Microsoft Foundry Agent Service subnet sizing mistakes can silently break production agents

Microsoft Foundry Agent Service supports private networking via VNet injection, allowing enterprises to keep agent traffic and data within customer-managed network boundaries. However, architects who undersize the delegated subnet — commonly choosing a /27 block — risk IP exhaustion that causes HTTP 429 errors, intermittent 5xx failures, and silent provisioning failures in production. The platform shares the subnet across all projects in a Foundry account, and agent sessions consume IP addresses similarly to how a connection pool consumes sockets. Unlike typical network failures, IP exhaustion in this setup produces no portal alerts or utilization dashboards, forcing engineers to diagnose issues through Application Insights traces. Proper subnet sizing requires understanding the IP-to-session allocation ratios for both hosted agents and prompt agents before deployment, not after production falls over.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in