Information Technology Services

Azure AI Foundry — Shared Responsibility and Governance Model

George Mason University — Information Technology Services Cloud Solutions Team
Version 1.0 | September 2026

Purpose

This document defines the shared responsibilities between Microsoft, George Mason University Information Technology Services (ITS), and departmental or research users of Azure AI Foundry. It establishes clear accountability across every layer of the service — from physical infrastructure to responsible AI use — so that every party understands what they own, what ITS manages on their behalf, and what Microsoft guarantees as the platform provider.

This model is based on the standard cloud shared responsibility framework extended to address the specific governance, compliance, and operational requirements of AI services at a research university.

How To Read This Document

Each responsibility category is described with:

  • What it covers — the scope of this area
  • Microsoft’s responsibility — what Azure guarantees as the platform
  • ITS responsibility — what central IT owns and manages
  • Department / Researcher responsibility — what the end user owns and manages

Responsibility codes used in the summary table:

  • M — Microsoft owns this fully
  • ITS — ITS owns this fully
  • D — Department / Researcher owns this fully
  • M/ITS — Shared between Microsoft and ITS
  • ITS/D — Shared between ITS and Department
  • M/ITS/D — All three parties share responsibility

Summary Table

Responsibility CategoryMicrosoftITSDepartment / Researcher
Physical Infrastructure✅ Primary——
Physical Data Center Security✅ Primary——
Azure Platform Availability✅ Primary——
Network Infrastructure (Azure)✅ Primary——
Model Hosting and Availability✅ Primary——
Model Updates and Versioning✅ PrimaryInformedInformed
Responsible AI Framework (Platform) (find link for what this means)✅ Primary——
Subscription Provisioning—✅ PrimaryRequests
AI Foundry Hub and Project Configuration—✅ Primary—
Security Baseline and Governance ControlsProvides tools✅ PrimaryComplies
Identity and Access Management—✅ PrimaryRequests to Add / Remove Users
Network Security (George Mason-side)—✅ Primary—
Compliance ConfigurationProvides tools✅ PrimaryProvides info
Cost Management InfrastructureProvides tools✅ PrimaryResponsible for use
Service Catalog and Intake Process—✅ PrimarySubmits requests
Platform Monitoring and Security LoggingProvides tools✅ PrimaryOptional
All Costs Generated By All Resources and Services Within SubscriptionProvides toolsGuides✅ Primary
User Code / Application Monitoring and LoggingProvides tools ✅ Primary
Model Selection and DeploymentProvides catalogGuides✅ Primary
Prompt Engineering and Design— ✅ Primary
Output Review and QualityContent safety tools ✅ Primary
Compliance with Responsible Use of Computing Policies—  Provides policy✅ Primary
Data Classification and GovernanceProvides toolsProvides policy✅ Primary
Application DevelopmentProvides SDKs ✅ Primary
Budget Management and Cost MonitoringProvides toolsAlerts and guidance✅ Primary
Responsible and Ethical AI UsePlatform controlsPolicy and guidance✅ Primary
Platform / Service Incident Reporting and ManagementPlatform monitoring✅ PrimaryReports issues

Detailed Responsibility Descriptions

1. Physical Infrastructure and Data Center Security

What it covers: Physical servers, networking hardware, power, cooling, and physical access controls at Azure data centers.

Microsoft: Owns entirely. Operates and secures all physical infrastructure supporting Azure services. Maintains SOC 2, ISO 27001, and FedRAMP certifications. George Mason has no visibility into or responsibility for this layer.

ITS: None. This is entirely Microsoft’s responsibility under the cloud model.

Department / Researcher: None.

2. Azure Platform Availability and SLAs

What it covers: Uptime guarantees, redundancy, failover, and disaster recovery at the Azure platform level.

Microsoft: Guarantees platform availability per published Azure SLAs — typically 99.9% or higher for AI Foundry services. Responsible for regional failover, platform-level redundancy, and incident response for platform outages.

ITS: Monitors platform health via Azure Service Health. Communicates platform outages to affected users. Does not control platform availability.

Department / Researcher: Responsible for designing applications and workflows that account for potential service interruptions. Should not build single-point-of-failure dependencies on any single model deployment.

3. Model Hosting and Availability

What it covers: Availability of AI models in the Azure AI Foundry catalog, including OpenAI, Anthropic, and more.

Microsoft: Hosts and operates models deployed via Azure AI Foundry. Responsible for model serving infrastructure, capacity, and throughput. Publishes quota limits and rate limits.

ITS: Deploys models within the George Mason subscription as requested. Monitors deployed model health. Does not control underlying model hosting.

Department / Researcher: Responsible for understanding quota limits for their deployed models. Responsible for requesting quota increases if needed. Responsible for selecting appropriate models for their workload.

4. Model Updates and Versioning

What it covers: Changes to model versions, deprecations, and new model releases in the Azure AI Foundry catalog.

Microsoft: Controls model versioning, updates, and deprecation schedules. Provides advance notice of deprecations per Azure lifecycle policies. Publishes release notes for model changes.

ITS: Monitors model deprecation notices and communicates to affected users. Updates default model recommendations as new versions become available. Maintains getting started documentation to reflect current model names.

⚠️ Important for users: Model names used in terminal configuration must match exactly what is shown in the Azure AI Foundry portal. When a model version is deprecated, users must update their configuration to reference the replacement model. ITS will communicate these changes, but users are responsible for updating their own configuration.

Department / Researcher: Responsible for updating application configurations and terminal environment variables when model versions change. Responsible for testing applications against new model versions before deprecation deadlines.

5. Subscription Provisioning and Configuration

What it covers: The creation and baseline configuration of Azure Subscriptions with AI Foundry enabled for departments and research teams.

Microsoft: Provides the subscription infrastructure and Azure AI Foundry platform configuration capabilities.

ITS: Owns end-to-end subscription provisioning using Terraform-based Infrastructure as Code. Configures the AI Foundry hub and project structure aligned to George Mason security standards. Establishes governance controls, logging, and monitoring baselines. Targets delivery within 8 business days of a completed, approved request.

Department / Researcher: Submits a complete request through the ITS Service Catalog including business purpose, data classification, org code, fund code, and business owner approval. Provides accurate information at intake — incomplete submissions delay provisioning. Designates a technical contact responsible for managing the subscription after delivery.

6. Security Baseline and Governance Controls

What it covers: Security controls applied to the Azure subscription and AI Foundry environment, including logging, monitoring, network restrictions, and policy enforcement.

Microsoft: Provides Azure Security Center, Microsoft Defender for Cloud, and built-in policy frameworks. Operates the underlying security infrastructure of the Azure platform.

ITS: Applies George Mason security baseline to every provisioned subscription using ITS-managed Azure Policy. Configures centralized logging and monitoring. Maintains NIST 800-53-aligned controls. Coordinates with Cybersecurity Operations for review and approval of each new subscription. Responsible for firewall configuration allowing appropriate access to AI Foundry endpoints.

Department / Researcher: Complies with ITS-established security baseline. Does not modify or disable governance controls without ITS approval. Reports suspected security incidents immediately to ITS. Responsible for security of applications built on top of the provisioned environment — ITS governs the platform, not the applications running on it.

7. Identity and Access Management

What it covers: User authentication, role assignments, and access control within the Azure AI Foundry environment.

Microsoft: Provides Microsoft Entra ID as the identity platform. Operates the authentication infrastructure.

ITS: Configures initial role assignments for the subscription owner and technical contacts. Maintains the George Mason Entra ID tenant. Provisions Azure accounts for users as required. Recommends Entra ID authentication over API key authentication, which is disabled by default, for interactive use.

Department / Researcher: Responsible for managing user access within their provisioned subscription. Responsible for adding and removing team members as personnel changes occur. Responsible for ensuring only authorized users have access to their AI Foundry environment. Must not share API keys or credentials.

⚠️ API Key Security: API keys provide direct access to your AI Foundry environment and must be treated like passwords. Do not share keys in email, chat, or code repositories. Rotate keys immediately if exposure is suspected, and periodically as users are added and removed. Keys can be regenerated in the Azure AI Foundry portal at any time.

8. Network Security

What it covers: Network controls governing traffic to and from Azure AI Foundry services.

Microsoft: Operates Azure networking infrastructure. Provides virtual network integration capabilities and private endpoint options.

ITS: Configures George Mason-side firewall rules allowing access to required Azure AI Foundry FQDNs from provisioned IP ranges. Maintains network connectivity between George Mason infrastructure and Azure. Coordinates with the network team on any required firewall changes for specific use cases.

Department / Researcher: Responsible for understanding network requirements for applications they build on AI Foundry. Notifies ITS if an application requires network access beyond the standard configuration. Does not attempt to modify network controls directly.

9. Compliance Configuration

What it covers: Configuration of the environment to support compliance requirements including FERPA, HIPAA, CMMC, and Data Use Agreements.

Microsoft: Azure AI Foundry supports a range of compliance certifications. Microsoft maintains compliance documentation and audit reports available via the Microsoft Trust Center.

ITS: Configures the subscription environment appropriate to the declared compliance requirements at intake. Coordinates with Cybersecurity Operations and the Office of Research Integrity for specialized compliance needs. Research with CMMC Level 2 or higher, HIPAA, or active Data Use Agreements must contact ITS before submitting a request to ensure appropriate configuration.

Department / Researcher: Responsible for accurately declaring compliance requirements at intake. Responsible for ensuring data submitted to AI models is appropriately classified and permitted for use in a cloud-hosted environment under their applicable agreements. Consult George Mason Data Stewardship Policy 1114 before submitting sensitive data.

10. Cost Management and Financial Responsibility

What it covers: Azure consumption costs including token usage, compute, storage, logging infrastructure, and required security controls.

Microsoft: Provides Azure Cost Management tools, billing dashboards, and budget alert capabilities.

ITS: Configures cost management infrastructure including budget alerts and spending dashboards at subscription creation. Provides guidance on cost estimation and optimization. Does not pay for departmental AI Foundry usage — all costs are billed to the department.

Department / Researcher: Fully responsible for all Azure consumption costs within their provisioned subscription. This includes token consumption from model inference, storage, logging, and required security controls. Must provide valid org code and fund code at intake. Must monitor usage and manage consumption to stay within budget. Must ensure appropriate funding is available for ongoing use. ITS recommends setting budget alerts at 80% and 100% of monthly budget targets.

⚠️ Cost awareness: AI model token consumption can accumulate quickly, particularly with large context windows or high-volume applications. Review the Azure Price Calculator and Microsoft model pricing before deploying for production workloads. ITS can provide guidance on cost estimation before deployment.

11. Service Catalog, Intake, and Request Management

What it covers: The process by which departments and researchers request and receive AI Foundry access.

Microsoft: Not involved in George Mason’s internal service delivery process.

ITS: Maintains the Service Catalog entry, intake form, and request workflow in TeamDynamix. Owns the request-to-delivery process targeting 8 business days or less for standard requests. Provides status updates to requestors throughout the process. Maintains the Knowledge Base and getting started documentation.

Department / Researcher: Submits complete and accurate requests through the ITS Service Catalog. Designates a business owner who can approve financial responsibility. Responds promptly to ITS follow-up questions — delayed responses extend provisioning time. Participates in post-provisioning onboarding.

12. Model Selection and Deployment Within the Subscription

What it covers: Selecting, deploying, and managing AI models within a provisioned AI Foundry subscription.

Microsoft: Provides the model catalog. Manages model availability, quota, and pricing.

ITS: Provides guidance on model selection for common use cases. Recommends appropriate models for research, teaching, and administrative workloads. Does not manage model deployments within departmental subscriptions after provisioning.

Department / Researcher: Fully responsible for selecting and deploying models appropriate for their use case within their subscription. Responsible for understanding the capabilities and limitations of chosen models. Responsible for managing model deployments, quotas, and configurations within their environment.

Model selection guidance: Use Sonnet models for most research tasks — summarization, writing assistance, analysis, and code generation. Use Opus models for complex reasoning, long documents, and tasks requiring deeper analytical capability. Opus models cost more per token. Consult the ITS Knowledge Base for detailed model comparison guidance.

13. Prompt Engineering and Application Design

What it covers: How users interact with AI models — prompt design, system instructions, context management, and application architecture.

Microsoft: Provides documentation and best practices. Operates content safety filtering at the platform level.

ITS: Provides general guidance and learning resources. Not responsible for prompt design or application architecture decisions made by departments.

Department / Researcher: Fully responsible for prompt design, system instructions, and how AI models are integrated into their workflows or applications. Responsible for testing prompts and validating outputs before use in research or operational contexts. Responsible for understanding the limitations of the models they deploy.

14. Output Review and Quality Assurance

What it covers: Review, validation, and responsible use of AI-generated outputs.

Microsoft: Operates platform-level content safety filtering. Does not review or validate outputs for individual use cases.

ITS: Provides policy guidance on responsible AI use. Not responsible for reviewing outputs of departmental AI applications.

Department / Researcher: Fully responsible for reviewing and validating AI-generated outputs before use. AI models can produce inaccurate, incomplete, or inappropriate outputs. Outputs used in research must be validated against authoritative sources. Outputs used in student-facing contexts must be reviewed for accuracy and appropriateness. Responsibility for the accuracy and integrity of AI-assisted work remains with the human researcher or faculty member.

15. Data Classification and Governance

What it covers: Ensuring that data submitted to AI models is appropriately classified and governed.

Microsoft: Provides data handling documentation and compliance certifications. Operates within the terms of the Microsoft Online Services Data Protection Agreement.

ITS: Maintains George Mason Data Stewardship Policy 1114. Provides data classification guidance. Configures the environment appropriate to declared data classification at intake. Does not review or classify data submitted to models during use.

Department / Researcher: Fully responsible for classifying data before submitting it to AI models. Responsible for ensuring data use complies with applicable regulations, Data Use Agreements, IRB requirements, and George Mason policy. Do not submit data classified as Restricted or Regulated to AI Foundry without consulting ITS and confirming the environment is configured appropriately for that data classification.

⚠️ Research data: If your research involves human subjects data, protected health information, export-controlled data, or data subject to a Data Use Agreement, contact ITS before submitting a request to ensure the environment is configured to meet your compliance obligations.

16. Application Development and Integration

What it covers: Building applications, tools, or automated workflows that use AI Foundry as a platform.

Microsoft: Provides SDKs, APIs, documentation, and development tools. Provides VS Code integration and Azure AI Foundry development resources.

ITS: Provides getting started documentation and connection guides for common development environments. Available for consultation on architecture questions. Not responsible for application development, testing, or maintenance within departmental subscriptions.

Department / Researcher: Fully responsible for application design, development, testing, security, and maintenance. Responsible for secure handling of API keys and credentials in application code — never commit credentials to source control. Responsible for implementing appropriate error handling, rate limiting, and cost controls in applications consuming AI Foundry APIs.

17. Responsible AI and Ethical Use

What it covers: Ensuring AI is used ethically, transparently, and in alignment with George Mason’s values and applicable regulations.

Microsoft: Provides the Responsible AI Standard and platform-level content safety controls. Publishes transparency notes for models in the Azure AI Foundry catalog.

ITS: Provides policy guidance aligned to George Mason’s AI governance framework. Communicates updates to responsible AI requirements as they evolve. Facilitates connection with George Mason’s AI governance bodies as they develop.

Department / Researcher: Fully responsible for ensuring AI use complies with George Mason’s responsible AI principles, academic integrity policies, applicable research ethics requirements, and discipline-specific norms. Responsible for transparent disclosure of AI use in research publications and student communications where required. Responsible for ensuring AI tools are used in ways that respect human dignity and institutional values.

18. Incident Reporting and Response

What it covers: Identifying, reporting, and responding to security incidents, service disruptions, or policy violations.

Microsoft: Monitors Azure platform security and reports platform-level incidents. Notifies Microsoft account teams of significant service events.

ITS: Triage and coordinates response to reported incidents. Escalates to Microsoft as appropriate. Communicates platform outages to affected users. Coordinates with Cybersecurity Operations on security incidents.

Department / Researcher: Responsible for reporting suspected security incidents, unauthorized access, or policy violations to ITS immediately. Contact ITS Support at 703-993-8870 or submit a ticket through the Service Catalog. Do not attempt to investigate or remediate security incidents independently.

One-Page Summary for Departmental Users

What ITS does for you:

  • Provisions your Azure subscription with AI Foundry configured to George Mason security standards
  • Sets up governance, logging, and monitoring
  • Manages the security baseline so you don’t have to
  • Provides documentation, getting started guides, and support
  • Handles network and firewall configuration

What you are responsible for:

  • All Azure consumption costs billed to your org code and fund code
  • Selecting and deploying models appropriate for your use case
  • Managing access for your team members
  • Classifying data correctly before submitting to AI models
  • Reviewing and validating AI-generated outputs
  • Keeping API keys secure and rotating them if exposed
  • Responsible and ethical use of AI in your research and work

What Microsoft handles:

  • Physical infrastructure and data center security
  • Azure platform availability and SLAs
  • Model hosting and serving infrastructure
  • Platform-level content safety

Document Maintenance

This document should be reviewed and updated:

  • When Microsoft updates Azure AI Foundry capabilities or terms
  • When George Mason AI governance policy evolves
  • When new compliance requirements are identified
  • At minimum annually

Owner: ITS Cloud Solutions Team

Contact: ITS Support

Aligned to George Mason Data Stewardship Policy 1114 and the ITS Cloud Strategy.

Related Articles