An Azure service that provides access to OpenAI’s GPT-3 models with enterprise capabilities.
Hello @Jorge Ortiz Flores ,
Thank you for helping us with the required details to assist you better
The observed 403 errors originate from two different scenarios, and each follows a separate resolution path.
- GPT deployments (chat and mini) The failures are not caused by a platform issue. Instead, requests are being blocked at the access layer due to configured authentication and network policies, meaning traffic is rejected before reaching the model backend.
- Embedding deployment (text-embedding-3-large) This issue is independent and is caused by a Content Safety enforcement block applied at the resource level. This type of block requires a formal review and cannot be resolved through configuration changes.
GPT models are returning 403 as
The behavior is consistent with security settings applied on the resource:
- Authentication mismatch
- Key-based authentication is disabled
- Application or Azure AI Search embedding flow still using API key
- Requests are rejected during access validation
- Network restrictions
- Public network access disabled while calls are made via public endpoint
- Firewall rules blocking incoming traffic
- Azure AI Search configuration
- Embedding skill still configured with apiKey instead of authIdentity
- Key authentication takes precedence when configured
How to unblock GPT resources
- Immediate workaround (fast recovery)
- Re-enable key-based authentication temporarily
- Location: Azure OpenAI resource → Keys and Endpoint → enable local auth This helps restore access quickly while long-term fixes are implemented.
Permanent resolution
- Migrate to Microsoft Entra ID authentication
- Use managed identity or token-based authentication
- Assign required role: Cognitive Services OpenAI User
- Update Azure AI Search embedding configuration
- Replace
apiKeywithauthIdentity - Enable managed identity on Azure AI Search
- Ensure role assignment on Azure OpenAI resource
- Replace
- Validate network access settings
- Check if public access is disabled
- Verify firewall rules allow traffic from calling service
- Validate private endpoint / trusted service configuration
How to resolve embedding (text-embedding-3-large)
This scenario requires review through the official process:
- Submit review request: Code of Conduct for Microsoft AI Services | Microsoft Learn
- This block is enforced by Content Safety systems and needs manual evaluation.
Please refer the following for further reference:
- gpt-5-chat Content filtering for Microsoft Foundry Models (classic) - Microsoft Foundry (classic) portal | Microsoft Learn Azure API Management Troubleshooting Scenario 5 - Request throttling problems and HTTP 403 - Forbidden issues - Azure | Microsoft Learn
- gpt-5-mini https://learn.microsoft.com/en-us/azure/foundry-classic/openai/how-to/managed-identity https://learn.microsoft.com/en-us/troubleshoot/azure/api-mgmt/availability/request-throttling-http-403#troubleshooting-steps
To summarize
- GPT-related errors are caused by authentication and network configuration mismatch, and can be resolved through authentication migration or network corrections.
- Embedding failure is due to a Content Safety enforcement block, which requires submission for review.
Following these steps should help restore functionality for GPT deployments and guide the next steps for the embedding scenario.
Please let us know the resolution updates
Thank you