Skip to content

Agent Landing Zone

Agent Landing Zone deploys a secure, production-ready Azure foundation for AI agents and, on top of it, an agent application. It provisions Azure AI Foundry, Azure AI Search, Azure Container Apps, Azure App Configuration, Key Vault, Cosmos DB and Azure Monitor with managed identities, least-privilege role assignments and optional private networking, and then deploys a retrieval-augmented agent application that is ready to use.

Source code: Azure/agent-landing-zone

Layers

Agent Landing Zone has two layers that you can deploy together or separately.

Layer What it contains Deployed by
Infrastructure Foundry account and project, model deployments, Azure AI Search, Storage, Cosmos DB, Container Apps environment, Container Registry, App Configuration, Key Vault, Log Analytics, Application Insights and, with network isolation, the virtual network, private endpoints, firewall, Bastion and jumpbox azd provision
Application The default agent application or your own application, described by an application definition azd deploy

azd up runs both layers in sequence.

Default application

The default application is a retrieval-augmented agent made of three components. Each component lives in its own repository, and manifest.json pins the exact version that each release validates.

Component Role Repository
Agent App UI Web chat front end Azure/agent-app-ui
Agent App Orchestrator Agent runtime that plans, retrieves and answers. Runs as a Foundry hosted agent by default, or as a Container App Azure/agent-app-orchestrator
Agent App Ingestion Indexes documents into Azure AI Search for retrieval Azure/agent-app-ingestion

You can replace this application with your own. See Custom applications.

Choose your path

I want to Go to
Deploy the infrastructure and the default application Deploy full stack
Deploy only the infrastructure and bring my own workload Deploy infra only
Deploy with private networking Network isolation
Run the orchestrator as a Foundry hosted agent, or switch to Container Apps Hosted agents
Change parameters and runtime settings Configuration
Deploy my own agent application Custom applications
Understand what the Bicep templates deploy Deploy with Bicep
Use Terraform Terraform implementation status
Upgrade, redeploy, monitor or delete an environment Operations
Fix a failed deployment Troubleshooting

Before you start

Cost

The deployment creates billable resources, including Azure AI Search, Cosmos DB, Container Apps, model deployments and, with network isolation, Azure Firewall, Bastion and a virtual machine. Delete environments you no longer use with azd down --purge.

Quota and region

The target region must offer every service in the deployment, and the subscription must have quota for the configured model deployments. A preflight check runs before provisioning and stops early when a service or quota is missing.

Duration

A first deployment usually takes 30 to 60 minutes. Deployments with network isolation take longer because of the firewall, private endpoints and private DNS zones.

© 2026 Azure AI Landing Zones