Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
josiahsiegel avatar

Azure Ml Foundry Workspace

  • 83 installs
  • 50 repo stars
  • Updated June 18, 2026
  • josiahsiegel/claude-plugin-marketplace

Provision and manage Azure AI Foundry workspaces, networking, and deployment stacks.

About

Plugin for Azure resource provisioning covering AI Foundry, networking, deployment stacks, and debugging. Includes cost optimization patterns.

  • Azure AI Foundry provisioning and configuration
  • Network design and cost optimization

Azure Ml Foundry Workspace by the numbers

  • 83 all-time installs (skills.sh)
  • +4 installs in the week ending Aug 2, 2026 (Skillselion tracking)
  • Ranked #609 of 1,039 Cloud & Infrastructure skills by installs in the Skillselion catalog
  • Data as of Aug 3, 2026 (Skillselion catalog sync)
npx skills add https://github.com/josiahsiegel/claude-plugin-marketplace --skill azure-ml-foundry-workspace

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs83
repo stars50
Last updatedJune 18, 2026
Repositoryjosiahsiegel/claude-plugin-marketplace

What it does

Provision and manage Azure AI Foundry workspaces, networking, and deployment stacks.

Files

SKILL.mdMarkdownGitHub ↗

Azure Machine Learning Workspace / Azure AI Foundry - Complete Deep-Dive Reference

Authoritative reference for every aspect of Azure Machine Learning Workspace (Azure AI Foundry) including architecture, networking, private endpoints, compute clusters, endpoint deployment, managed identities, ACR integration, storage accounts, all CLI and PowerShell commands, log reading, debugging, and Terraform integration.

---

1. ARCHITECTURE AND CORE CONCEPTS

Workspace Resource Hierarchy

Azure Subscription
  └── Resource Group
        ├── Azure ML Workspace (Microsoft.MachineLearningServices/workspaces)
        │     ├── Dependent Resources (auto-created or BYO)
        │     │     ├── Azure Storage Account (default datastore)
        │     │     ├── Azure Key Vault (secrets, connection strings)
        │     │     ├── Azure Application Insights (telemetry)
        │     │     └── Azure Container Registry (Docker images for environments)
        │     ├── Compute Targets
        │     │     ├── Compute Instances (dev/test VMs)
        │     │     ├── Compute Clusters (AmlCompute - training)
        │     │     ├── Serverless Compute (on-demand)
        │     │     ├── Kubernetes Compute (AKS / Arc-enabled)
        │     │     └── Attached Compute (Databricks, HDInsight, VMs)
        │     ├── Data Assets (versioned references to data)
        │     ├── Datastores (connections to storage)
        │     ├── Environments (Docker + conda specs)
        │     ├── Models (registered trained models)
        │     ├── Endpoints
        │     │     ├── Managed Online Endpoints (real-time)
        │     │     ├── Kubernetes Online Endpoints (BYO infra)
        │     │     ├── Batch Endpoints (large-scale scoring)
        │     │     └── Serverless Endpoints (MaaS - pay-per-token)
        │     ├── Jobs (training runs, pipelines, sweeps)
        │     ├── Components (reusable pipeline steps)
        │     ├── Schedules (recurring job triggers)
        │     └── Registries (cross-workspace sharing)
        └── AI Foundry Hub (kind=hub) + Projects (kind=project)

AI Foundry Hub/Project vs Classic Workspace

FeatureClassic Workspace (kind=Default)AI Foundry Hub + Project
Portalml.azure.comai.azure.com
ScopeSingle workspaceHub shares infra across projects
NetworkingPer-workspaceHub-level (shared across projects)
IdentityPer-workspaceHub-level identity, project inherits
Model catalogYesYes, plus additional Foundry models
Prompt flowYesYes
AI agentsLimitedFull AI Agent Service
Use caseClassical ML, custom trainingGenAI, LLM apps, AI agents

Workspace Creation - All Methods

CLI:

# Install/upgrade ML extension
az extension add --name ml --upgrade

# Create resource group
az group create --name ml-rg --location eastus

# Create workspace with all dependencies auto-created
az ml workspace create \
  --name my-ml-workspace \
  --resource-group ml-rg \
  --location eastus

# Create workspace with explicit dependencies
az ml workspace create \
  --name my-ml-workspace \
  --resource-group ml-rg \
  --location eastus \
  --storage-account /subscriptions/<sub>/resourceGroups/ml-rg/providers/Microsoft.Storage/storageAccounts/mlstorage \
  --key-vault /subscriptions/<sub>/resourceGroups/ml-rg/providers/Microsoft.KeyVault/vaults/mlkeyvault \
  --app-insights /subscriptions/<sub>/resourceGroups/ml-rg/providers/Microsoft.Insights/components/mlinsights \
  --container-registry /subscriptions/<sub>/resourceGroups/ml-rg/providers/Microsoft.ContainerRegistry/registries/mlacr \
  --public-network-access Disabled \
  --managed-network AllowInternetOutbound \
  --image-build-compute cpu-build-cluster \
  --enable-data-isolation true \
  --tags Environment=Production Team=DataScience

# Create AI Foundry Hub
az ml workspace create \
  --name my-ai-hub \
  --resource-group ml-rg \
  --location eastus \
  --kind hub \
  --storage-account aihubstorage \
  --key-vault aihubkeyvault

# Create AI Foundry Project within Hub
az ml workspace create \
  --name my-ai-project \
  --resource-group ml-rg \
  --location eastus \
  --kind project \
  --hub-id /subscriptions/<sub>/resourceGroups/ml-rg/providers/Microsoft.MachineLearningServices/workspaces/my-ai-hub

# Show workspace details
az ml workspace show \
  --name my-ml-workspace \
  --resource-group ml-rg

# List all workspaces
az ml workspace list \
  --resource-group ml-rg \
  --output table

# Update workspace
az ml workspace update \
  --name my-ml-workspace \
  --resource-group ml-rg \
  --description "Updated workspace" \
  --public-network-access Disabled

# Delete workspace
az ml workspace delete \
  --name my-ml-workspace \
  --resource-group ml-rg \
  --permanently-delete --all-resources

# Diagnose workspace configuration
az ml workspace diagnose \
  --name my-ml-workspace \
  --resource-group ml-rg

PowerShell (Az.MachineLearningServices):

# Install the module
Install-Module -Name Az.MachineLearningServices -Scope CurrentUser -Repository PSGallery -Force

# Create workspace
New-AzMLWorkspace `
  -Name "my-ml-workspace" `
  -ResourceGroupName "ml-rg" `
  -Location "eastus" `
  -StorageAccountId "/subscriptions/<sub>/resourceGroups/ml-rg/providers/Microsoft.Storage/storageAccounts/mlstorage" `
  -KeyVaultId "/subscriptions/<sub>/resourceGroups/ml-rg/providers/Microsoft.KeyVault/vaults/mlkeyvault" `
  -ApplicationInsightId "/subscriptions/<sub>/resourceGroups/ml-rg/providers/Microsoft.Insights/components/mlinsights" `
  -IdentityType "SystemAssigned" `
  -PublicNetworkAccess "Disabled"

# Get workspace
Get-AzMLWorkspace -Name "my-ml-workspace" -ResourceGroupName "ml-rg"

# List workspaces
Get-AzMLWorkspace -ResourceGroupName "ml-rg"

# Update workspace
Update-AzMLWorkspace `
  -Name "my-ml-workspace" `
  -ResourceGroupName "ml-rg" `
  -Description "Updated workspace" `
  -Tag @{Environment="Production"}

# Remove workspace
Remove-AzMLWorkspace -Name "my-ml-workspace" -ResourceGroupName "ml-rg"

# Diagnose workspace
Invoke-AzMLWorkspaceDiagnose -Name "my-ml-workspace" -ResourceGroupName "ml-rg"

---

2. NETWORKING

Azure ML supports three managed network isolation modes (Disabled, AllowInternetOutbound, AllowOnlyApprovedOutbound) with the managed VNet approach recommended for production. Private endpoints provide inbound connectivity, and outbound rules control egress from compute resources.

Key DNS Zones

ServicePrivate DNS Zone
ML Workspace APIprivatelink.api.azureml.ms
ML Notebooksprivatelink.notebooks.azure.net
Storage Blobprivatelink.blob.core.windows.net
Storage Fileprivatelink.file.core.windows.net
Key Vaultprivatelink.vaultcore.azure.net
Container Registryprivatelink.azurecr.io
Application Insightsprivatelink.monitor.azure.com

Key Service Tags

Service TagPurpose
AzureMachineLearningML workspace management (inbound 44224, outbound 443)
BatchNodeManagementCompute cluster management (inbound 29876-29877)
StorageAccess to Azure Storage (outbound 443)
AzureActiveDirectoryAuthentication (outbound 443)

For full VNet configuration, private endpoint setup, NSG rules, and outbound rule management, see [references/networking.md](references/networking.md).

---

3. COMPUTE

Azure ML offers multiple compute targets: Compute Instances for dev/test, AmlCompute Clusters for scalable training, Serverless Compute for on-demand jobs without cluster management, and Kubernetes Compute for BYO infrastructure scenarios.

GPU VM SKU Quick Reference

VM SeriesGPUGPU MemoryUse Case
Standard_NC24ads_A100_v41x A10080 GBTraining, fine-tuning
Standard_ND96amsr_A100_v48x A100 80GB640 GBLarge model training
Standard_ND_H100_v58x H100640 GBGenAI, LLM training
Standard_ND_H200_v58x H2001120 GBLatest: 2x perf vs H100
Standard_NCads_H100_v51x H100 NVL94 GBInference, fine-tuning
Standard_NC4as_T4_v31x T416 GBBudget inference

For the complete GPU SKU table, compute instance/cluster CLI reference, serverless compute, Kubernetes attach, and debugging commands, see [references/compute.md](references/compute.md).

---

4. ENDPOINT DEPLOYMENT

Azure ML supports four endpoint types: Managed Online Endpoints (recommended for real-time inference with blue-green deployments), Batch Endpoints (large-scale scoring on compute clusters), Kubernetes Online Endpoints (BYO AKS/Arc infrastructure), and Serverless Endpoints (pay-per-token Model-as-a-Service).

Endpoint Types Quick Reference

TypeUse CaseAuth ModesScaling
Managed OnlineReal-time inferencekey, aml_tokenPer-deployment instance count
BatchLarge-scale scoringmanaged identityCompute cluster auto-scale
Kubernetes OnlineBYO infra real-timekey, aml_tokenK8s pod scaling
Serverless (MaaS)Pay-per-token LLMkeyAutomatic

For full endpoint creation, deployment, traffic splitting, log retrieval, and batch invocation commands, see [references/endpoints.md](references/endpoints.md).

---

5-7. IDENTITIES, ACR, AND STORAGE

Managed identities (system-assigned or user-assigned) control access between workspace, compute, endpoints, and dependent resources. ACR stores Docker images for environments and model serving, requiring Premium SKU for private endpoints and an image-build-compute cluster when behind a VNet. Storage accounts serve as the default datastore for blobs, file shares, job outputs, and MLflow artifacts.

Identity Types

Identity TypeUse Case
System-Assigned (workspace)Default workspace operations, auto-lifecycle
User-Assigned (workspace)CMK encryption, cross-resource sharing
System-Assigned (compute)Per-cluster storage/ACR access
User-Assigned (compute)Fine-grained, reusable access control

Key RBAC Roles

RoleDescription
AzureML Data ScientistRun jobs, manage compute, deploy models
AzureML Compute OperatorCreate/manage compute resources
Azure AI DeveloperAI Foundry project development
Azure AI Inference Deployment OperatorDeploy models to endpoints

For full identity configuration, role assignment commands, ACR integration, private ACR setup, datastore registration, and storage account details, see [references/identities-acr-storage.md](references/identities-acr-storage.md).

---

8-9. CLI AND POWERSHELL

The az ml CLI extension provides comprehensive workspace management through 20+ command groups covering workspaces, compute, jobs, models, endpoints, environments, data, datastores, components, schedules, registries, and connections. The Az.MachineLearningServices PowerShell module offers equivalent functionality for Windows-native automation.

Key az ml Command Groups

Command GroupPurpose
az ml workspaceManage workspaces (create, diagnose, provision-network, outbound-rule)
az ml computeManage compute (create, start, stop, connect-ssh, attach)
az ml jobManage jobs (create, stream, cancel, download)
az ml online-endpointManage online endpoints (create, invoke, get-credentials)
az ml online-deploymentManage deployments (create, get-logs, traffic)
az ml batch-endpointManage batch endpoints (create, invoke, list-jobs)
az ml serverless-endpointManage serverless endpoints (create, get-credentials)

For the complete command reference, job management deep-dive, schedule management, and full PowerShell cmdlet reference, see [references/cli-powershell.md](references/cli-powershell.md).

---

10. TERRAFORM INTEGRATION

Azure ML workspaces can be fully provisioned with Terraform using the azurerm provider. A production setup includes the workspace, VNet/subnets, NSG, storage account, key vault, ACR, Application Insights, private endpoints, DNS zones, compute clusters, and RBAC role assignments.

Key Terraform Resources

ResourcePurpose
azurerm_machine_learning_workspaceML workspace (Default, Hub, Project)
azurerm_machine_learning_compute_clusterAmlCompute training clusters
azurerm_machine_learning_compute_instanceDev/test compute instances
azurerm_machine_learning_workspace_network_outbound_rule_*Managed network outbound rules

For the full production-ready Terraform configuration (providers, networking, storage, key vault, ACR, workspace, compute, role assignments, and outputs), see [references/terraform.md](references/terraform.md).

---

11. TROUBLESHOOTING AND DEBUGGING

Azure ML provides multiple debugging surfaces: real-time job log streaming, deployment container logs (inference-server and storage-initializer), compute instance SSH access for system-level diagnostics, Log Analytics queries for historical analysis, and the az ml workspace diagnose command for configuration validation.

Common Error Categories

CategoryCommon Errors
ComputeQuotaExceeded, AllocationFailed, disk full, GPU not detected
EndpointsScoringError, HealthCheckFailure, ImageBuildFailed, 429/503 errors
NetworkingDNS resolution failure, connection timeout, storage/ACR access denied
JobsEnvironmentBuildError, OutOfMemoryError, NCCL timeout, blob not found

For full error reference tables, log locations, Log Analytics queries, endpoint metrics monitoring, workspace diagnostics, and the secure workspace setup checklist, see [references/troubleshooting.md](references/troubleshooting.md).

---

Additional Resources

Detailed reference files for each topic area:

  • [references/networking.md](references/networking.md) -- VNet, private endpoints, DNS zones, NSG rules, service tags
  • [references/compute.md](references/compute.md) -- GPU SKUs, compute instances, clusters, serverless, Kubernetes
  • [references/endpoints.md](references/endpoints.md) -- Managed online, batch, Kubernetes, and serverless endpoints
  • [references/identities-acr-storage.md](references/identities-acr-storage.md) -- Managed identities, ACR integration, storage accounts
  • [references/cli-powershell.md](references/cli-powershell.md) -- Complete az ml CLI and PowerShell command reference
  • [references/terraform.md](references/terraform.md) -- Full production-ready Terraform configuration
  • [references/troubleshooting.md](references/troubleshooting.md) -- Log reading, debugging, error tables, setup checklist

External Documentation

Related skills

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.