Foundry and Claude: the agent is ready, but discipline is not

Foundry removes the infrastructure barrier for Claude AI agents. Explore five new tools and what truly determines a pilot’s production success.

  • The entry barrier has fallen
  • What Microsoft addressed over the summer
  • Five tools that turn a model into an agent
  • Simple on the outside does not mean simple inside

The entry barrier has fallen

In two summer months, Microsoft completed a task list that had looked like a year's roadmap in June: Hosted Agents, Voice Live, and Toolboxes in Foundry reached GA; Claude on Azure gained five new tools; and building an agent from separate model calls became platform configuration. The barrier to production agents is lower than ever—and that is a reason to reconsider where the real bottleneck lies in an AI project.

What Microsoft addressed over the summer

In June 2026, Claude reached general availability in Foundry: Messages API, prompt caching, extended thinking, and streaming tool calls. The model is hosted on Azure, authenticated through Entra ID, and billed through Azure Marketplace. This resolved procurement and governance concerns: legal and security teams at large companies gained a clear accountability framework for a third-party model. July and August addressed the second concern: operations.

Hosted Agents, Voice Live, and Toolboxes moved from beta to GA; Model Router expanded its pool of models and regions; Foundry Local was added; and the Python, JavaScript, Java, and .NET SDKs were updated. The difference between June and August is simple: June settled whom to pay for the model; August addressed how an agent running on it can make it to production.

Five tools that turn a model into an agent

Claude on Azure now includes structured outputs, web search, web fetch, an MCP connector, and tool search.

Each addresses a specific gap between a demonstration and a working system: structured outputs eliminate parsing unpredictable text responses; web search and web fetch give the model access to data newer than its training cutoff; the MCP connector connects an agent to external systems through an open protocol instead of requiring a custom integration for every source; and tool search solves a problem that previously went unspoken: an agent with around fifty connected tools cannot conveniently select the right one without an index.

Assess where AI can deliver impact in your process

Simple on the outside does not mean simple inside

Agent-framework releases that summer reveal the other side of the showcase

Version 1.14 introduced MLflow observability, workflow checkpoint and resume, and the experimental AGENT-HOOKS-0.1 enforcement middleware layer. Version 1.18 added a maximum tool execution duration, a stop-reason signal for tool-call loops, shared vector store abstractions, and support for mixed workflow arguments.

These are exactly the things nobody shows in a conference demo: what happens when an agent gets stuck in a call loop, how to see which step led to a wrong decision, and how to roll back a workflow when an external service returns an unexpected response. This summer's TTU improved across the market: time to the first working agent call fell from weeks of infrastructure configuration to reading a changelog.

But a company's TTU is determined not by the platform, but by whether it built around the agent the same checkpoints, observability, and execution-time limits that Microsoft built into its framework by default.

The simple result—an agent that reliably solves a task without an engineer's supervision—still requires exactly as much engineering work as before.

That work is simply now visible separately from infrastructure work, so it can no longer be dismissed with “the platform has not been connected yet.”

What this changes for business

  1. Web fetch and the MCP connector expand what an agent can reach—and therefore expand what can go wrong: an agent with access to an external API and arbitrary MCP servers, without explicit permission definitions, becomes a source of incidents.

  2. An agent's security is now determined by which tools the model is allowed to call and who verified them.

  3. The layer between the agent and the outside world that logs and limits calls is exactly where it is decided whether a pilot will reach production without an incident in its first month.

  4. For companies that have kept AI at the experimental stage for the past two years, August 2026 is a signal to change perspective: there is no longer a technical reason to remain in pilot mode. GA status, Marketplace billing, and SDKs in four languages mean procurement and legal barriers are gone too.

  5. Only one question remains, and it is not about the model: is the team ready to operate the agent as rigorously as any other production service—with logs, rollbacks, and permission boundaries?

How this works in practice

RAG remains the answer to where an agent gets knowledge about a specific business: web search provides fresh public data but does not replace an index of internal documents and the company's customer database. The MCP connector removes the need to build a new integration for every system, but someone must define which MCP servers may be connected—and that is a security-governance task, not the responsibility of an individual agent developer.

Microsoft's Python and .NET SDKs handle model calls; orchestrating multiple agents, rolling back state, and controlling what an agent can call remain the integrator's responsibility when building on top of the platform rather than relying on it entirely.

Conclusion

Through Foundry, Microsoft removed two barriers for companies in succession: procurement first, then infrastructure. Both times, removing the barrier revealed that the real work lay elsewhere. An agent that can call Claude's five new tools is no better than one without them if nobody has decided what happens when a call fails, who can see its logs, and what data it may access. The platform became simpler; the discipline around it did not.

Discuss the article: Foundry and Claude: Agent Ready, Discipline…

Enter your email or phone number so we can get back to you.

Send via: