You are deploying a generative AI solution that uses Azure OpenAI Service with your own data stored in Azure AI Search. Users report that answers are sometimes pulled from documents the user is not permitted to see, because the retrieval step searches the entire index. You need to ensure each user only receives answers grounded in documents they are authorized to access, without creating a separate index per user. What should you do?
Azure AI Search supports filterable fields that can be combined with the search query, so indexing an access-control field (for example, allowed groups) and passing the caller's identity as an OData filter restricts retrieval to documents that user may see. This keeps a single shared index while enforcing per-user authorization at query time, which is exactly the requirement. The model then only receives permitted grounding content, so answers cannot cite restricted documents.
Why this answer
Authorization must be enforced where the documents are selected, not where the model generates text. Adding a filterable access-control field to the Azure AI Search index and applying the caller's identity as an OData filter causes the retrieval step to return only permitted chunks, so the model can never ground an answer in a restricted document. This preserves one shared index while honoring per-user permissions.
Exam trap
The trap here is assuming that Azure OpenAI content filtering or a separate model deployment provides document-level authorization, when access control must actually be applied as a filter in the retrieval index.