---
title: "Microsoft Foundry: Complete Guide and Data Security Implications (2026)"
description: Discover Microsoft Foundry, Microsoft's unified AI platform. How it works, key components, and what it means for your M365 data security and governance.
image: https://blog.idecsi.com/hubfs/Microsoft%20Foundry%20_%20guide%20complet%20et%20enjeux%20pour%20la%20s%C3%A9curit%C3%A9%20(2026).png
---

[![Logo-Idecsi-Black-tagline](https://blog.idecsi.com/hs-fs/hubfs/LOGOS%20IDECSI/LOGOS%20OFFICIELS/Logo-Idecsi-Black-tagline.png?width=1010&height=319&name=Logo-Idecsi-Black-tagline.png)](https://www.idecsi.com/)

- Solutions

  DETOX® pour M365
  
  Audit, Remediation & ROI
  
  [Discover DETOX](https://info.idecsi.com/detox-m365?hsLang=en)
  
  ![Audit, Remediation & ROI](https://blog.idecsi.com/hubfs/ILLU-4.png)

  Solutions
  
  IDECSI gives security and IT teams full control over their data — across DSPM, Data Access Governance, Human Risk Management, and Data Volume Management.

    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) M365 Data Security Platform](https://www.idecsi.com/solution/mydatasecurity/)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Data storage optimization](https://www.idecsi.com/solution/mydatamanagement/)
- Challenges

  M365 Checklist
  
  15 Warning Signs Your M365 Data Is at Risk
  
  [Get the checklist](https://info.idecsi.com/checklist-15-warningsigns?hsLang=en)
  
  ![Checklist risques M365](https://blog.idecsi.com/hubfs/Frame-2147255341.png)

  Your 2026 Challenges
  
  Address your most critical data security and governance challenges - across your M365 environment

    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Gain visibility accross M365](https://www.idecsi.com/challenges/visibility-microsoft-365)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Get Ready For Copilot M365](https://www.idecsi.com/challenges/m365-copilot/)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Control external user access](https://www.idecsi.com/challenges/external-access-microsoft-365/)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Prevent Sensitive Data Exposure](https://www.idecsi.com/challenges/sensitive-data-m365/)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Gain visibility across Microsoft 365](https://www.idecsi.com/challenges/visibility-microsoft-365/)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Ensure regulatory compliance](https://www.idecsi.com/challenges/compliance-m365/)
- Resources

  Is Your Tenant Ready for Copilot?
  
  A Security & Governance Playbook
  
  [Download](https://info.idecsi.com/whitepapper_copilot?hsLang=en)
  
  ![Copilot guide](https://blog.idecsi.com/hubfs/Frame-2147255339.png)

  Our resources
  
  Check out our useful resources for improving data protection

    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Blog](https://blog.idecsi.com)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Help Center](https://help.idecsi.com/)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Ressources & News](https://blog.idecsi.com/resources?hsLang=en)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) About us](https://www.idecsi.com/about-us/)
- [Customers](https://blog.idecsi.com/resources-customer?hsLang=en)
- - [English](https://blog.idecsi.com/microsoft-foundry-guide-security)
    - [Français](https://blog.idecsi.com/fr/microsoft-foundry)

Search

[Request a demo](https://info.idecsi.com/demo-idecsi?hsLang=en)

Microsoft 365

10 September 2026

# Microsoft Foundry: Complete Guide and Data Security Implications (2026)

![](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/Microsoft%20Foundry%20_%20guide%20complet%20et%20enjeux%20pour%20la%20s%C3%A9curit%C3%A9%20%282026%29.png)

- [Home](https://www.idecsi.com/)
- [Blog](https://blog.idecsi.com)
- Microsoft Foundry: Complete Guide and Data Security Implications (2026)

On November 18, 2025, at Microsoft Ignite, Microsoft rebranded Azure AI Foundry as **Microsoft Foundry**. The third rename in two years for the same underlying technology, the announcement created real confusion across enterprise IT and security teams: is this a cosmetic rebrand or a meaningful architectural shift? And more importantly, what does it mean for your organization's data security posture?

This guide answers both questions with facts, with a dedicated focus on what Microsoft Foundry changes, and what it does not change, about access management and permissions in Microsoft 365.

---

## **What Is Microsoft Foundry?**

According to Microsoft's official documentation, Foundry is "a unified Azure platform-as-a-service offering for enterprise AI operations, model builders, and application development."

In practice, it is the platform where developers and IT teams build, deploy, and operate AI applications and agents at enterprise scale.

The platform has evolved rapidly since its initial release:

- November 2023: Azure AI Studio launched in Public Preview
- November 2024 (Ignite 2024): rebranded as Azure AI Foundry, with a first consolidation of Azure AI services
- November 2025 (Ignite 2025, November 18): rebranded as Microsoft Foundry, with a strategic shift positioning AI agents as first-class citizens in the Microsoft ecosystem

Dropping "Azure" from the product name is deliberate. It signals that Foundry is no longer just another Azure service. Microsoft now positions it as the third strategic pillar of its product portfolio, alongside Microsoft 365 and Microsoft Fabric.

---

## **Microsoft Foundry Key Components**

Microsoft Foundry brings several previously distinct services together under a single portal, accessible at ai.azure.com.

**Foundry Agent Service** is the production runtime for AI agents. Reaching general availability on March 16, 2026, it enables teams to build agents that reason, plan, and act across tools, data, and enterprise workflows. It is built on the OpenAI Responses API and compatible with open-source frameworks including LangGraph.

**Foundry Control Plane** is the centralized governance dashboard. It gives IT teams full visibility across all agents, models, tools, and data deployed within an Azure subscription. It is the single point of control for managing access, monitoring performance, and enforcing security policies.

**Foundry IQ** is the knowledge layer that connects agents to enterprise data. It supports internal data sources including SharePoint, OneLake, and Azure Blob Storage, with access control list (ACL) synchronization and support for Microsoft Purview sensitivity labels. In practice, an agent connected to Foundry IQ can query your SharePoint documents and return only the content the user is actually authorized to access.

**The model catalog** provides access to over 11,000 models: OpenAI's GPT-5 family, Anthropic's Claude, xAI's Grok, Microsoft's Phi-4, NVIDIA Nemotron models, and more. Azure is currently the only cloud simultaneously offering models from both OpenAI and Anthropic.

**Foundry Local** enables running models directly on local machines or in sovereign, air-gapped environments with no cloud dependency. Reaching general availability in April 2026, it addresses the sovereignty and compliance requirements of organizations that cannot expose their data to external cloud services.

---

## **Microsoft Foundry and Microsoft 365: A Direct Connection**

Microsoft Foundry does not operate in isolation. Its integration with Microsoft 365 is native and deep, which is precisely the central concern for security teams. \[ADAPTED FROM FR\]

Foundry agents can be published directly to Microsoft 365 Copilot, Microsoft Teams, or BizChat with one click. They authenticate using Microsoft Entra ID via the On-Behalf-Of (OBO) delegated identity mechanism. This means agents act on behalf of the signed-in user, inheriting that user's permissions.

Foundry IQ natively accesses SharePoint and OneLake data. When an agent queries a knowledge base connected to SharePoint, the platform enforces the user's permissions: the agent cannot surface documents the user is not authorized to see.

The critical point is this: **Foundry agents inherit existing M365 permissions.** Where those permissions are properly configured, security is maintained. Where they are not, agents will replicate the same exposure, with the speed and precision of an industrial AI engine.

---

## **Data Security and Governance Implications**

This is what CISOs and IT administrators need to assess before any Microsoft Foundry deployment.

### **Foundry Amplifies Existing M365 Permission Gaps**

Foundry IQ synchronizes ACLs from SharePoint and OneLake so agents respect user access rights. But that synchronization mirrors the actual state of permissions. If a user unknowingly has access to a directory containing sensitive HR data because a share was never revoked, the Foundry agent will access it too. The agent's ability to proactively retrieve, synthesize, and surface information makes that kind of exposure far more visible than in typical human usage.

This is the same dynamic observed with Microsoft 365 Copilot: AI does not grant new permissions, but it surfaces and amplifies poorly governed ones.

A few numbers that frame the stakes: \[US CONTEXT ADDED\]

- Generative AI is now involved in 32% of data security incidents, according to the 2026 Microsoft Data Security Index
- 80% of data breaches originate from internal errors, not external attacks
- The average cost of a data loss event for a mid-market organization is estimated at $2.5M

### **What Foundry Delivers Natively on Security**

It would be inaccurate to present Microsoft Foundry as a platform without safeguards. Foundry ships with a substantial, enterprise-grade security stack that continues to evolve.

Unified RBAC under the Microsoft.CognitiveServices namespace lets teams manage access to models, agents, tools, and data through a single, consistent control model aligned with Azure. Native integration with Microsoft Defender and Entra ID handles identity protection and monitoring. Foundry Control Plane centralizes governance across all agents deployed within a subscription.

Since March 2026, integrations with Palo Alto Networks Prisma AIRS and Zenity have reached general availability. They provide real-time detection of prompt injection, sensitive data leakage, malicious content, and tool misuse, directly within Foundry workflows.

Microsoft Purview is integrated for regulatory compliance, including GDPR, HIPAA, and the EU AI Act. Sensitivity labels are extracted during indexing and enforced at every query. \[US CONTEXT ADDED: For US organizations subject to HIPAA or CMMC, Purview label enforcement provides the auditability layer required for compliance documentation.\]

### **What Foundry Does Not Solve: Upstream M365 Governance**

This is the most important point for any CIO or CISO preparing to deploy Foundry agents.

An organization's data security posture is not limited to the security of its AI platform. Foundry secures agents and their runtime behavior. It does not fix upstream M365 permissions. An overshared SharePoint site that has been exposed for years, anonymous links that were never revoked, external guest access that became stale: Foundry IQ synchronizes those states as-is.

Microsoft's own documentation is explicit: "User-level access controls are only enforced when explicitly configured for synchronization." In other words, the security of the entire chain depends on the quality of M365 governance that exists before the first agent is ever deployed.

---

## **How to Prepare Your M365 Environment Before Deploying Microsoft Foundry**

The prerequisite is not narrowly technical. There is no infrastructure to install. It is a governance prerequisite: ensuring that M365 access rights actually reflect what should be shared, with whom, and for how long.

In practice, this means:

1. **Identify high-risk shares**: anonymous links, "entire organization" shares, inactive external guest access, sensitive data sitting in public spaces. Mapping the tenant is the unavoidable starting point.
2. **Involve data owners directly**: IT cannot correct years of accumulated permissions alone. Remediation has to come from users themselves, who are the only ones who can judge whether a share is still legitimate. Empowering data owners is the condition for effective, lasting remediation.
3. **Tighten external sharing controls in Microsoft 365**: external sharing is consistently the most underestimated exposure vector, and one of the first that Foundry agents are likely to replicate.
4. **Establish periodic governance cycles**: not a one-time audit before deployment, but recurring campaigns every six months, so permission quality keeps pace with the natural evolution of the tenant.

IDECSI's DETOX for M365 is a turnkey program built specifically for this prerequisite: full tenant scan, user-level remediation for data owners on their own shares, results measurable in weeks, with no heavy IT lift. Over one million users have completed the process, averaging seven remediations per user, with up to 50% of risks eliminated in the first campaign.

---

## **Conclusion**

Microsoft Foundry represents a structural shift in Microsoft's enterprise AI strategy. It is not a simple rebrand: it is a production platform for deploying AI agents capable of acting across your organization's full data and workflow landscape.

For IT and security teams, the question is not whether Foundry is secure in itself. It is. The question is whether the M365 environment it builds on is well-governed enough to trust. A well-configured agent running on a poorly governed tenant is still an agent accessing the wrong data.

**Assess your M365 tenant readiness before deploying your first Foundry agents.** It is the prerequisite that most organizations skip, and the one that determines whether AI becomes a productivity asset or a liability.

\[Request an IDECSI Demo\]

---

## Q&A

 Q1: What is Microsoft Foundry and how is it different from Azure AI Foundry?

Microsoft Foundry is the new name for Azure AI Foundry since November 2025. The change is not purely cosmetic: it marks a strategic repositioning of AI agents as first-class citizens in the Microsoft ecosystem, a consolidation of Azure AI services under a single resource provider, and an elevation of the platform as the third pillar of Microsoft's product portfolio alongside Microsoft 365 and Microsoft Fabric.

 Q2: Does Microsoft Foundry have access to my Microsoft 365 data?

Agents built with Microsoft Foundry can access M365 data through Foundry IQ, the platform's knowledge layer. That connection uses the signed-in user's identity via Microsoft Entra ID (On-Behalf-Of) and enforces existing SharePoint permissions. An agent can only surface content the user is already authorized to access. This is precisely why M365 access governance is a mandatory prerequisite before any Foundry deployment.

 Q3: What are the security risks of deploying Microsoft Foundry agents in an enterprise environment?

The primary risk is not the platform itself, which includes enterprise-grade security controls (RBAC, Defender, Purview, Prisma AIRS). The structural risk is that Foundry agents inherit and amplify existing M365 permission gaps. Overshared files, stale anonymous links, inactive external guest access: if those exist on your tenant, Foundry agents will access them with the same reach as a human user, but with far greater retrieval speed and synthesis capability.

 Q4: Does Microsoft Foundry comply with HIPAA and other US data security regulations?

Microsoft Foundry is built on Azure and inherits its compliance certifications, including HIPAA, SOC 2, and FedRAMP. Microsoft Purview sensitivity label enforcement is integrated into Foundry IQ, providing the audit trail required for regulated data. That said, compliance posture depends on how the platform is configured. ACL synchronization for SharePoint-indexed sources must be explicitly enabled, and per-user security trimming requires proper Entra ID integration. Organizations in regulated industries should validate their specific configuration against applicable frameworks before production deployment.

 Q5: What is the best way to prepare your Microsoft 365 tenant for Foundry agents?

Start with a full tenant permission audit: identify overshared resources, anonymous links, inactive external access, and sensitive data in public spaces. Then involve data owners directly in remediation, since IT teams cannot correct years of accumulated permissions alone. Establish a recurring governance cycle, every six months at minimum, to maintain permission quality over time. Platforms like IDECSI's DETOX for M365 are designed for exactly this use case: a complete tenant scan, user-driven remediation, and measurable results within four to six weeks, without requiring significant IT resources.

 Recent articles

[Microsoft 365 SharePoint Storage Costs in 2026: What's Changing](https://blog.idecsi.com/microsoft-365-sharepoint-storage-costs-2026?hsLang=en)

[Zero Trust Data Governance for Microsoft 365: CISO Guide](https://blog.idecsi.com/zero-trust-data-governance-microsoft-365?hsLang=en)

[Cybersecurity Awareness Month: A CISO's M365 Action Plan](https://blog.idecsi.com/cybersecurity-awareness-month-ciso-action-plan-m365?hsLang=en)

 Best practices to improve Microsoft Teams security

[![Download the infographic ](https://no-cache.hubspot.com/cta/default/4272098/825ad7d1-e961-4a7a-a6b3-6e380b22285f.png)](https://cta-redirect.hubspot.com/cta/redirect/4272098/825ad7d1-e961-4a7a-a6b3-6e380b22285f)

 Share this article

<https://twitter.com/intent/tweet?text=https://blog.idecsi.com/microsoft-foundry-guide-security> <http://www.facebook.com/sharer.php?u=https://blog.idecsi.com/microsoft-foundry-guide-security> <https://www.linkedin.com/sharing/share-offsite/?url=https://blog.idecsi.com/microsoft-foundry-guide-security>

Subscribe to our newsletter and receive new contents every month

 Our articles

These articles may   
interest you

![](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/Co%C3%BBt%20du%20stockage%20Microsoft%20365%20en%202026.png)

 Microsoft 365

 Microsoft 365 SharePoint Storage Costs in 2026: What's Changing 

<https://blog.idecsi.com/microsoft-365-sharepoint-storage-costs-2026?hsLang=en> [Lire l'article](https://blog.idecsi.com/microsoft-365-sharepoint-storage-costs-2026?hsLang=en)

![](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/Illus-Blog-Supervision.png)

 Microsoft 365

 Security

 Microsoft 365 Phishing: Why Oversharing Makes a Compromised Account Far More Dangerous 

<https://blog.idecsi.com/fr/phishing-microsoft-365-risques-donnees-partagees-1?hsLang=en> [Lire l'article](https://blog.idecsi.com/fr/phishing-microsoft-365-risques-donnees-partagees-1?hsLang=en)

![](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/image%20%2858%29.png)

 Microsoft 365

 Security

 Securing AI Agents in Microsoft 365: Best Practices for 2026 

<https://blog.idecsi.com/securing-ai-agents-microsoft-365?hsLang=en> [Lire l'article](https://blog.idecsi.com/securing-ai-agents-microsoft-365?hsLang=en)

### Data protection, let's discuss your project?

 

[![Contact us](https://no-cache.hubspot.com/cta/default/4272098/bea4f372-c84f-4ec4-980c-ca663747fbfe.png)](https://cta-redirect.hubspot.com/cta/redirect/4272098/bea4f372-c84f-4ec4-980c-ca663747fbfe)

![video background](https://idecsi2a-dev-idecsi.pf27.wpserveur.net/wp-content/uploads/2022/02/video-background-idecsi-responsive-1.png)

[![Logo-Idecsi-White-Ss-ES](https://blog.idecsi.com/hubfs/LOGOS%20IDECSI/LOGOS%20OFFICIELS/Logo-Idecsi-White-Ss-ES.svg)](https://www.idecsi.com/)

 +33 1 84 79 38 30

- <https://twitter.com/IDECSI>
- <https://www.facebook.com/IDECSI-306865969441428/>
- <https://www.linkedin.com/company/idecsi/>

- [Why choose IDECSI?](https://www.idecsi.com/user-security/)
- [About us](https://www.idecsi.com/about-us/)
- [Join the team](https://www.welcometothejungle.com/fr/companies/idecsi)

- Solutions 
    - [Visibility](https://www.idecsi.com/challenge-data-visibility/)
    - [Detection](https://www.idecsi.com/challenge-threat-detection/)
    - [User engagement](https://www.idecsi.com/challenge-involve-user/)
    - [Access review](https://www.idecsi.com/challenge-rights-review/)
    - [Remediation](https://www.idecsi.com/challenge-remediation/)
    - [Sensitive data](https://www.idecsi.com/challenge-sensitive-data/)

- [Products](https://www.idecsi.com/solution/) 
    - [MyDataSecurity](https://www.idecsi.com/solution/mydatasecurity/)
    - [Advanced Monitoring](https://www.idecsi.com/solution/advanced-monitoring/)
    - [MyDataManagement](https://www.idecsi.com/solution/mydatamanagement/)

- Resources 
    - [Resources & News](https://blog.idecsi.com/resources?hsLang=en)
    - [Blog](https://blog.idecsi.com)
    - [Customer success](https://blog.idecsi.com/resources-customer?hsLang=en)
    - [Extranet](https://extranet.idecsi.com?hsLang=en)

 © IDECSI

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Nathan Colombani",
    "url" : "https://blog.idecsi.com/author/nathan-colombani"
  },
  "dateModified" : "2026-09-10T06:30:01.108Z",
  "datePublished" : "2026-09-10T06:30:01.000Z",
  "headline" : "Microsoft Foundry: Complete Guide and Data Security Implications (2026)",
  "image" : [ "https://blog.idecsi.com/hubfs/Microsoft%20Foundry%20_%20guide%20complet%20et%20enjeux%20pour%20la%20s%C3%A9curit%C3%A9%20(2026).png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.idecsi.com/microsoft-foundry-guide-security",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.idecsi.com/hubfs/Logo-Idecsi-Black-tagline.png"
    },
    "name" : "IDECSI"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Microsoft Foundry is the new name for Azure AI Foundry since November 2025. The change is not purely cosmetic: it marks a strategic repositioning of AI agents as first-class citizens in the Microsoft ecosystem, a consolidation of Azure AI services under a single resource provider, and an elevation of the platform as the third pillar of Microsoft's product portfolio alongside Microsoft 365 and Microsoft Fabric."
    },
    "name" : "Q1: What is Microsoft Foundry and how is it different from Azure AI Foundry?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Agents built with Microsoft Foundry can access M365 data through Foundry IQ, the platform's knowledge layer. That connection uses the signed-in user's identity via Microsoft Entra ID (On-Behalf-Of) and enforces existing SharePoint permissions. An agent can only surface content the user is already authorized to access. This is precisely why M365 access governance is a mandatory prerequisite before any Foundry deployment."
    },
    "name" : "Q2: Does Microsoft Foundry have access to my Microsoft 365 data?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "The primary risk is not the platform itself, which includes enterprise-grade security controls (RBAC, Defender, Purview, Prisma AIRS). The structural risk is that Foundry agents inherit and amplify existing M365 permission gaps. Overshared files, stale anonymous links, inactive external guest access: if those exist on your tenant, Foundry agents will access them with the same reach as a human user, but with far greater retrieval speed and synthesis capability."
    },
    "name" : "Q3: What are the security risks of deploying Microsoft Foundry agents in an enterprise environment?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Microsoft Foundry is built on Azure and inherits its compliance certifications, including HIPAA, SOC 2, and FedRAMP. Microsoft Purview sensitivity label enforcement is integrated into Foundry IQ, providing the audit trail required for regulated data. That said, compliance posture depends on how the platform is configured. ACL synchronization for SharePoint-indexed sources must be explicitly enabled, and per-user security trimming requires proper Entra ID integration. Organizations in regulated industries should validate their specific configuration against applicable frameworks before production deployment."
    },
    "name" : "Q4: Does Microsoft Foundry comply with HIPAA and other US data security regulations?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Start with a full tenant permission audit: identify overshared resources, anonymous links, inactive external access, and sensitive data in public spaces. Then involve data owners directly in remediation, since IT teams cannot correct years of accumulated permissions alone. Establish a recurring governance cycle, every six months at minimum, to maintain permission quality over time. Platforms like IDECSI's DETOX for M365 are designed for exactly this use case: a complete tenant scan, user-driven remediation, and measurable results within four to six weeks, without requiring significant IT resources."
    },
    "name" : "Q5: What is the best way to prepare your Microsoft 365 tenant for Foundry agents?"
  } ]
}
```