Running automations on your Azure Foundry
An automation can run its model calls on Anthropic through StackJack (the default: your own Anthropic key if you added one, otherwise StackJack credits) or on a model deployed in your organization's…
Written By Christopher Scaminaci
Last updated 3 days ago
An automation can run its model calls on Anthropic through StackJack (the default: your own Anthropic key if you added one, otherwise StackJack credits) or on a model deployed in your organization's own Azure subscription through Azure AI Foundry: Claude, or one of the other models Azure sells that can run an automation. On Azure Foundry, Azure bills the model usage to your subscription and StackJack charges no credits for the model usage. StackJack still runs the automation itself: the schedule, the webhook trigger, every tool call, the approvals and the run history work the same way.
You choose per automation. Nothing moves until you set an automation to run on your Azure Foundry.
The same connection can also serve an AI thinking step on any automation, and StackJack's own AI help (the automation builder's assistant, its AI-assist suggestions and support research on your tickets), each billed by Azure. See AI thinking steps on Your Azure Foundry and StackJack's AI help on your Azure Foundry.
What you need
- An Enterprise plan or an Agent Runner plan. Foundry runs use the same plan rule as running automations on your own Anthropic key.
- An owner or an administrator of your StackJack organization to connect Foundry. Members can see the connection but cannot change it.
- An Azure subscription. A pay-as-you-go or Enterprise Agreement subscription works. To deploy Claude, it must be a subscription Azure sells Claude on; the other models do not need that. See Subscriptions Azure will not sell Claude on.
Connect Foundry
Open Automations → Foundry. There are two ways to connect.
Set up on your Azure subscription (recommended)
StackJack creates the Azure pieces for you, using your own Microsoft Azure sign-in.
- Connect Microsoft Azure under Connectors first, signed in as a person with Owner rights on the subscription (or Contributor plus Role Based Access Control Administrator).
- In Automations → Foundry, click Start setup and pick the subscription. A subscription Azure will not sell Claude on can still be picked for the other models, and says so.
- Pick the Azure region and the models to deploy. Any Claude model an automation can use is offered; Opus 5 and Haiku 4.5 are ticked as a suggestion. The models other than Claude that StackJack checked are offered too when Azure hosts them in that region; a Preview model shows its label and its end date. On a subscription Azure will not sell Claude on, only the other models are listed, and none is ticked. Leave a capacity blank to use all the free quota the subscription has for that model. If you pick more models than one setup can hold, StackJack asks you to pick fewer.
- Review what StackJack found: your Owner rights, whether Azure hosts each model in that region, and how much quota is free. Nothing is created at this point.
- If the setup includes a Claude model, accept the terms. Deploying Claude accepts Anthropic's terms on your organization's behalf. The person with Owner rights types your organization's legal name, its two-letter country code and its industry, and ticks I accept. StackJack never fills these in for you. StackJack records who accepted, when, and the list of terms shown: Anthropic's Commercial Terms of Service, Usage Policy and Supported Regions, and the Microsoft Product Terms for Azure. The screen also lists each model StackJack will deploy, with its version and who sells it (every model other than Claude is sold and billed by Microsoft Azure), and StackJack records that list too. A setup with no Claude model has no terms step: Microsoft Azure sells and bills its models, and StackJack stores no organization details for it.
- Click Start setup. StackJack creates one resource group, one Azure AI Foundry resource and the deployments in your subscription, stores one of the resource's keys, and checks each deployment. This usually takes a few minutes, and the page updates by itself. Each deployment of a model other than Claude gets its check in the background when setup finishes.
How StackJack signs in. Where StackJack Foundry Runner is already allowed in the chosen subscription's Microsoft Entra directory, the setup asks how StackJack signs in to the account: Keyless (StackJack Foundry Runner), the recommended choice and the default, or A stored account key. With keyless, StackJack stores no key. With your Azure sign-in it gives the runner its narrow role on the account and Microsoft's built-in Cost Management Reader role on the resource group (so the Azure cost card fills by itself), checks that the narrow role works before the setup finishes, and signs in as the runner for every call. Where the runner is not allowed there yet, the setup uses a stored key and says: "To set up without a key, allow StackJack Foundry Runner in this subscription's Microsoft Entra directory first, then start the setup again."
If setup stops, the page says why, with Azure's own message when Azure refused a step. Fix the cause and click Retry setup, or remove the connection and connect with a key instead.
The Azure resources are yours, on your bill. Removing the connection never deletes them: see Remove the connection for what happens to the key StackJack created, and Delete everything StackJack created to delete the resources as well.
Connect with a key
Use this when you deployed the models in Azure AI Foundry yourself, when you want a model that setup does not deploy, or when your organization's Azure policies block automated setup.
- In the Azure portal, open your Azure AI Foundry resource and copy its name (or its endpoint URL) and one of its two keys.
- In Automations → Foundry, click Paste a key, paste the resource name and the key, and list each deployment with the model it runs: a Claude model, one of the models other than Claude that StackJack checked, or Another Azure model (type its Azure catalog name and pick its catalog format).
- Click Save. Saving stores the key and does not check the Claude deployments; click Test connection to check them. Each deployment of a model other than Claude that the save added or changed gets its check in the background right after the save, and a new key re-checks every one of them.
The key is sent once and stored in StackJack's key vault. It is never shown again.
Attach an existing Foundry account without a key
Once StackJack Foundry Runner is allowed, an owner or an administrator can connect an Azure AI Foundry account your organization built itself without a key. The card Attach an existing Foundry account says: "Pick the Azure subscription and the Azure AI Foundry account your organization built itself. StackJack lists the account's deployments from Azure and signs in with StackJack Foundry Runner, without a key. Your Microsoft Azure connection needs rights to grant roles on the account's resource group."
- Click Attach an existing Foundry account.
- Pick the subscription and the Foundry account, and click Attach.
With your Azure sign-in, StackJack gives the runner its narrow role on the account and Microsoft's built-in Cost Management Reader role on the resource group, and checks that the narrow role works before the connection is used. If the runner is not allowed in that subscription's Microsoft Entra directory yet, the card offers to allow it there first. An account that another StackJack organization already connected this way cannot be attached: "This Foundry account is already connected to another StackJack organization."
Subscriptions Azure will not sell Claude on
These rules apply when you deploy Claude. A setup that includes a Claude model stops early, with a plain reason, on a subscription Azure will not sell Claude on:
- A subscription bought through a Cloud Solution Provider (CSP). Azure does not sell Claude on CSP subscriptions. To use Claude on Azure, create a pay-as-you-go subscription that your organization owns directly with Microsoft, and run the setup on that subscription. The rest of your Azure estate can stay with your partner.
- A free trial, student or Azure Pass subscription.
- A subscription with its spending limit turned on. Remove the spending limit in the Azure portal, or use another subscription.
A Visual Studio or partner (MPN) subscription may get a warning, not a stop. If such a subscription runs on monthly credits only, Azure refuses the setup and the page shows Azure's reason. One with a card on file works.
A setup with no Claude model can use any of these subscriptions: StackJack offers the other models on them, and Azure's own answer decides the rest (the quota it reports, or its reason if it refuses a deployment). StackJack checks the subscription again each time a setup deploys Claude, a retry included.
Organizations in Europe
Azure Foundry stores your automation data at rest in the Azure region you choose (Sweden Central in Europe). StackJack sets up every model as a Global Standard deployment, Claude or not, and Microsoft may process the prompts and responses of any Global deployment, including one you create yourself, in any Azure region. Claude models on Azure have no EU-only processing option. On StackJack's European service, an owner or administrator reads that notice and ticks I understand before connecting Foundry, whichever models the organization plans to use, and Foundry runs stay off until someone does. An organization that moves to the European service is asked once, before its first run there. An organization that ticked the earlier wording of this notice is not asked again: the tick covers the same fact, that model processing may happen outside the EU.
Models other than Claude
Besides Claude, an automation can run on the models Azure sells that can do an automation's work: a model that calls tools while it streams its answer, reports its usage, accepts a tool's result exactly as the tool returned it, reads at least 128,000 tokens where its vendor publishes the figure, writes at least 8,192 tokens in one turn, and is not retired. StackJack checked these families on Azure:
- OpenAI: the GPT-4o, GPT-4.1, GPT-5 and later GPT lines, the o-series, and the codex and pro models;
- xAI: Grok;
- DeepSeek;
- Meta: Llama;
- Mistral;
- Microsoft: MAI;
- MoonshotAI: Kimi;
- OpenAI open-weight: gpt-oss.
Each model shows its name, and its labels: Preview and its end date when Azure gives one, context size not published when its vendor does not publish it, and cost not estimated when StackJack has no Azure list price for it. After a model's end date, its automations do not run: "Azure retired
What is not offered:
- Cohere Command A and Phi-4 mini instruct cannot run an automation, and a check of them would still be billed, so StackJack refuses them with a sentence that says why.
- A model other than Claude that needs an Azure Marketplace agreement, and a model Azure is retiring, are not deployed by setup (Azure refuses a new deployment of a model it is retiring). Deploy such a model yourself and add it with Connect with a key. An existing deployment of a model Azure is retiring runs until its end date.
A model StackJack has not verified. Azure adds models faster than StackJack checks them. To use one, pick Another Azure model under Connect with a key. It shows Not verified by StackJack. Its deployment is checked like any other, and its runs are refused until the check passes; StackJack cannot estimate its cost, so the spend guard cannot stop its runs; and web search is not available on it.
The check on each deployment
Before any automation runs on a model other than Claude, StackJack checks that model's deployment in your Azure subscription with two short test calls, billed by Azure to your subscription. The first asks the model to call a test tool, with one of StackJack's real tool definitions beside it. The second sends a tool result back exactly as a tool returns it. The check runs in the background after a save, a key paste, Test connection or setup, and the connection page shows each deployment's state:
- "Checking… Runs on this model are refused until the check passes."
- "Passed its check."
- "Failed its check: …" followed by what the model did wrong, for example that it did not return a tool call when asked to.
- "StackJack could not check this deployment; press Test connection to try again."
After Test connection, the page names the deployments it is checking in the background and updates as the checks finish, for up to 15 minutes; after that, reload the page to see a result. A deployment Azure has just created can be unreachable for a few minutes, so a check that meets that is repeated once, about ten minutes later.
While a deployment is still being checked, an automation on its model still saves, and the builder says: "StackJack is still checking this model. Runs of this automation are refused until the check passes; a webhook event or a scheduled start in the meantime is refused and is not run again later." Such a run fails with "StackJack has not finished checking this model on your Azure Foundry. Open the Foundry connection page and press Test connection."
The daily check
Once a day, StackJack checks each deployment of a model other than Claude again, with two small test calls billed to your Azure subscription, typically well under a cent. A deployment StackJack set up is called only when Azure reports a new model version for it; on the other nights StackJack only reads the deployment's version and end date from Azure, which is not billed. If StackJack cannot read a deployment's model version from Azure, it checks that deployment with the two calls instead.
- If a daily check does not give a clear answer, StackJack repeats it once at full size. Only a failed full-size check switches a deployment off. A model that keeps needing the full size is checked at full size each day.
- A deployment whose first check could not finish gets the full-size check each night until it passes, fails, or gives no answer three times.
- A deployment that gives no answer three times in a row is not checked again until you press Test connection.
- While your organization's plan for Foundry runs has ended, while your organization moves between StackJack regions, or while the region notice on the Foundry page is not yet accepted, StackJack makes no daily check.
- A deployment that failed its check is not checked every day. It is checked again when you press Test connection, paste a key, or change its model.
- When the daily check switches deployments off, StackJack refuses their runs and e-mails your organization once that night, listing every deployment it switched off with the reason. If there are too many to name in one e-mail, it names as many as fit and counts the rest. Fix the cause, then open the Foundry connection page and press Test connection. You are not e-mailed about the same deployment again until it passes a check.
What a check can cost, at most, on the most expensive model on StackJack's list in each family:
The figures are estimates at Azure's list prices (Global deployments, East US 2, read on 28 September 2026); your Azure price may differ. A typical check costs about a tenth of a cent on GPT-5.4 mini. A deployment that needs the full size each day, or whose first check has not finished, costs up to the right-hand figure each night. A check after a save, a key paste or Test connection costs at most the right-hand figure, and the one repeat after a new deployment at most the same again.
Set an automation to run on Foundry
In the advanced builder, the Run on choice appears below the model once your organization has a working Foundry connection. Pick Your Azure Foundry, pick a model your connection has a deployment for, and save. The list shows every model you mapped, Claude and the others, by name and with its labels. A model whose deployment is still being checked, or failed its check, shows that state and cannot be picked. Reasoning effort is offered for Claude and for the OpenAI reasoning models only. A model other than Claude runs only on your Azure Foundry: "This model runs only on your Azure Foundry."
The chat assistant and your connected AI assistant (through StackJack's automation-building tools) can make the same choices. They offer the models your connection has mapped and say when a model is still being checked. Your connected AI assistant also sees, for each automation, its model and its label, where it runs, and whether its web-search notice is confirmed.
A save is refused, with a sentence that says why, when the automation asks for something Foundry cannot run:
- An AI thinking step that does not run on Your Azure Foundry in the fixed steps that run before or after the automation: "This automation runs on your Azure Foundry, so its AI thinking steps must run there too. Set the step's AI provider to Your Azure Foundry." See AI thinking steps on Your Azure Foundry;
- Automation memory on a model other than Claude, and on any model while memory on Azure Foundry is switched off on StackJack: "Automation memory can't be used on Azure Foundry yet. Turn memory off, or set the automation to run on StackJack." On a Claude model, StackJack keeps the memory itself: see Automation memory on Azure Foundry;
- Code execution;
- A model with no deployment on your Foundry connection. Add a deployment for it under Automations → Foundry, or pick a model you have deployed;
- A model whose deployment failed its check, or a model Azure retired;
- Web fetch on a model other than Claude, or web search on a model that does not have it (see Web search and web fetch);
- A switch to the other engine while the automation has saved memories: "This automation has saved memories. Move them to your Azure Foundry first, or clear them." (or "…Move them to StackJack first, or clear them." when you switch back). Move the memory first; see Move memory.
The builder shows each of these before you press Save, in the same words, except the last one: StackJack finds the saved memories only when you press Save.
Runs on Azure Foundry also have no file tools (read, write, edit and search) yet.
If a Foundry run cannot start — the connection was removed or failed its last check, the automation's model has no working deployment or its deployment is still being checked, Azure retired the model, or your plan ended — the run fails with the reason. It never falls back to StackJack's Anthropic account. A run that paused for an approval fails if its model's deployment was changed to another kind of model while it waited: "This run's model changed while it was paused. Start the automation again."
The run page shows a model's reasoning as its thinking when the model streams it, and each web search as a built-in tool call with its sources, whichever model ran.
A staging copy keeps its engine. A copy starts on its automation's Run on choice, and a deploy never changes which engine the live automation runs on. If you switch the copy (or the live automation) to the other engine, the deploy is refused until both run on the same one. See Deploying a staging copy to production.
Web search and web fetch
- Claude models: an automation that has web search or web fetch switched on uses them on Azure the same way: Azure runs them and bills them to your subscription (each web search is charged per search; a fetched page is charged as the text the model reads).
- The OpenAI models StackJack checked (the general-purpose GPT-4o, GPT-4.1, GPT-5 and later GPT models): web search works through Microsoft's Bing, and Azure bills each search. Web fetch does not.
- Every other model — the o-series, the codex and pro models, GPT chat latest, every model that is not an OpenAI model, and every model StackJack has not verified — has neither. A save with them switched on is refused: "Web fetch is available on Claude models only." or "Web search is available on Claude models and on the OpenAI models StackJack has checked. Turn it off to run this automation on
The web-search notice. Before an automation uses web search on an OpenAI model, a person confirms this notice for that automation:
Web search on OpenAI models in your Azure Foundry uses Microsoft's Bing, under Microsoft's Grounding with Bing terms. The model writes the searches itself from what the automation is working on, which can include ticket text and other data from your connected tools. What is searched leaves your Azure region, Microsoft's data protection addendum does not cover it, and Azure bills each search.
A save, a version restore or a staging deploy that turns web search on for such a model, or that moves an automation with web search on onto one, shows the notice with a box to tick, and is refused until you tick it: "Web search on OpenAI models uses Microsoft's Bing. Read the notice and confirm it to save this change." One confirmation covers the automation and its staging copies, for any model. An automation that uses web search on such a model without a confirmation shows the notice and a Confirm button on its page, and its runs fail until someone confirms: "This automation's web search needs its notice confirmed before it runs. Open the automation in StackJack and confirm the web-search notice."
- The chat assistant shows you the notice and never confirms it for you; you tick the box when you save.
- Your connected AI assistant confirms it with its consent tool (
stackjack_accept_agent_consent, consent typeweb_search), after it shows you the notice. - StackJack staff cannot confirm it for your organization.
Automation memory on Azure Foundry
An automation that runs on your Azure Foundry on a Claude model can use automation memory. StackJack keeps its notes itself, in StackJack's own database, not in Anthropic's platform, and the automation reads and writes them during its runs exactly as it would on StackJack. The Memory card on the automation's page browses, clears, redacts and erases them the same way.
On a model other than Claude, memory is not available yet, and a save with memory on is refused.
The limits
A change that would pass a limit changes nothing, and the model is told why, for example: "This automation's memory is full (at most 1,000 files and 5 MB), so nothing was saved. Delete or shorten memory files that are no longer needed, then try again." or "A memory file can hold at most 100 KB, so nothing was saved. Split it into smaller files." Content is never cut short. When history is over its limit, StackJack removes the oldest versions; a change is never refused for history.
Redacting a version works as on StackJack, with one rule: the version that is a memory's current content cannot be redacted: "This version is the memory's current content, so it cannot be redacted. Change or clear the memory first, then redact this version."
Move memory
Memories belong to the engine an automation runs on: StackJack's engine, or your Azure Foundry, where StackJack keeps them. Before you switch where an automation runs, move its memories to the other engine on its page. The Memory card says: "Memories belong to the engine an automation runs on. Move them before you switch where this automation runs; until you switch, its runs go without memory."
- On the automation's page, find Move memory to your Azure Foundry (or Move memory to StackJack's engine) on the Memory card, and click Move.
- Confirm: "This copies every memory to the other engine's store, then retires the old one. Switch where this automation runs afterwards." Click Move memory.
- Switch where the automation runs in the builder, and save.
Move memory to your Azure Foundry is offered only while your organization has a finished Foundry connection and StackJack has memory on Azure Foundry switched on. Move memory to StackJack's engine is always offered, with or without a connection, so you can always take your memories back.
A move copies every memory and then switches the automation over to the copy. If it cannot finish, the automation keeps its memories where they were. It is refused, with nothing moved, when:
- a run that can change the memories has not finished: "This automation has a run in progress that can change its memories. Let the run finish, or stop it, and then try again.";
- another move of the same memories is running: "A move of this automation's memory is already in progress. Try again when it finishes.";
- the memories changed while they were being copied: "This automation's memories changed while they were being moved, so nothing was moved. Try again.";
- the memories are more than a Foundry automation's memory holds: "These memories are more than a Foundry automation's memory holds (1,000 files and 5 MB), so nothing was moved. Clear some first.", or one memory is larger than 100 KB;
- on a move to your Azure Foundry, StackJack cannot read every memory on StackJack's engine: "Some of this automation's memories are in folders nested more than 50 levels deep, which StackJack cannot read, so nothing was moved. Move them to a shallower folder first.", or, when the list of memories never finished, "StackJack could not read the full list of this automation's memories, so nothing was moved. Try again later.";
- memory on Azure Foundry is switched off: "Memory on Azure Foundry is not available yet, so nothing was moved.";
- your organization's connection is missing or not finished: "Your organization's Azure Foundry connection is missing or not finished, so nothing was moved. Finish it under Automations → Foundry first."
A move takes a moment for a large memory. The old copy is retired, and Erase all memory erases it too.
AI thinking steps on Your Azure Foundry
An AI thinking step asks an AI model a question in the fixed steps that run before or after an automation. Its AI provider picks who answers:
- StackJack (Anthropic), billed the way the automation's own model calls are;
- Your Azure Foundry, on your organization's own Claude deployment; Azure bills it, and StackJack charges no credits for it.
The editor says: "Who answers the question. "Your Azure Foundry" runs it on your organization's own Claude deployment, and Azure bills it; StackJack (Anthropic) is billed the way the automation's own model calls are."
- On an automation that runs on your Azure Foundry, every AI thinking step must use Your Azure Foundry, and a new step starts on it. A step on another provider is refused at save and at run: "This automation runs on your Azure Foundry, so its AI thinking steps must run there too. Set the step's AI provider to Your Azure Foundry."
- On an automation that runs on StackJack, Your Azure Foundry is offered while your organization has a working Foundry connection and StackJack has AI thinking steps on Azure Foundry switched on.
- Claude models only: "AI thinking steps on Azure Foundry can use Claude models only."
- A deployment of the step's model is needed: "This AI thinking step runs on your Azure Foundry. Connect Foundry and add a deployment of
- While StackJack has AI thinking steps on Azure Foundry switched off, a save with such a step is refused: "AI thinking steps on Azure Foundry are switched off on StackJack right now." On an automation that runs on your Azure Foundry, the builder then offers no AI thinking step and shows that sentence instead.
If your Foundry cannot answer when the step runs, the step fails and says why, and nothing else answers in its place: "This step runs on your Azure Foundry, which is not available:
StackJack's AI help on your Azure Foundry
StackJack's own AI help can run on your organization's Azure Foundry instead of your own Anthropic key or StackJack credits. Find the card StackJack's AI help on your Azure Foundry under Automations → Foundry, once you are connected. It says:
When this is on, the automation builder's assistant, its AI-assist suggestions and the research StackJack's support team runs on your organization's support tickets use the Claude deployment you pick below.
StackJack's AI help then runs on your Azure Foundry and Azure bills it, not StackJack credits. If that deployment cannot be used, StackJack refuses the request and never uses your own Anthropic key or StackJack credits instead.
- Pick the Claude deployment for AI help. The list offers your deployments of Opus 5.5, Opus 5, Opus 4.8, Sonnet 5, Fable 5 and Fable 5.1. With none, the card says: "None of your deployments can run StackJack's AI help. Declare a Claude deployment of Opus 5.5, Opus 5, Opus 4.8, Sonnet 5, Fable 5 or Fable 5.1 first."
- Tick Run StackJack's AI help on your Azure Foundry.
It is off until an owner or an administrator ticks it. Members see the choice but cannot change it. Turning it off is always possible; AI help then uses your organization's own Anthropic key, or StackJack credits if no key is on file.
While it is on:
- The builder's assistant (the guided wizard and the chat builder) and the AI-assist suggestions take no StackJack credits. In the chat builder, the cost line under the conversation says so after each such turn: "AI help ran on your Azure Foundry · Azure bills it".
- If your Foundry cannot answer, the request is refused with the reason, for example "StackJack's AI help runs on your Azure Foundry, which is not available right now:
- If the chosen deployment is gone from your connection, the card says: "The deployment chosen for StackJack's AI help,
- If StackJack switches AI help on Azure Foundry off, the card shows "AI help on Azure Foundry is switched off on StackJack right now." and, while your box is ticked, "Until it is back on, StackJack refuses its AI help requests. Clear the box to use your own Anthropic key or StackJack credits instead."
StackJack Foundry Runner
StackJack Foundry Runner is StackJack's own app in Microsoft Entra. Find the card StackJack Foundry Runner under Automations → Foundry. It says: "StackJack's own app, which StackJack uses to sign in to your Azure Foundry without a key, show Azure's cost for your Foundry resource group and rotate the key StackJack created on a schedule. An owner or administrator allows it once in your organization's Microsoft Entra directory; allowing it gives it no access to anything by itself." Until then the card says "StackJack Foundry Runner is not allowed in your Microsoft Entra directory yet."
An owner or an administrator allows it once:
- Click Allow StackJack Foundry Runner.
- Sign in to Microsoft with an account in your organization's Microsoft Entra directory, and accept.
Back on the Foundry tab, the card says "StackJack Foundry Runner is now allowed in your Microsoft Entra directory." and shows where it is allowed: "StackJack Foundry Runner is allowed in your Microsoft Entra directory
- If your directory does not let users allow apps, the card says "Your Microsoft Entra directory needs an administrator to approve StackJack Foundry Runner." and offers Ask an Entra administrator to approve for the same directory.
- If the sign-in did not finish: "The sign-in to Microsoft did not finish, so nothing changed. Try again."
Allowing the runner gives it no access by itself. Keyless sign-in and each feature below give it the Azure roles they need, and only when an owner or an administrator turns them on. StackJack gives each role with that person's own Microsoft Azure sign-in (connect Microsoft Azure under Connectors first), so that person needs the right to give roles in Azure, for example Owner on the connection's resource group. A feature turned on before the runner is allowed says: "StackJack Foundry Runner is not allowed in your Microsoft Entra directory. Allow it on the Foundry tab."
With those roles, StackJack also gives the runner one more narrow role on the connection's resource group. With it the runner can read the role assignments that apply to that resource group, including the ones it inherits from the subscription and the management group above it, and delete only its own. It cannot give any role. StackJack uses it only after your organization is deleted from StackJack, to remove the runner's own access. If Azure refuses this role, the feature still works, but StackJack cannot remove its access by itself: remove the StackJack Foundry Runner enterprise application from your Microsoft Entra directory instead.
To take the runner away, the card says: "To take it away, remove its enterprise application in Microsoft Entra; withdrawing only your own consent leaves it in place." Remove connection first removes the roles StackJack gave the runner for that connection, with your own Microsoft Azure sign-in. If you have no Azure sign-in on the Connectors page, or Azure refuses, the role stays in your Azure and the page says: "StackJack could not remove some of its access to your Azure. Remove the StackJack Foundry Runner enterprise application from your Microsoft Entra directory to end it. Azure can keep honoring the removed role for more than 90 minutes; StackJack stops its own use at once."
Keyless sign-in
A connection that signs in without a key uses StackJack Foundry Runner with two roles: its narrow role on your Foundry account, and Microsoft's built-in Cost Management Reader role on the resource group, which lets StackJack show Azure's cost for it. The narrow role can call the models on that one account. It cannot read the account's keys, use fine-tuning or files, read stored completions, run evaluations or use Content Safety.
Switch an existing connection. On a connection StackJack set up with a key, once the runner is allowed in its directory, the card offers Switch to keyless sign-in and asks first: "Switch this connection to keyless sign-in? StackJack gives StackJack Foundry Runner access to this Foundry account with your Azure sign-in and checks that it works. Then StackJack stops using the stored key and regenerates the key it created, so that key stops working wherever it is used; if Azure refuses, the result names the key that is still valid in Azure." Click Switch. The page updates as it goes and then says "This connection now signs in without a key." Where the runner is not allowed yet, the card says "Allow StackJack Foundry Runner first to switch this connection to keyless sign-in."
A new role takes a few minutes. Azure can take several minutes to apply a new role. If it still has not after 15 minutes, the step stops with "Azure has not applied StackJack's access to your Foundry account yet. Try again in a few minutes."
Removing access takes longer. Azure can keep honoring a removed role for more than 90 minutes.
- Remove connection stops StackJack's own use at once, even while Azure still honors the role.
- A role you remove yourself in the Azure portal does not stop StackJack at once. Until Azure stops honoring it, automations set to run on your Azure Foundry keep running on that account, on your Azure bill.
When access must end at once, use Remove connection. On a connection with a stored key, regenerating that key in the Azure portal also ends StackJack's access, within seconds.
If the role is gone. When Azure no longer lets the runner in, runs say: "StackJack Foundry Runner no longer has access to your Foundry account. Give it its role again in the Azure portal, or remove the connection on the Foundry tab and connect again."
Rotate the key
For a connection that StackJack set up with a key, an owner or an administrator can have StackJack replace the key it created. The Key rotation card says: "StackJack can replace the key it created for this Azure account." It shows when StackJack last rotated it.
- Click Rotate key. The card asks first: "Both keys of this Azure account will change. Anything else that uses one of them stops working."
- Click Rotate both keys.
StackJack uses your own Microsoft Azure sign-in for every step. It regenerates the key it is not using, starts using the new key, waits until every call that read the old key has finished, and then regenerates the old key too. The card says "The new key is in use" and when StackJack finishes: "StackJack finishes the rotation at
If the rotation stops part-way, the card says what is true at that point and how to finish it; Rotate key always finishes it. If your Azure sign-in cannot be used: "Sign in to Azure again and press Rotate key to finish. Your old key is still valid until then."
StackJack rotates only a key it created. On a connection you made with a pasted key: "StackJack can rotate only a key it created. Replace the key on the Foundry tab instead."
Let StackJack rotate the key on a schedule
On a connection StackJack set up with a key, the Key rotation card can offer Let StackJack rotate this key. Tick it, and StackJack gives StackJack Foundry Runner a narrow role on this Azure account, with your own Microsoft Azure sign-in. The role can only read the account and read and regenerate its keys. The runner must be allowed first (see StackJack Foundry Runner). Under the box the card says how often, for example: "StackJack rotates this key every 90 days and e-mails the owner each time. Clear the box to stop." A scheduled rotation takes the same steps as Rotate key, signed in as StackJack Foundry Runner instead of with your Azure sign-in.
If three scheduled rotations in a row fail, the card says StackJack stopped rotating this key: "Three scheduled rotations in a row failed, so StackJack stopped and does not try again until a person acts. Press Rotate key to rotate it and restart the schedule."
Azure cost
For a connection StackJack set up or attached, the Azure cost card can show what Azure reports for the connection's resource group: "What Azure reports for this resource group. StackJack shows it and never bills it." A connection that signs in without a key already has the role this needs, so its card fills after the next daily read with no click.
- Allow StackJack Foundry Runner first (see StackJack Foundry Runner).
- Click Show Azure's cost. StackJack gives the runner Microsoft's built-in Cost Management Reader role on the resource group, with your own Microsoft Azure sign-in.
StackJack reads the cost once a day. The card shows what Azure reported for Claude in the resource group this month and last month (Azure reports cost several hours late), with StackJack's own estimate for this month's Foundry runs beside it: "Azure's charges can differ from StackJack's estimate: discounts, retried calls and cancelled answers are billed by Azure." Until the first read: "The first figures appear after the next daily read."
- A subscription Azure does not show cost for: "Azure does not show cost for this subscription to StackJack. Your CSP partner can turn on cost visibility." Click Check again once your partner has turned it on.
- If StackJack can no longer read the cost: "StackJack can no longer read this resource group's cost." An owner or an administrator can click Grant cost access again.
Remove the connection
Open Automations → Foundry and click Remove connection. The confirmation says what removing does for your connection:
- A connection that signs in without a key: "Remove this connection? StackJack removes its access to your Azure Foundry. Automations set to run on Azure Foundry stop running until you connect again or set them to run on StackJack. Azure can keep honoring the removed role for more than 90 minutes; StackJack stops its own use at once."
- A key you pasted: "Remove this connection? StackJack deletes the stored key. Automations set to run on Azure Foundry stop running until you connect again or set them to run on StackJack. Your Azure resources are not changed." The key you pasted still works in Azure; regenerate it there if you want.
- A connection StackJack set up with a key, when your Azure sign-in can be used: "Remove this connection? StackJack regenerates the key it created for this account with your Azure sign-in, so that key stops working wherever it is used, then deletes its copy. If Azure refuses, the key stays valid in Azure until someone with rights to the account rotates or deletes it, and the result says so. Automations set to run on Azure Foundry stop running until you connect again or set them to run on StackJack. Your other Azure resources are not changed." Without an Azure sign-in StackJack can use, the confirmation says the key stays valid and how to have StackJack regenerate it: sign in to Microsoft Azure on the Connectors page first, or regenerate or delete the key in the Azure portal.
The confirmation also says:
- "StackJack's AI help stops using your Azure Foundry. Once the connection is removed, it uses your organization's own Anthropic key, or StackJack credits if no key is on file." (when AI help runs on your Azure Foundry)
- "The memories StackJack keeps for your Foundry automations stay. Move an automation's memory on its page before you set it to run on StackJack."
StackJack stops using the connection at once. For a connection StackJack set up, the page shows "Removing StackJack's access to your Azure Foundry" and updates as it goes, then says "The connection is removed." with what happened to the key. Until then a Foundry run fails with: "Your organization disconnected its Azure Foundry, so StackJack stopped running automations there. To use Foundry again, finish Disconnect and connect it again under Automations → Foundry, or set the automation to run on StackJack."
If removing does not finish, the page says so: Disconnect did not finish ("Press Remove connection again to finish it. StackJack does not use this connection until it is finished.") or Disconnect stopped before it finished ("It made no progress for 30 minutes. Press Retry to continue it, or press Remove connection again.").
Delete everything StackJack created
For a connection that StackJack set up on your subscription, an owner or an administrator can delete what StackJack created, not only the connection. Click Delete everything StackJack created. StackJack reads your Azure first and lists exactly what it would delete and keep; nothing changes yet:
- This deletes: StackJack's access to your Azure (its role assignments) and the key it stored; each deployment; the Foundry account, purged so its name and quota are released; StackJack's own Azure roles in the resource group, once nothing uses them; and the resource group, when StackJack created it and it holds nothing else.
- This keeps: the resource group, with the reason, for example when it also holds your own resources.
- Two notes, always: "Azure can keep honoring the removed role for more than 90 minutes; StackJack stops its own use at once." and "A Claude deployment creates no separate Azure Marketplace resource, so there is none to remove. Deleting the account and its resource group does not cancel your subscription's Azure Marketplace agreement for Claude, and StackJack never changes that agreement."
Type the Foundry account's name to confirm, and click Delete everything. StackJack checks again that it created the account, then deletes each item with your own Microsoft Azure sign-in. The page shows "Deleting everything StackJack created in your Azure" and updates as it goes, then says "The full teardown finished." with a line for each item. It works even while Foundry runs are paused and whatever your plan.
- On an account StackJack did not create: "StackJack deletes only the Azure resources it created. Remove this account in the Azure portal."
- If it stops part-way, the page says "The full teardown did not finish" (or "The full teardown stopped before it finished" after 30 minutes with no progress) and offers Retry, which continues from the step that stopped.
The two sentences about AI help and memory in Remove the connection apply here too.
The spend guard
Each Foundry run has a spend guard: StackJack stops the run when its estimated model cost reaches a limit. StackJack cannot see your Azure price, so the estimate uses a list price, and your actual cost can differ: Anthropic's list price for a Claude model, and Azure's list price for every other model. The guard is on by default at $10 a run. Change the limit, or turn the guard off, under Run on in the builder. The estimate includes each web search at its list price ($10 per 1,000 on Claude, $14 per 1,000 on OpenAI models). Where Azure charges a higher rate for long requests and does not publish where that rate starts, StackJack estimates at the higher rate, and the run page says the estimate may be high. If StackJack has no list price for the automation's model, the builder says so under the limit: those runs are not estimated, and the guard cannot stop them.
Quota and retries
Azure limits how many requests and tokens a minute your subscription's deployments of a model accept, and the limit is shared by every deployment of that model in the subscription. A busy automation can reach it. The run then waits and retries the model call. Azure may bill a retried call. A tool call is never repeated: StackJack runs the tools itself and records each one before it is sent.
The Foundry tab shows each deployment's limits, and warns when a deployment's quota is low. Ask Microsoft for more quota when runs slow down.
Costs
- Model usage: billed by Azure to your subscription. StackJack charges no credits for the model usage.
- Web search and web fetch: billed by Azure to your subscription.
- AI thinking steps on Your Azure Foundry: billed by Azure to your subscription, on any automation.
- StackJack's AI help on your Azure Foundry: billed by Azure to your subscription, when you tick it.
- Memory StackJack keeps for a Foundry automation: no StackJack charge. The model's reads and writes are part of the model usage Azure bills.
- The checks of models other than Claude: billed by Azure to your subscription. See The daily check.
- StackJack: the same plan you already have for running automations on your own key. There is no per-run fee.
The run page shows a Foundry run's estimated model cost at the list price of its model, never credits, and says that the Azure portal shows what Azure billed. For a model with no list price it says the cost is not estimated. The automation's cost panel shows no credits for a Foundry automation: it shows how much context each step re-reads, which is what drives the Azure bill, at the model's list price.