diff --git a/docs/relational-databases/system-stored-procedures/sp-invoke-external-rest-endpoint-transact-sql.md b/docs/relational-databases/system-stored-procedures/sp-invoke-external-rest-endpoint-transact-sql.md index 959452af06c..03fde95843b 100644 --- a/docs/relational-databases/system-stored-procedures/sp-invoke-external-rest-endpoint-transact-sql.md +++ b/docs/relational-databases/system-stored-procedures/sp-invoke-external-rest-endpoint-transact-sql.md @@ -251,6 +251,9 @@ Only calls to endpoints for the following services are allowed: | Azure Maps | `*.atlas.microsoft.com` | | Azure AI Translator | `api.cognitive.microsofttranslator.com` | +> [!NOTE] +> Azure AI Foundry resources might also expose an endpoint under `services.ai.azure.com` (for example, `https://.services.ai.azure.com`), but that domain isn't in the allowed endpoints list. Use the corresponding `https://.cognitiveservices.azure.com` endpoint for both the database scoped credential name and the request URL. + [Outbound firewall rules for Azure SQL Database and Azure Synapse Analytics](/azure/azure-sql/database/outbound-firewall-rule-overview) control mechanism can be used to further restrict outbound access to external endpoints. > [!NOTE]