Network and security for AI workloads: a private endpoint closes the entrance, not the exit

A private endpoint controls ingress; it authenticates nobody and does not decide where the agent writes afterwards. The three boundaries of an AI workload — entrance, identity, and exit —, the three DNS zones Foundry requires, the roles that were renamed, and the egress control almost every project leaves open.

Continue ReadingNetwork and security for AI workloads: a private endpoint closes the entrance, not the exit

Guardrails and agent evaluation: what separates a demo from a production system

Guardrails contain at runtime; evaluation measures over time — and neither does the other's job. Content Safety, Prompt Shields, evaluators that see the tool call and not just the answer, red teaming with PyRIT, and the maturity signal that separates a demo from a system: a deployment blocked by a number.

Continue ReadingGuardrails and agent evaluation: what separates a demo from a production system

Model Context Protocol (MCP): the standard that connects AI agents to tools and data

MCP has become the open standard for connecting AI agents to tools and data. What it is, what changed in detail in revision 2026-07-28 - stateless protocol, no sessions or initialize, subscriptions/listen, no SSE resumability, extensions and OAuth - with a migration checklist and how to host it on Azure.

Continue ReadingModel Context Protocol (MCP): the standard that connects AI agents to tools and data