---
title: "Microsoft Foundry Models free inference"
description: "$200 for new accounts; it does not recur. See verified limits, model IDs, privacy terms, and primary sources for Microsoft Foundry Models."
canonical_url: "https://freeinferencing.com/provider/azure_ai_foundry/"
md_url: "https://freeinferencing.com/provider/azure_ai_foundry.md"
last_updated: "2026-09-19"
---

# Microsoft Foundry Models

> $200 for new accounts; it does not recur.

## Classification

- **Directory:** Current
- **Free access:** One-time trial
- **Status:** Current trial
- **Confidence:** High
- **Payment card:** Yes
- **Account:** Not documented
- **Equivalent paid value:** $200.00 once
- **API endpoint:** `https://{resource}.services.ai.azure.com/api/`

## Models mentioned

No stable model IDs were recorded in this snapshot.

## Limits and terms

```yaml
general_cloud_credit_usd: 200
duration_days: 30
recurrence: false
```

## What happens to your prompts?

**Partially private.** Base inference is stateless and no-training, but abuse review and stateful features can retain content for human access.

Privacy is audited separately from price. Review the current governing terms before sending sensitive or regulated data.

## Data governance and agreements

```yaml
data_governance:
  review_status: reviewed
  plan_scope: Microsoft Foundry Azure Direct Models, including Azure OpenAI and
    partner models; stateful APIs and modified abuse-monitoring customers
    differ.
  prompt_retention: Base inference is stateless, but prompts and completions
    selected for potential abuse can be stored for authorized human review.
    Assistants, Responses history, Stored Completions, Batch, and customer data
    sources intentionally persist content.
  response_retention: Same abuse-monitoring and feature-specific rules as prompts.
  ordinary_logging: Prompts and outputs are evaluated synchronously by safety
    systems. Usage, resource, security, and billing telemetry is retained;
    automated review alone does not store content.
  model_training: Microsoft says prompts, completions, embeddings, and fine-tuning
    data are not used to train, retrain, or improve base models without customer
    permission or instruction.
  product_improvement: Customer content is excluded from general model improvement
    absent permission; safety classification and service telemetry remain part
    of delivery.
  human_or_operator_access: Only content flagged for potential recurring or severe
    abuse enters the separated review store and can be accessed by authorized
    Microsoft employees through controlled, request-specific access. Approved
    modified-monitoring customers avoid this storage and human review.
  subprocessors_and_routing: Content stays within the Azure service boundary and
    selected deployment geography subject to Global or DataZone routing;
    partner-model licenses and Microsoft subprocessors apply.
  deletion_controls: Stateless model processing stores no model state. Customers
    manage Assistants, Responses, files, batches, Stored Completions,
    fine-tuning assets, and data sources; qualified managed customers can
    request modified abuse monitoring.
  caveat: “Not used for training” does not mean “never retained.” Free or
    unmanaged access should assume standard abuse monitoring and should avoid
    sensitive prompts unless the deployment's controls are confirmed.
agreements:
  customer_agreement: https://www.microsoft.com/licensing/docs/customeragreement
  product_terms: https://www.microsoft.com/licensing/terms/productoffering/MicrosoftAzure/all
  privacy_statement: https://privacy.microsoft.com/privacystatement
  data_protection_addendum: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA
```

## Eligibility

```yaml
new_customer_only: true
phone_required: true
non_prepaid_payment_card_required: true
automatic_charging: false
```

## API compatibility and modalities

- **Compatibility:** OpenAI V1, Foundry Native
- **Modalities:** Model inference


## Before you build with Microsoft Foundry Models

### Read the classification narrowly

This record describes the bounded offer supported by evidence on 2026-09-19; it does not guarantee permanence, production suitability, uptime, latency, model quality, or access from every account and region. “One-time trial” should be interpreted together with the Current directory placement, High confidence, Yes payment-card status, and the plan-specific sources below.

### Resolve the live model route

No stable model ID is recorded. Resolve the current machine-readable ID, endpoint, authentication method, and request shape from the provider's live documentation before writing fixed production configuration.

### Match the quota to the workload shape

Translate the allowance into peak requests per minute, input and output tokens, concurrency, retries, and every daily or monthly ceiling that applies to the intended account. The first limit reached by the workload is the practical ceiling. A large token pool can still fail interactive bursts, and a high request limit can still fail long-context work. Include tool calls and retry traffic, test the largest realistic payload, and treat research, experimental, and community access as conditional on their eligibility and fair-use terms.

### Preserve billing and privacy boundaries

The recorded payment-card requirement is Yes, and account access is not documented. Confirm both in the live signup flow, set provider-side budgets when charges are possible, and observe the balance or usage fields after a complete request. The prompt-handling classification is **Partially private** because Base inference is stateless and no-training, but abuse review and stateful features can retain content for human access. Re-read the terms for the exact route and plan before sending sensitive, regulated, or proprietary content.

### Follow the evidence, then re-check it

This record links 11 first-party sources covering the offer, catalog, limits, pricing, terms, privacy, or adoption evidence available to the audit. Prefer the newest and most specific governing document or live catalog when sources disagree. A dated finding can become stale even when the page remains online, so retain the source and snapshot that supported the decision and submit a correction when a provider changes a material term.

### Plan fallback without policy drift

A fallback should preserve modality, context length, streaming, structured output, tools, safety controls, and data terms, not only API syntax. Decide which errors may retry, cap retry storms, and prevent an exhausted free route from silently switching to a billable model. Rotating aliases and free pools can change behavior without changing the endpoint, so retain the response model field and test at least one substitute route before the primary offer becomes unavailable.

### Monitor the offer as a dependency

Capture the model ID, response model, rate-limit headers, usage fields, latency, HTTP status, and provider request identifier. Watch authorization failure, quota exhaustion, catalog removal, policy revision, and balance movement as separate failure modes. Re-check the live catalog and governing sources on a schedule proportionate to the workload's importance, and keep an owner and exit path for any production dependency on volatile free capacity.

### Test one complete request before scaling

Start with the smallest permitted request using the exact credential, model ID, endpoint, region, and account type intended for deployment. Record the status, headers, usage fields, response model, latency, and dashboard balance movement. Then exercise an invalid model, quota exhaustion, or rate limit so failure is explicit and cannot silently switch to a paid route. Validate streaming, structured output, and tool calls separately because a free model can expose fewer features than its paid counterpart. Keep a budget ceiling outside the application whenever billing is possible, and do not send sensitive data until the observed route matches the reviewed agreement.

## Primary sources

- [Azure free account](https://azure.microsoft.com/free/): Official Trial
- [Foundry Models pricing](https://azure.microsoft.com/en-us/pricing/details/ai-foundry-models/microsoft/): Official Pricing
- [Foundry application integration](https://learn.microsoft.com/en-us/azure/foundry/how-to/integrate-with-other-apps): Official Docs
- [Microsoft Customer Agreement](https://www.microsoft.com/licensing/docs/customeragreement): Official Terms
- [Microsoft Azure Product Terms](https://www.microsoft.com/licensing/terms/productoffering/MicrosoftAzure/all): Official Terms
- [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement): Official Privacy
- [Microsoft Products and Services DPA](https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA): Official Dpa
- [Data privacy and security for Azure Direct Models](https://learn.microsoft.com/en-us/azure/foundry/responsible-ai/openai/data-privacy): Official Docs
- [Azure AI Foundry has grown to more than 70,000 customers (2025-05-19)](https://azure.microsoft.com/en-us/blog/azure-ai-foundry-your-ai-app-and-agent-factory/): Official Blog
- [PyPI download stats for azure-ai-projects](https://pypistats.org/packages/azure-ai-projects): Package Registry Stats
- [2025 Stack Overflow Developer Survey technology section](https://survey.stackoverflow.co/2025/technology): Independent Survey

## Sitemap

See the full [semantic sitemap](/sitemap.md) for every page and markdown mirror.
