microsoft-foundry / microsoft-foundry/foundry-samples

Question: Agent Injection in agent snet (sample byo / general)

Open
#656 3 comments 0 reactions 5 assignees View on GitHub

@aprilk-ms is already working on this.

Since Aug 6, 2026.

bug question
Dominant language
Bicep
Stars
445
Forks
494
Avg merge
11h 35m
Merged PRs (30d)
38

Description

I am experiencing deployment failures when using network injection for Azure AI Foundry. The deployments reach an "Accepted" or "Running" state before eventually failing without a clear error message.

I would like to clarify if there are any limitations or specific requirements regarding the following configurations on the delegated subnet:

  • The use of a Route Table (UDR). (we have a default udr pointing to the azure firewall)
  • The association of a Network Security Group (NSG).
  • Enabling Private Endpoint Network Policies.
  • Enabling the "private subnet" setting (no default outbound access).
  • We have a number of deny policies related to private subnet, the need of a NSG being associated and a Route Table.

I did not go over the exercise to change them one by one so reaching out if there is more info on the above. I see that the Microsoft performs a "Creates or updates a Service Association Link" with caller Microsoft Azure Legion but I don't see any other interactions with the existing subnet. So I don't think deny policies are the problem here.

I'm using "15b-private-network-standard-agent-setup-byovnet"

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.