Designing Scalable and Secure Agent-First Platforms with Azure Container Apps Sandboxes
This article discusses a paradigm shift from traditional user-driven applications to continuously acting, multi-agent systems, highlighting the new challenges in making AI agents production-ready. It introduces Microsoft Foundry for agent governance and Azure Container Apps Sandboxes as a solution for providing isolated, secure execution environments. The post outlines an architectural pattern that combines these services to enable scalable, compliant, and reliable deployment of autonomous AI agents. Real-world examples from KPMG and Cognite illustrate how this approach facilitates regulated client work and complex industrial analytics.
- →Secure Execution with Azure Container Apps Sandboxes
- →Shift to Agent-First Application Design
- →Challenges in Productionizing AI Agents
- →Microsoft Foundry for Agent Building and Governance
- →Emerging Architectural Pattern for Enterprise AI Agents
Features (1) ›
- Secure Execution with Azure Container Apps Sandboxes
Azure Container Apps Sandboxes introduces dedicated, hardware-isolated microVM environments for agent code execution. These sandboxes offer strong separation, sub-second startup, controlled identity, and scoped access to systems, ensuring security and compliance for agent tasks.
Notes (5) ›
- Shift to Agent-First Application Design
The article explains the fundamental shift from traditional request-response applications to continuously acting multi-agent applications that autonomously reason and execute steps at runtime to achieve described outcomes.
- Challenges in Productionizing AI Agents
It highlights the complexities of moving AI agents from pilot stages to production, emphasizing critical requirements such as first-class identity, comprehensive observability, runtime guardrails, security, and compliance for enterprise-grade operation.
- Microsoft Foundry for Agent Building and Governance
Microsoft Foundry is presented as the platform for building, grounding in enterprise knowledge, and governing AI agents. It provides agents with first-class identity through Entra Agent ID and enables tracing and evaluation of live agents.
- Emerging Architectural Pattern for Enterprise AI Agents
A recommended architectural pattern combines Microsoft Foundry for agent governance and development with Azure Container Apps Sandboxes for secure, isolated, and scalable runtime execution. This enables organizations to deploy thousands of concurrent agents without compromising security or platform integrity.
- Real-world Implementations of Agent-First Platforms
The article showcases practical applications, including KPMG's Digital Gateway Powered by Claude, which uses over 30,000 concurrent Azure Container Apps Sandboxes for regulated client work, and Cognite Atlas AI for industrial operational analytics.
https://azure.microsoft.com/en-us/blog/designing-agent-first-platforms-what-changes-when-agents-do-the-work/
Related releases
- Azure on Ensuring Resilience in the AI Era: Beyond Static Diagrams Microsoft Azure Blog ·
- Microsoft Foundry Expands AI Agent Capabilities with New Models, Voice, and Resilient Workflows Microsoft Azure Blog ·
- Azure AI Foundry model Kimi-K2.7-Code 2026-06-12 reaches end of life in 7 days endoflife.date ·
- Azure HorizonDB adds PostgreSQL 18 support in public preview Azure Updates ·
- Azure AI Foundry model gpt-4o 2024-05-13 end-of-life date moved to 2026-12-09 endoflife.date ·
- Terraform Azure Provider v5.7.0 Adds Private DNS & Windows VM Resources Terraform AzureRM Provider Releases ·