Copilot Studio and Microsoft Foundry are not competitors — they sit at different levels of abstraction, and three changes in 2026 have quietly retired most of the advice written about choosing between them. A decision framework built on who owns the runtime, where the data already lives, and who operates the agent on day ninety, with the cost shapes, governance asymmetries and interop paths verified against Microsoft's own documentation.
Microsoft Foundry is no longer a place to call models — it is a platform for hosting, grounding, governing and operating agents. A working architecture guide to prompt and hosted agents, Foundry IQ, Toolbox, MCP and A2A, model choice and Claude, agent identity and RBAC, private networking, evaluation and Agent 365 — with every capability marked GA, Preview or retiring, and the places Microsoft's own documentation contradicts itself named rather than smoothed over.
A research-grounded enterprise reference architecture for autonomous AI agents: agent identity, task-bound authorization, tool and MCP gateways, memory security, runtime containment, observability, and incident response — with an OWASP agentic Top 10 mapping, a bounded-autonomy model, and a 38-control matrix.
Architecture documents die in slide decks. This one is a clickable package: fifteen linked views, an asset-mapped control catalog, ADRs, a risk register, and a phased runbook — all driven by one canonical model you can explore in the browser.
Governance earns its keep when it speeds decisions up, not when it slows them down. A working model for architecture governance inside large infrastructure programs.
AI services are entering organizations through every door at once. Treating them as enterprise platforms — with identity, data boundaries, logging, and governance — is the difference between adoption and exposure.
Zero Trust fails when it is treated as a shopping list. A durable design starts from identity, device health, and explicit policy — and earns its rollout with evidence.
Landing zone security is mostly decided before the first workload arrives. The guardrails, identity boundaries, and logging defaults that matter — and the ones that just add friction.
Can agentic AI actually run security operations? The interesting problem is not the triage decision — it is everything around it: authority, tenant isolation, evidence, approval, and audit. This is the full target architecture, published as something you can click through.
Microsoft's AI portfolio is not five versions of the same product — it is a layered enterprise architecture with an experience layer, two build platforms, a control plane, and the identity, data and threat controls underneath. A practical architecture guide to what each platform is for, which workloads belong where, how agent identity and authority actually flow, and what has to be true before an organization scales any of it.
A field-tested strategy for moving a VMware estate to Azure without pretending lift-and-shift is easy: how to run the provider evaluation, design waves around downtime tolerance, protect data integrity, plan a rollback you can actually execute, and validate the result — in a regulated, always-on environment.