Skip to main content
Glama

appinsights_set_connection

Idempotent

Securely register the D365 F&O environment's Application Insights / Log Analytics connection for the CURRENT session. The client secret is encrypted in memory (AES-256-GCM), never written to disk and never echoed back. Once set, appinsights_query and appinsights_diagnose_slowness use it automatically until it expires or you call appinsights_clear_connection.

HOW TO GET THE VALUES: workspaceId -- the Log Analytics WORKSPACE ID (GUID, not the App Insights app id) behind the Application Insights resource the environment is linked to (D365FO: System administration > Monitoring and Telemetry parameters > Application Insights Registry tab shows the connection string; the workspace id is on that Log Analytics workspace resource's Overview blade in the Azure Portal). tenantId/clientId/clientSecret -- an Entra ID app registration granted the 'Log Analytics Reader' (or 'Monitoring Reader') role on that workspace resource (Azure Portal > workspace > Access control (IAM) > Add role assignment). Read-only -- no write access is ever needed or used.

In a locked server deployment (APPINSIGHTS_LOCK_SERVER_CONFIG=true) this tool is disabled and the server's own environment credentials are used instead.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
clientIdYesApp registration (client) id (GUID), granted Log Analytics Reader on the workspace.
tenantIdYesEntra (Azure AD) tenant id (GUID).
ttlMinutesNoMinutes the connection stays cached for this session (1-480). Default 60.
workspaceIdYesLog Analytics workspace ID (GUID) behind the linked Application Insights resource.
clientSecretYesApp registration client secret. Encrypted in memory; never logged or persisted.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description goes well beyond annotations by disclosing that the client secret is AES-256-GCM encrypted in memory, never written to disk, never echoed back, and that only read-only permissions are needed/used. It also explains session-scoped lifetime and automatic reuse behavior. No contradiction with annotations was found.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is detailed but well-structured, with the core behavior front-loaded and the credential-procurement guidance separated into a clearly labeled section. Every sentence adds useful information, including the locked-server caveat that directly affects whether the agent should attempt this call.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a session-configuration tool, the description covers the critical setup, reuse, expiry, clearing, and locked-server behavior, along with detailed credential guidance. The only minor gap is that it does not describe the success/error response shape, but with no output schema and a semantically simple setter operation, this is a low-risk omission.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the schema already documents every parameter. The description adds meaningful real-world guidance for sourcing workspaceId and the Entra ID parameters, including the critical distinction between workspace ID and App Insights app ID, plus required roles. However, ttlMinutes receives no extra description-level guidance beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb ('register') and resource ('the D365 F&O environment's Application Insights / Log Analytics connection') and further scopes it to the 'CURRENT session'. It also distinguishes itself from siblings by noting that appinsights_query and appinsights_diagnose_slowness use this connection automatically and that appinsights_clear_connection removes it.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly explains when to use the tool: before querying or diagnosing via Application Insights, and that it remains active until expiry or explicit clearing. It also documents the locked-server deployment scenario where the tool is disabled and server credentials are used instead, which is a clear exclusion/alternative condition.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.