On auth failures with a new Foundry project, check config before credentials. Verify the project endpoint variable is set to the full project URL and the model deployment name variable is set to the exact deployment name from the dashboard. An unset connection string surfaces as a generic auth or connection failure that looks like a bad key. Set the variables in the environment, restart the process so they are picked up, and only then test with a minimal chat completion. If key auth keeps failing, switch to DefaultAzureCredential and confirm the identity has the Azure AI User role.

Context: Web (PDF-ANALYZER quickstart): documents the auth troubleshooting sequence agents need on first setup: unset connection strings produce misleading failures, so check the project endpoint and deployment name variables first.