Microsoft Foundry
Microsoft Foundry
Start with meaning, then move to detail.
This lesson explains Microsoft Foundry as part of operating Hermes with explicit security boundaries. You will learn what it does, when it matters, and the smallest safe test that proves it works.
If you are new, do not memorize names. Focus on three questions: what problem does this solve, what access does it need, and how can you verify the result?
For practice, inspect the first example, identify its effects, run it on test data, and compare the result with the source claim.
For advanced readers, inspect Prerequisites, Quick Start, Microsoft Entra ID (keyless, RBAC) — recommended, then verify failure modes and version compatibility.
You only need to know which files and accounts the agent may access.
A clear outcome before you read.
- Understand Microsoft Foundry without assumed prior knowledge.
- Separate the source description from what still needs testing in your environment.
- Read the first command and identify its inputs and outputs before copying it.
Use Hermes Agent with Microsoft Foundry — OpenAI-style and Anthropic-style endpoints, auto-detection of transport and deployed models
What does the source say, and in what order?
- 01Prerequisites
Start here to understand the core idea or structure.
- 02Quick Start
Read this after the foundation, then connect it to the previous step.
- 03Microsoft Entra ID (keyless, RBAC) — recommended
Read this after the foundation, then connect it to the previous step.
- 04Why use Entra ID?
Read this after the foundation, then connect it to the previous step.
- 05One-time setup (Azure side)
Read this after the foundation, then connect it to the previous step.
- 06One-time setup (Hermes side)
Read this after the foundation, then connect it to the previous step.
- 07Configuration written to config.yaml
Read this after the foundation, then connect it to the previous step.
- 08Credential resolution order
Read this after the foundation, then connect it to the previous step.
- 09Deployment patterns
Read this after the foundation, then connect it to the previous step.
- 10Sovereign clouds (Government, China)
Finish here to verify the result and special cases.
Copy only after you understand the effect.
hermes model
# → Select "Azure Foundry"
# → Enter your endpoint URL
# → Choose Authentication:
# 1. API key
# 2. Microsoft Entra ID (managed identity / workload identity / az login)
# → (Entra) Hermes probes DefaultAzureCredential; on success it never asks for a key
# → (API key) Enter your API key
# Hermes probes the endpoint and auto-detects transport + models
# → Pick a model from the list (or type a deployment name manually)az role assignment create \
--assignee <principal-or-agent-identity-client-id> \
--role "Azure AI User" \
--scope <foundry-resource-id>hermes model
# → Select "Azure Foundry"
# → Enter your endpoint URL
# → Authentication: 2 (Microsoft Entra ID)
# → (optional) user-assigned managed identity client ID
# → (optional) Azure tenant ID
# → Hermes probes DefaultAzureCredential() and reports which inner
# credential succeeded (e.g. AzureCliCredential, ManagedIdentityCredential)Read the first command and identify its inputs and outputs before copying it.
Match every command to your installed Hermes version, review the files and accounts it can reach, and use non-sensitive data for the first test. If this explanation differs from the source, the official source wins.