Loading Now

Agent Factory: Building your first AI agent with the tools to deliver real-world outcomes

Agents reach their potential only when equipped with the right tools—and their reliability hinges on how you govern them.

This article is the second in our six-part series, Agent Factory, where we share best practices, design patterns, and tools to help you incorporate and develop agentic AI effectively.

In our previous entry, we discussed five prevalent agentic AI design patterns: tool usage, reflection, planning, multi-agent collaboration, and adaptive reasoning. These patterns show how agents can be organised to deliver dependable, scalable automation in real-world scenarios.

The landscape is changing. Earlier trials relied on single-model prompts and rigid workflows. Today, we’re talking about extensibility—enabling agents to have a broad, evolving suite of capabilities without being tied to a specific vendor or rewriting integrations for each new requirement. Companies are striving to enhance how developers can:

  • Integrate with numerous APIs, services, data sources, and workflows.
  • Reapply those integrations across various teams and operating environments.
  • Maintain enterprise-level control over permissions regarding data and tool usage.

The key takeaway from the previous year’s evolution in agentic AI is clear: agents are only as capable as the tools you provide them, and their trustworthiness depends on the governance around those tools.

Extensibility Through Open Standards

In the early days of developing agents, integrating tools was often a unique, platform-specific task. Each framework came with its own rules for defining tools, data management, and authentication, leading to consistent challenges:

  • Redundant effort—the same internal API had to be implemented differently across environments.
  • Vulnerable integrations—minor alterations to schemas could disrupt multiple agents at once.
  • Restricted reusability—tools tailored for one team or environment were challenging to share across projects or platforms.
  • Disparate governance—different environments enforced varying policies and security measures.

As organisations began rolling out agents in hybrid and multi-cloud settings, these inefficiencies became significant hurdles. Teams needed a way to standardise how tools are described, discovered, and used, regardless of the operating environment.

This is where open protocols come into play. Just as HTTP revolutionised the web by establishing a common language for clients and servers, open protocols for agents aim to improve tools’ portability, interoperability, and governance.

A leading example is the Model Context Protocol (MCP)—a standard that outlines tool capabilities and I/O schemas, allowing any MCP-compliant agent to discover and utilise them dynamically. With MCP:

  • Tools are self-describing, speeding up discovery and integration.
  • Agents can find and engage with tools during runtime without manual setup.
  • Tools can be hosted anywhere—be it on-premises, in a partner’s cloud, or within a different business unit—while maintaining governance.

Azure AI Foundry supports MCP, letting you integrate existing MCP servers directly into your agents. This means you benefit from open interoperability while achieving enterprise-class security, observability, and management. You can learn more about MCP at MCP Dev Days.

A diagram of a server

Once you establish a standard for portability through open protocols like MCP, the next question arises: what tools should your agents incorporate, and how can you organise them to deliver quick value while staying flexible?

At Azure AI Foundry, we perceive this as creating an enterprise toolchain—a multi-layered set of capabilities that balances speed (getting valuable tools operational quickly), differentiation (showcasing what makes your business unique), and reach (linking with all systems where operations occur).

1. Built-in Tools for Quick Outcomes: Azure AI Foundry offers ready-to-use tools that cater to common enterprise needs: conducting searches across SharePoint and data lakes, running Python scripts for data analysis, performing multi-step web searches using Bing, and initiating browser automation tasks. These tools not only save time but also let teams build high-value agents in days rather than weeks, without the early integration hassles.

Azure AI Foundry Agents playground interface where an AI agent is set up with Azure Search and Cosmos DB connections. The agent responds to a browser automation task, including filling out a Microsoft Forms link with delivery details.

2. Custom Tools for Competitive Advantage: Every organisation possesses unique systems and processes that off-the-shelf tools cannot replicate easily. Azure AI Foundry simplifies the process of wrapping these into agentic AI tools—be it APIs from your ERP, quality control systems in manufacturing, or services from a partner. By employing OpenAPI or MCP, these tools become portable and accessible across teams, projects, and clouds, all while benefiting from Foundry’s security, policy, and observability standards.

Running a Python script in VS Code that registers an MCP tool for an Azure REST API. The terminal shows the creation of an agent, a thread, and a message, with the run status marked as ‘In Progress.

3. Connectors for Maximum Reach: Through Azure Logic Apps, Foundry can link agents to over 1,400 SaaS and on-prem systems—covering CRM, ERP, ITSM, data warehouses, and more. This drastically reduces integration workload, letting you connect to existing enterprise processes without building every connector from scratch.

A Logic Apps workflow in the Azure portal showing an automation that triggers an AI agent when a new email arrives. The workflow steps include initializing content, iterating through actions, generating markdown from HTML, and completing the content with the AI agent.

A prime example of this toolchain comes from NTT DATA, which developed agents in Azure AI Foundry that integrate the Microsoft Fabric Data Agent alongside other enterprise systems. These agents empower employees in HR, operations, and beyond to engage naturally with data—uncovering real-time insights and enabling action—cutting time-to-market by 50% and giving non-technical users intuitive, self-service access to enterprise information.

For extensibility to transition from prototype to enterprise-ready automation, governance plays a vital role. Azure AI Foundry adopts a secure-by-default strategy for tool management:

  • Authentication and identity with built-in connectors: Enterprise-grade connectors—such as SharePoint and Microsoft Fabric—utilise on-behalf-of (OBO) authentication. When an agent accesses these tools, Foundry ensures that the user’s permissions are upheld through managed Entra IDs, maintaining existing authorisation protocols. With Microsoft Entra Agent ID, every agentic project created in Azure AI Foundry appears in a dedicated view within the Microsoft Entra admin centre, giving security teams a consolidated view of all agents that require management across Microsoft. This linkage represents an initial stride toward standardising governance for AI agents across organisations. While Entra ID is native, Azure AI Foundry also accommodates integrations with external identity solutions, ensuring that customers using platforms like Okta or Google Identity can securely authenticate agents and users.
  • Custom tools with OpenAPI and MCP: Tools adhering to OpenAPI allow seamless connectivity via managed identities, API keys, or unauthenticated access. These tools can be registered directly in Foundry, aligning with best practices for API design. Furthermore, Foundry is enhancing MCP security to include stored credentials, project-level managed identities, and third-party OAuth flows, moving toward comprehensive, enterprise-grade integration.
  • API governance with Azure API Management (APIM): APIM provides robust control for managing tool access by enabling central publishing, policy enforcement (including authentication, rate limits, and payload validation), and monitoring. Additionally, you can deploy self-hosted gateways within VNets or on-premises settings to apply business policies close to backend systems. In concert with this, Azure API Centre functions as a centralised repository for API design-time inventory and discovery—enabling teams to register, catalogue, and manage private MCP servers alongside existing APIs. These functionalities extend the governance standards typical of APIs to encompass agentic AI tools without requiring extra engineering work.
  • Observability and auditability: Every tool invocation within Foundry—whether internal or external—is tracked with detailed logging. This information includes identity, tool names, inputs, outputs, and results, supporting continuous reliability checks and simpler auditing.

Effective enterprise-level management ensures tools are secure and monitored—but success also depends on how they’re designed and operated from the outset. Drawing from the guidance offered by Azure AI Foundry and practical customer insights, several key principles arise:

  1. Begin with the contract. Treat every tool as an API product. Clearly define the inputs, outputs, and error handling while ensuring consistency in schemas across teams. Avoid cramming too many disparate actions into a single tool; smaller, specialised tools are easier to test, monitor, and reuse.
  2. Select the right packaging. For proprietary APIs, determine early whether OpenAPI or MCP is more suitable for your needs. OpenAPI tools are ideal for well-documented REST APIs, while MCP tools shine when portability and cross-environment utilisation are priorities.
  3. Centralise governance. Publish custom tools behind Azure API Management or a self-hosted gateway to apply authentication, throttling, and payload validation uniformly. This practice keeps policy logic out of tool code and eases the rollout of changes.
  4. Link every action to identity. Always track which user or agent is invoking the tool. For built-in connectors, use identity passthrough or OBO. For custom tools, opt for Entra ID or the appropriate API key/credential configuration, applying least-privilege principles.
  5. Implement monitoring early. Integrate tracing, logging, and evaluation mechanisms before transitioning into production. Early visibility allows you to track performance patterns, spot regression issues, and fine-tune tools without incurring downtime.

Following these practices ensures the tools you adopt today stay secure, portable, and manageable as your agent ecosystem expands.

What’s Next

In part three of the Agent Factory series, we‘ll cover observability for AI agents—how to trace each action, assess tool performance, and monitor agent behaviour in real time. We’ll cover built-in Azure AI Foundry features, integration patterns with Azure Monitor, and best practices for turning telemetry into continuous improvement.

If you missed the first post in the series, check it out: The New Era of Agentic AI—Common Use Cases and Design Patterns.

Share this content:


Discover more from Qureshi

Subscribe to get the latest posts sent to your email.

Discover more from Qureshi

Subscribe now to keep reading and get access to the full archive.

Continue reading