All skills
microsoft avatar

/microsoft-foundry

@04110d9
by microsoftmicrosoft/skills3.1k stars
351

Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end. USE FOR: foundry, azd ai agent, azd provision/deploy, hosted agent scaffold/develop/run/deploy/troubleshoot, prompt agent create, create agent, update agent, add tool to agent, invoke agent, agent.yaml, agent insights, pull agent insights, evaluate agent, batch eval, continuous eval, continuous monitoring, agent CI/CD, optimize prompt, improve prompt, prompt optimizer, optimize agent instructions, Agent Optimizer scaffold, dataset curation from traces, deploy model, model fine-tuning (SFT/DPO/RFT), Foundry project, RBAC, role assignment, permissions, quota, capacity, region, deployment failure, AI Services, create Foundry resource, knowledge index, customize deployment, onboard, availability, training-data, grader, distillation, large file upload. DO NOT USE FOR: Azure Functions, App Service, general Azure deploy (use azure-deploy), general Azure prep (use azure-prepare).

Use this Skill: https://skilld.dev/gh/microsoft/skills/microsoft-foundry

This session only. Nothing lands on disk.

resourceprivate-networkprivate-network.md

≈1.6k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Microsoft Foundry Private Networking

Quick Reference

Property Value
Best for Foundry with VNet isolation, private endpoints, subnet delegation, APIM + Foundry, VPN/Bastion access
Tools Azure CLI
MCP Tools AskUserQuestion - ask user questions; microsoft_docs_search - verify facts before presenting; microsoft_docs_fetch - fetch full Learn pages for validation
Workflow Ground in Learn → Gather → Plan → Scaffold → Validate → Deploy → Test

Key Documentation

Topic URL
Networking options (decision) https://learn.microsoft.com/azure/foundry/agents/concepts/networking-options
Network isolation https://learn.microsoft.com/azure/foundry/how-to/configure-private-link
Agent Service VNet https://learn.microsoft.com/azure/foundry/agents/how-to/virtual-networks
Networking deep dive (subnet/IP) https://learn.microsoft.com/azure/foundry/agents/concepts/agents-networking-deep-dive
Managed VNet https://learn.microsoft.com/azure/foundry/how-to/managed-virtual-network
Feature limitations https://learn.microsoft.com/azure/foundry/how-to/configure-private-link#foundry-feature-limitations

When to Use

  • User asks about Foundry networking, private endpoints, or VNet isolation
  • User asks about BYO VNet, Managed VNet, or hybrid patterns
  • User wants to deploy Foundry agents in a private network
  • User needs APIM integration with private Foundry agents

Do NOT use for:


Step 0 — Ground in Microsoft Learn

Use microsoft_docs_fetch to get docs from Key Documentation sources. Use microsoft_docs_search to verify any technical fact before presenting it to the user. If Learn contradicts a reference file, Learn wins. Cite the URL. If Learn doesn't cover it, say so — do not invent facts, limits, flags, or compatibility claims.


End-to-End Deployment Workflow

Important: All following steps are mandatory. Communicate the plan with the user before acting.

Step 1 — Gather Requirements

Read references/intake.md. One pass, three tiers:

  • Tier 1 (Core): Subscription, VNet model, agents, region, RG, VNet — determine approach at the end
  • Tier 2 (Architecture): DNS, topology, NSG, on-prem, identity, BYO resources
  • Tier 3 (Enterprise): Model, client access, auth, policies, monitoring

Determine the approach (official template / adapt closest / extend user’s IaC) at the end of Tier 1. Continue through Tiers 2–3.


Step 2 — Plan Generation

Use the confirmed requirements from references/intake.md.

OFFICIAL path: Load the template's README from its GitHub URL (via references/template-index.md). Run microsoft_docs_search for its prerequisites. Present a deployment plan using the user's actual values.

ADAPT path: Load the closest template's README. Present a deployment plan highlighting what will be modified from the base template.

EXTEND path: Load references/custom-template-adaptation.md. Read the user's existing template. Follow the gap analysis framework to present what's covered, what's missing, and any issues. Get approval before modifying.

Get confirmation before proceeding.


Step 3 — Scaffold & Parameterize

Read references/scaffold.md.


Step 4 — Pre-Deployment Validation

Catch blockers before deploying. These checks apply to all paths.

Sovereign cloud: Run az cloud show --query name -o tsv. If AzureUSGovernment or AzureChinaCloud, check whether the templates being used (official or user-provided) handle sovereign cloud endpoints. Official templates hardcode core.windows.net and Azure Public AAD endpoints.

RBAC: Verify deploying identity has Owner, or Contributor + User Access Administrator.

Policy: Run az deployment group what-if. Fix any violations before deploying.

Quota:

az cognitiveservices account list-skus --location <region> --kind AIServices -o table

Provider Registrations: Microsoft.CognitiveServices, Microsoft.DocumentDB, Microsoft.Search, Microsoft.Network, and Microsoft.App (required for agent subnet delegation). The template README lists the authoritative set.

Do NOT deploy until all pre-flight checks pass.


Step 5 — Deploy & Track

OFFICIAL / ADAPT path: Read references/deploy.md for deployment command, monitoring, and error recovery.

EXTEND path: Deploy using the user's existing deployment workflow (their CLI commands, pipeline, or CI/CD). The monitoring and error recovery guidance in references/deploy.md still applies.


Step 6 — Test & Validate

Read references/post-deployment-validation.md. These checks apply to all paths — PE verification, RBAC audit, publicNetworkAccess audit, and end-to-end agent test work regardless of how the infrastructure was deployed.

If any test fails, run microsoft_docs_search for the error before attempting remediation.


Error Handling

⚠️ Critical retry rule: If a deployment fails after the capability host step starts, a service association (legionservicelink) stays on the agent subnet. Simplest retry: use a new VNet name. To reuse the same subnet, first purge the account and delete the capability host, then wait for the link to clear before redeploying. See references/deploy.md.

For all other errors, check microsoft_docs_search for current remediation before acting.

Source: SKILL.md on GitHub

2 warnings3d4 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill provides a comprehensive environment for managing the end-to-end lifecycle of AI agents, models, and infrastructure on Microsoft Foundry. It includes sub-skills for deployment, evaluation, fine-tuning, and troubleshooting. The skill utilizes dynamic code execution and shell command wrappers, which are used within the context of local development and cloud orchestration. All external resources and dependencies originate from trusted organizations and well-known services.

  • Socket3d

    2 alerts: gptSecurity, gptAnomaly

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    36/36 files flagged

Signed by skilld at 04110d9. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 19 hours ago.

Activeupdated last week
metadata
{
  "author": "Microsoft",
  "version": "1.2.26"
}

README badge

README badge for microsoft/skills/microsoft-foundry