Azure NeuroMap MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| NEUROMAP_HOME | No | Directory where snapshots and maps are stored. Defaults to `~/.neuromap`. Treat that folder as sensitive and do not commit it. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| scan_infrastructureA | Scan Azure (read-only) and rebuild the graph: every resource, resource groups, RBAC role assignments, and access settings. Uses DefaultAzureCredential (az login, managed identity, env vars). Needs Reader. subscription_ids: limit the scan; omit to scan every enabled subscription visible. enrich: also read child settings Resource Graph lacks (SQL/PostgreSQL/MySQL/Redis firewall rules, App Service access restrictions, Service Bus/Event Hubs network rules). Without it those verdicts are 'unknown'. |
| infra_summaryB | Counts by resource kind and relationship, scan time, subscriptions, unattached NSGs and public IPs. |
| find_resourceA | Find nodes by full resource id, IP address (private or public), exact or partial name. kind filters results: network kinds (vnet, subnet, nsg, nic, vm, vmss, pip, pe, lb, appgw, firewall, fwpolicy, wafpolicy, ipgroup, vnetgw, lng, ercircuit, gwconnection, ...), data/PaaS kinds (storage, keyvault, sql-server, sql-db, sql-mi, postgres, mysql, cosmos, webapp, aks, acr, redis, servicebus, eventhub, cognitive, search, uami), or the short type of any other resource (e.g. 'logic/workflows'). For an IP, declared ranges containing it are also returned (subnets, on-premises ranges from local network gateways, point-to-site pools). |
| get_nodeB | Full detail of one node plus everything linked to it, up to depth 3. ref: resource id, IP or unique name. Relationships include CONTAINS, IN_SUBNET, PROTECTED_BY, HAS_NIC, HAS_PUBLIC_IP, PEERED_WITH, ROUTES_VIA, EGRESS_VIA, CONNECTS_TO, MEMBER_OF, BALANCES_TO, USES_POLICY, VNET_INTEGRATION, HOSTED_ON, USES_IDENTITY, MANAGED_BY, HAS_ROLE, OPEN_TO_ALL_NETWORKS, VNET_RULE_ALLOWS, IP_RULE_ALLOWS, and REFERENCES (any other ARM id found in properties, with its exact property path). |
| nsg_rules_forA | Every NSG layer on a VM, NIC, private endpoint, public IP or subnet, in Azure evaluation order. Inbound shows subnet NSG then NIC NSG. Outbound shows NIC NSG then subnet NSG. Rules are sorted by priority, default rules included. |
| search_nsg_rulesA | Search NSG rules across the whole estate, with what each NSG is attached to. port: destination port, matched against single ports, ranges and '*'. source/destination: a CIDR or IP (overlap match), a service tag like 'VirtualNetwork', or 'internet' to match Internet, *, 0.0.0.0/0 and ::/0. access: Allow or Deny. direction: Inbound or Outbound. protocol: Tcp, Udp, Icmp. |
| get_accessB | Network access verdict for one resource (SQL, Storage, Key Vault, Cosmos, App Service, AKS, ACR, Redis, PostgreSQL, MySQL, Service Bus, Event Hubs, AI services, Search, ...). Returns public_endpoint (disabled | vnet_injected | restricted | all_networks | ...),
|
| list_public_exposureA | List resources by public-endpoint verdict. Default: all_networks and all_networks_with_denies. states: any of disabled, vnet_injected, restricted, all_networks, all_networks_with_denies, enabled_no_allow_rules, gated_by_nsg, perimeter_controlled, no_inbound_endpoint, decided_per_app, unknown, not_evaluated. kind: e.g. storage, keyvault, sql-server, webapp, cosmos, aks, acr, redis, disk, containerapp, aca-env, logicapp, loganalytics, appinsights, dce, automation, purview. |
| who_has_accessB | Active Azure RBAC role assignments that apply to a resource: on the resource, its parent resources, its resource group, subscription, management groups and root, marked inherited or direct. scope_coverage says per scope whether assignments were collected (a scope that was not collected is unknown, never zero). Each assignment has capabilities computed from the role definition's actions/notActions: assign_roles, write_resource, delete_resource. Also returns data-plane auth facts (Key Vault access policies, SQL Entra admin, ...). |
| identity_permissionsC | What a resource's system-assigned and user-assigned managed identities hold: roles and scopes. |
| firewall_rulesB | Azure Firewall (or Firewall Policy) rules in processing order: DNAT, network, application. Parent-policy rule collection groups come first. IP groups are expanded. Includes threat intel, IDPS and DNS proxy settings, and classic (non-policy) rules. Missing policy data is listed as unknown. |
| search_firewall_rulesB | Search every firewall's effective rules. port: destination port (ranges and '*' match). source/destination: IP, CIDR, service tag or 'internet' (matches *, 0.0.0.0/0). fqdn: matched against target FQDN patterns (wildcards honored). action: Allow, Deny or DNAT. rule_type: dnat, network or application. |
| ingress_pathsA | Every declared ingress path: firewall DNAT (with allowed sources), public load balancer rules and inbound NAT rules, App Gateway listener -> backend routes (with effective WAF mode), and public IPs attached directly to NICs. target: limit to paths into or through one resource (VM, NIC, firewall, LB, App Gateway, IP). port: limit to a frontend port. include_private: also show internal LB / private App Gateway listeners. |
| route_forB | User-defined routes that apply to a subnet, NIC, VM, VMSS or subnet-injected service, with each VirtualAppliance next hop resolved to the resource that owns that IP (firewall, NVA, internal LB), or to an explicit 'ip:x' node when no scanned resource owns it. |
| hybrid_connectivityB | VPN and ExpressRoute: each gateway with its VNet, SKU, BGP and point-to-site settings, its connections (type, status, BGP) and remote side (on-prem ranges, gateway IP, ER peerings), and the spoke VNets that use it through peering. |
| export_mapA | Write the interactive offline 'neurosystem' HTML map of the current snapshot and return its path. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| map_my_infra | |
| access_review | |
| internet_ingress_review | |
| explain_resource |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| summary | Summary of the latest snapshot |
TDQS
Scored across 16 tools
Most tools have distinct scopes (find/get, scan/summary/export, per-resource vs estate-wide searches). A few pairs overlap conceptually—nsg_rules_for vs search_nsg_rules, firewall_rules vs search_firewall_rules, and who_has_access vs identity_permissions—but descriptions clarify per-resource vs global/bulk and RBAC vs managed-identity scopes.
All names use lowercase snake_case consistently, which is the dominant pattern. Minor deviations exist: some are verb-first (scan_infrastructure, find_resource, get_node), others noun-first (infra_summary, firewall_rules, ingress_paths), and who_has_access is a question phrase, but the set remains readable and predictable.
16 tools is slightly above the ideal 3–15 range but still well-scoped for a comprehensive Azure network graph and security analysis server. Each tool appears to cover a distinct analysis need, with no obvious filler.
The surface covers scanning, resource lookup, NSG/firewall rule analysis, routes, hybrid connectivity, RBAC/identity permissions, access verdicts, public exposure, and map export—strong coverage for read-only infrastructure analysis. Minor gaps like snapshot comparison or private DNS zone specifics are not fatal but leave some adjacent lifecycle concerns uncovered.