Ein KI-Tool in Foundry für die Dokument- und Medienanalyse zum Klassifizieren von Inhalten, Extrahieren von Entitäten und Generieren von strukturiertem Verständnis
Azure AI Content Understanding analyzer copy: grantCopyAuthorization returns 200, but target-side copy fails with ModelNotFound / permission error
Hi,
we are trying to copy custom Azure AI Content Understanding analyzers between Azure AI Foundry / Cognitive Services resources using the documented REST API flow.
Scenario
- Source resource: Azure AI Foundry / Content Understanding resource in West Europe
- Target resource 1: Azure AI Foundry / Content Understanding resource in West Europe
- Target resource 2: Azure AI Foundry / Content Understanding resource in Sweden Central
- All resources are in the same subscription and tenant
- All resources are
Microsoft.CognitiveServices/accounts/AIServices - The custom analyzer exists on the source resource
- The source analyzer status is
ready - The source analyzer can be read successfully via
GET - The source analyzer uses:
- completion model:
gpt-5.2 - embedding model:
text-embedding-3-large
- completion model:
- Both target resources have completion and embedding model deployments configured
- Both target resources have
/contentunderstanding/defaultsconfigured - A user-assigned managed identity exists
- The managed identity has
Cognitive Services Userassigned on:- the source resource
- the West Europe target resource
- the Sweden Central target resource
- Public network access is enabled on all resources
- We tested both:
-
*.services.ai.azure.com -
*.cognitiveservices.azure.com
-
The REST calls are currently authenticated with API keys:
- source resource key for the source-side
grantCopyAuthorizationcall - target resource key for the target-side
copycall
API version
The documented analyzer copy API uses:
api-version=2025-11-01
We also tested:
2025-05-01-preview
but that returns 404 for these analyzer copy endpoints.
We also checked whether a newer 2026-05-01 API version applies here, but that appears to belong to Azure AI Search / Content Understanding skill integration, not to the Content Understanding analyzer management API. For the analyzer copy endpoints, 2025-11-01 appears to be the current documented version.
Flow used
1. Read the source analyzer
GET:
https://source-resource.services.ai.azure.com/contentunderstanding/analyzers/analyzer-id?api-version=2025-11-01
Result:
HTTP 200
status: ready
models:
completion: gpt-5.2
embedding: text-embedding-3-large
So the analyzer definitely exists and is readable on the source resource.
2. Read target defaults
GET:
https://target-resource.services.ai.azure.com/contentunderstanding/defaults?api-version=2025-11-01
Result:
{
"modelDeployments": {
"gpt-5.2": "gpt-5.2",
"prebuilt-analyzer-completion": "gpt-5.2",
"prebuilt-analyzer-embedding": "text-embedding-3-large"
}
}
The exact deployment names differ per target resource, but both targets have valid completion and embedding model mappings.
3. Call grantCopyAuthorization on the source analyzer
POST:
https://source-resource.services.ai.azure.com/contentunderstanding/analyzers/analyzer-id:grantCopyAuthorization?api-version=2025-11-01
Request body:
{
"targetAzureResourceId": "/subscriptions/subscription-id/resourceGroups/resource-group/providers/Microsoft.CognitiveServices/accounts/target-resource",
"targetRegion": "target-region"
}
We also tested this variant with targetIdentity:
{
"targetAzureResourceId": "/subscriptions/subscription-id/resourceGroups/resource-group/providers/Microsoft.CognitiveServices/accounts/target-resource",
"targetRegion": "target-region",
"targetIdentity": {
"type": "UserAssigned",
"userAssignedIdentity": "/subscriptions/subscription-id/resourceGroups/resource-group/providers/Microsoft.ManagedIdentity/userAssignedIdentities/identity-name"
}
}
The grantCopyAuthorization call returns HTTP 200.
Response shape:
{
"targetAzureResourceId": "...",
"targetRegion": "...",
"expiresAt": "..."
}
Important observation:
The response does not contain a source property.
Some SDK/docs references describe source as part of the copy authorization object, but the REST response we receive only contains targetAzureResourceId, targetRegion, and expiresAt.
This happens consistently for:
- same-region target
- cross-region target
- with
targetIdentity - without
targetIdentity -
services.ai.azure.com -
cognitiveservices.azure.com
4. Call copy on the target resource
Immediately after grantCopyAuthorization, we call copy on the target resource.
POST:
https://target-resource.services.ai.azure.com/contentunderstanding/analyzers/analyzer-id:copy?api-version=2025-11-01&allowReplace=true
Request body:
{
"sourceAzureResourceId": "/subscriptions/subscription-id/resourceGroups/resource-group/providers/Microsoft.CognitiveServices/accounts/source-resource",
"sourceAnalyzerId": "analyzer-id",
"sourceRegion": "westeurope"
}
We use sourceRegion = westeurope because Azure AI Foundry / Azure Portal shows the source Content Understanding resource location as West Europe.
Actual result with sourceRegion = westeurope
Copying to the same-region West Europe target fails with:
{
"error": {
"code": "NotFound",
"message": "Resource not found.",
"innererror": {
"code": "ModelNotFound",
"message": "Source analyzer 'analyzer-id' was not found."
}
}
}
Copying to the Sweden Central target fails with:
{
"error": {
"code": "NotFound",
"message": "Resource not found.",
"innererror": {
"code": "ModelNotFound",
"message": "The resource 'source-resource-id' has not granted the necessary permissions for the source analyzer 'analyzer-id' to copy to the target resource."
}
}
}
This is confusing because the analyzer can be read successfully from the source immediately before the grant/copy flow.
Additional region test
Before aligning the config to the Azure Portal location, we also tested sourceRegion = germanywestcentral.
With that value, the copy operation reached a different failure mode:
{
"error": {
"code": "InternalServerError",
"message": "An unexpected error occurred.",
"innererror": {
"code": "InternalResourceManagementError",
"message": "Internal resource management error: InternalRM returned an Exception"
}
}
}
So we observed two different failure modes depending on sourceRegion:
sourceRegion = westeurope
=> Source analyzer not found / grant not accepted
sourceRegion = germanywestcentral
=> InternalResourceManagementError
The actual resource location shown in Azure AI Foundry / Azure Portal is West Europe, so we believe westeurope should be the correct value. However, the error behavior suggests there may be an internal region/routing mismatch.
What we verified
- Source analyzer exists
- Source analyzer
GETreturns HTTP200 - Source analyzer status is
ready - Source analyzer uses supported models
- Target resources exist
- Target resources have completion deployments
- Target resources have embedding deployments
- Target
/contentunderstanding/defaultsreturns valid mappings - User-assigned managed identity exists
- Managed identity has
Cognitive Services Useron source and both targets - Public network access is enabled
-
grantCopyAuthorizationreturns HTTP200 -
copyis called immediately aftergrantCopyAuthorization - Token expiration should not be the issue
- API keys are resource-specific:
- source key used against source resource
- target key used against target resource
- We tested
grantCopyAuthorizationwith and withouttargetIdentity - We tested
services.ai.azure.comandcognitiveservices.azure.com - We tested same-region copy and cross-region copy
- We tested
2025-05-01-preview, which returns404 - We use
2025-11-01, which is the documented analyzer copy API version
Questions
- Is it expected that
grantCopyAuthorizationfor API version2025-11-01returns HTTP200but does not include asourceproperty? - If the missing
sourceproperty is expected, what exact request body should be sent to the target-sidecopyendpoint so that the authorization is accepted? - If the missing
sourceproperty is not expected, what configuration, permission, or authentication setup is required so thatgrantCopyAuthorizationreturns a complete authorization object? - Is cross-resource copying of custom Content Understanding analyzers supported when the REST calls are authenticated with API keys?
- Does cross-resource analyzer copy require Entra ID / managed identity authentication instead of API-key authentication, even though the REST examples use
Ocp-Apim-Subscription-Key? - Should
sourceRegionuse the Azure Portal / ARM resource location, e.g.westeurope, or can Content Understanding have a different internal data-plane region? - Why would
sourceRegion = westeuropeproduceSource analyzer was not found, while another region value reachesInternalResourceManagementError? - Are there known issues copying custom Content Understanding analyzers between Foundry resources in different regions or between resources created at different times / different Content Understanding generations?
- Is there a way to inspect which internal region or data-plane location a Content Understanding analyzer belongs to?
- What diagnostic information should we provide to Microsoft support beyond the
x-ms-request-idvalues fromgrantCopyAuthorizationandcopy?
Thanks.
EDIT:
With my testing i would say :
Same-resource analyzer copy succeeds with 201 Created for the same analyzer. Cross-resource copy using the documented 2025-11-01 REST flow fails with 404 ModelNotFound: Source analyzer '<id>' was not found, although GET source analyzer returns 200 ready, grantCopyAuthorization returns 200, target defaults include the required model deployments, and the same Entra principal can read both resources. The grant response also does not include the documented source property.