Flat Spell Technologies

Azure AI Foundry · FedRAMP Moderate engineering

Azure AI Foundry configuration for FedRAMP Moderate systems

Technical how-tos for building private, identity-aware AI applications inside a verified federal cloud authorization boundary. Start with the architecture and scope decisions, then choose an implementation guide.

What makes an Azure AI Foundry deployment eligible?

Azure AI Foundry is the name many teams use to search for what Microsoft now documents as Microsoft Foundry. The platform combines models, projects, agents, tools, and management features. Those components do not automatically share one compliance boundary.

A FedRAMP Moderate-aligned configuration starts with an authorized cloud service offering and its current package. Verify the exact cloud, region or geography, service, model deployment type, feature status, and external dependencies. Your application still needs implemented controls, documented responsibilities, assessment evidence, and the applicable authorization decision.

Before sending regulated data: verify the provider package and your approved system boundary. These guides describe engineering patterns; no template or model catalog entry grants FedRAMP authorization.

Azure Government is not a universal prerequisite for every FedRAMP Moderate workload. Choose the offering required by the agency and data handling requirements. Likewise, a Government subscription does not make every preview, tool, model, or connected service acceptable.

Verified public offering records and service scope

As checked on October 7, 2026, the FedRAMP Marketplace lists these Microsoft offerings. The current Marketplace uses “FedRAMP Certified” terminology; these are provider offering records, not an authorization for your application.

Public FedRAMP Marketplace records checked October 7, 2026
Offering and package IDListed statusCertification profile
Azure Commercial Cloud — F1209051525FedRAMP Certified; ongoing certificationRev5; JAB path; Class D (High)
Azure Government (includes Dynamics 365) — F1603087869FedRAMP Certified; ongoing certificationRev5; JAB path; Class D (High)

Microsoft’s service compliance scope inventory, whose public and Government tables are marked February 2026, lists Azure OpenAI, Azure AI Search, and Document Intelligence within FedRAMP High scope in both clouds. The Government table also lists Microsoft Foundry portal and Azure AI Content Safety. A portal listing does not establish coverage for every agent capability, preview, model, or API; verify each component against the applicable package. A High-scope service can support a Moderate system’s inherited controls, subject to its boundary and customer responsibilities.

Full package review remains required. The Marketplace’s Quick Start guide directs reviewers to request security documentation using the package ID. Microsoft’s Service Trust Portal lists the Azure Commercial System Security Plan and Appendix A, but downloading the SSP requires signing in to a Microsoft cloud services account. These guides do not claim to have reviewed those protected documents.

Reference architecture: private, identity-aware AI

Application-controlled retrieval and inference path
  1. Authenticated user
    Verified tenant, audience, groups, and roles
  2. Application gateway and runtime
    Request authorization, rate limits, deterministic managed identity
  3. Private service connections
    Approved model deployment, document store, Search, and logs
  4. Evidence and operations
    Configuration snapshots, access decisions, redacted telemetry, recovery tests

Use separate identities for ingestion, retrieval, inference, and tool execution. Keep network paths and data-plane permissions explicit. A private endpoint restricts inbound access; it does not automatically restrict an agent’s outbound tool calls or enforce document-level authorization.

Microsoft’s Government documentation currently lists Foundry in US Gov Virginia and US Gov Arizona, with a feature subset. The documented Government project endpoint is https://{resource}.services.ai.azure.us/api/projects/{project}; a Government agent client uses the https://ai.azure.us/.default token scope. Those values are not interchangeable with commercial endpoints.

Choose a technical implementation guide

01 / FOUNDATION

Private endpoints and identity

Configure account access, DNS, agent egress, least-privilege roles, and positive and negative network tests.

Configure the private network →
02 / KNOWLEDGE

Document-based RAG

Build chunk-level ACL filtering, ingestion boundaries, source citations, and authorization tests before generation.

Build permission-aware RAG →
03 / AUTOMATION

Agents and function calling

Choose supported agent capabilities, constrain tool dispatch, and enforce authorization outside the model.

Configure controlled agents →
04 / DOCUMENTS

Document extraction

Separate OCR, model interpretation, deterministic validation, and human approval in a bounded pipeline.

Build the extraction workflow →
05 / PLANNING

Models, deployment types, and cost

Compare region and data-zone processing, deployment eligibility, token charges, and supporting services.

Choose models and estimate cost →
06 / OPERATIONS

Evaluation and observability

Exercise cross-user leakage, injection, tool misuse, retention, and redacted monitoring before release.

Verify readiness and evidence →

Map engineering outputs to the Moderate control implementation

Example implementation evidence; confirm applicability in your SSP
ConcernRelevant NIST SP 800-53 families / controlsEvidence to produce
Access and privilegeAC-2, AC-3, AC-6; IA-2, IA-5Role exports, user authentication tests, denied tool and document access
Boundary and transmissionSC-7, SC-8, SC-13Private DNS results, public-path denial, approved egress, TLS and cryptographic configuration review
Data and recoverySC-28; CP-9, CP-10Store inventory, encryption/key settings, retention and restore exercises
Audit and monitoringAU-2, AU-3, AU-6, AU-9, AU-11; CA-7Redacted event schema, access protection, retention settings, alert tests
Change controlCM-2, CM-3, CM-6; SI-2, SI-4Pinned dependencies, reviewed infrastructure changes, model/version records, regression results

This table supports control mapping. It does not establish that a control is fully satisfied or that all Moderate requirements are covered. Review inherited controls and customer responsibilities separately.

Deployment checklist and release gate

  1. Record the provider offering, authorization reference, system boundary, and applicable customer responsibilities.
  2. Approve the model, version, deployment SKU, processing geography, API, and feature status.
  3. Provision approved stores and private connections; verify the actual endpoint names in the selected cloud.
  4. Assign separate runtime roles and enforce per-user data and tool authorization.
  5. Configure retention, safety settings, egress, and content-minimized telemetry.
  6. Run denied-access, injection, deletion, recovery, quota, and release-regression tests.
  7. Package configuration and results for review through your program’s assessment and authorization process.

The implementation examples are small, inspectable components. Live Azure deployment, package review, and runtime acceptance tests must be completed in your environment before production use.

Sources and technical review

Technical review: . Microsoft documentation changes over time; recheck feature availability and your authorization package before deployment.

Microsoft’s Azure FedRAMP guidance describes shared responsibilities and notes that Azure Policy provides only a partial view of overall compliance. Use the cloud services in audit scope documentation to locate the provider’s current scope inventory.

Confirm the offering and applicable authorization status in the FedRAMP Marketplace and review the provider package and your system security plan. Service availability is not an authorization determination.