diff --git a/docs/relational-databases/system-stored-procedures/sp-invoke-external-rest-endpoint-transact-sql.md b/docs/relational-databases/system-stored-procedures/sp-invoke-external-rest-endpoint-transact-sql.md index 959452af06c..cb8a7b54f0a 100644 --- a/docs/relational-databases/system-stored-procedures/sp-invoke-external-rest-endpoint-transact-sql.md +++ b/docs/relational-databases/system-stored-procedures/sp-invoke-external-rest-endpoint-transact-sql.md @@ -251,6 +251,9 @@ Only calls to endpoints for the following services are allowed: | Azure Maps | `*.atlas.microsoft.com` | | Azure AI Translator | `api.cognitive.microsofttranslator.com` | +> [!NOTE] +> Azure AI Foundry resources might expose an endpoint under `*.services.ai.azure.com`, which isn't in the endpoints allow list. Use the corresponding `https://.cognitiveservices.azure.com` endpoint for both the database scoped credential name and the request URL. + [Outbound firewall rules for Azure SQL Database and Azure Synapse Analytics](/azure/azure-sql/database/outbound-firewall-rule-overview) control mechanism can be used to further restrict outbound access to external endpoints. > [!NOTE] diff --git a/docs/t-sql/statements/create-external-model-transact-sql.md b/docs/t-sql/statements/create-external-model-transact-sql.md index 8ecd94ded1d..d1cc4324e31 100644 --- a/docs/t-sql/statements/create-external-model-transact-sql.md +++ b/docs/t-sql/statements/create-external-model-transact-sql.md @@ -200,6 +200,11 @@ The created `DATABASE SCOPED CREDENTIAL` used by an external model must follow t - The credential must point to a path that's more generic than the request URL. For example, a credential created for path `https://northwind.azurewebsite.net/customers` can't be used for the URL `https://northwind.azurewebsite.net`. +> [!NOTE] +> On Azure SQL Database and Azure SQL Managed Instance, the allowed domains for AI endpoints are `*.cognitiveservices.azure.com`, `*.api.cognitive.microsoft.com`, and `*.openai.azure.com`. +> +> Azure AI Foundry resources might expose an endpoint under `*.services.ai.azure.com`, which isn't in the endpoints allow list. Use the corresponding `https://.cognitiveservices.azure.com` endpoint for both the database scoped credential name and the request URL. For the full list, see [Allowed endpoints](../../relational-databases/system-stored-procedures/sp-invoke-external-rest-endpoint-transact-sql.md#allowed-endpoints). + #### Collation and credential name rules [RFC 3986 Section 6.2.2.1](https://www.rfc-editor.org/rfc/rfc3986#section-6.2.2.1) states that "When a URI uses components of the generic syntax, the component syntax equivalence rules always apply; namely, that the scheme and host are case-insensitive." [RFC 7230 Section 2.7.3](https://www.rfc-editor.org/rfc/rfc7230#section-2.7.3) mentions that "all other are compared in a case-sensitive manner."