Formerly known as Azure AI Services or Azure Cognitive Services is a unified collection of prebuilt AI capabilities within the Microsoft Foundry platform
Publishing agents and workflows in Azure AI Foundry relies on the same underlying Agent Application resource. A 404 SystemError during publish usually means the Agent Application resource or deployment wasn’t created correctly, or required permissions/identity setup is missing.
Use these checks to unblock publishing and then verify the published endpoint works:
- Confirm permission to publish
- Publishing requires the Azure AI Project Manager role on the Foundry resource (account) scope, not just on the project.
- If Publish Agent or Publish workflow is disabled or fails, ask a subscription/admin owner to assign this role at the Foundry account scope.
- Publish the agent from Agent Builder
- Open the agent in Agent Builder.
- Save the current version.
- Select Publish Agent.
- Expected result: publishing completes and the agent version shows a published status. This creates:
- An Agent Application Azure resource.
- A Deployment referencing that agent version.
- Reassign tool permissions after publishing
- When an agent is published, it gets a new Entra agent identity; permissions from the project identity do not transfer.
- For any tools that use agent identity (for example, calling other Azure resources), go to each downstream Azure resource and assign the required RBAC role to the new agent application identity. Otherwise tool calls can fail after publish.
- Publish and update workflows
- After the underlying agents publish successfully, publish the workflow again.
- If updating an already-published agent, use Publish Updates so the existing Agent Application and deployment point to the new version while keeping the same endpoint.
- Verify the Agent Application and deployment
- In Azure, confirm the Agent Application resource exists and that its deployment state is running.
- If needed, use the management API to:
-
GETthe deployment and checkstate. -
POST .../startto start a stopped deployment.
-
- Test the published endpoint
- Get an access token:
-
az account get-access-token --resource https://ai.azure.com
-
- Call the Responses protocol endpoint for the Agent Application with
curl. - If the call returns:
-
403 Forbidden: assign the Azure AI User role on the Agent Application resource to the caller. -
401 Unauthorized: reauthenticate and ensure the token is requested forhttps://ai.azure.com.
-
- Get an access token:
- If the workflow still fails with 404
- Confirm the workflow is targeting the correct, published agent names and that those agents are successfully published and running as above.
- If everything above is correct and 404 persists, capture the error ID and region from the banner and raise it through support or the training forum, as it can indicate a transient or region-specific backend issue.
Following these steps ensures the agent and workflow are published as Agent Applications with running deployments, correct identities, and the right RBAC so the training assessment can validate them.
References: