Microsoft Certified: Azure AI Apps and Agents Developer Associate course
5 modules, one per exam domain. 56 lessons, each opening with its key concepts; 6 timed practice tests.
One purchase covers the lessons and the tests.

What does the AI‑103 course cover?
Every module is one of the 5 exam domains Microsoft Azure publishes, in exam order, with the domain's share of the exam as its bar. Implement Generative AI and Agentic Solutions and Plan and Manage an Azure AI Solution carry the most at 33% and 28%. The exam runs 120 minutes. Microsoft does not publish a fixed question count. Expect multiple choice and multiple response items, and the exam can include interactive components. Open a module for its lessons; the practice tests close the course.
Choose the right Foundry models and services, deploy them with the right deployment type, and run them securely, observably and responsibly.
28% of the exam · Exam domain: Plan and manage an Azure AI solution
Choose Foundry Services and Models
Match each workload to a model, a grounding service and the agent capabilities it needs before you deploy anything.
- 1.1
Microsoft Foundry: Resources, Projects and Foundry Tools
Azure AI Foundry is now Microsoft Foundry and Azure AI Services are now Foundry Tools · One Foundry resource holds projects, model deployments and Agent Service · Hub-based projects live in the Foundry (classic) portal · Azure OpenAI resources can be upgraded and keep their endpoint, keys and state · Agents moved from the Assistants API to the Responses API
25 minHigh priority
- 1.2
Choosing a Model for Each Task
Small models suit narrow, high-volume tasks such as routing · Reasoning models trade latency and tokens for multistep accuracy · Models sold by Azure carry Azure billing, an SLA and Microsoft support · Model router picks a model per prompt in Balanced, Quality or Cost mode · Embedding and rerank models are separate choices from the chat model
25 minHigh priority
- 1.3
Choosing Grounding and Retrieval Services
Azure AI Search serves hybrid, vector and semantic retrieval over your own index · Foundry IQ adds permission-aware knowledge bases with agentic retrieval · File search covers documents that users provide · Grounding with Bing sits outside the Microsoft compliance boundary · Content Understanding turns documents, images, audio and video into searchable content
25 minHigh priority
- 1.4
Choosing Agent Types, Tools and Memory
Prompt agents are configuration that Foundry runs · Hosted agents run your own framework code in a container · Tools cover knowledge, actions, MCP servers and toolboxes · Memory keeps user-specific context across sessions · Give an agent the narrowest tool set that meets the requirement
25 minHigh priority
Deploy and Set Up AI Solutions
Pick deployment types, provision capacity and stand up agent infrastructure that a pipeline can manage.
- 1.5
Deployment Types and Data Residency
Global Standard is the starting point with the highest default quota · Data Zone keeps processing inside the US, EU or APAC zone · Standard keeps processing in the Azure geography · Batch costs 50% less with a 24-hour target turnaround · Developer serves fine-tuned model evaluation only
25 minHigh priority
- 1.6
Provisioned Throughput, Spillover and Flex Processing
Provisioned deployments reserve PTUs for consistent latency · Hourly PTU charges stop only when the deployment is deleted · Spillover sends overflow traffic to a standard deployment · Flex processing halves the price for delay-tolerant work · Reservations are bought per deployment type and don't guarantee capacity
25 minCore topic
- 1.7
Agent Infrastructure: Basic and Standard Setup
Standard setup brings your own Storage, Azure AI Search and Cosmos DB · Standard setup keeps agent data in your own tenant · Capability host settings can't change after creation · Network injection needs a subnet delegated to Microsoft.App/environments · Private MCP and private search need standard setup
25 minCore topic
- 1.8
Foundry Projects in CI/CD
Code-first agent definitions version every change · Evaluation runs act as release gates · Infrastructure as code creates resources, projects and deployments · Connections hold credentials outside agent code · Publishing promotes a tested version to a stable endpoint
25 minCore topic
Manage, Monitor and Secure AI Systems
Keep AI systems within quota and budget, give every caller the least access it needs, and see what happens inside them.
- 1.9
Quotas, Rate Limits and Cost Control
Quota is TPM and RPM per region, subscription and model · Handle 429 with exponential backoff that honors Retry-After · Move quota between deployments before asking for more · An AI gateway can enforce per-project token limits · Batch, Flex and prompt caching cut unit cost
25 minHigh priority
- 1.10
Keyless Access and Foundry Roles
Foundry User is the least-privilege developer role · Foundry Agent Consumer only calls agent endpoints · Azure Owner and Contributor have no data actions · API keys bypass RBAC, so disable key auth for keyless setups · Managed identities need data-plane roles on the resources they call
25 minHigh priority
- 1.11
Private Networking, Encryption and Data Handling
Disable public network access and add private endpoints · Link the privatelink DNS zones to the virtual network · Customer-managed keys need soft delete and purge protection · Prompts and completions aren't used to train models · Modified abuse monitoring needs Microsoft approval
25 minHigh priority
- 1.12
Monitoring, Tracing and Threat Protection
Traces follow OpenTelemetry GenAI conventions in Application Insights · Spans such as invoke_agent and execute_tool give a latency breakdown · Turn off content recording to keep prompts out of traces · Azure Monitor metrics show spillover and service tier use · Defender for AI Services raises alerts in Defender XDR
25 minHigh priority
Implement Responsible AI
Configure guardrails, detect attacks and evaluate safety before and after an agent ships.
- 1.13
Guardrails and Content Filters
A guardrail is a named set of risks, intervention points and actions · Severity thresholds decide which levels are flagged · Microsoft.DefaultV2 is the default model guardrail · An agent guardrail fully overrides its deployment's guardrail · The asynchronous filter streams tokens before checks finish
25 minHigh priority
- 1.14
Prompt Shields, Groundedness and Protected Material
User prompt attacks are scanned at user input · Document attacks are scanned at user input and tool response · Spotlighting marks documents as lower trust · Groundedness detection checks responses against their sources · Protected material detection covers text and code
25 minHigh priority
- 1.15
Safety Evaluations, Red Teaming and Oversight
Risk and safety evaluators run on hosted safety models · The AI red teaming agent reports attack success rate · Approval-required tools keep a person in the loop · allowed_tools limits what an agent can call · Trace logs and Content Credentials support audits
25 minHigh priority
Module assessment
Drawn from the lessons above, a different set each attempt.
Build apps and agents with the Foundry SDK and the Responses API, connect tools and memory, orchestrate agents, and evaluate and improve them.
33% of the exam · Exam domain: Implement generative AI and agentic solutions
Build Generative Apps with the Foundry SDK
Connect code to a Foundry project, call models through the Responses API, and ground answers in your data.
- 2.1
Connecting an App to a Foundry Project
azure-ai-projects 2.x provides AIProjectClient · DefaultAzureCredential gives keyless Microsoft Entra ID auth · get_openai_client returns an OpenAI-compatible client · The v1 API removes monthly api-version parameters · Tokens use the https://ai.azure.com/.default scope
25 minHigh priority
- 2.2
The Responses API: Conversations and State
Conversations store multi-turn items on the service · previous_response_id chains turns without a conversation object · Background mode runs long responses asynchronously · Server-side compaction keeps long contexts under a threshold · Content filter results arrive in the content_filters array
25 minHigh priority
- 2.3
Structured Outputs and Function Calling
Strict JSON schema mode guarantees the output shape · The model proposes function calls and your code runs them · function_call_output returns results with the same call_id · tool_choice controls whether a tool must be called · Fixed business rules belong in code
25 minHigh priority
- 2.4
Retrieval-Augmented Generation Patterns
Grounding instructions restrict answers to retrieved passages · Give the model an out when the answer isn't there · Filter weak passages on the reranker score · Citations let users check each claim · Groundedness evaluators measure fabrication
25 minHigh priority
Reasoning Models, Prompts and Tokens
Control reasoning effort, write prompts that work, and keep token spend predictable.
- 2.5
Working with Reasoning Models
reasoning_effort sets how much the model thinks · Reasoning tokens are billed as output tokens · Cap output with max_output_tokens or max_completion_tokens · reasoning.summary is the supported view of reasoning · Pass reasoning items back after function calls
25 minHigh priority
- 2.6
Prompt Engineering Techniques
State the goal, constraints and output format · Repeat key instructions after long content · Give the model an out to reduce fabrication · Prime the output with its first words · Ask for a short preamble for a faster first token
25 minCore topic
- 2.7
Prompt Caching and Token Analytics
Caching needs an identical first 1,024 tokens · Put stable content first and dynamic content last · prompt_cache_key improves matching for shared prefixes · GPT-5.6 adds cache breakpoints and cache-write charges · Usage fields report cached and reasoning tokens
25 minCore topic
- 2.8
Model Router, Rules Engines and Reflection
Model router chooses a model for each prompt · Its context window is the smallest underlying model's · Rules engines handle audited, fixed decisions · Reflection uses a critic call to check a draft · Multistep workflows split work across models and code
25 minCore topic
Build Agents with Foundry Agent Service
Define agents, give them the right tools, and connect knowledge, actions, MCP servers and memory.
- 2.9
Agent Types, Versions and Publishing
Prompt agents are declarative and hosted agents run your code · Each change creates a new agent version · Publishing gives a stable endpoint and needs Foundry Project Manager · Hosted agent versions are immutable and take all traffic · Assistants concepts map to conversations, items and responses
25 minHigh priority
- 2.10
Knowledge Tools: File Search, Azure AI Search, SharePoint and Web
File search chunks and embeds uploaded files into vector stores · The Azure AI Search tool queries an existing index · The SharePoint tool passes the user's identity · Web search returns url_citation annotations · Bing Custom Search limits grounding to chosen public domains
25 minHigh priority
- 2.11
Action Tools: Functions, OpenAPI, Code Interpreter and Computer Use
OpenAPI tools call REST APIs from a spec · Code Interpreter runs Python in a sandbox with no outbound network · Generated files return as container_file_citation annotations · Computer use acts on screenshots inside a sandbox · Managed identity calls need the right audience and a data-plane role
25 minHigh priority
- 2.12
MCP Servers and Toolboxes
MCP tools name a server, its URL and the allowed tools · require_approval pauses calls for a decision · Synchronous MCP calls time out after 100 seconds · Private MCP needs standard setup with private networking · Toolboxes put many tools behind one managed endpoint
25 minHigh priority
- 2.13
Memory and Structured Inputs
Memory stores user profile, chat summary and procedural memory · Scope memory with {{$userId}} for per-user isolation · Set a default TTL and delete single items · Structured inputs template instructions and tool properties · Keep secrets in project connections
25 minCore topic
Orchestrate Multiple Agents
Coordinate agents with Agent Framework patterns and keep people in control of high-impact steps.
- 2.14
Orchestration Patterns in Microsoft Agent Framework
Sequential runs agents in a fixed order · Concurrent runs agents in parallel on the same input · Handoff passes control based on context · Group Chat and Magentic coordinate a team of agents · Visual workflows retire on December 1, 2026
25 minHigh priority
- 2.15
Magentic Orchestration in Depth
A manager agent plans and assigns the work · The progress ledger picks the next speaker · Plan review lets a person approve or revise the plan · Stall and round limits trigger replanning or a stop · manager_factory isolates state between workflows
25 minCore topic
- 2.16
Human-in-the-Loop Controls
Approval-required tools pause before they run · request_info asks a person for input · Responses resume the workflow through workflow.run() · Checkpoints re-emit pending requests on restore · MCP approvals arrive as mcp_approval_request items
25 minHigh priority
Evaluate and Improve
Measure quality and safety with evaluators, monitor agents continuously, and fine-tune when prompting is not enough.
- 2.17
Evaluating Generative Output
Quality evaluators judge coherence, fluency, relevance and groundedness · Similarity metrics need ground truth · AI-assisted evaluators need a judge deployment · A run is either turn-level or conversation-level · Rubric evaluators score custom weighted criteria
25 minHigh priority
- 2.18
Evaluating Agents
System evaluators judge outcomes and process evaluators judge tool steps · Intent Resolution and Task Adherence catch different failures · Tool evaluators read sample.output_items · Composite evaluators batch several checks into one judge call · Continuous evaluation rules score live responses
25 minHigh priority
- 2.19
Fine-Tuning and Continuous Improvement
SFT, DPO and RFT suit different kinds of data · Training tiers differ in data residency · Continuous fine-tuning starts from a fine-tuned model · Idle fine-tuned deployments are deleted after 15 days · Fine-tuning needs both data-plane and control-plane roles
25 minCore topic
Module assessment
Drawn from the lessons above, a different set each attempt.
Generate and edit images and video, analyze visual content with multimodal models and Content Understanding, and keep visual workloads safe.
13% of the exam · Exam domain: Implement computer vision solutions
Generate Images and Video
Use gpt-image-1, FLUX and Sora 2 with the controls each one exposes.
- 3.1
Image Generation with GPT-image Models
GPT-image models return base64 image data · Quality, size and n set cost and output · Transparent backgrounds need PNG output · partial_images streams progress while an image renders · dall-e-3 retired on March 4, 2026
25 minHigh priority
- 3.2
Image Editing, Inpainting and FLUX Models
Masks are PNGs whose transparent areas mark the edit · The edit API combines up to 16 input images · input_fidelity preserves faces and style · FLUX.1-Kontext-pro edits from text plus one image · FLUX.2 models take several reference images through the provider API
25 minHigh priority
- 3.3
Video Generation with Sora 2
Video jobs are created, polled and downloaded · Sizes are 720x1280 and 1280x720 with 4, 8 or 12 seconds · A reference image must match the output size · Remix changes one detail and keeps the motion · Real people, faces and copyrighted material are blocked
25 minHigh priority
Understand Images and Video
Analyze, caption and extract from visual content with multimodal models and Content Understanding.
- 3.4
Visual Analysis with Multimodal Models
detail low, high and auto trade tokens for resolution · Chat Completions takes 10 images and the Responses API takes 50 · Vision models ignore EXIF data and file names · Spatial, medical and counting tasks are documented limits · Alt text serves the image's purpose in context
25 minHigh priority
- 3.5
Content Understanding for Images and Video
Image fields use generate and classify · Video analysis samples about one frame per second · returnDetails adds shot boundaries and timestamps · Segmentation fills fields for each scene · prebuilt-imageSearch, prebuilt-videoSearch and prebuilt-audioSearch serve RAG
25 minHigh priority
Responsible AI for Visual Content
Filter unsafe visuals, stop injected instructions and show where generated content came from.
- 3.6
Visual Content Safety
Image analysis returns severities 0, 2, 4 and 6 · Image-with-text analysis uses the full 0 to 7 scale · Custom categories (rapid) catch new symbols without training · Blocklists match exact text only · contentFilter errors need a changed prompt
25 minHigh priority
- 3.7
Injection Defense, Provenance and Visual Policy
Text inside images is third-party content · Scan extracted text with Prompt Shields · Approvals stop injected instructions from acting alone · Content Credentials sign generated images · Visual policy rules cover watermarks, symbols and brands
25 minCore topic
Module assessment
Drawn from the lessons above, a different set each attempt.
Extract meaning from text with Azure Language and language models, translate it, and build speech into agents.
13% of the exam · Exam domain: Implement text analysis solutions
Analyze and Translate Text
Choose between Azure Language features and prompted models, protect personal data, and translate at the right fidelity.
- 4.1
Azure Language Features and Agents
Core features are PII detection, language detection, NER and text analytics for health · Custom NER trains on labeled examples of your own categories · Text analytics for health detects assertions such as negation · The intent routing agent combines CLU with custom question answering · The Azure Language MCP server exposes features as agent tools
25 minHigh priority
- 4.2
PII Detection and Redaction
PII detection handles text, conversations and native documents · Redaction policies include characterMask, entityMask and syntheticReplacement · List default in piiCategories to keep the standard set · valueExclusionPolicy exempts chosen terms · Redact before the model sees the data
25 minHigh priority
- 4.3
Text Analysis with Language Models
Prompted models handle custom labels and explanations · Strict JSON schemas keep output machine-readable · Foundry Tools return fixed labels with no prompt to maintain · Domain summaries need explicit rules and examples · Evaluate extraction quality against labeled samples
25 minCore topic
- 4.4
Translation with Azure Translator
Text translation can now use an LLM with tone variants · Adaptive custom translation adapts LLM output with 5 to 10,000 pairs · Custom Translator trains a dedicated NMT model · Synchronous document translation handles one file with no Blob Storage · Batch document translation reads and writes Blob containers
25 minHigh priority
Build Speech Solutions
Recognize, synthesize and translate speech, and give agents a voice.
- 4.5
Speech to Text
Real-time, fast and batch transcription fit different jobs · Phrase lists fix vocabulary with no training · Custom speech adapts to acoustics and domain terms · Compare word error rate on the same test data · Continuous recognition handles long audio
25 minHigh priority
- 4.6
Text to Speech and SSML
SSML controls pronunciation, style and language · express-as sets a style and styledegree its strength · Multilingual voices switch languages with the lang element · Custom lexicons hold pronunciations for one locale · Batch synthesis creates audio longer than 10 minutes
25 minCore topic
- 4.7
Voice Agents and Speech Translation
Voice Live is managed speech-to-speech for agents · The generative model sets the Voice Live pricing tier · Cascaded pipelines trade latency for control · Speech translation covers two target languages per call · Live Interpreter follows speakers who switch languages
25 minHigh priority
Module assessment
Drawn from the lessons above, a different set each attempt.
Index and search content with Azure AI Search, connect retrieval to agents, and extract structured data from documents with Content Understanding.
13% of the exam · Exam domain: Implement information extraction solutions
Retrieval and Grounding with Azure AI Search
Build indexing pipelines, tune hybrid and vector search, and connect retrieval to agents.
- 5.1
Indexing Pipelines and Integrated Vectorization
An indexer ties a data source, a skillset and an index together · The vectorizer must use the same embedding model as indexing · OCR plus Text Merge puts image text back into content · Index projections write one search document per chunk · Custom Web API skills time out after 30 seconds unless raised, up to 230
25 minHigh priority
- 5.2
Hybrid, Vector and Semantic Search
Hybrid search merges keyword and vector results with RRF · Keyword matching wins on exact codes and names · Semantic ranker reranks the top 50 results · Captions and answers are verbatim extracts · Query rewrite expands a query into up to 10 variants
25 minHigh priority
- 5.3
Vector Index Design: Filters and Compression
Queries and documents need the same embedding model · preFilter keeps recall with selective filters · filterOverride replaces the global filter for one subquery · Binary quantization cuts index size the most · Rescoring with oversampling restores relevance
25 minCore topic
- 5.4
Securing and Maintaining Indexes
Indexers behind private endpoints need the private execution environment · Shared private links wait for owner approval · Deletion detection must exist from the first run · Permission metadata refreshes through /resync · Some index changes need a new index
25 minCore topic
- 5.5
Agentic Retrieval and Foundry IQ
Agentic retrieval plans subqueries from the question and history · minimal effort skips query planning · Foundry IQ knowledge bases are permission-aware · Knowledge sources can be indexed or remote · Agents connect to retrieval as a tool
25 minHigh priority
Extract Information from Documents
Use Content Understanding analyzers to turn documents into grounded Markdown and structured fields.
- 5.6
Content Understanding Document Analyzers
Content extraction covers OCR, layout, tables, barcodes and formulas · Markdown output suits RAG and JSON output suits automation · Fields use extract, classify or generate · Confidence and grounding support human review · prebuilt-read, prebuilt-layout and prebuilt-digitalParse need no model
25 minHigh priority
- 5.7
Classification, Segmentation and Routing
enableSegment splits a file into documents · Each category can route to an analyzer by analyzerId · An other category catches content that fits nothing · Classification needs no training data · Composed analyzers classify and route domain packets
25 minHigh priority
- 5.8
Custom Analyzers, Agentic Mode and Model Deployments
Copy a prebuilt definition to keep production stable · Custom analyzers derive from four base analyzers · Agentic mode reasons, calculates and validates across one file · Analyzers use your Foundry model deployments · Deployment guardrails apply to Content Understanding
25 minCore topic
Module assessment
Drawn from the lessons above, a different set each attempt.
Each test mirrors the real exam: 120 minutes, 60 questions, all domains in proportion. Learning mode shows the explanation after each answer; exam mode runs the clock and scores at the end. The study plan below schedules them across the weeks.
- 1
Practice test 1
Full-length practice exam covering all five AI-103 domains in Microsoft's published proportions: planning and managing an Azure AI solution, generative AI and agentic solutions, computer vision, text analysis, and information extraction. Scenarios use current Microsoft Foundry naming, roles and APIs, and every option is explained.
60 questions · 120 min
- 2
Practice test 2
Second full-length AI-103 practice exam across all five domains, with new scenarios on spillover and quotas, guardrails for agents, red teaming, prompt caching, Code Interpreter, web search, toolboxes, image and video generation, speech translation, index projections and Content Understanding classification. Every option is explained.
60 questions · 120 min
- 3
Practice test 3
Third full-length AI-103 practice exam across all five domains, with new scenarios on upgrading Azure OpenAI to Foundry, Foundry roles, standard agent setup, hosted agent identity and egress controls, rubric evaluators and graders, memory, reasoning tokens, custom code interpreters, human-in-the-loop workflows, image edits, Content Credentials, SSML lexicons, Voice Live pricing, shared private links, query rewriting and ACL-aware indexing. Every option is explained.
60 questions · 120 min
- 4
Practice test 4
Fourth full-length AI-103 practice exam across all five domains, with new scenarios on asynchronous content filtering, custom blocklists, model version upgrade policies, provisioned throughput sizing and migration, AI gateway token limits, customer-managed keys, trace content controls, Defender for AI Services, server-side compaction, OpenAPI and SharePoint tool authentication, file search limits, computer use, Magentic plan review, agent evaluators, image output settings, Content Safety image severities, fast transcription, SSML styles and visemes, PII redaction policies, vector filter modes, quantization and Content Understanding analyzers. Every option is explained.
60 questions · 120 min
- 5
Practice test 5
Fifth full-length AI-103 practice exam across all five domains, with new scenarios on Flex processing, models sold by Azure, cross-tenant fine-tuned deployments, customer-managed key networking and roles, PTU reservations, protected trace tables, Defender prompt evidence and AI model security, search throttling, the Task Adherence API, modified guardrails, computer use domain checks, GPT-5.6 tool calling, reasoning defaults and verbosity, OpenAPI and bearer token rules, SharePoint retrieval limits, Azure AI Search tool filters and citations, file search readiness and deletion, Magentic intermediate outputs and events, prompt cache keys, DPO, cloud evaluation workflows, FLUX guidance, Sora 2 limits, multimodal severities, image input limits, PII exclusions and redaction policies, SSML styles and roles, visemes, realtime transcription, strict postfiltering, hybrid counts and Content Understanding analyzers. Every option is explained.
60 questions · 120 min
- 6
Practice test 6
Sixth full-length AI-103 practice exam across all five domains, with new scenarios on rerank models, web search and the compliance boundary, fine-tuning training tiers, provisioned billing, computer use access, project connection roles, Flex headers and metrics, tracing without Entra ID, .NET GenAI tracing, abuse monitoring checks, batch file limits, data handling, Code Vulnerability and safety thresholds, reasoning policy, markdown from reasoning models, PDF input, parallel tool calls, structured inputs, OpenAPI auth, file search query processing, long-running and private MCP servers, Magentic prompts, AI Search and web search tool settings, Intent Resolution, reasoning context, evaluation data mapping, prompt cache modes, continuous fine-tuning, FLUX models, gpt-image candidates, vision limits, multimodal embeddings, video analysis, multimodal moderation, Translator options, PII synonyms, continuous recognition, multilingual voices, realtime translation, vector weights and thresholds, multi-vector queries and Content Understanding layout features. Every option is explained.
60 questions · 120 min
Try 15 free questions on the certificate page before you buy.
How long does it take to prepare with this course?
About 23 hours of lessons, 56 of them at roughly 25 minutes each. The modules run in exam order, so the heaviest domains come first. Pick a pace and the plan lays itself out.
- Week 1Plan and Manage an Azure AI Solution6h 15m of lessons6h 15m
- Week 2Implement Generative AI and Agentic SolutionsPractice tests 1 and 27h 55m of lessons7h 55m
- Week 3Implement Computer Vision SolutionsPractice tests 3 and 42h 55m of lessons2h 55m
- Week 4Implement Text Analysis Solutions · Implement Information Extraction SolutionsPractice tests 5 and 6 · Schedule the exam once you clear 75% on a fresh test6h 15m of lessons6h 15m
Ready to start the AI-103 course?
The course and the practice tests come together in one purchase.
Course + practice tests
Lifetime access: pay once, study forever
Plus tax where applicable
- 56 interactive lessons with checkpoints
- 6 full-length practice tests
- 360+ exam-style questions
- Detailed explanations for every answer
- Exam mode & learning mode
- Unlimited retakes
- Access on any device
AI-103 course + practice tests
from$19.99course + tests