VIDEO 4 · COMPANION LAB
Prove access. Follow the trace.
Apply document permissions and collect a useful, sanitized request trace.
45–60 minutes · Work on your laptop in lesson.ipynb or your terminal. The core exercise uses fictional data and needs no API key.
STEP 01 · WATCH → BUILD
Open your practice notebook.
Download the ZIP and extract it. Open a terminal inside azure-engineer-lifecycle. Use Python 3.12 or newer for the local exercise.
python3 -m venv .venv
source .venv/bin/activate
python -m unittest -v test_exerciseWindows PowerShell
py -3.12 -m venv .venv
.venv\Scripts\Activate.ps1
python -m unittest -v test_exerciseIts tests initially fail because the functions are unfinished. Your task is to implement them in exercise.py.
Prefer a guided notebook?
Open lesson.ipynb in your existing Jupyter or VS Code Python environment, using the virtual environment above. Or install JupyterLab locally:
python -m pip install jupyterlab
python -m jupyterlab lesson.ipynbThe notebook walks through the same editable Python files and checks. No browser code runner or automatic grader is involved.
Done when the notebook opens or the terminal tests run, and you can identify the unfinished functions.
READ THE CONCEPT BEHIND THIS STEP
Concept references · original explanation based on these sources.
- Data, models and application engineeringlearn.microsoft.com · Training for AI engineers
- Evaluation before and after deploymentlearn.microsoft.com · Run evaluations from the Microsoft Foundry portal
- Follow requests and diagnose failureslearn.microsoft.com · Tracing and data handling
The lifecycle diagram summarizes the role; it is not a certification process.
The notebook and local tests are our original exercise. These references explain the engineering principles.
Sign in to save checkpoints and private notes. Downloads are available without signing in.
YOUR EVIDENCE
Keep what you learned.
OPTIONAL · USE YOUR AZURE CREDITS
Take it to the official exercise.
Use the official D0/D1 setup and traced_agent starter; confirm actual client spans in Application Insights. For document authorization, separately follow the RAG sample login/ACL guide and test the real authenticated identity on both query and citation/download paths.
Setup requirements and source scope
Reference solution instruments a grounded Foundry agent with client spans and exports them to Application Insights. Authentication and telemetry alone do not demonstrate per-document authorization.
- Local simulation: Python 3.12 stdlib plus Jupyter, no key.
- Current upstream D lab requires Python 3.13 and excludes 3.14; requirements pin azure-ai-projects==2.3.0, openai<3 and azure-ai-evaluation[redteam]==1.18.3.
- Needs Foundry project, deployed model, grounded agent, PROJECT_ENDPOINT, AGENT_NAME, and connected Application Insights. Its azd template does not create/connect Application Insights.
- The official lab enables message-content capture for teaching; use fictional input and deliberate collection settings.
- Foundry server trace view and Application Insights custom/client span view are distinct.
- Do not make the full PyRIT/red-team dependency installation mandatory for an introductory local notebook.
Use a separate Azure lab environment. Review regional availability, quota and estimated costs before provisioning, and remove only the resources you created when finished. Credentials stay in your local environment.
Signed-in profiles and learning activity are visible to the app owner. Project notes stay private. Your profile & data