Microsoft Foundry and Azure OpenAI
Microsoft Foundry and Azure OpenAI
The models running in your own Azure subscription, behind your own identity and network.
What this is
Microsoft Foundry (formerly Azure AI Foundry) is the place Microsoft puts models inside Azure. It carries OpenAI's models alongside Anthropic, Meta, Mistral and Microsoft's own, behind one resource, one permission model and one network boundary.
It is not a chat product. It is the platform a chat product would be built on, which is why it can be pointed at your documents and wired into your systems.
The subscription is yours. CloudCentric builds and administers it, and the resources and the data sit under your company's name.
What you get
What the deployment involves
The work is the environment around the model, not the model.
Subscription and landing zone
Where the resources live, how they are grouped, what policy applies to them and how the spend is attributed.
Private networking
Private endpoints so the model is reachable from your network and not from the public internet, with DNS that resolves correctly from every place that needs it.
Identity instead of keys
Managed identity and Entra role assignments, so access is granted to named people and services rather than to a key somebody pasted into a config file.
Retrieval over your content
Azure AI Search indexing the documents that matter, with the chunking and refresh strategy chosen for how that content actually changes.
Deployment type and data residency
Standard, data zone or provisioned, chosen for where processing must happen and how predictable the throughput needs to be.
Monitoring and spend
Request logging, latency and token spend visible per application, so usage is attributable.
How it works
How the work runs
Look at the tenant
Subscriptions, identity, network position and what the licensing already covers.
Stand up the environment
Resources, policy, networking and identity, before any application work starts.
Connect the content
Indexing the documents, with permissions checked before anything is readable.
Hand over with the controls on
Monitoring, spend reporting and a named migration plan for the model versions in use.
In practice
What gets built on it
Foundry is the platform. These are the things that end up running on it.
An answer desk over SharePoint
Staff ask a question in Teams and get an answer with the document named. Azure AI Search does the retrieval, Entra decides what each person is allowed to see.
Agents that reach a business system
Work that goes past Microsoft content — checking a job in the practice system, pulling a balance from accounting — which is where the retail Copilot licence stops.
Document extraction at volume
A recurring document type read into fields, with the review screen and the write-back running in the same subscription.
A private endpoint for internal tools
One governed model endpoint that internal applications call, instead of several teams each signing up for their own consumer account.
What matters
The parts that take the time
None of this is switch-flipping, and the difficulty is where the value is.
Model retirement is scheduled by the vendor
Deployed models carry published retirement dates on a roughly 18-month cycle. Part of the handover is knowing which versions are in use and when they move.
Locking down the network breaks things in order
Private endpoints change how every dependent service resolves the model. Doing it after the applications are live means finding each break one at a time.
Quota is subscription-scoped and finite
Requests and tokens per minute are capped and the model changed in 2026. Capacity gets checked against the real workload before anything is designed around it.
Permission sprawl becomes visible immediately
Retrieval returns what the person asking is entitled to see, so a decade of accumulated SharePoint access gets reviewed first.
Chunking decides answer quality
How documents are split and what metadata rides along with each piece does more for answer quality than the choice of model.
Content changes mean re-indexing
The index is a copy. How often it rebuilds, and what that costs, is a design decision made at the start.
Who it is for
When Foundry is the right answer
You are already on Microsoft 365
The identity system and much of the licensing are in place, which is most of the groundwork.
The data cannot leave your control
Professional firms and anyone with client confidentiality obligations.
It has to reach a business system
Work that goes past Microsoft content and into a line-of-business application.
You want one place to change models
Several model families behind one resource and one permission model.
Questions
Frequently asked questions
Is this the same as Microsoft 365 Copilot?
No. Copilot is a per-user licence that works across your Microsoft content. Foundry is the platform for building something specific to your business, including work Copilot cannot reach.
Is our data used to train Microsoft's models?
No. Microsoft states that prompts, completions and embeddings are not used to train foundation models without your permission or instruction.
Does it have to be Azure?
No. Where the estate is already on AWS, Bedrock is usually the better answer for the same reasons.
Who owns the subscription?
Your company. CloudCentric administers it; the resources and the billing sit under your name.
What happens when a model is retired?
The replacement is tested against the same evaluation set before the switch, so the change is measured rather than hoped for.
Is CloudCentric a Microsoft partner?
Yes, CloudCentric is enrolled in the Microsoft partner programme and administers Microsoft 365 tenants for clients across the Lowcountry.
Also on this site
Talk about your tenant
What is already in place usually decides how much of this there is to do.
(844) 422-7000