Deep Dive
push_pin
Pinned
Jul 8, 2026
The AI Gateway in Azure API Management: A Control Plane for Enterprise AI
One control plane for enterprise AI — how APIM's AI gateway gives security, network, and infrastructure teams governance over models, MCP tools, agents.
Deep Dive
push_pin
Pinned
Jul 9, 2026
Zero-Secrets Architecture on Azure: Managed Identity for AI Agents
The governance case for keyless Azure: why shared keys are a liability, how managed identity plus RBAC fixes it, and how teams enforce it.
Latest Updates
All updates →
The Learning Loop Is the Moat: An Architect's Read on Nadella's Reverse Information Paradox

Microsoft Foundry's Production-Agent Release: A Solution Architect's Read

Zed and DeltaDB: Version Control Between Commits

Magentic-UI + Fara-7B: A Local-First Computer-Use Agent You Can Actually Run

Microsoft Agent Framework Makes Tool and File Access Approval-by-Default

Dev Tunnels: Test Webhooks and Share Local Apps Without a Deploy

Microsoft Ignite 2025: Microsoft Foundry - The Unified Enterprise AI Platform

Build Custom MCP Catalogs with Docker: Enterprise Control for AI Tooling
Recent Journal Entries
Explore Full Journal →
The Auth Chapter Every MCP Tutorial Skips: Real SSO for Microsoft Graph
How a production MCP server signs into Microsoft 365 with real SSO: public client + PKCE, delegated permissions, On-Behalf-Of, and 85 Graph tools kept safe.

Groundedness Detection vs Groundedness Evaluation: Two Azure Products, One Name
Azure has two features named Groundedness — a runtime detection API that blocks ungrounded answers, and an offline evaluator that scores them in CI.

The Production Guardrail Stack: Presidio + Azure Content Safety + NeMo Guardrails Around a MAF Agent
How to compose PII redaction (Presidio), Azure AI Content Safety, and NeMo Guardrails as layered middleware around a Microsoft Agent Framework agent.

Defense-in-Depth for AI Agents on Azure: Prompt Shields, Spotlighting, and the Coverage Gap
What Azure's Prompt Shields and Spotlighting actually block against jailbreaks and prompt injection — and the gap: they don't fire on agent tool calls.

Cost Control for LLM Apps: Caching, Batching, Model Tiers
Cut your Azure OpenAI bill with model-tier routing, the four caches, output discipline, and batching. The levers that move the bill, in order of impact.

Observability for AI Agents on Azure: OpenTelemetry GenAI to the Agent Dashboard
Tracing AI agents on Azure Monitor with OpenTelemetry GenAI conventions — the invoke_agent → chat → execute_tool span tree and the KQL to reconstruct it.

The Agent Harness
The harness is the loop around a model that calls tools, manages context, gates actions, and decides when to stop. Its defaults are the product.

Every Evaluator in the Azure AI Evaluation SDK, and When to Use Each
A reference to all 39 evaluators in Azure's AI Evaluation SDK — quality, RAG, agent, safety, and custom — organized by which you can actually import.

The OBO Chain Through MCP: Passing User Identity from an Agent to Microsoft Graph
How an AI agent reaches Microsoft Graph as the signed-in user through MCP — why token passthrough fails, and how OBO and RBAC secure the chain.