Identity and Access Boundary
Governs who administers Foundry resources, builds in projects, and invokes agents through Microsoft Entra ID role-based access control, separating control-plane from data-plane roles and offering least-privilege options like the Foundry Agent Consumer role and per-agent scopes. Removes static API keys by enforcing token-based authentication and disabling local auth.