All skills
microsoft avatar

/microsoft-foundry

@04110d9
by microsoftmicrosoft/skills3.1k stars
351

Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end. USE FOR: foundry, azd ai agent, azd provision/deploy, hosted agent scaffold/develop/run/deploy/troubleshoot, prompt agent create, create agent, update agent, add tool to agent, invoke agent, agent.yaml, agent insights, pull agent insights, evaluate agent, batch eval, continuous eval, continuous monitoring, agent CI/CD, optimize prompt, improve prompt, prompt optimizer, optimize agent instructions, Agent Optimizer scaffold, dataset curation from traces, deploy model, model fine-tuning (SFT/DPO/RFT), Foundry project, RBAC, role assignment, permissions, quota, capacity, region, deployment failure, AI Services, create Foundry resource, knowledge index, customize deployment, onboard, availability, training-data, grader, distillation, large file upload. DO NOT USE FOR: Azure Functions, App Service, general Azure deploy (use azure-deploy), general Azure prep (use azure-prepare).

Use this Skill: https://skilld.dev/gh/microsoft/skills/microsoft-foundry

This session only. Nothing lands on disk.

referencesstandard-agent-setup.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Standard Agent Setup

⚠️ Warning: This page covers Foundry's Standard Agent Setup (capability host + bring-your-own Cosmos DB / Azure Storage / Azure AI Search). The default azd ai agent flow uses Basic Agent Setup and does not provision a capabilityHosts/agents resource — stop reading this page if you arrived from azd ai agent. See foundry-agent/create/create-hosted.md and the canonical env vars in environment-variables.md.

MANDATORY: Read Standard Agent Setup docs before proceeding with standard setup.

Overview

Microsoft Foundry supports two agent setup configurations:

Setup Capability Host Description
Basic None Default setup. All resources are Microsoft-managed. No additional connections required.
Standard Azure AI Services Advanced setup. Bring-your-own storage and search connections for full control over data residency and scaling.

Standard Setup Connections

Connection Service Required Purpose
Thread storage Azure Cosmos DB ✅ Yes Store conversation threads in your own Cosmos DB instance
File storage Azure Storage ✅ Yes Store uploaded files in your own Azure Storage account
Vector store Azure AI Search ✅ Yes Use your own Azure AI Search instance for vector/knowledge retrieval
Azure AI Services Azure AI Services ❌ Optional Use OpenAI models from a different AI Services resource

💡 Tip: Standard setup is recommended for production workloads that require control over data storage, custom vector search, or integration with models from a separate AI Services resource.

Prerequisites

Before starting deployment, confirm the following with the user:

  1. RBAC role on the resource group: The user must have Owner or User Access Administrator role on the target resource group. The Bicep template assigns RBAC roles (Storage Blob Data Contributor, Cosmos DB Operator, AI Search roles) to the project's managed identity — this will fail without Microsoft.Authorization/roleAssignments/write permission.
  2. Subscription quota: Verify the target region has available quota for AI Services. If quota is exhausted, try an alternate region (e.g., swedencentral, eastus, westus3).
  3. Azure Policy compliance: Some subscriptions enforce policies (e.g., storage accounts must disable public network access). If the Bicep template fails due to policy violations, patch the template to comply (e.g., set publicNetworkAccess: 'Disabled' and defaultAction: 'Deny' on the storage account).

Deployment

  • Standard setup always creates a new Foundry resource and a new project. Do not ask the user for a project endpoint — one will be provisioned as part of the deployment.
  • Always use the official Bicep template: Standard Agent Setup Bicep Template

⚠️ Warning: Capability host provisioning is asynchronous and can take 10–20 minutes. After deploying the Bicep template, you must poll the deployment status until it succeeds. Do not assume the setup is complete immediately.

Post-Deployment: Model & Agent

After infrastructure provisioning succeeds:

  1. Deploy a model to the new AI Services account (e.g., gpt-4o). If GlobalStandard SKU quota is exhausted, fall back to Standard SKU.
  2. Create the agent using MCP tools (agent_update) or the Python SDK (client.agents.create_version). See SDK Operations for details.

References

Source: SKILL.md on GitHub

2 warnings3d4 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill provides a comprehensive environment for managing the end-to-end lifecycle of AI agents, models, and infrastructure on Microsoft Foundry. It includes sub-skills for deployment, evaluation, fine-tuning, and troubleshooting. The skill utilizes dynamic code execution and shell command wrappers, which are used within the context of local development and cloud orchestration. All external resources and dependencies originate from trusted organizations and well-known services.

  • Socket3d

    2 alerts: gptSecurity, gptAnomaly

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    36/36 files flagged

Signed by skilld at 04110d9. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated last week
metadata
{
  "author": "Microsoft",
  "version": "1.2.26"
}

README badge

README badge for microsoft/skills/microsoft-foundry