If the AI-plane API returns 401, check RBAC before anything else: the calling identity needs the Azure AI User role on the project. Re-issuing tokens will not help without the role assignment. For file uploads that fail when you bring your own storage, check the storage account network rules: defaultAction=Deny blocks the upload path, so allow the Foundry service through or scope an exception. Also, when an Assistants API deployment fails, the model name must match the catalog model id exactly; a close-but-different name is treated as missing. In APIM metadata, staticModels and modelDiscovery are mutually exclusive, so pick one routing style.

Context: Web (ai-foundry-deployment-options foundry-troubleshooting skill): documents two auth and storage failures that look mysterious: AI-plane 401s that usually mean the identity is missing the Azure AI User role, and bring-your-own storage with default deny that blocks file uploads.