{"id":22513,"date":"2026-10-07T20:29:08","date_gmt":"2026-10-07T20:29:08","guid":{"rendered":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry"},"modified":"2026-10-07T20:29:08","modified_gmt":"2026-10-07T20:29:08","slug":"safety-evaluation-in-microsoft-foundry","status":"publish","type":"post","link":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry","title":{"rendered":"Safety Evaluation in Microsoft Foundry"},"content":{"rendered":"<h3>Safety evaluation tests the system behavior, not only the final answer<\/h3>\n<p>Microsoft Foundry provides risk and safety evaluators for harmful content and agent-specific risks, including prohibited actions and sensitive-data leakage. Agent evaluation extends beyond a final text response because a system can fail through tool selection, data access, or an unsafe action even when the visible answer appears harmless.<\/p>\n<p><a href=\"https:\/\/www.exam-labs.com\/dumps\/AI-103\">AI-103<\/a> frames production safety as an evidence problem: teams need repeatable tests that show whether an agent respects instructions and policy across representative conversations, tools, and failure paths. That evidence should be versioned with the agent so later model or tool changes can be compared against a known baseline.<\/p>\n<p>Use <a href=\"https:\/\/www.exam-labs.com\/blog\/ai-guardrails-and-content-safety-where-controls-actually-sit\">AI guardrails<\/a> during runtime, but evaluate them offline and in controlled preproduction runs. Guardrails enforce policy on live traffic; evaluation tells you whether the complete system still behaves acceptably after prompts, models, tools, or policies change.<\/p>\n<p>Define the safety claim before choosing evaluators. \u201cThis agent is safe\u201d is too broad to test. \u201cThe agent does not disclose secrets, execute prohibited actions, or generate severe self-harm guidance in these supported workflows\u201d can be tied to datasets, thresholds, and release decisions.<\/p>\n<p>Safety requirements should name the protected subject and unacceptable effect. \u201cNo sensitive data leakage\u201d becomes more testable when the team identifies which data classes, tool outputs, memory fields, and retrieved sources count as sensitive for that particular agent.<\/p>\n<h3>Choose evaluators that match the actual failure modes<\/h3>\n<p>Foundry risk evaluators cover categories such as violence, sexual content, self-harm, hateful or unfair content, indirect attack jailbreaks, and code vulnerability, while agent evaluators can assess behavior such as tool-call accuracy, task adherence, prohibited actions, or data leakage. Use the smallest set that maps to the application\u2019s real risks.<\/p>\n<p>A customer-service agent may need strong privacy, harassment, and escalation tests. A coding agent may need code-vulnerability and prohibited-action checks. A research agent that reads external documents needs indirect prompt-injection scenarios. Reusing the same evaluator list for every agent can create impressive dashboards without meaningful coverage.<\/p>\n<p><a href=\"https:\/\/www.exam-labs.com\/blog\/llm-evaluation-judges-metrics-and-what-they-miss\">LLM evaluation<\/a> should also include human or deterministic checks where model-based judges are weak. Safety scores are useful signals, but high-consequence decisions should not depend on one evaluator interpreting ambiguous policy text.<\/p>\n<p>Document what each evaluator cannot prove. A content-safety score does not prove authorization, a tool-call score does not prove business correctness, and a leakage evaluator cannot find secrets that never appear in the test data.<\/p>\n<p>Evaluator selection should also consider language coverage and domain vocabulary. A risk classifier that performs well on ordinary English may need additional human review for specialized medical, legal, or multilingual content where benign terminology can resemble harmful language.<\/p>\n<h3>Build test datasets around realistic attacks and ordinary traffic<\/h3>\n<p>Safety evaluation needs adversarial examples, but it also needs normal user requests. An agent that blocks every difficult conversation can score well on some risk metrics while failing the product. Include benign, borderline, and clearly disallowed cases so false positives are visible.<\/p>\n<p>Represent the ways users actually interact with the system: short prompts, multi-turn clarification, copied documents, multilingual input, tool results, long context, ambiguous requests, and role transitions. Attackers exploit boundary conditions, and ordinary users trigger them accidentally.<\/p>\n<p>Keep provenance for each test case. Record why the example exists, what risk it targets, expected behavior, source incident if any, and whether sensitive data has been sanitized. A large unlabeled prompt list becomes hard to maintain as policy changes.<\/p>\n<p>Version the dataset with the application. If a release changes tools or data sources, add cases for the new attack surface before comparing scores so the new version is not evaluated on an obsolete threat model.<\/p>\n<p>Adversarial datasets should include chained attacks that unfold over several turns. An agent may resist a direct prohibited request but gradually accept a dangerous premise after repeated benign-seeming setup messages, especially when conversation memory persists across turns.<\/p>\n<h3>Evaluate process behavior as well as outcomes<\/h3>\n<p>Agent systems can reach the right final answer through an unsafe path. An agent might retrieve data it was not entitled to see, call a privileged tool unnecessarily, or expose sensitive intermediate results before eventually returning a compliant response.<\/p>\n<p>Process evaluation examines the steps taken to reach the outcome. Tool-selection accuracy, parameter correctness, prohibited actions, task navigation, and trace analysis can show whether the agent behaved safely throughout the workflow.<\/p>\n<p><a href=\"https:\/\/www.exam-labs.com\/blog\/agent-tools-and-multi-step-reasoning-a-practical-mental-model\">Agent tools<\/a> belong inside the safety test plan because effectful capabilities create risks that final-response scoring cannot see. Negative cases should prove the agent refuses or requests approval when identity, resource scope, or business preconditions are not satisfied.<\/p>\n<p>Preserve traces for failed tests so engineers can see the decision sequence. A pass\/fail score without the tool call, model response, guardrail event, and policy decision can be too thin to support remediation.<\/p>\n<p>Process evaluation is particularly important for actions that are later reversed. A final state can look correct even if the agent briefly disclosed information or executed an unnecessary write before compensating, and that intermediate behavior still matters for safety.<\/p>\n<h3>Turn evaluator scores into release gates carefully<\/h3>\n<p>Foundry evaluation can support thresholds and repeated reports, but a release gate should reflect business tolerance rather than an arbitrary target. A threshold that is too low normalizes known failures; a threshold that is too high can block releases because of evaluator noise rather than real risk.<\/p>\n<p>Use <a href=\"https:\/\/www.exam-labs.com\/blog\/llm-evaluation-and-regression-testing-from-benchmark-to-release-gate\">regression testing<\/a> to compare versions on the same cases and slices. Relative degradation can be more actionable than a single absolute score, especially when the evaluator itself is probabilistic.<\/p>\n<p>Gate high-severity risks separately. One severe data-leakage example should not disappear inside an average of hundreds of harmless cases. Report counts and worst-case examples alongside aggregate rates.<\/p>\n<p>Require investigation for new failure clusters even if the overall threshold passes. A model update can introduce a narrow failure mode affecting one language, tool, or customer segment while improving the overall score.<\/p>\n<p>Release gates should store the exact failing examples, not only the score. When a threshold regresses, engineers need representative cases to understand whether the issue is broad policy drift, one evaluator change, or a narrow workflow defect.<\/p>\n<h3>Human review remains necessary for policy nuance<\/h3>\n<p>Model-based evaluators scale coverage but cannot replace policy owners for ambiguous or high-impact judgments. Human reviewers should examine a sample of passes and failures, especially around new policy, edge cases, and severe outcomes.<\/p>\n<p>Calibrate reviewers with shared examples and decision rules. If two reviewers consistently disagree, the policy or expected behavior may be underspecified rather than the agent being uniquely difficult to judge.<\/p>\n<p>Use disagreement as data. It can reveal language that should be clarified in agent instructions, tool approval policy, or evaluator rubric, and it can identify where a binary safety label is too coarse.<\/p>\n<p>Keep reviewers focused on risk evidence instead of writing style. A response can be awkward but safe, or polished but unsafe; evaluation should not let general quality preferences obscure the specific safety claim.<\/p>\n<p>Human calibration sessions should periodically revisit old examples after policy changes. An answer that was acceptable six months ago may no longer match current product rules, and stale labels can make evaluation look stable while governance has changed.<\/p>\n<h3>Production telemetry should feed the next evaluation cycle<\/h3>\n<p>Offline evaluation cannot enumerate every real conversation. Production incidents, near misses, blocked actions, user reports, and unusual tool paths should feed new sanitized test cases so the evaluation set evolves with the system.<\/p>\n<p><a href=\"https:\/\/www.exam-labs.com\/blog\/production-monitoring-for-ai-apps-from-symptom-to-root-cause\">AI monitoring<\/a> helps identify which scenarios deserve replay. A spike in policy blocks or a repeated sequence of failed tool calls can reveal a new safety edge case before it becomes a widely reported incident.<\/p>\n<p>Do not copy raw customer conversations into evaluation datasets without governance. Preserve the mechanism of the failure while removing identities, secrets, and unnecessary business content.<\/p>\n<p>Track whether a regression was fixed by prompt change, tool permission, guardrail configuration, model selection, or product workflow. That history makes future failures easier to diagnose and prevents teams from repeatedly treating systemic issues as prompt tweaks.<\/p>\n<p>Production-derived test cases should include the surrounding conditions that made the failure possible, such as tool availability, user role, retrieved document, or conversation history. Reducing an incident to one isolated prompt can remove the mechanism that actually caused the unsafe behavior.<\/p>\n<h3>A credible safety program is traceable and repeatable<\/h3>\n<p>Safety evaluation is strongest when another engineer can reproduce the claim: which agent version, which model, which tool set, which guardrails, which dataset, which evaluator versions, and which thresholds produced the result. Without that context, a \u201cPASS\u201d label ages quickly.<\/p>\n<p>Store reports with release artifacts and owners. Safety evidence should be available during incident review, audit, and future model migration rather than living only in a portal view that nobody revisits.<\/p>\n<p>For <a href=\"https:\/\/www.exam-labs.com\/blog\/microsoft-ai-agents\">Microsoft AI agents<\/a>, Foundry evaluation provides a managed layer for quality and risk measurement. The engineering team still owns threat modeling, dataset coverage, release policy, and the explicit decision to accept any residual risk that evaluation exposes.<\/p>\n<p>The goal is not a perfect evaluator score. It is a system where unsafe behavior is explicitly defined, tested before release, observable in production, and converted into new evidence when reality exposes a gap.<\/p>\n<p>Risk acceptance should be explicit when a known failure cannot be fixed immediately. Record severity, affected scenarios, temporary mitigations, owner, and review date so a passing aggregate report cannot silently bury an unresolved high-impact issue.<\/p>\n","protected":false},"excerpt":{"rendered":"<p class=\"post__text\">Safety evaluation tests the system behavior, not only the final answer Microsoft Foundry provides risk and safety evaluators for harmful content and agent-specific risks, including prohibited actions and sensitive-data leakage. Agent evaluation extends beyond a final text response because a system can fail through tool selection, data access, or an unsafe action even when the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1029],"tags":[],"class_list":["post-22513","post","type-post","status-publish","format-standard","hentry","category-technology"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Safety evaluation tests the system behavior, not only the final answer Microsoft Foundry provides risk and safety evaluators for harmful content and agent-specific risks, including prohibited actions and sensitive-data leakage. Agent evaluation extends beyond a final text response because a system can fail through tool selection, data access, or an unsafe action even when the\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Allen Rodriguez\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Exam-Labs - Pass Your Certification Exam Easily\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Safety Evaluation in Microsoft Foundry - Exam-Labs\" \/>\n\t\t<meta property=\"og:description\" content=\"Safety evaluation tests the system behavior, not only the final answer Microsoft Foundry provides risk and safety evaluators for harmful content and agent-specific risks, including prohibited actions and sensitive-data leakage. Agent evaluation extends beyond a final text response because a system can fail through tool selection, data access, or an unsafe action even when the\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-10-07T20:29:08+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-10-07T20:29:08+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Safety Evaluation in Microsoft Foundry - Exam-Labs\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Safety evaluation tests the system behavior, not only the final answer Microsoft Foundry provides risk and safety evaluators for harmful content and agent-specific risks, including prohibited actions and sensitive-data leakage. Agent evaluation extends beyond a final text response because a system can fail through tool selection, data access, or an unsafe action even when the\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/safety-evaluation-in-microsoft-foundry#blogposting\",\"name\":\"Safety Evaluation in Microsoft Foundry - Exam-Labs\",\"headline\":\"Safety Evaluation in Microsoft Foundry\",\"author\":{\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/author\\\/admin#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/#organization\"},\"datePublished\":\"2026-10-07T20:29:08+00:00\",\"dateModified\":\"2026-10-07T20:29:08+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/safety-evaluation-in-microsoft-foundry#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/safety-evaluation-in-microsoft-foundry#webpage\"},\"articleSection\":\"Technology\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/safety-evaluation-in-microsoft-foundry#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/category\\\/technology#listItem\",\"name\":\"Technology\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/category\\\/technology#listItem\",\"position\":2,\"name\":\"Technology\",\"item\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/category\\\/technology\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/safety-evaluation-in-microsoft-foundry#listItem\",\"name\":\"Safety Evaluation in Microsoft Foundry\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/safety-evaluation-in-microsoft-foundry#listItem\",\"position\":3,\"name\":\"Safety Evaluation in Microsoft Foundry\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/category\\\/technology#listItem\",\"name\":\"Technology\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/#organization\",\"name\":\"Exam Labs Blog - IT Certifications in Easy Way\",\"description\":\"Pass Your Certification Exam Easily\",\"url\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/author\\\/admin#author\",\"url\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/author\\\/admin\",\"name\":\"Allen Rodriguez\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/safety-evaluation-in-microsoft-foundry#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c3fe64bebd9f43850f9d0596b6003fdf570626ed3ea459dd1696b69cc880ef83?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Allen Rodriguez\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/safety-evaluation-in-microsoft-foundry#webpage\",\"url\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/safety-evaluation-in-microsoft-foundry\",\"name\":\"Safety Evaluation in Microsoft Foundry - Exam-Labs\",\"description\":\"Safety evaluation tests the system behavior, not only the final answer Microsoft Foundry provides risk and safety evaluators for harmful content and agent-specific risks, including prohibited actions and sensitive-data leakage. Agent evaluation extends beyond a final text response because a system can fail through tool selection, data access, or an unsafe action even when the\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/safety-evaluation-in-microsoft-foundry#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/author\\\/admin#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/author\\\/admin#author\"},\"datePublished\":\"2026-10-07T20:29:08+00:00\",\"dateModified\":\"2026-10-07T20:29:08+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/\",\"name\":\"Exam Labs Blog - IT Certifications in Easy Way\",\"description\":\"Pass Your Certification Exam Easily\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.exam-labs.com\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Safety Evaluation in Microsoft Foundry - Exam-Labs","description":"Safety evaluation tests the system behavior, not only the final answer Microsoft Foundry provides risk and safety evaluators for harmful content and agent-specific risks, including prohibited actions and sensitive-data leakage. Agent evaluation extends beyond a final text response because a system can fail through tool selection, data access, or an unsafe action even when the","canonical_url":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry#blogposting","name":"Safety Evaluation in Microsoft Foundry - Exam-Labs","headline":"Safety Evaluation in Microsoft Foundry","author":{"@id":"https:\/\/www.exam-labs.com\/blog\/author\/admin#author"},"publisher":{"@id":"https:\/\/www.exam-labs.com\/blog\/#organization"},"datePublished":"2026-10-07T20:29:08+00:00","dateModified":"2026-10-07T20:29:08+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry#webpage"},"isPartOf":{"@id":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry#webpage"},"articleSection":"Technology"},{"@type":"BreadcrumbList","@id":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.exam-labs.com\/blog\/#listItem","position":1,"name":"Home","item":"https:\/\/www.exam-labs.com\/blog\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.exam-labs.com\/blog\/category\/technology#listItem","name":"Technology"}},{"@type":"ListItem","@id":"https:\/\/www.exam-labs.com\/blog\/category\/technology#listItem","position":2,"name":"Technology","item":"https:\/\/www.exam-labs.com\/blog\/category\/technology","nextItem":{"@type":"ListItem","@id":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry#listItem","name":"Safety Evaluation in Microsoft Foundry"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.exam-labs.com\/blog\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry#listItem","position":3,"name":"Safety Evaluation in Microsoft Foundry","previousItem":{"@type":"ListItem","@id":"https:\/\/www.exam-labs.com\/blog\/category\/technology#listItem","name":"Technology"}}]},{"@type":"Organization","@id":"https:\/\/www.exam-labs.com\/blog\/#organization","name":"Exam Labs Blog - IT Certifications in Easy Way","description":"Pass Your Certification Exam Easily","url":"https:\/\/www.exam-labs.com\/blog\/"},{"@type":"Person","@id":"https:\/\/www.exam-labs.com\/blog\/author\/admin#author","url":"https:\/\/www.exam-labs.com\/blog\/author\/admin","name":"Allen Rodriguez","image":{"@type":"ImageObject","@id":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/c3fe64bebd9f43850f9d0596b6003fdf570626ed3ea459dd1696b69cc880ef83?s=96&d=mm&r=g","width":96,"height":96,"caption":"Allen Rodriguez"}},{"@type":"WebPage","@id":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry#webpage","url":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry","name":"Safety Evaluation in Microsoft Foundry - Exam-Labs","description":"Safety evaluation tests the system behavior, not only the final answer Microsoft Foundry provides risk and safety evaluators for harmful content and agent-specific risks, including prohibited actions and sensitive-data leakage. Agent evaluation extends beyond a final text response because a system can fail through tool selection, data access, or an unsafe action even when the","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.exam-labs.com\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry#breadcrumblist"},"author":{"@id":"https:\/\/www.exam-labs.com\/blog\/author\/admin#author"},"creator":{"@id":"https:\/\/www.exam-labs.com\/blog\/author\/admin#author"},"datePublished":"2026-10-07T20:29:08+00:00","dateModified":"2026-10-07T20:29:08+00:00"},{"@type":"WebSite","@id":"https:\/\/www.exam-labs.com\/blog\/#website","url":"https:\/\/www.exam-labs.com\/blog\/","name":"Exam Labs Blog - IT Certifications in Easy Way","description":"Pass Your Certification Exam Easily","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.exam-labs.com\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"Exam-Labs - Pass Your Certification Exam Easily","og:type":"article","og:title":"Safety Evaluation in Microsoft Foundry - Exam-Labs","og:description":"Safety evaluation tests the system behavior, not only the final answer Microsoft Foundry provides risk and safety evaluators for harmful content and agent-specific risks, including prohibited actions and sensitive-data leakage. Agent evaluation extends beyond a final text response because a system can fail through tool selection, data access, or an unsafe action even when the","og:url":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry","article:published_time":"2026-10-07T20:29:08+00:00","article:modified_time":"2026-10-07T20:29:08+00:00","twitter:card":"summary_large_image","twitter:title":"Safety Evaluation in Microsoft Foundry - Exam-Labs","twitter:description":"Safety evaluation tests the system behavior, not only the final answer Microsoft Foundry provides risk and safety evaluators for harmful content and agent-specific risks, including prohibited actions and sensitive-data leakage. Agent evaluation extends beyond a final text response because a system can fail through tool selection, data access, or an unsafe action even when the"},"aioseo_meta_data":[],"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.exam-labs.com\/blog\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.exam-labs.com\/blog\/category\/technology\" title=\"Technology\">Technology<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tSafety Evaluation in Microsoft Foundry\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.exam-labs.com\/blog\/"},{"label":"Technology","link":"https:\/\/www.exam-labs.com\/blog\/category\/technology"},{"label":"Safety Evaluation in Microsoft Foundry","link":"https:\/\/www.exam-labs.com\/blog\/safety-evaluation-in-microsoft-foundry"}],"_links":{"self":[{"href":"https:\/\/www.exam-labs.com\/blog\/wp-json\/wp\/v2\/posts\/22513","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.exam-labs.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.exam-labs.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.exam-labs.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.exam-labs.com\/blog\/wp-json\/wp\/v2\/comments?post=22513"}],"version-history":[{"count":0,"href":"https:\/\/www.exam-labs.com\/blog\/wp-json\/wp\/v2\/posts\/22513\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.exam-labs.com\/blog\/wp-json\/wp\/v2\/media?parent=22513"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.exam-labs.com\/blog\/wp-json\/wp\/v2\/categories?post=22513"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.exam-labs.com\/blog\/wp-json\/wp\/v2\/tags?post=22513"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}