Azure AI Content Understanding analyzer copy: grantCopyAuthorization returns 200, but target-side copy fails with ModelNotFound / permission error

Björn Trier 0 Zuverlässigkeitspunkte
2026-07-01T07:55:29.2733333+00:00

Hi,

we are trying to copy custom Azure AI Content Understanding analyzers between Azure AI Foundry / Cognitive Services resources using the documented REST API flow.

Scenario

  • Source resource: Azure AI Foundry / Content Understanding resource in West Europe
  • Target resource 1: Azure AI Foundry / Content Understanding resource in West Europe
  • Target resource 2: Azure AI Foundry / Content Understanding resource in Sweden Central
  • All resources are in the same subscription and tenant
  • All resources are Microsoft.CognitiveServices/accounts / AIServices
  • The custom analyzer exists on the source resource
  • The source analyzer status is ready
  • The source analyzer can be read successfully via GET
  • The source analyzer uses:
    • completion model: gpt-5.2
    • embedding model: text-embedding-3-large
  • Both target resources have completion and embedding model deployments configured
  • Both target resources have /contentunderstanding/defaults configured
  • A user-assigned managed identity exists
  • The managed identity has Cognitive Services User assigned on:
    • the source resource
    • the West Europe target resource
    • the Sweden Central target resource
  • Public network access is enabled on all resources
  • We tested both:
    • *.services.ai.azure.com
    • *.cognitiveservices.azure.com

The REST calls are currently authenticated with API keys:

  • source resource key for the source-side grantCopyAuthorization call
  • target resource key for the target-side copy call

API version

The documented analyzer copy API uses:

api-version=2025-11-01

We also tested:

2025-05-01-preview

but that returns 404 for these analyzer copy endpoints.

We also checked whether a newer 2026-05-01 API version applies here, but that appears to belong to Azure AI Search / Content Understanding skill integration, not to the Content Understanding analyzer management API. For the analyzer copy endpoints, 2025-11-01 appears to be the current documented version.

Flow used

1. Read the source analyzer

GET:

https://source-resource.services.ai.azure.com/contentunderstanding/analyzers/analyzer-id?api-version=2025-11-01

Result:

HTTP 200
status: ready
models:
  completion: gpt-5.2
  embedding: text-embedding-3-large

So the analyzer definitely exists and is readable on the source resource.

2. Read target defaults

GET:

https://target-resource.services.ai.azure.com/contentunderstanding/defaults?api-version=2025-11-01

Result:

{
  "modelDeployments": {
    "gpt-5.2": "gpt-5.2",
    "prebuilt-analyzer-completion": "gpt-5.2",
    "prebuilt-analyzer-embedding": "text-embedding-3-large"
  }
}

The exact deployment names differ per target resource, but both targets have valid completion and embedding model mappings.

3. Call grantCopyAuthorization on the source analyzer

POST:

https://source-resource.services.ai.azure.com/contentunderstanding/analyzers/analyzer-id:grantCopyAuthorization?api-version=2025-11-01

Request body:

{
  "targetAzureResourceId": "/subscriptions/subscription-id/resourceGroups/resource-group/providers/Microsoft.CognitiveServices/accounts/target-resource",
  "targetRegion": "target-region"
}

We also tested this variant with targetIdentity:

{
  "targetAzureResourceId": "/subscriptions/subscription-id/resourceGroups/resource-group/providers/Microsoft.CognitiveServices/accounts/target-resource",
  "targetRegion": "target-region",
  "targetIdentity": {
    "type": "UserAssigned",
    "userAssignedIdentity": "/subscriptions/subscription-id/resourceGroups/resource-group/providers/Microsoft.ManagedIdentity/userAssignedIdentities/identity-name"
  }
}

The grantCopyAuthorization call returns HTTP 200.

Response shape:

{
  "targetAzureResourceId": "...",
  "targetRegion": "...",
  "expiresAt": "..."
}

Important observation:

The response does not contain a source property.

Some SDK/docs references describe source as part of the copy authorization object, but the REST response we receive only contains targetAzureResourceId, targetRegion, and expiresAt.

This happens consistently for:

  • same-region target
  • cross-region target
  • with targetIdentity
  • without targetIdentity
  • services.ai.azure.com
  • cognitiveservices.azure.com

4. Call copy on the target resource

Immediately after grantCopyAuthorization, we call copy on the target resource.

POST:

https://target-resource.services.ai.azure.com/contentunderstanding/analyzers/analyzer-id:copy?api-version=2025-11-01&allowReplace=true

Request body:

{
  "sourceAzureResourceId": "/subscriptions/subscription-id/resourceGroups/resource-group/providers/Microsoft.CognitiveServices/accounts/source-resource",
  "sourceAnalyzerId": "analyzer-id",
  "sourceRegion": "westeurope"
}

We use sourceRegion = westeurope because Azure AI Foundry / Azure Portal shows the source Content Understanding resource location as West Europe.

Actual result with sourceRegion = westeurope

Copying to the same-region West Europe target fails with:

{
  "error": {
    "code": "NotFound",
    "message": "Resource not found.",
    "innererror": {
      "code": "ModelNotFound",
      "message": "Source analyzer 'analyzer-id' was not found."
    }
  }
}

Copying to the Sweden Central target fails with:

{
  "error": {
    "code": "NotFound",
    "message": "Resource not found.",
    "innererror": {
      "code": "ModelNotFound",
      "message": "The resource 'source-resource-id' has not granted the necessary permissions for the source analyzer 'analyzer-id' to copy to the target resource."
    }
  }
}

This is confusing because the analyzer can be read successfully from the source immediately before the grant/copy flow.

Additional region test

Before aligning the config to the Azure Portal location, we also tested sourceRegion = germanywestcentral.

With that value, the copy operation reached a different failure mode:

{
  "error": {
    "code": "InternalServerError",
    "message": "An unexpected error occurred.",
    "innererror": {
      "code": "InternalResourceManagementError",
      "message": "Internal resource management error: InternalRM returned an Exception"
    }
  }
}

So we observed two different failure modes depending on sourceRegion:

sourceRegion = westeurope
=> Source analyzer not found / grant not accepted

sourceRegion = germanywestcentral
=> InternalResourceManagementError

The actual resource location shown in Azure AI Foundry / Azure Portal is West Europe, so we believe westeurope should be the correct value. However, the error behavior suggests there may be an internal region/routing mismatch.

What we verified

  • Source analyzer exists
  • Source analyzer GET returns HTTP 200
  • Source analyzer status is ready
  • Source analyzer uses supported models
  • Target resources exist
  • Target resources have completion deployments
  • Target resources have embedding deployments
  • Target /contentunderstanding/defaults returns valid mappings
  • User-assigned managed identity exists
  • Managed identity has Cognitive Services User on source and both targets
  • Public network access is enabled
  • grantCopyAuthorization returns HTTP 200
  • copy is called immediately after grantCopyAuthorization
  • Token expiration should not be the issue
  • API keys are resource-specific:
    • source key used against source resource
    • target key used against target resource
  • We tested grantCopyAuthorization with and without targetIdentity
  • We tested services.ai.azure.com and cognitiveservices.azure.com
  • We tested same-region copy and cross-region copy
  • We tested 2025-05-01-preview, which returns 404
  • We use 2025-11-01, which is the documented analyzer copy API version

Questions

  1. Is it expected that grantCopyAuthorization for API version 2025-11-01 returns HTTP 200 but does not include a source property?
  2. If the missing source property is expected, what exact request body should be sent to the target-side copy endpoint so that the authorization is accepted?
  3. If the missing source property is not expected, what configuration, permission, or authentication setup is required so that grantCopyAuthorization returns a complete authorization object?
  4. Is cross-resource copying of custom Content Understanding analyzers supported when the REST calls are authenticated with API keys?
  5. Does cross-resource analyzer copy require Entra ID / managed identity authentication instead of API-key authentication, even though the REST examples use Ocp-Apim-Subscription-Key?
  6. Should sourceRegion use the Azure Portal / ARM resource location, e.g. westeurope, or can Content Understanding have a different internal data-plane region?
  7. Why would sourceRegion = westeurope produce Source analyzer was not found, while another region value reaches InternalResourceManagementError?
  8. Are there known issues copying custom Content Understanding analyzers between Foundry resources in different regions or between resources created at different times / different Content Understanding generations?
  9. Is there a way to inspect which internal region or data-plane location a Content Understanding analyzer belongs to?
  10. What diagnostic information should we provide to Microsoft support beyond the x-ms-request-id values from grantCopyAuthorization and copy?

Thanks.

EDIT:

With my testing i would say :
Same-resource analyzer copy succeeds with 201 Created for the same analyzer. Cross-resource copy using the documented 2025-11-01 REST flow fails with 404 ModelNotFound: Source analyzer '<id>' was not found, although GET source analyzer returns 200 ready, grantCopyAuthorization returns 200, target defaults include the required model deployments, and the same Entra principal can read both resources. The grant response also does not include the documented source property.

Azure Content Understanding in Foundry Tools
Azure Content Understanding in Foundry Tools

Ein KI-Tool in Foundry für die Dokument- und Medienanalyse zum Klassifizieren von Inhalten, Extrahieren von Entitäten und Generieren von strukturiertem Verständnis

0 Kommentare Keine Kommentare

Ihre Antwort

Antworten können von Fragestellenden als „Angenommen“ und von Moderierenden als „Empfohlen“ gekennzeichnet werden, wodurch Benutzende wissen, dass diese Antwort das Problem des Fragestellenden gelöst hat.