All skills
microsoft avatar

/microsoft-foundry

@04110d9
by microsoftmicrosoft/skills3.1k stars
351

Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end. USE FOR: foundry, azd ai agent, azd provision/deploy, hosted agent scaffold/develop/run/deploy/troubleshoot, prompt agent create, create agent, update agent, add tool to agent, invoke agent, agent.yaml, agent insights, pull agent insights, evaluate agent, batch eval, continuous eval, continuous monitoring, agent CI/CD, optimize prompt, improve prompt, prompt optimizer, optimize agent instructions, Agent Optimizer scaffold, dataset curation from traces, deploy model, model fine-tuning (SFT/DPO/RFT), Foundry project, RBAC, role assignment, permissions, quota, capacity, region, deployment failure, AI Services, create Foundry resource, knowledge index, customize deployment, onboard, availability, training-data, grader, distillation, large file upload. DO NOT USE FOR: Azure Functions, App Service, general Azure deploy (use azure-deploy), general Azure prep (use azure-prepare).

Use this Skill: https://skilld.dev/gh/microsoft/skills/microsoft-foundry

This session only. Nothing lands on disk.

resourceprivate-networkreferencesintake.md

≈1.7k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Intake

Collect all inputs in one pass, tiered by priority. Extract implicit answers from the user’s message before asking. Use AskUserQuestion for unanswered items — batch related questions.


Tier 1 — Core

1.0 Verify Subscription

Run:

az account show --query "{Name:name, Id:id, State:state}" -o table

Confirm with user. Switch if needed:

az account set --subscription "<name-or-id>"

1.1 Extract Known Answers

Scan the user's message before asking:

User Says Inferred
"my existing VNet" / "my VNet" BYO VNet
"managed virtual network" Managed VNet
"user-assigned identity" / "UAI" User-assigned identity
"APIM" / "API Management" Needs APIM
"MCP servers on the VNet" Needs MCP subnet
"I have a Bicep/Terraform template" Extend existing IaC
"add Foundry to my existing infra" Extend existing IaC

1.2 Architecture Questions

For unanswered items, use AskUserQuestion:

VNet model: BYO VNet or Managed VNet?

Agents: Agent workloads, or just models/projects?

Region: Which Azure region? After answer, verify capacity:

az cognitiveservices account list-skus --location <region> --kind AIServices -o table

If empty, warn the user and suggest alternatives.

Resource Group: New or existing?

VNet: New or existing? If new: address space (default 192.168.0.0/16), subnet CIDRs (agent /24, PE /24).

1.3 Determine Approach

Based on the answers collected, select one of three paths:

User has existing IaC they want to extend?
├── Yes → EXTEND
│
└── No → check template-index.md
    ├── Template fits as-is → OFFICIAL
    └── Partial or no fit → ADAPT (start from closest template)

OFFICIAL: Load template-index.md, fetch the best-fit README from GitHub. Present the match using the template's descriptive name.

ADAPT: Fetch the closest template's README. Explain what doesn't fit, present the delta, offer to adapt.

EXTEND: The user has existing Bicep/Terraform — no template selection needed yet. Continue to Tier 2.

Confirm the approach with the user before continuing to Tier 2.


Tier 2 — Architecture

Skip questions already answered or not applicable.

BYO VNet only

Topology: Standalone, hub-spoke, or Azure vWAN?

On-prem connectivity: VPN Gateway, ExpressRoute, or none?

DNS: Azure-provided, custom DNS resolver, or on-prem DNS forwarding?

Address space: Is 192.168.0.0/16 available, or use a specific range?

NSG / Firewall: Existing rules on the subnets?

Deployment executor: Where will post-deployment commands run? (VM, Bastion, VPN, Cloud Shell)

Subscription scope: Same subscription/tenant, cross-subscription, or cross-tenant?

Team ownership: Same team controls VNet, DNS, NSG, and policy? If different team, block and get pre-approval before deploying.

Managed VNet only

Outbound mode: Internet outbound (default) or approved outbound only?

MCP: Public MCP endpoints or private MCP on VNet?

Client access: Where will clients connect from? (Same VNet, peered VNet, on-prem via VPN/ER, Azure-hosted service)

Both paths

MCP servers: Needed on VNet?

APIM: Needed?

Identity: System-assigned (default) or user-assigned?

BYO resources: Reuse existing Cosmos DB / Storage / AI Search, or create new?

If reusing, confirm all in same region as VNet. If reusing AI Search, it must accept Entra ID (AAD) data-plane auth — a key-only service makes agents fail with HTTP 403. Enable with az search service update --name <search-name> --resource-group <search-rg> --auth-options aadOrApiKey --aad-auth-failure-mode http401WithBearerChallenge.

Key Vault / App Insights: If user mentions existing ones, collect resource IDs. Optional.


Tier 3 — Enterprise

Agent tools: Which tools? (AI Search, Cosmos DB, Storage, MCP, external APIs, Bing grounding, Code Interpreter)

Model: Name, vendor, version. Verify version format:

Vendor Format Example
OpenAI Date 2025-04-14
Mistral AI Integer 1
Meta Integer 9

Client type: SDK, web app, Teams bot, other service?

Client network path: Inside VNet, peered VNet, VPN/ExpressRoute?

Authentication: Entra ID (recommended) or API key?

Entra ID token audience for Foundry Agents API: https://ai.azure.com

GitHub access: Can deployment environment reach github.com? If not, pre-stage template.

Azure Policy: Known policies (e.g., disableLocalAuth, defaultOutboundAccess)? If unknown, what-if catches them in Step 4.

Monitoring: Existing Log Analytics workspace, create new, or not needed?


Validate Against Learn

After collecting all requirements, validate the user's configuration against current documentation. Use microsoft_docs_fetch on the relevant pages below, then microsoft_docs_search for any requirement-specific concerns not covered.

Reference Pages

Topic URL
Networking options (decision) https://learn.microsoft.com/azure/foundry/agents/concepts/networking-options
Network isolation overview https://learn.microsoft.com/azure/foundry/how-to/configure-private-link
Agent Service private networking https://learn.microsoft.com/azure/foundry/agents/how-to/virtual-networks
Networking deep dive (subnet/IP) https://learn.microsoft.com/azure/foundry/agents/concepts/agents-networking-deep-dive
Managed VNet configuration https://learn.microsoft.com/azure/foundry/how-to/managed-virtual-network
Agent Service FAQ — VNet https://learn.microsoft.com/azure/foundry/agents/faq#virtual-networking
Supported regions & availability https://learn.microsoft.com/azure/foundry/reference/region-support
NSP https://learn.microsoft.com/azure/foundry/how-to/add-foundry-to-network-security-perimeter
Feature Limitations https://learn.microsoft.com/en-us/azure/foundry/how-to/configure-private-link#foundry-feature-limitations

These URLs may change. If a fetch returns 404, use microsoft_docs_search to find the current page.

If a conflict is found, present:

  1. The constraint and its source URL
  2. Which requirement it affects
  3. Options to resolve

Do NOT proceed until all conflicts are resolved or accepted.


Confirmation

Present a summary of all gathered requirements. Ask: "Confirm this is accurate before I generate a deployment plan."

Do NOT proceed to Plan Generation until you validated requirements against documents and the user confirms.

Source: SKILL.md on GitHub

2 warnings3d4 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill provides a comprehensive environment for managing the end-to-end lifecycle of AI agents, models, and infrastructure on Microsoft Foundry. It includes sub-skills for deployment, evaluation, fine-tuning, and troubleshooting. The skill utilizes dynamic code execution and shell command wrappers, which are used within the context of local development and cloud orchestration. All external resources and dependencies originate from trusted organizations and well-known services.

  • Socket3d

    2 alerts: gptSecurity, gptAnomaly

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    36/36 files flagged

Signed by skilld at 04110d9. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated last week
metadata
{
  "author": "Microsoft",
  "version": "1.2.26"
}

README badge

README badge for microsoft/skills/microsoft-foundry