Microsoft Foundry Skill
MANDATORY: Read this skill and the relevant sub-skill BEFORE calling any Foundry MCP tool.
Sub-Skills
| Sub-Skill |
When to Use |
Reference |
| deploy |
Containerize, build, push to ACR, create/update/start/stop/clone agent deployments |
deploy |
| invoke |
Send messages to an agent, single or multi-turn conversations |
invoke |
| observe |
Eval-driven optimization loop: evaluate → analyze → optimize → compare → iterate |
observe |
| trace |
Query traces, analyze latency/failures, correlate eval results to specific responses via App Insights customEvents |
trace |
| troubleshoot |
View container logs, query telemetry, diagnose failures |
troubleshoot |
| create |
Create new hosted agent applications. Supports Microsoft Agent Framework, LangGraph, or custom frameworks in Python or C#. Downloads starter samples from foundry-samples repo. |
create |
| eval-datasets |
Harvest production traces into evaluation datasets, manage dataset versions and splits, track evaluation metrics over time, detect regressions, and maintain full lineage from trace to deployment. Use for: create dataset from traces, dataset versioning, evaluation trending, regression detection, dataset comparison, eval lineage. |
eval-datasets |
| project/create |
Creating a new Azure AI Foundry project for hosting agents and models. Use when onboarding to Foundry or setting up new infrastructure. |
project/create/create-foundry-project.md |
| resource/create |
Creating Azure AI Services multi-service resource (Foundry resource) using Azure CLI. Use when manually provisioning AI Services resources with granular control. |
resource/create/create-foundry-resource.md |
| models/deploy-model |
Unified model deployment with intelligent routing. Handles quick preset deployments, fully customized deployments (version/SKU/capacity/RAI), and capacity discovery across regions. Routes to sub-skills: preset (quick deploy), customize (full control), capacity (find availability). |
models/deploy-model/SKILL.md |
| quota |
Managing quotas and capacity for Microsoft Foundry resources. Use when checking quota usage, troubleshooting deployment failures due to insufficient quota, requesting quota increases, or planning capacity. |
quota/quota.md |
| rbac |
Managing RBAC permissions, role assignments, managed identities, and service principals for Microsoft Foundry resources. Use for access control, auditing permissions, and CI/CD setup. |
rbac/rbac.md |
Onboarding flow: project/create → deploy → invoke
Agent Lifecycle
| Intent |
Workflow |
| New agent from scratch |
create → deploy → invoke |
| Deploy existing code |
deploy → invoke |
| Test/chat with agent |
invoke |
| Troubleshoot |
invoke → troubleshoot |
| Fix + redeploy |
troubleshoot → fix → deploy → invoke |
Project Context Resolution
Resolve only missing values. Extract from user message first, then azd, then ask.
- Check for
azure.yaml; if found, run azd env get-values
- Map azd variables:
| azd Variable |
Resolves To |
AZURE_AI_PROJECT_ENDPOINT / AZURE_AIPROJECT_ENDPOINT |
Project endpoint |
AZURE_CONTAINER_REGISTRY_NAME / AZURE_CONTAINER_REGISTRY_ENDPOINT |
ACR registry |
AZURE_SUBSCRIPTION_ID |
Subscription |
- Ask user only for unresolved values (project endpoint, agent name)
Validation
After each workflow step, validate before proceeding:
- Run the operation
- Check output for errors or unexpected results
- If failed → diagnose using troubleshoot sub-skill → fix → retry
- Only proceed to next step when validation passes
Agent Types
| Type |
Kind |
Description |
| Prompt |
"prompt" |
LLM-based, backed by model deployment |
| Hosted |
"hosted" |
Container-based, running custom code |
Agent: Setup Types
| Setup |
Capability Host |
Description |
| Basic |
None |
Default. All resources Microsoft-managed. |
| Standard |
Azure AI Services |
Bring-your-own storage and search (public network). See standard-agent-setup. |
| Standard + Private Network |
Azure AI Services |
Standard setup with VNet isolation and private endpoints. See private-network-standard-agent-setup. |
MANDATORY: For standard setup, read the appropriate reference before proceeding:
- Public network: references/standard-agent-setup.md
- Private network (VNet isolation): references/private-network-standard-agent-setup.md
Tool Usage Conventions
- Use the
ask_user or askQuestions tool whenever collecting information from the user
- Use the
task or runSubagent tool to delegate long-running or independent sub-tasks (e.g., env var scanning, status polling, Dockerfile generation)
- Prefer Azure MCP tools over direct CLI commands when available
- Reference official Microsoft documentation URLs instead of embedding CLI command syntax
References
Dependencies
Scripts in sub-skills require: Azure CLI (az) ≥2.0, jq (for shell scripts). Install via pip install azure-ai-projects azure-identity for Python SDK usage.
Reference Index
Load these on demand — do NOT read all at once:
| Reference |
When to Load |
references/auth-best-practices.md |
Auth Best Practices |
references/private-network-standard-agent-setup.md |
Private Network Standard Agent Setup |
references/standard-agent-setup.md |
Standard Agent Setup |
Source: jonathan-vella/apex — distributed by TomeVault.
1---2name: jonathan-vella-apex-microsoft-foundry3description: Microsoft Foundry Skill4---56# Microsoft Foundry Skill78> **MANDATORY:** Read this skill and the relevant sub-skill BEFORE calling any Foundry MCP tool.910## Sub-Skills1112| Sub-Skill | When to Use | Reference |13| ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- |14| **deploy** | Containerize, build, push to ACR, create/update/start/stop/clone agent deployments | [deploy](foundry-agent/deploy/deploy.md) |15| **invoke** | Send messages to an agent, single or multi-turn conversations | [invoke](foundry-agent/invoke/invoke.md) |16| **observe** | Eval-driven optimization loop: evaluate → analyze → optimize → compare → iterate | [observe](foundry-agent/observe/observe.md) |17| **trace** | Query traces, analyze latency/failures, correlate eval results to specific responses via App Insights `customEvents` | [trace](foundry-agent/trace/trace.md) |18| **troubleshoot** | View container logs, query telemetry, diagnose failures | [troubleshoot](foundry-agent/troubleshoot/troubleshoot.md) |19| **create** | Create new hosted agent applications. Supports Microsoft Agent Framework, LangGraph, or custom frameworks in Python or C#. Downloads starter samples from foundry-samples repo. | [create](foundry-agent/create/create.md) |20| **eval-datasets** | Harvest production traces into evaluation datasets, manage dataset versions and splits, track evaluation metrics over time, detect regressions, and maintain full lineage from trace to deployment. Use for: create dataset from traces, dataset versioning, evaluation trending, regression detection, dataset comparison, eval lineage. | [eval-datasets](foundry-agent/eval-datasets/eval-datasets.md) |21| **project/create** | Creating a new Azure AI Foundry project for hosting agents and models. Use when onboarding to Foundry or setting up new infrastructure. | [project/create/create-foundry-project.md](project/create/create-foundry-project.md) |22| **resource/create** | Creating Azure AI Services multi-service resource (Foundry resource) using Azure CLI. Use when manually provisioning AI Services resources with granular control. | [resource/create/create-foundry-resource.md](resource/create/create-foundry-resource.md) |23| **models/deploy-model** | Unified model deployment with intelligent routing. Handles quick preset deployments, fully customized deployments (version/SKU/capacity/RAI), and capacity discovery across regions. Routes to sub-skills: `preset` (quick deploy), `customize` (full control), `capacity` (find availability). | [models/deploy-model/SKILL.md](models/deploy-model/SKILL.md) |24| **quota** | Managing quotas and capacity for Microsoft Foundry resources. Use when checking quota usage, troubleshooting deployment failures due to insufficient quota, requesting quota increases, or planning capacity. | [quota/quota.md](quota/quota.md) |25| **rbac** | Managing RBAC permissions, role assignments, managed identities, and service principals for Microsoft Foundry resources. Use for access control, auditing permissions, and CI/CD setup. | [rbac/rbac.md](rbac/rbac.md) |2627Onboarding flow: `project/create` → `deploy` → `invoke`2829## Agent Lifecycle3031| Intent | Workflow |32| ---------------------- | ------------------------------------ |33| New agent from scratch | create → deploy → invoke |34| Deploy existing code | deploy → invoke |35| Test/chat with agent | invoke |36| Troubleshoot | invoke → troubleshoot |37| Fix + redeploy | troubleshoot → fix → deploy → invoke |3839## Project Context Resolution4041Resolve only missing values. Extract from user message first, then azd, then ask.42431. Check for `azure.yaml`; if found, run `azd env get-values`442. Map azd variables:4546| azd Variable | Resolves To |47| --------------------------------------------------------------------- | ---------------- |48| `AZURE_AI_PROJECT_ENDPOINT` / `AZURE_AIPROJECT_ENDPOINT` | Project endpoint |49| `AZURE_CONTAINER_REGISTRY_NAME` / `AZURE_CONTAINER_REGISTRY_ENDPOINT` | ACR registry |50| `AZURE_SUBSCRIPTION_ID` | Subscription |51523. Ask user only for unresolved values (project endpoint, agent name)5354## Validation5556After each workflow step, validate before proceeding:57581. Run the operation592. Check output for errors or unexpected results603. If failed → diagnose using troubleshoot sub-skill → fix → retry614. Only proceed to next step when validation passes6263## Agent Types6465| Type | Kind | Description |66| ---------- | ---------- | ------------------------------------- |67| **Prompt** | `"prompt"` | LLM-based, backed by model deployment |68| **Hosted** | `"hosted"` | Container-based, running custom code |6970## Agent: Setup Types7172| Setup | Capability Host | Description |73| ------------------------------ | ----------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |74| **Basic** | None | Default. All resources Microsoft-managed. |75| **Standard** | Azure AI Services | Bring-your-own storage and search (public network). See [standard-agent-setup](references/standard-agent-setup.md). |76| **Standard + Private Network** | Azure AI Services | Standard setup with VNet isolation and private endpoints. See [private-network-standard-agent-setup](references/private-network-standard-agent-setup.md). |7778> **MANDATORY:** For standard setup, read the appropriate reference before proceeding:79>80> - **Public network:** [references/standard-agent-setup.md](references/standard-agent-setup.md)81> - **Private network (VNet isolation):** [references/private-network-standard-agent-setup.md](references/private-network-standard-agent-setup.md)8283## Tool Usage Conventions8485- Use the `ask_user` or `askQuestions` tool whenever collecting information from the user86- Use the `task` or `runSubagent` tool to delegate long-running or independent sub-tasks (e.g., env var scanning, status polling, Dockerfile generation)87- Prefer Azure MCP tools over direct CLI commands when available88- Reference official Microsoft documentation URLs instead of embedding CLI command syntax8990## References9192- [Hosted Agents](https://learn.microsoft.com/azure/ai-foundry/agents/concepts/hosted-agents?view=foundry)93- [Runtime Components](https://learn.microsoft.com/azure/ai-foundry/agents/concepts/runtime-components?view=foundry)94- [Foundry Samples](https://github.com/azure-ai-foundry/foundry-samples)95- [Python SDK](references/sdk/foundry-sdk-py.md)9697## Dependencies9899Scripts in sub-skills require: Azure CLI (`az`) ≥2.0, `jq` (for shell scripts). Install via `pip install azure-ai-projects azure-identity` for Python SDK usage.100101## Reference Index102103Load these on demand — do NOT read all at once:104105| Reference | When to Load |106| ---------------------------------------------------- | ------------------------------------ |107| `references/auth-best-practices.md` | Auth Best Practices |108| `references/private-network-standard-agent-setup.md` | Private Network Standard Agent Setup |109| `references/standard-agent-setup.md` | Standard Agent Setup |110111---112> Source: [jonathan-vella/apex](https://github.com/jonathan-vella/apex) — distributed by [TomeVault](https://tomevault.io).113<!-- tomevault:4.0:skill_md:2026-06-15 -->