All skills
microsoft avatar

/microsoft-foundry

@04110d9
by microsoftmicrosoft/skills3.1k stars
351

Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end. USE FOR: foundry, azd ai agent, azd provision/deploy, hosted agent scaffold/develop/run/deploy/troubleshoot, prompt agent create, create agent, update agent, add tool to agent, invoke agent, agent.yaml, agent insights, pull agent insights, evaluate agent, batch eval, continuous eval, continuous monitoring, agent CI/CD, optimize prompt, improve prompt, prompt optimizer, optimize agent instructions, Agent Optimizer scaffold, dataset curation from traces, deploy model, model fine-tuning (SFT/DPO/RFT), Foundry project, RBAC, role assignment, permissions, quota, capacity, region, deployment failure, AI Services, create Foundry resource, knowledge index, customize deployment, onboard, availability, training-data, grader, distillation, large file upload. DO NOT USE FOR: Azure Functions, App Service, general Azure deploy (use azure-deploy), general Azure prep (use azure-prepare).

Use this Skill: https://skilld.dev/gh/microsoft/skills/microsoft-foundry

This session only. Nothing lands on disk.

resourcecreatereferencesworkflows.md

≈1.7k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Detailed Workflows: Create Foundry Resource

Table of Contents: Workflow 1: Create Resource Group · Workflow 2: Create Foundry Resource · Workflow 3: Register Resource Provider

Workflow 1: Create Resource Group - Detailed Steps

Step 1: Ask user preference

Ask the user which option they prefer:

  1. Use an existing resource group
  2. Create a new resource group

Step 2a: If user chooses "Use existing resource group"

Count and list existing resource groups:

# Count total resource groups
TOTAL_RG_COUNT=$(az group list --query "length([])" -o tsv)

# Get list of resource groups (up to 5 most recent)
az group list --query "[-5:].{Name:name, Location:location}" --out table

Handle based on count:

If 0 resources found:

  • Inform user: "No existing resource groups found"
  • Ask if they want to create a new one, then proceed to Step 2b

If 1-4 resources found:

  • Display all X resource groups to the user
  • Let user select from the list
  • Fetch the selected resource group details:
    az group show --name <selected-rg-name> --query "{Name:name, Location:location, State:properties.provisioningState}"
  • Display details to user, then proceed to create Foundry resource

If 5+ resources found:

  • Display the 5 most recent resource groups
  • Present options:
    1. Select from the 5 displayed
    2. Other (see all resource groups)
  • If user selects a resource group, fetch details:
    az group show --name <selected-rg-name> --query "{Name:name, Location:location, State:properties.provisioningState}"
  • If user chooses "Other", show all:
    az group list --query "[].{Name:name, Location:location}" --out table
    Then let user select, and fetch details as above
  • Display details to user, then proceed to create Foundry resource

Step 2b: If user chooses "Create new resource group"

  1. List available Azure regions:
az account list-locations --query "[].{Region:name}" --out table

Common regions:

  • eastus, eastus2 - US East Coast
  • westus, westus2, westus3 - US West Coast
  • centralus - US Central
  • westeurope, northeurope - Europe
  • southeastasia, eastasia - Asia Pacific
  1. Ask user to choose a region from the list above

  2. Create resource group in the chosen region:

az group create \
  --name <resource-group-name> \
  --location <user-chosen-location>
  1. Verify creation:
az group show --name <resource-group-name> --query "{Name:name, Location:location, State:properties.provisioningState}"

Expected output: State: "Succeeded"

Workflow 2: Create Foundry Resource - Detailed Steps

Step 1: Verify prerequisites

# Check Azure CLI version (need 2.0+)
az --version

# Verify authentication
az account show

# Check resource provider registration status
az provider show --namespace Microsoft.CognitiveServices --query "registrationState"

If provider not registered, see Workflow #3: Register Resource Provider.

Step 2: Choose location

Always ask the user to choose a location. List available regions and let the user select:

# List available regions for Cognitive Services
az account list-locations --query "[].{Region:name, DisplayName:displayName}" --out table

Common regions for AI Services:

  • eastus, eastus2 - US East Coast
  • westus, westus2, westus3 - US West Coast
  • centralus - US Central
  • westeurope, northeurope - Europe
  • southeastasia, eastasia - Asia Pacific

Important: Do not automatically use the resource group's location. Always ask the user which region they prefer.

Step 3: Create Foundry resource

az cognitiveservices account create \
  --name <resource-name> \
  --resource-group <rg> \
  --kind AIServices \
  --sku S0 \
  --location <location> \
  --yes

Parameters:

  • --name: Unique resource name (globally unique across Azure)
  • --resource-group: Existing resource group name
  • --kind: Must be AIServices for multi-service resource
  • --sku: Must be S0 (Standard - the only supported tier for AIServices)
  • --location: Azure region (always ask user to choose from available regions)
  • --yes: Auto-accept terms without prompting

Step 4: Verify resource creation

# Check resource details to verify creation
az cognitiveservices account show \
  --name <resource-name> \
  --resource-group <rg>

# View endpoint and configuration
az cognitiveservices account show \
  --name <resource-name> \
  --resource-group <rg> \
  --query "{Name:name, Endpoint:properties.endpoint, Location:location, Kind:kind, SKU:sku.name}"

Expected output:

  • provisioningState: "Succeeded"
  • Endpoint URL
  • SKU: S0
  • Kind: AIServices

Step 5: Get access keys

az cognitiveservices account keys list \
  --name <resource-name> \
  --resource-group <rg>

This returns key1 and key2 for API authentication.

Workflow 3: Register Resource Provider - Detailed Steps

When Needed

Required when:

  • First time creating Cognitive Services in subscription
  • Error: ResourceProviderNotRegistered
  • Insufficient permissions during resource creation

Steps

Step 1: Check registration status

az provider show \
  --namespace Microsoft.CognitiveServices \
  --query "registrationState"

Possible states:

  • Registered: Ready to use
  • NotRegistered: Needs registration
  • Registering: Registration in progress

Step 2: Register provider

az provider register --namespace Microsoft.CognitiveServices

Step 3: Wait for registration

Registration typically takes 1-2 minutes. Check status:

az provider show \
  --namespace Microsoft.CognitiveServices \
  --query "registrationState"

Wait until state is Registered.

Step 4: Verify registration

az provider list --query "[?namespace=='Microsoft.CognitiveServices']"

Required Permissions

To register a resource provider, you need one of:

  • Subscription Owner role
  • Contributor role
  • Custom role with Microsoft.*/register/action permission

If you are not the subscription owner:

  1. Ask someone with the Owner or Contributor role to register the provider for you
  2. Alternatively, ask them to grant you the /register/action privilege so you can register it yourself

Alternative registration methods:

  • Azure CLI (recommended): az provider register --namespace Microsoft.CognitiveServices
  • Azure Portal: Navigate to Subscriptions → Resource providers → Microsoft.CognitiveServices → Register
  • PowerShell: Register-AzResourceProvider -ProviderNamespace Microsoft.CognitiveServices

Source: SKILL.md on GitHub

2 warnings3d4 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill provides a comprehensive environment for managing the end-to-end lifecycle of AI agents, models, and infrastructure on Microsoft Foundry. It includes sub-skills for deployment, evaluation, fine-tuning, and troubleshooting. The skill utilizes dynamic code execution and shell command wrappers, which are used within the context of local development and cloud orchestration. All external resources and dependencies originate from trusted organizations and well-known services.

  • Socket3d

    2 alerts: gptSecurity, gptAnomaly

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    36/36 files flagged

Signed by skilld at 04110d9. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated last week
metadata
{
  "author": "Microsoft",
  "version": "1.2.26"
}

README badge

README badge for microsoft/skills/microsoft-foundry