All skills
microsoft avatar

/microsoft-foundry

@04110d9
by microsoftmicrosoft/skills3.1k stars
351

Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end. USE FOR: foundry, azd ai agent, azd provision/deploy, hosted agent scaffold/develop/run/deploy/troubleshoot, prompt agent create, create agent, update agent, add tool to agent, invoke agent, agent.yaml, agent insights, pull agent insights, evaluate agent, batch eval, continuous eval, continuous monitoring, agent CI/CD, optimize prompt, improve prompt, prompt optimizer, optimize agent instructions, Agent Optimizer scaffold, dataset curation from traces, deploy model, model fine-tuning (SFT/DPO/RFT), Foundry project, RBAC, role assignment, permissions, quota, capacity, region, deployment failure, AI Services, create Foundry resource, knowledge index, customize deployment, onboard, availability, training-data, grader, distillation, large file upload. DO NOT USE FOR: Azure Functions, App Service, general Azure deploy (use azure-deploy), general Azure prep (use azure-prepare).

Use this Skill: https://skilld.dev/gh/microsoft/skills/microsoft-foundry

This session only. Nothing lands on disk.

rbacrbac.md

≈1.8k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Microsoft Foundry RBAC Management

Reference for managing RBAC for Microsoft Foundry resources: user permissions, managed identity configuration, and service principal setup for CI/CD.

Quick Reference

Property Value
CLI Extension az role assignment, az ad sp
Resource Type Microsoft.CognitiveServices/accounts
Best For Permission management, access auditing, CI/CD setup

When to Use

  • Grant user access to Foundry resources or projects
  • Set up developer permissions (Project Manager, Owner roles)
  • Audit role assignments or validate permissions
  • Configure managed identity roles for connected resources
  • Create service principals for CI/CD pipeline automation
  • Troubleshoot permission errors

Foundry Built-in Roles

Role Create Projects Data Actions Role Assignments
Foundry Agent Consumer No Invoke agents only No
Foundry User No Yes No
Foundry Project Manager Yes Yes Yes (Foundry User only)
Foundry Account Owner Yes No Yes (Foundry User only)
Foundry Owner Yes Yes Yes

⚠️ Warning: Foundry User is auto-assigned via Portal but NOT via SDK/CLI. Automation must explicitly assign roles.

Workflows

All scopes follow the pattern: /subscriptions/<subscription-id>/resourceGroups/<resource-group>/providers/Microsoft.CognitiveServices/accounts/<foundry-resource-name>

For project-level scoping, append /projects/<project-name>.

1. Assign User Permissions

az role assignment create --role "53ca6127-db72-4b80-b1b0-d745d6d5456d" --assignee "<user-email-or-object-id>" --scope "<foundry-scope>" # Foundry User

2. Assign Developer Permissions

# Project Manager (create projects, assign Foundry User roles)
az role assignment create --role "eadc314b-1a2d-4efa-be10-5d325db5065e" --assignee "<user-email-or-object-id>" --scope "<foundry-scope>" # Foundry Project Manager

# Full ownership including data actions
az role assignment create --role "c883944f-8b7b-4483-af10-35834be79c4a" --assignee "<user-email-or-object-id>" --scope "<foundry-scope>" # Foundry Owner

3. Audit Role Assignments

# List all assignments
az role assignment list --scope "<foundry-scope>" --output table

# Detailed with principal names
az role assignment list --scope "<foundry-scope>" --query "[].{Principal:principalName, PrincipalType:principalType, Role:roleDefinitionName}" --output table

# Foundry roles only
az role assignment list --scope "<foundry-scope>" --query "[?contains(roleDefinitionName, 'Foundry')].{Principal:principalName, Role:roleDefinitionName}" --output table

4. Validate Permissions

# Current user's roles on resource
az role assignment list --assignee "$(az ad signed-in-user show --query id -o tsv)" --scope "<foundry-scope>" --query "[].roleDefinitionName" --output tsv

# Check actions available to a role
az role definition list --name "Foundry User" --query "[].permissions[].actions" --output json

Permission Requirements by Action:

Action Required Role(s)
Deploy models Foundry Account Owner, Foundry Owner
Create projects Foundry Project Manager, Foundry Account Owner, Foundry Owner
Assign Foundry User role Foundry Project Manager, Foundry Account Owner, Foundry Owner
Full data access Foundry User, Foundry Project Manager, Foundry Owner

5. Configure Managed Identity Roles

# Get managed identity principal ID
PRINCIPAL_ID=$(az cognitiveservices account show --name <foundry-resource-name> --resource-group <resource-group> --query identity.principalId --output tsv)

# Assign roles to connected resources (repeat pattern for each)
az role assignment create --role "<role-name>" --assignee "$PRINCIPAL_ID" --scope "<resource-scope>"

Common Managed Identity Role Assignments:

Connected Resource Role Purpose
Azure Storage Storage Blob Data Reader Read files/documents
Azure Storage Storage Blob Data Contributor Read/write files
Azure Key Vault Key Vault Secrets User Read secrets
Azure AI Search Search Index Data Reader Query indexes
Azure AI Search Search Index Data Contributor Query and modify indexes
Azure Cosmos DB Cosmos DB Account Reader Read data

6. Create Service Principal for CI/CD

# Create SP with minimal role
az ad sp create-for-rbac --name "foundry-cicd-sp" --role "53ca6127-db72-4b80-b1b0-d745d6d5456d" --scopes "<foundry-scope>" --output json # Foundry User
# Output contains: appId, password, tenant — store securely

# For project management permissions
az ad sp create-for-rbac --name "foundry-cicd-admin-sp" --role "eadc314b-1a2d-4efa-be10-5d325db5065e" --scopes "<foundry-scope>" --output json # Foundry Project Manager

# Add Contributor for resource provisioning
SP_APP_ID=$(az ad sp list --display-name "foundry-cicd-sp" --query "[0].appId" -o tsv)
az role assignment create --role "Contributor" --assignee "$SP_APP_ID" --scope "/subscriptions/<subscription-id>/resourceGroups/<resource-group>"

💡 Tip: Use least privilege — start with Foundry User and add roles as needed.

CI/CD Scenario Recommended Role Additional Roles
Deploy models only Foundry Account Owner None
Manage projects Foundry Project Manager None
Full provisioning Foundry Owner Contributor (on RG)
Read-only monitoring Reader Foundry User (for data)

CI/CD Pipeline Login:

az login --service-principal --username "<app-id>" --password "<client-secret>" --tenant "<tenant-id>"
az account set --subscription "<subscription-id>"

Error Handling

Issue Cause Resolution
"Authorization failed" when deploying models Missing Foundry Account Owner or Foundry Owner role Assign Foundry Account Owner at account scope
Cannot create projects Missing Project Manager or Owner role Assign Foundry Project Manager role
"Access denied" on connected resources Managed identity missing roles Assign appropriate roles to MI on each resource
Portal works but CLI fails Portal auto-assigns roles, CLI doesn't Explicitly assign Foundry User via CLI
Service principal cannot access data Wrong role or scope Verify Foundry User is assigned at correct scope
"Principal does not exist" User/SP not found in directory Verify the assignee email or object ID is correct
Role assignment already exists Duplicate assignment attempt Use az role assignment list to verify existing assignments

Additional Resources

Source: SKILL.md on GitHub

2 warnings3d4 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill provides a comprehensive environment for managing the end-to-end lifecycle of AI agents, models, and infrastructure on Microsoft Foundry. It includes sub-skills for deployment, evaluation, fine-tuning, and troubleshooting. The skill utilizes dynamic code execution and shell command wrappers, which are used within the context of local development and cloud orchestration. All external resources and dependencies originate from trusted organizations and well-known services.

  • Socket3d

    2 alerts: gptSecurity, gptAnomaly

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    36/36 files flagged

Signed by skilld at 04110d9. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated last week
metadata
{
  "author": "Microsoft",
  "version": "1.2.26"
}

README badge

README badge for microsoft/skills/microsoft-foundry