A unified Azure platform for creating and managing AI models, agents, and applications with built‑in enterprise security, monitoring, and governance
Hi Erkki, thank you for your questions. A few additions to the answer above.
- Send telemetry to your own tenant. Enable tracing into Application Insights and route diagnostic settings to a Log Analytics workspace you control. Cross-tenant delivery usually needs Azure Lighthouse or customer approval, but it covers most support needs like latency, errors, and token usage without any portal access.
- Don't count on Lighthouse fixing the Agents blade. Lighthouse delegates control plane RBAC, but the Agents experience checks the tenant that owns the resource. Test this in a sandbox early.
- Use a multi-tenant app registration for programmatic access. Have the customer consent so a service principal exists in their tenant, then assign it a narrow Foundry role at the project scope. Pin the tenant explicitly in your credential.
- Consider a thin publisher-owned admin API. If neither side should see the underlying assets, a small service that calls Foundry with a scoped identity is easier to secure and audit than opening up the portal.
- Review the deny assignment settings. Check whether data actions are denied along with control plane actions, since that may explain the "workspace not found" error.