AI how-tos · Build, verify, operate
Practical AI how-tos for enterprise applications
Start with the task you want to solve: answer questions from documents, automate a bounded workflow, extract structured records, or deploy and evaluate a private AI application.
This collection organizes our Azure AI Foundry technical guides by use case. The walkthroughs focus on engineering for regulated systems, including FedRAMP Moderate boundaries; their configuration and authorization requirements depend on your cloud and workload.
Choose an AI task
Each guide includes prerequisites, implementation details, verification steps, and primary-source references. Use the checks as part of a reviewed implementation in your own environment.
Build a document Q&A assistant
Connect a model to approved documents through retrieval-augmented generation (RAG). Follow the ingestion, chunking, tenant/group filtering, source-citation, and authorization-recheck design.
Before you start: Have a source permission model, an approved embedding/retrieval design, and a scoped model deployment.
Check the result: Test that a user cannot retrieve another tenant’s or group’s documents, even when a prompt asks for them.
Build permission-aware RAG →Give an agent controlled tools
Let an agent request a bounded operation, such as reading an authorized case status. Follow function schemas, tool allowlists, strict argument validation, and server-side authorization.
Before you start: Define the exact permitted actions and the identity used by each backend operation.
Check the result: Reject unknown tools, extra arguments, and unauthorized record identifiers before a backend call occurs.
Configure agent function calling →Extract structured data from documents
Separate OCR from model interpretation, then validate the returned structure and source evidence. Follow schema checks, amount/page validation, restricted data paths, and human review.
Before you start: Choose an approved document-processing service and define the required output fields and review rules.
Check the result: Keep malformed output and uncertain records out of downstream systems until the validation or review decision passes.
Build a document-extraction workflow →Choose a model and estimate cost
Choose the model, version, deployment type, and processing geography for the workload. Estimate token consumption and supporting-service costs using the applicable current rates.
Before you start: Define quality, latency, data-handling, and budget constraints before selecting a deployment.
Check the result: Record the approved deployment and compare measured usage with the pilot estimate.
Choose models and estimate cost →Configure a private AI deployment
Set up private endpoints, cloud-correct DNS, managed identity, and dependency access. Follow the distinction between inbound service access and outbound agent/tool connectivity.
Before you start: Inventory the cloud, client runtime, model deployment, stores, tool backends, and telemetry destinations.
Check the result: Prove permitted access and denied public paths, unauthorized identities, and unapproved destinations separately.
Configure private endpoints and identity →Evaluate and monitor an AI application
Build a repeatable evaluation set and operational checks for retrieval quality, prompt injection, tool misuse, deletion, and content-minimized telemetry.
Before you start: Define acceptance criteria, a synthetic test corpus, and an approved log/retention design.
Check the result: Block release when a security or quality check fails, then preserve the configuration and sanitized evidence.
Evaluate readiness and observability →Follow a build path
Use these sequences to connect the individual guides into a complete engineering workstream. Define the source data, permitted actions, and success criteria before adding a model.
Document knowledge assistant
Document-to-workflow automation
- Extract and validate the required fields.
- Route uncertain or consequential records through the defined review decision.
- Expose only approved, authorized tool operations.
- Test invalid inputs, unauthorized actions, and trace handling.
Prepare trusted data for AI
AI applications need a repeatable source-data pipeline. Use the Data Factory guides to build scoped ingestion, validate the schema, and publish a recoverable batch. Keep source permissions with the published data so downstream retrieval can enforce them.
- Build managed-identity SQL-to-ADLS ingestion.
- Design incremental loads and safe checkpoint commits.
- Monitor freshness, data quality, and pipeline cost.
A successful ingestion run is one step in the data contract. Verify the intended records, access rules, and publication state before making the batch available to an AI workflow.
Browse the platform guides
Azure AI Foundry
Review offering scope, architecture decisions, private connectivity, model deployment, and the full set of AI implementation guides.
Explore Azure AI Foundry →Azure Data Factory
Review runtime selection, hybrid ingestion, controlled releases, and evidence for the upstream data integration platform.
Explore Azure Data Factory →Before you deploy
- Record the approved cloud, services, features, data-handling boundary, and customer responsibilities.
- Use synthetic inputs to verify network paths, scoped identities, document permissions, and tool authorization.
- Define quality and security acceptance checks, retention/deletion behavior, and human review rules.
- Release reviewed configuration with sanitized monitoring, rollback/recovery instructions, and measured cost assumptions.
The linked guides record their technical review dates and verification limits. Public service listings and example configurations do not replace provider-package review, live acceptance tests, or your program’s authorization decision.