Microsoft AI-103 Exam Prep
Developing AI Apps and Agents on Azure (Page 4 )

Updated On: 3-Oct-2026
View Related Case Study

HOTSPOT (Drag and Drop is not supported)
You have a Microsoft Foundry project that contains an agent named PaymentAgent.
PaymentAgent includes a function tool that issues customer refunds by using an external API.
You are creating a workflow in YAML.
You need to ensure that the workflow pauses for human approval and continues with the refund step only after approval is granted.
How should you complete the workflow definition? To answer, select the appropriate options in the answer area.
Note: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Box 1: ask_question
To create a human-in-the-loop approval step in a Microsoft Foundry workflow, you should fill in the missing type with ask_question.
In Microsoft Foundry, the ask_question step is specifically designed to pause a workflow, prompt a user for input (such as an approval or rejection), and store the response in a variable that can be evaluated by subsequent logic.
Box 2: approval == "approved"
Execute Condition:
Use a condition such as steps.approval.output == 'approved' (or a similar logical check based on your choice variable) to ensure the refund only executes when authorized.


Reference:

https://learn.microsoft.com/en-us/azure/foundry/agents/concepts/workflow



View Related Case Study

You have an Azure Speech in Foundry Tools resource that hosts a custom speech to text model deployed to a custom endpoint. An agent uses the endpoint to perform real-time speech recognition.
You are approaching the expiration date of the custom speech to text model.
What is the expected behavior when the model expires?

  1. Speech recognition requests will return a 4xx error until a new custom model is deployed.
  2. Speech recognition requests will continue to use the expired custom model until the model is removed manually.
  3. Speech recognition requests will fall back to the most recent base model for the same locale.
  4. The custom model will be deleted automatically when the model expires.

Answer(s): C

Explanation:

When the custom speech-to-text model expires, the real-time endpoint will automatically fall back to using the most recent base model for that locale.
Because of this automated fallback design, your agent's real-time speech recognition streams will not fail or throw a connection error. However, you will likely experience a drop in transcription accuracy, as the fallback base model lacks the domain-specific vocabulary, acronyms, or unique audio adaptations built into your custom model.
Immediate Impact Summary
Real-Time Endpoints: Continue to process requests. The endpoint swaps the expired custom model for the newest standard base model behind the scenes.
Batch Transcriptions (If used): Any batch transcription jobs explicitly targeting the expired custom model ID will fail with a 4xx error code.
Customization Loss: Specific jargon, formatting rules, or accents trained into your model will temporarily stop applying to incoming agent audio.


Reference:

https://learn.microsoft.com/en-us/azure/ai-services/speech-service/how-to-custom-speech-model-and-endpoint
-lifecycle



View Related Case Study

You have a Microsoft Foundry project that contains a model deployment.
You have an application that calls the deployment by using the Azure OpenAI v1 API and
DefaultAzureCredential.
The developers at your company receive HTTP 403 errors when they send inference requests, even after running az login.
You need to ensure that the developers can perform model inference. The solution must follow the principle of least privilege.
Which role-based access control (RBAC) role should you assign to the developers?

  1. Cognitive Services User
  2. Cognitive Services OpenAI User
  3. Contributor
  4. Cognitive Services Data Reader

Answer(s): B

Explanation:

To resolve the HTTP 403 Forbidden errors when making inference calls via the Azure OpenAI v1 API and
DefaultAzureCredential, users must be assigned the Cognitive Services OpenAI User built-in Azure RBAC role.
Why This Happens
Running az login successfully authenticates the user with Microsoft Entra ID, but it does not grant data-plane access permissions. By default, standard control-plane roles (like Reader or Foundry User) only allow users to view project metadata or manage settings, not send prompts to the model deployment endpoint itself.
Recommended Role Definition
Role Name: Cognitive Services OpenAI User
Permissions Granted: This role provides the absolute minimum privileges required to execute chat completions, embeddings, and general inference tasks
(Microsoft.CognitiveServices/accounts/OpenAI/deployments/search/action and
Microsoft.CognitiveServices/accounts/OpenAI/deployments/causalLanguageModeling/action). It does not allow users to deploy new models, view access keys, or alter configurations
Scope Placement: Assign this role to the users (or a Microsoft Entra ID Group) at the Azure OpenAI resource level or the Resource Group level containing your Microsoft Foundry infrastructure.


Reference:

https://learn.microsoft.com/en-us/azure/foundry-classic/openai/how-to/managed-identity



View Related Case Study

You have a Microsoft Foundry project that contains an agent. The agent has a Model Context Protocol (MCP)
tool that queries a knowledge base stored in Azure AI Search.
Some agent runs return answers from the base model without invoking the knowledge base, which results in responses without grounded citations.
You are provided with the following code snippet that runs the agent.

You need to add the correct tool _choice parameter to the code to deterministically force the agent to invoke the MCP tool on each run.
What should you add?

  1. tool_choice={“required”}
  2. tool_choice={“auto”}
  3. tool_choice={“type”:“knowledge_base”}
  4. tool_choice ={“type”:“mcp”}

Answer(s): A

Explanation:

To deterministically force the agent to invoke your Model Context Protocol (MCP) tool on every run, you must pass tool_choice="required" into the run_create_and_process method.
The 'required' tool choice: Setting this parameter to 'required' forces the underlying Azure OpenAI model to invoke one of your available tools on every response, ensuring the agent doesn't guess answers from the base model.


Reference:

https://learn.microsoft.com/en-us/azure/foundry/agents/concepts/tool-best-practice



View Related Case Study

You have a Microsoft Foundry project named Project1 that contains an agent. The agent uses an OpenAPI 3.0
specification to call an external weather service.
The weather service requires a key to be passed in an HTTP header. The key value is stored as a connection in Project1.
You need to ensure that the key value from the connection is included automatically whenever the OpenAPI
tool is invoked.
What should you configure in the OpenAPI specification?

  1. a header parameter defined for each operation
  2. an Azure Key Vault connection
  3. an API key security scheme
  4. a Bearer token security scheme

Answer(s): C

Explanation:

To ensure Microsoft Foundry automatically injects the API key from your project connection whenever the
OpenAPI tool is invoked, your OpenAPI 3.0 specification must explicitly include a securitySchemes component mapping to the exact header name, and a global or operation-level security requirement referencing that scheme.The orchestrator matches the name field in the specification against the key stored inside your project's custom connection.
1. Required OpenAPI 3.0 Configuration
You must add both the components.securitySchemes block and the security block to your specification file:
openapi: 3.0.0
info:
title: External Weather Service version: 1.0.0
paths:
/weather:
get:
operationId: getWeather responses:
'200':
description: Successful weather retrieval
# 1. Define the security scheme in the components section components:
*-> securitySchemes:
weatherApiKey: # Arbitrary logical identifier for this scheme
*-> type: apiKey in: header name: X-Weather-API-Key # MUST match the "key" name configured in your Foundry Connection
# 2. Apply the security requirement globally (or inside individual operations)
security:
- weatherApiKey: [] # Instructs Foundry to enforce this scheme on the API requests in: header: Explicitly instructs the Foundry proxy layer to attach the credential value to the HTTP request headers (rather than as a query parameter).name: This string value is the exact HTTP header key (e.g.,
X-Weather-API-Key or Authorization). Crucially, this value must identically match the "Key" property given to the secret in your Microsoft Foundry Custom Connection.
security: Actively triggers the authentication workflow for the tool's endpoints. Without this block, Microsoft
Foundry treats the API call as anonymous and strips out connection values.


Reference:

https://learn.microsoft.com/en-us/azure/foundry/agents/how-to/tools/openapi



Viewing page 4 of 39
Viewing questions 16 - 20 out of 187 questions


Post your Comments and Discuss Microsoft AI-103 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!