Azure OpenAI Service and models sold by Azure in Microsoft Foundry
Microsoft states prompts and completions are not used to train, retrain or improve the base models and are not available to the model providers. Data at rest stays in the customer designated geography. Flagged content may be read by authorised Microsoft employees unless the customer is approved for modified abuse monitoring, which is limited to account managed customers.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AVD-2026-0014
- Kind
- API and platform
- Jurisdiction
- United States
- Last verified
- Added
- The models are stateless, no prompts or completions are stored in the model, and prompts and completions are not used to train, retrain or improve the base models.
- Prompts and completions are not available to OpenAI or other providers of models sold by Azure.
- Data stored at rest, including the abuse monitoring data store, is held in the customer designated geography.
- Human reviewers are authorised Microsoft employees using secure access workstations and just in time approval, and are located in the European Economic Area for deployments there.
Dimension by dimension
10 dimensions, each one stated, silent or open
Used for training by default, Retention period, Deletion on request, Storage region and residency, Subprocessor list published, Human review of content, Opt out available, DPA available, Persistent memory across sessions, Last change to the terms. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- Used for training by defaultStated
- No. Prompts, completions, embeddings and training data are not used to train generative AI foundation models without your permission or instruction.Microsoft Learn, data, privacy and security for Foundry models sold by Azure, primary source, 5 June 2026.
- Retention periodSilent
- The current pages print no number of days. They describe a stateless model and an abuse monitoring data store for flagged content without stating how long it is held.Microsoft Learn, data, privacy and security for Foundry models sold by Azure, primary source, 5 June 2026.
- Deletion on requestStated
- Stored data and fine tuned models can be deleted by the customer at any time.Microsoft Learn, data, privacy and security for Foundry models sold by Azure, primary source, 5 June 2026.
- Storage region and residencyStated
- Processing is in the customer geography for standard deployments, anywhere within the zone for data zone deployments, and data at rest stays in the customer designated geography.Microsoft Learn, data, privacy and security for Foundry models sold by Azure, primary source, 5 June 2026.
- Subprocessor list publishedStated
- Model providers are named and walled off. Prompts and completions are not available to OpenAI or to other providers of models sold by Azure.Microsoft Learn, data, privacy and security for Foundry models sold by Azure, primary source, 5 June 2026.
- Human review of contentStated
- Review is automated by default, and human review is an escalation by authorised Microsoft employees using secure access workstations and just in time approval.Microsoft Learn, data, privacy and security for Foundry models sold by Azure, primary source, 5 June 2026.
- Opt out availableStated
- Modified abuse monitoring removes the storage and human review, and it is an application gated on limited access eligibility for account managed customers.Microsoft Learn, abuse monitoring, primary source, 5 June 2026.
- DPA availableStated
- The Microsoft Products and Services Data Protection Addendum is named as the instrument governing data processing for these models.Microsoft Learn, data, privacy and security for Foundry models sold by Azure, primary source, 5 June 2026.
- Persistent memory across sessionsStated
- Statefulness is opt in per feature. The responses API, assistants threads and stored completions each create a data store the customer configures.Microsoft Learn, data, privacy and security for Foundry models sold by Azure, primary source, 5 June 2026.
- Last change to the termsStated
- The page carries a document date of 18 May 2026 and a last update of 5 June 2026, and its own change log names 3 October 2025 as the most recent substantive revision.Microsoft Learn, data, privacy and security for Foundry models sold by Azure, primary source, 5 June 2026.
What it changes
For a buyer or a workplace AI policy
The widely repeated thirty day abuse retention figure is not on Microsoft's current pages. They were reachable and simply do not print a duration, which makes this an absent facet rather than a disputed one. If your risk register carries thirty days for this service, it is carrying a number the vendor no longer publishes, and the right move is to get the period in writing from your account team rather than to keep citing a document that does not say it.
Sources
What this record was verified against
- Microsoft Learn, data, privacy and security for Foundry models sold by AzurePrimary · 5 June 2026
- Microsoft Learn, abuse monitoringPrimary · 5 June 2026
Related
Records that sit beside this one
Microsoft 365 Copilot, now named Microsoft Copilot
United States · verified 15 September 2026
Prompts, responses and data accessed through Microsoft Graph are not used to train foundation large language models.
The OpenAI API and platform
United States · verified 15 September 2026
The platform guide states that as of 1 March 2023, data sent to the OpenAI API is not used to train or improve OpenAI models.
Does zero data retention survive an abuse investigation?
Global · verified 15 September 2026
OpenAI states a flagged image is retained for manual review even where zero data retention, modified abuse monitoring or eyes off is enabled.
Amazon Bedrock
United States · verified 15 September 2026
Amazon Bedrock uses a zero data retention security model, so by default it does not store model inputs or outputs.
GitHub Copilot Business and Enterprise
United States · verified 15 September 2026
GitHub states it does not use Copilot Business or Copilot Enterprise customer data to train AI models.
Cursor and its privacy mode
United States · verified 15 September 2026
The terms of service state that Cursor will not use content to train any AI models unless you have explicitly agreed.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AVD-2026-0014 is permanent and is never reused.
- In a sentence
- According to the GAGE AI Vendor Data Ledger (as of 15 September 2026), azure openai service and models sold by azure in microsoft foundry.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Azure OpenAI Service and models sold by Azure in Microsoft Foundry. AI Vendor Data Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0014-azure-openai-foundry-models
- MLA
- "Azure OpenAI Service and models sold by Azure in Microsoft Foundry." AI Vendor Data Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0014-azure-openai-foundry-models.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Azure OpenAI Service and models sold by Azure in Microsoft Foundry." AI Vendor Data Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0014-azure-openai-foundry-models.
- Permalink
- https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0014-azure-openai-foundry-models
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any terms change a vendor announces.
Back to the full ledger, or every record for United States and every api and platform record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.