Azure AI Services
Your GenAI system is built — now run it where the enterprise already lives. Azure's AI stack is the most complete commercial offering on earth — and this reel is the architect's map of it.
▶ Watch this reelWhat you'll learn
- Azure OpenAI & Foundry
- AI Search & documents
- Safety & the boundary
- Identity, network & Copilots
Remember this
- Azure OpenAI = OpenAI models inside YOUR tenancy: version-pinned deployments, quota per deployment, data out of training — the InfoSec fast-track
- Azure AI Search gives GA-10's whole retrieval stack as a service: vectors, hybrid BM25+vector fusion, and an LLM semantic ranker
- Document Intelligence decides RAG quality at ingestion; Content Safety is AG-09's guardrail as an API — screen input AND output
- Managed identity + private endpoints answer the three security questions before they're asked — and M365 Copilot shares the same stack
The stack in one view
| Layer | Service | Replaces (our hand-built) |
|---|---|---|
| Models | Azure OpenAI / AI Foundry | public OpenAI API + model management |
| Retrieval | Azure AI Search | pgvector + retriever (GA-10) |
| Ingestion | Document Intelligence | PDF parsing, layout, tables |
| Safety | Content Safety | guardrail classifiers (AG-09) |
| Identity | Managed Identity + RBAC | API keys in config (AG-23) |
| Network | Private Endpoints | public API surface |
Azure OpenAI vs public OpenAI API
- Tenancy: prompts/completions stay in your boundary; never train OpenAI models.
- Deployments: named, version-pinned; upgrades are deliberate.
- Quota: tokens-per-minute per deployment — size it like compute.
- AI Foundry: portal + SDK control plane — model catalog, playgrounds, eval, tracing.
Azure AI Search
- Vectors (HNSW), hybrid text+vector with score fusion, semantic ranker (LLM re-rank top-N).
- Rule from GA-10 holds: hybrid is the production default; exact terms need BM25.
Document Intelligence & Content Safety
- Extraction quality decides RAG quality. Scan → layout → tables → clean text.
- Screen input AND output (AG-09's boundary as an API). Indirect-injection detector for retrieved docs (AG-22).
Enterprise mechanics
- Managed identity: no keys, no rotation; RBAC scoped per deployment.
- Private endpoints: no public traffic.
- M365 Copilot shares the stack — Graph connectors let your app and Copilot share indexes.
Decision heuristic
Pick Azure when the enterprise already lives there. The integration tax of a separate vendor stack (identity, network, compliance sign-off) usually exceeds any model-price difference.
Code: The Azure GenAI reference call
from azure.identity import DefaultAzureCredential
from openai import AzureOpenAI
# Identity: managed identity — no keys in config
# Model: version-pinned deployment
# Data: inside your tenancy, never training
client = AzureOpenAI(
azure_endpoint="https://my-resource.openai.azure.com/",
azure_ad_token_provider=lambda: DefaultAzureCredential()
.get_token("https://cognitiveservices.azure.com/.default").token,
api_version="2024-12-01-preview",
)
resp = client.chat.completions.create(
model="my-gpt4o",
messages=[{"role": "user", "content": question}],
)
# Retrieval, safety, documents: sibling services on the
# same identity — one boundary, one compliance story.