Skip to main content
Glama
README.md
# azure-mcp-platform

> MCP server for Azure resource management, AI Foundry, and Entra ID — inspect and operate Azure infrastructure through AI agents.

[![Glama Quality Score](https://glama.ai/mcp/servers/akkireddy-challa/azure-mcp-platform/badges/score.svg)](https://glama.ai/mcp/servers/akkireddy-challa/azure-mcp-platform)
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)
[![Python](https://img.shields.io/badge/python-3.11+-blue.svg)](https://www.python.org/)
[![Azure](https://img.shields.io/badge/Azure-MCP-0078D4.svg)](https://learn.microsoft.com/en-us/azure/developer/azure-mcp-server/)
[![MCP](https://img.shields.io/badge/MCP-compatible-green.svg)](https://modelcontextprotocol.io/)

---

## What is this?

`azure-mcp-platform` wraps the [official Azure MCP Server](https://learn.microsoft.com/en-us/azure/developer/azure-mcp-server/) with production-ready configuration, Entra ID authentication, and platform-engineering patterns for operating Azure environments safely from AI agents.

Built for platform engineers running multi-tenant Azure environments with AI Foundry, AKS, and enterprise SSO via Entra ID.

---

## Available Tools

| Tool | Category | Description |
|---|---|---|
| `list_resource_groups` | Resource Mgmt | List all resource groups in a subscription |
| `list_resources` | Resource Mgmt | List resources in a resource group by type |
| `get_resource` | Resource Mgmt | Get details of a specific Azure resource |
| `list_ai_foundry_projects` | AI Platforms | List Azure AI Foundry projects and deployments |
| `get_aks_cluster` | Containers | Get AKS cluster status and node pool health |
| `list_entra_users` | Identity | List Entra ID users and group memberships (read-only) |
| `get_key_vault_secrets` | Security | List secret names (not values) in Key Vault |
| `list_storage_accounts` | Storage | List storage accounts and their access tiers |

---

## Quick Start

### Prerequisites

- Python 3.11+
- Azure CLI authenticated: `az login`
- Appropriate Azure RBAC role: `Reader` minimum
- (Optional) Service principal with `Reader` + `AcrPull` for CI environments

### Run Locally

```bash
git clone https://github.com/akkireddy-challa/azure-mcp-platform.git
cd azure-mcp-platform
pip install -r requirements.txt
az login
python server.py
```

### Configure with Claude Desktop

Add to `claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "azure": {
      "command": "python",
      "args": ["/path/to/azure-mcp-platform/server.py"],
      "env": {
        "AZURE_SUBSCRIPTION_ID": "your-subscription-id",
        "AZURE_TENANT_ID": "your-tenant-id"
      }
    }
  }
}
```

---

## Example Usage

Ask your AI agent:

- *"List all resource groups in my subscription"*
- *"What AKS clusters are running in the production resource group?"*
- *"Show me all AI Foundry projects and their model deployments"*
- *"Which storage accounts in rg-data have public access enabled?"*
- *"List all users in the platform-engineers Entra group"*

---

## Security Model

- **Read-only by default**: all tools use `GET` operations only.
- **Entra ID SSO**: authenticates via Azure CLI credential chain or Managed Identity.
- **No secrets exposed**: Key Vault tool lists secret names only, never values.
- **Subscription-scoped**: tools operate within a single configured subscription.
- **Recommended role**: `Reader` at subscription scope for full read access.

```bash
# Assign Reader role to a service principal
az role assignment create \
  --assignee <service-principal-id> \
  --role Reader \
  --scope /subscriptions/<subscription-id>
```

---

## Use Cases at Telia

This pattern is used to allow AI agents to:

- Audit resource configurations across multi-tenant Azure environments.
- Cross-reference AKS cluster state with AI Foundry model deployments.
- Investigate Entra ID group membership for access reviews.
- Inspect cost anomalies by listing resources and their SKUs.

---

## Roadmap

- [ ] `get_cost_analysis` — query Azure Cost Management for spend by resource group
- [ ] `list_policy_assignments` — show Azure Policy compliance state
- [ ] `get_monitor_alerts` — list active Azure Monitor alerts
- [ ] `list_app_registrations` — Entra ID app registrations and permissions
- [ ] Managed Identity support for AKS pod deployment
- [ ] GitHub Actions workflow for CI validation

---

## Related Projects

| Repo | Purpose |
|---|---|
| [k8s-mcp-server](https://github.com/akkireddy-challa/k8s-mcp-server) | Kubernetes cluster diagnostics via MCP |
| [grafana-mcp-observability](https://github.com/akkireddy-challa/grafana-mcp-observability) | Grafana dashboards and alerts via MCP |
| [phoenix-mcp-eval](https://github.com/akkireddy-challa/phoenix-mcp-eval) | LLM tracing and evaluation via MCP |

---

## License

MIT License. See [LICENSE](LICENSE) for details.

---

Built by [Akkireddy Challa](https://github.com/akkireddy-challa) — Platform Engineer at Telia, Stockholm.

TDQS

A3.7/5.0

Scored across 3 tools

Disambiguation4/5

The three tools are clearly distinct: two Censys operations (search vs. get) and one Azure operation. However, the server name implies an Azure-only platform while including Censys tools, which could mislead an agent about the server's scope, though the tools themselves are unambiguous.

Naming Consistency5/5

All tool names follow a consistent provider_verb_noun pattern (censys_search_hosts, censys_get_host, azure_list_resource_groups), making it predictable and easy to parse.

Tool Count2/5

With only 3 tools spanning two unrelated domains (Censys and Azure), the set feels under-scoped for a 'platform' server. Each domain has minimal coverage, making the count too low for the implied breadth.

Completeness2/5

Censys is limited to host search and host details, missing certificate search, account info, or other common endpoints. Azure only lists resource groups, lacking create/update/delete or any other resource operations. The surface is severely incomplete for both domains.

Maintenance

ActivityMaintained
ResponsivenessNo issues