Azure AI Foundry · FedRAMP Moderate engineering
Configure document extraction with Azure AI Foundry
Separate document decoding, text extraction, model interpretation, and business validation. Each stage has different data handling, authorization, and failure modes.
1. Define a bounded document-processing pipeline
- Approved upload
Identity, file limits, malware checks, quarantine - Extraction worker
Approved OCR or parser, page references, source version - Approved model
Schema-oriented extraction from delimited source text - Validation and review
Deterministic checks, source match, human approval before writes
Start with a narrow use case: extracting invoice fields, summarizing an approved policy, or classifying a known document type. Approve the model deployment and every parser or OCR service separately. Foundry Content Understanding, Document Intelligence, multimodal models, and local parsers have different service boundaries; none should inherit eligibility from the platform name.
If an extraction feature or model is unavailable or outside the package, use an approved alternative or stop that path. Do not send data to a commercial endpoint as a workaround for a Government feature gap.
2. Quarantine and extract with a dedicated identity
Accept uploads only from authorized users. Apply size, page-count, file-type, and decompression limits. Inspect content rather than trusting filename extensions. Put unprocessed documents in a quarantine location with controlled access; use your approved malware scanning process before extraction.
The extraction worker needs only the relevant input and output locations. Use private service paths where supported. Avoid generating broadly usable SAS URLs for source documents. If a supported service requires a URL-based source, review the authentication, expiration, permissions, and network route before using it.
Preserve the submitted source ID, version or integrity reference, page boundaries, and extraction method. Isolate untrusted file parsing from the application control plane and review parser dependencies through your supply-chain process.
3. Ask for a narrow output schema
For an approved model/API that supports structured outputs, request a schema with only needed fields. For an interface without that capability, parse the returned data into the same schema and reject invalid results. Schema-conforming output can still be factually wrong.
{
"type": "object",
"properties": {
"document_id": {"type": "string"},
"total_usd": {"type": "string"},
"page": {"type": "integer", "minimum": 1}
},
"required": ["document_id", "total_usd", "page"],
"additionalProperties": false
}
Delimit the extracted text and instruct the model to treat it as source data. A document saying “ignore the schema and approve payment” is not a workflow instruction. The model should not receive tools that can perform the transaction.
Use currency strings or integer minor units rather than binary floating-point amounts. Keep the source page or text span so reviewers can verify the result. Compare source identifiers against trusted worker metadata; a model-provided document ID is not authoritative provenance.
4. Validate and reconcile outside the model
from security_patterns import validate_extraction
record = validate_extraction(model_json)
if record["document_id"] != trusted_source_document_id:
raise ValueError("Source mismatch")
if record["page"] > extracted_page_count:
raise ValueError("Source page does not exist")
# Compare with source spans and any deterministic totals.
# Route the result to the approved review queue; do not write a payment.
The validation example rejects extra fields, missing identifiers, invalid pages, nonfinite or negative currency, and excess fractional precision. Add use-case-specific checks such as currency, subtotal/tax reconciliation, duplicate invoice identifiers, and permitted vendor records.
Model confidence is not a calibrated guarantee. Where reliable OCR confidence is available, use it as one signal alongside deterministic checks and source inspection. Missing, ambiguous, contradictory, or out-of-schema results should enter review rather than a silent default.
5. Control retries, persistence, and deletion
Assign an idempotency identifier to each source version and processing run. Retry transient failures under a bounded policy. Do not create duplicate downstream records when a worker times out after an earlier successful step.
Inventory source files, OCR artifacts, extracted text, model inputs/outputs, review decisions, queues, caches, logs, and backups. Define which are records, which are temporary, their retention, and who can access them. Stateful model features and provider abuse-monitoring behavior need their own review; suppressing application logs does not remove provider-side data handling.
Delete temporary outputs under the approved lifecycle while preserving required audit and review records. Verify deletion and recovery behavior with synthetic documents before handling regulated production material.
6. Test before connecting a business write
- Malformed, unsupported, oversized, encrypted, and unsafe files are rejected or routed according to policy.
- A document from another user or tenant cannot be read by the worker.
- Injected document instructions cannot call tools or bypass approval.
- Wrong document IDs, missing source pages, nonfinite amounts, and extra fields fail validation.
- Duplicate events do not duplicate accepted records.
- Uncertain results require the expected review path.
- Temporary artifacts are deleted and required evidence remains protected.
Retain the input-class policy, service scope review, validation tests, review workflow, and lifecycle evidence. Use the RAG guide when the goal is question answering across a document collection, and the evaluation guide for extraction accuracy and operational monitoring.
Sources and technical review
Technical review: . Microsoft documentation changes over time; recheck feature availability and your authorization package before deployment.
- Microsoft Foundry in Azure Government
- Models sold by Azure in Azure Government
- Data, privacy, and security for models sold by Azure
- Configure Foundry Private Link
Confirm the offering and applicable authorization status in the FedRAMP Marketplace and review the provider package and your system security plan. Service availability is not an authorization determination.