A fully managed platform in Microsoft Foundry for hosting, scaling, and securing AI agents built with any supported framework or model
Hello @Leo Tam (IT, Contractor)
The DNS configuration appears correct for resources inside RAG-VNET, but the key issue is the Basic Agent setup.
The Basic Agent deployments don’t support private Azure AI Search resources. Access to Azure AI Search through a private endpoint requires a Standard Agent setup with virtual network injection.
The successful test from the Linux VM proves that the private endpoint and private DNS zone work from RAG-VNET. It doesn’t prove that the Basic Agent runtime uses that network path. The Basic Agent runtime isn’t deployed into the delegated subnet in the supported private-network architecture.
The supported resolution is:
- Create a Standard Agent setup.
- Supply the required bring-your-own Azure Storage, Azure Cosmos DB, and Azure AI Search resources.
- Configure VNet injection during creation, using the subnet delegated to Microsoft.App/environments.
- Create private endpoints for the three dependent resources; Foundry doesn’t create them automatically.
- Use the project managed identity for the Azure AI Search connection and grant it the required Search data-plane role.
- Recreate the Foundry IQ RemoteTool connection and agent in the Standard project.
These requirements are documented in the private-network setup instructions.
The knowledge-base connection should continue using the Azure AI Search service endpoint: https://testaisearch.search.windows.net and the project connection should use the RemoteTool category with ProjectManagedIdentity authentication.
Adding network injection to an existing agent setup isn’t supported in every scenario, and secured Standard capability settings require all three BYO resources. Creating a new Standard project is therefore the cleanest supported path.
References:
Set up private networking for Foundry Agent Service
Azure AI Search tool networking limitations
Connect agents to Foundry IQ knowledge bases
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.