Tag
Ai-Agents
49 posts filed under Ai-Agents.
Building a Multi-Agent E-Commerce Platform: The Complete Guide
Start here. A guided index to 40 chapters on building production multi-agent systems with Microsoft Agent Framework, in Python and C#, against one open-source e-commerce platform.
The Auth Chapter Every MCP Tutorial Skips: Real SSO for Microsoft Graph
How a production MCP server signs into Microsoft 365 with real SSO: public client + PKCE, delegated permissions, On-Behalf-Of, and 85 Graph tools kept safe.
Groundedness Detection vs Groundedness Evaluation: Two Azure Products, One Name
Azure has two features named Groundedness — a runtime detection API that blocks ungrounded answers, and an offline evaluator that scores them in CI.
The Production Guardrail Stack: Presidio + Azure Content Safety + NeMo Guardrails Around a MAF Agent
How to compose PII redaction (Presidio), Azure AI Content Safety, and NeMo Guardrails as layered middleware around a Microsoft Agent Framework agent.
Defense-in-Depth for AI Agents on Azure: Prompt Shields, Spotlighting, and the Coverage Gap
What Azure's Prompt Shields and Spotlighting actually block against jailbreaks and prompt injection — and the gap: they don't fire on agent tool calls.
Observability for AI Agents on Azure: OpenTelemetry GenAI to the Agent Dashboard
Tracing AI agents on Azure Monitor with OpenTelemetry GenAI conventions — the invoke_agent → chat → execute_tool span tree and the KQL to reconstruct it.
The Agent Harness
The harness is the loop around a model that calls tools, manages context, gates actions, and decides when to stop. Its defaults are the product.
Every Evaluator in the Azure AI Evaluation SDK, and When to Use Each
A reference to all 39 evaluators in Azure's AI Evaluation SDK — quality, RAG, agent, safety, and custom — organized by which you can actually import.
The OBO Chain Through MCP: Passing User Identity from an Agent to Microsoft Graph
How an AI agent reaches Microsoft Graph as the signed-in user through MCP — why token passthrough fails, and how OBO and RBAC secure the chain.
Choosing the Right Agent Identity: Managed Identity, Entra Agent ID, OBO, or Service Principal
The first design decision for any Azure AI agent is which identity it uses — a decision matrix across managed identity, Entra Agent ID, and OBO.
Microsoft Foundry's Production-Agent Release: A Solution Architect's Read
Foundry made hosted agents GA and put agent identity first with Entra Agent ID — but governance tooling is still preview and there's no SLA yet.
Zero-Secrets Architecture on Azure: Managed Identity for AI Agents
The governance case for keyless Azure: why shared keys are a liability, how managed identity plus RBAC fixes it, and how teams enforce it.











