Microsoft Foundry
Microsoft Foundry is Microsoft's Azure platform for building AI apps and agents, with a large model catalogue, tools, testing and safety controls in one place.
Microsoft Foundry is where companies build AI apps and agents on Microsoft’s Azure cloud. An agent here means a model given instructions plus tools, so it can think through a request and then take an action. Foundry collects the pieces an agent needs: the models, the tools, the place it runs, and the checks that keep it honest and safe. It used to be called Azure AI Studio and then Azure AI Foundry.
Start with the models. Foundry’s catalogue sorts them into two groups. Models sold by Azure include every Azure OpenAI model plus selected models from other makers. Azure bills them through your Azure subscription (your paid Azure account). They come with service-level agreements, which are written promises about how well the service will run, and Microsoft supports them. Models from partners and community mostly come from outside organisations, such as partner companies and research labs. If Azure does not sell one, Microsoft’s terms call it a non-Microsoft product. That matters when you ask who helps if a model breaks.
Next come the agents. The simplest kind is a prompt agent: you write instructions, pick a model and tick the tools it may use, for example file search or searching the web. Foundry then runs it for you, so you write no server code. Teams that already have agent code, for example built with LangGraph, can package it as a container, a sealed bundle of code and settings. Foundry runs that as a hosted agent. It gets its own endpoint (a web address other programs can call), grows to handle more traffic, and has its own identity. Either way, you can swap the model without rewriting the agent.
Here is an everyday example. A bank wants a help agent that answers from its policy documents. The team picks a model, adds file search over those documents and writes instructions such as “only answer from policy”. Before a customer’s question reaches the model, a guardrail can scan it. A guardrail is a set of safety checks. The agent then searches the files and drafts an answer, and another check scans the reply before the customer sees it.
Finally, Foundry watches what happens. Tracing records each model call and tool call, so an engineer can see why a request was slow or wrong. Evaluators are automatic graders. They score answers for quality, safety and whether the agent used its tools correctly. Dashboards track token use (tokens are the small chunks of text a model reads and writes), speed, errors and quality scores over time. Builders can do all this in the Foundry portal, a website. Or they can write code with software kits for Python, C#, JavaScript or Java. Finished agents can be shared into Microsoft Teams and Microsoft Copilot.
Foundry does not make an AI system correct by itself. Its guardrails rely on classifier models, which are models that sort text and flag likely harm. A flag is a best guess, not a promise. Some agent checks are also still in preview, which means not finished yet. It also needs an Azure subscription, because it is a place to build AI apps rather than a chat app you open to ask questions.
Building a serious AI app means juggling many separate pieces.
Follow one agent from set-up to a checked answer.
- 1 · pickA builder chooses a model from the Foundry catalogue and writes instructions for the agent.
- 2 · equipThe builder attaches tools, for example searching the web, searching files or running code in a code interpreter.
- 3 · runThe agent runtime hosts the agent, manages the conversation and makes the tool calls.
- 4 · guardGuardrails can scan the user's input and the final output for harmful content.
- 5 · watchTracing and evaluations show each step the agent took and score the quality of its answers.
Foundry is the place the agent lives; the model inside it can be swapped without rewriting the agent.
| Who | What they ask | What it works with |
|---|---|---|
| Bank support team | “Can we build a help agent that answers from our own policy documents and hides harmful replies?” | A prompt agent with file search and guardrails |
| App developer | “Which model gives good answers for this task, and can we switch later?” | The Foundry model catalogue and evaluations |
| Platform engineer | “Why did the agent take so long on that request?” | Traces of model calls and tool calls |
| Team already using another agent framework | “Can Foundry run our existing LangGraph code?” | A hosted agent packaged as a container |
- It gathers agents, models and tools under one managed Azure resource.
- It can run a simple prompt agent for you with no application code or containers.
- It offers built-in evaluators for quality, safety and agent tool use.
- It lets teams apply identity, access control and content filters across a project.
- Guardrails reduce harmful content but rely on classifiers, so they are not a guarantee.
- Partner and community models that Azure does not sell count as non-Microsoft products under Microsoft's terms.
- Some features, such as agent guardrails, are still in preview.
- It needs an Azure subscription; it is not a free chat app for the public.
Sources used
This explainer is written in original language. The links below support its factual claims.
- docsWhat is Microsoft Foundry?, Microsoft Learn · read 28 Sept 2026
- docsAgents in Microsoft Foundry, Microsoft Learn · read 28 Sept 2026
- docsFoundry Models sold by Azure, Microsoft Learn · read 28 Sept 2026
- docsFoundry Models from partners and community, Microsoft Learn · read 28 Sept 2026
- docsObservability in generative AI, Microsoft Learn · read 28 Sept 2026
- docsGuardrails and controls overview in Microsoft Foundry, Microsoft Learn · read 28 Sept 2026