Ask any enterprise team standing up Microsoft Foundry in production and you’ll hear the same non-negotiable: the agent can’t run on the open internet. The moment it touches proprietary data, internal APIs, or regulated workloads, security wants it inside the company’s own virtual network — behind private endpoints, a central firewall, and controlled DNS. That configuration — a Foundry Standard Agent injected into a Bring-Your-Own (BYO) VNet — is the topology most large organizations actually ship to production.