A high-level guide to setting up and scaling an AI Foundry Resource within an enterprise
Updated Jul 16, 2025
Version 1.0Hi arung
It appears that setting project-scoped RBAC is not working as expected. Currently, developers must be assigned the Azure AI User role at the Azure AI Foundry Resources scope in order to access LLM and AI service endpoints.
The issue is that assigning this role at the Foundry Resources level causes the permissions to be inherited by all child Foundry Projects. This inheritance makes it impossible to restrict a user’s access to a specific Foundry project only.