 --- a/litellm/proxy/guardrails/guardrail_hooks/agent_365/agent_365.py +++ b/litellm/proxy/guardrails/guardrail_hooks/agent_365/agent_365.py @@ -508,7 +508,7 @@ class Agent365Guardrail(CustomGuardrail): return Unavailable( detail=( f"Entra rejected the gateway's own Agent 365 credentials ({error.misconfigured}); " - "check the guardrail's client_id, client_secret and resource_app_id" + "check the guardrail's client_id and client_secret" ), fail_open=self.unreachable_fallback == "fail_open", ) diff --git a/tests/test_litellm/proxy/guardrails/guardrail_hooks/test_agent_365.py b/tests/test_litellm/proxy/guardrails/guardrail_hooks/test_agent_365.py index a43ffd34145..fd2f14471ce 100644 --- a/tests/test_litellm/proxy/guardrails/guardrail_hooks/test_agent_365.py +++ b/tests/test_litellm/proxy/guardrails/guardrail_hooks/test_agent_365.py @@ -1280,6 +1280,9 @@ class TestPreflightCallerSignIn: assert isinstance(verdict, Unavailable) assert verdict.fail_open is False assert "bad client_secret" in verdict.detail + assert "resource_app_id" not in verdict.detail, ( + "the field was removed from the config; do not tell admins to check it" + ) @pytest.mark.asyncio async def test_endpoint_unreachable_fail_open_is_unavailable(self):