Microsoft Foundry Control Plane provides a management, operations, and governance layer for AI applications and agents in enterprise environments. The platform targets developers and AI engineers, enabling them to monitor agent operations, apply security controls and policies, evaluate performance, and manage fleets from the build stage through production.
The platform is designed for agentic systems that perform inference, call tools, and take actions based on data. It can track agent operation end to end, including inputs, inference steps, tool calls, outputs, response time, and cost. It also supports pre-production evaluations and continuous evaluation of production traffic to measure task adherence, tool-call accuracy, safety, and quality.
Continuous Monitoring and Runtime Controls
Foundry Control Plane enables teams to set thresholds for evaluations and trigger alerts when regressions emerge, helping them move from intermittent testing to continuous oversight as the number of agents grows. The platform provides evaluation tools tailored to agentic systems, including task adherence, tool-call accuracy, intent understanding, source grounding, and exposure of sensitive data.
At the execution level, intervention points can be configured for user inputs, tool calls and their responses, and outputs. These controls target the detection or blocking of personally identifiable information, indirect prompt injection, agent deviation from its task, prohibited actions, and content risks. They also address direct and indirect injection requests, including attempts to manipulate the agent through multi-turn contexts, before the agent executes the action.
Tracing, Security, and Identity
The platform relies on OpenTelemetry standards to trace agent operations from inference through tool calls, with the ability to integrate with Azure Monitor and Application Insights to diagnose deviations, failures, and performance bottlenecks. It also includes AI Red Teaming Agent to simulate adversarial attacks and scan agents for vulnerabilities before deployment, aggregating weaknesses and issuing readiness reports.
Microsoft Entra Agent ID gives each agent a persistent identity from the build stage, enabling the application of policy-based access controls, conditional permissions, and lifecycle management. Jailbreak attempts and threat signals can be surfaced in Microsoft Defender for investigation and response, while data security and compliance policies in Microsoft Purview extend to AI interactions, including data loss prevention policies, auditing, and retention of prompts and responses.
Fleet Management and Integration with External Systems
The platform provides a unified interface for displaying alerts related to security, policies, cost, and performance, while tracking agent operations, success rates, and spending in real time. Teams can manage agents, models, and tools across projects, and monitor compliance status, prevented behaviors, and usage trends week over week.
Foundry Control Plane is not limited to agents built in Microsoft Foundry; it also supports agents from Microsoft first-party systems and external systems. Agents operating outside Foundry can be registered through the AI gateway, which uses Azure API Management to provide secure routing, apply policies, and collect telemetry. External agents can also send OpenTelemetry-compatible traces, enabling unified visibility across different cloud environments and platforms.
Pricing and Distinction from Agent 365
Foundry Control Plane pricing is usage-based and tied to monitoring services, security controls, and Microsoft Security services. AI evaluations are billed according to input and output tokens, while monitoring and tracing are billed as Azure logs, and security controls are billed per text or image record.
Microsoft explains that Foundry Control Plane is aimed at developers and AI engineers, with a focus on deep tracing, evaluation, runtime controls, and fleet management. Agent 365, by contrast, is aimed at IT and security administrators, focusing on inventory, access control, identity management, and enterprise-wide policies. Both products rely on the security capabilities of Microsoft Entra, Microsoft Defender, and Microsoft Purview.