Four Ways to Reach a Model in Another Azure Region From Microsoft Foundry
Author(s): Dave R | Microsoft Azure & AI MVP ☁️ Originally published on Towards AI. How each pattern handles identity, routing, and private networking, and which Foundry features stop working when a gateway sits in the path. Microsoft Foundry model availability is regional, so the model or Foundry Agent Service feature you need can live outside the region your project was approved for. Foundry supports four ways to reach it, and they differ in who owns identity, routing, and the network path. One of them also makes first-party tools such as SharePoint grounding fail with bad_request. This guide compares all four patterns, shows the API Management option running on a fully private network, lists which features survive the hop, and ends with a decision flow you can apply to your own landing zone. Four patterns connecting a Foundry project in one Azure region to model deployments in another region.The article explains why cross-region model access is fundamentally an ownership decision across three boundaries—control plane, identity, and the data path—and then lays out four supported patterns for reaching a remote Foundry model. It starts with a direct Foundry-to-Foundry connection (simple, but lacking per-call enforcement), then covers using Azure API Management (APIM) as a model gateway with a parameterized single route (enabling token limits, token metrics, caching, load balancing, and circuit breaking). Next it presents APIM in front of the agent surface for stronger ingress governance (but with firm constraints because Foundry still must validate the caller token for on-behalf-of scenarios and tools). Finally, it describes dynamic model connections for the Responses API where the model name is in the JSON body (shifting routing decisions to the project). The guide details what continues to work through an APIM “gateway hop,” what doesn’t (notably first-party on-behalf-of tools), how to keep content filtering and monitoring consistent, and how to implement the gateway pattern fully privately using subnets, private endpoints, and private DNS. It concludes with a decision flow and build order, emphasizing that once you choose ownership and networking strategy, the correct pattern largely follows. Read the full blog for free on Medium. Join thousands of data leaders on the AI newsletter. Join over 80,000 subscribers and keep up to date with the latest developments in AI. From research to projects and ideas. If you are building an AI startup, an AI-related product, or a service, we invite you to consider becoming a sponsor. Published via Towards AI
