Azure MCP Server
Allows managing Azure Kubernetes Service (AKS) clusters, including creating clusters, scaling node pools, rotating credentials, and checking cluster health.
Allows creating and managing Azure Database for PostgreSQL Flexible Servers, including validating SKUs, applying naming conventions, and provisioning servers.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Azure MCP ServerWhat's our Azure spend this month by resource group?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Azure MCP Server
Talk to Azure in plain English. This MCP server connects your AI assistant (Claude Code, Cursor, VS Code Copilot) directly to Azure, letting you manage infrastructure through conversation instead of clicking through the Azure Portal or memorizing CLI commands.
25 modules. 202 tools. Every Azure service you need. Zero portal clicks.
Why This Exists
Managing Azure at scale means dozens of teams, hundreds of resource groups, and thousands of resources across multiple subscriptions. Every persona — developer, DevOps engineer, architect, FinOps analyst, IT admin, security engineer — needs Azure access, but the learning curve is steep and the portal is slow.
This MCP server eliminates that friction. Instead of:
Clicking through 8 portal blades to create a VM
Memorizing
azCLI flags for AKS cluster creationWriting ARM/Bicep templates for one-off resources
Manually cross-referencing pricing pages before provisioning
Hunting through Log Analytics for why something broke
You just ask your AI assistant — and it does it, using your own Azure permissions, with org standards enforced automatically.
Related MCP server: MCP Cloud Services Server
What Makes This Valuable
For Developers
Spin up infrastructure in seconds. "Create a PostgreSQL server in westeurope for the payments team dev environment" — it validates naming conventions, applies required tags, checks approved SKUs, and creates the resource.
Debug without context switching. "Why is my VM unreachable?" — the agent checks NSG rules, NIC config, VM status, activity logs, and metrics in one flow.
Get cost estimates before you provision. Every create operation can check Azure Retail Prices first, so you know what you're committing to.
For DevOps / Platform Engineers
Manage AKS clusters conversationally. Scale node pools, rotate credentials, check cluster health — without
kubectlor portal gymnastics.Compare environments. "Show me the differences between rg-payments-dev and rg-payments-prod" — instant resource-by-resource diff.
Track long-running operations. VM creation, AKS provisioning, database migrations — all tracked in the background with status polling.
For FinOps
Cost breakdowns on demand. "What's our spend this month by resource group?" or "Which service is costing us the most?" — instant answers from Cost Management APIs.
Budget management. Create and monitor budgets with alert thresholds, all through conversation.
Find waste. The optimization scanner finds idle VMs, unattached disks, and oversized resources automatically.
For Security Engineers
Security posture at a glance. Secure Score, Defender recommendations, active security alerts, and policy compliance — all in one conversation.
Audit NSG rules. Instantly find overly permissive rules (0.0.0.0/0 on SSH/RDP) across your entire subscription.
Policy compliance. List non-compliant resources and understand what's failing and why.
For IT Admins
Manage VDI environments. Azure Virtual Desktop host pools, session hosts, drain mode, user sessions — full lifecycle management.
App registrations without the portal maze. Create Entra ID app registrations, add client secrets, manage service principals — all through conversation.
Role assignments. Grant and revoke access, list who has what permissions, manage managed identities.
For Architects
Export existing infrastructure as templates. Export any resource group as an ARM template for IaC adoption.
What-if deployment analysis. Test what a template deployment would change before committing.
Architecture reviews. The guided workflow checks tagging, redundancy, security, networking, and cost across an entire resource group.
Real-Life Examples
"I need a new dev environment for the identity team"
You: Create a resource group for the identity team's dev environment in westeurope
Agent: [Checks org naming conventions: must be rg-{team}-{env}-{region}]
[Checks required tags: team, environment, cost-center]
Creating rg-identity-dev-westeurope with tags:
team: identity
environment: dev
cost-center: CC-1234
Done. Resource group created.
You: Now add a PostgreSQL Flexible Server there, Standard_B1ms, version 16
Agent: [Validates SKU against approved list]
[Checks naming conventions]
Creating PostgreSQL server... This is a long-running operation.
Server 'pg-identity-dev-westeurope' creation started. Estimated: ~5 minutes.
Use list_active_operations to check progress."Our staging app is returning 503 errors"
You: /troubleshoot — our App Service 'payments-staging' is returning 503s
Agent: Let me investigate step by step.
1. App status: RUNNING (no obvious crash)
2. Recent activity log: App restarted 3 times in the last hour
3. Metrics: CPU at 95%, memory at 88% — resource exhaustion
4. App settings: WEBSITE_NODE_DEFAULT_VERSION = 14 (outdated)
5. No security alerts.
Findings:
- The app is CPU/memory constrained and restarting repeatedly
- Node.js 14 is EOL — upgrade recommended
Suggested fixes:
1. Scale up the App Service Plan (currently B1 — consider S1 or P1v2)
2. Update Node.js runtime to 18-lts or 20-lts
3. Check for memory leaks in the application code"How much are we spending and where can we save?"
You: /cost-analysis for this month
Agent: [Fetches cost summary, by-resource-group, by-service breakdowns]
Monthly spend so far: $47,230
Top resource groups:
rg-data-prod-westeurope: $12,400 (26%)
rg-payments-prod-eastus: $8,900 (19%)
rg-identity-staging-westeu: $3,200 (7%)
Top services:
Virtual Machines: $18,500 (39%)
Azure Cosmos DB: $11,200 (24%)
AKS: $6,800 (14%)
Running optimization scan...
Found 7 suggestions:
[HIGH] NSG 'nsg-legacy' allows 0.0.0.0/0 on port 22
[MEDIUM] VM 'vm-test-loadgen-01' deallocated for 30+ days — delete?
[MEDIUM] 4 resources missing required tags
[LOW] 3 unattached managed disks (12 GB total) — $2.40/month waste"Set up a new AKS cluster for the media team"
You: Create an AKS cluster for the media team in westeurope, 3 nodes, Standard_D4s_v5
Agent: [Validates VM SKU against approved list: Standard_D4s_v5 is approved]
[Checks naming conventions]
[Estimates cost: ~$438/month for 3x D4s_v5 nodes]
Before I create this, here's the summary:
- Name: aks-media-dev-westeurope
- Region: westeurope
- Nodes: 3x Standard_D4s_v5 (System pool)
- Network: Azure CNI
- Identity: System-assigned managed identity
- Estimated cost: ~$438/month
Shall I proceed?
You: Yes, go ahead
Agent: AKS cluster creation started. This takes ~8-15 minutes.
Tracking ID: op-a1b2c3d4
You: (later) What's the status?
Agent: [Checks operation status]
AKS cluster 'aks-media-dev-westeurope' is now running.
FQDN: aks-media-dev-westeurope-dns-abc123.hcp.westeurope.azmk8s.io"Register a new app for the billing service"
You: Create an Entra ID app registration for the billing service API,
single-tenant, and generate a client secret
Agent: [Creates app registration via Microsoft Graph]
App created:
Display name: billing-service-api
App ID: 12345678-abcd-...
Object ID: 87654321-dcba-...
Sign-in audience: AzureADMyOrg
[Generates client secret]
Secret created:
Key ID: secret-key-id-...
Value: aBcDeFgH...xYz
Expires: 2027-03-31
IMPORTANT: Save this secret now — it cannot be retrieved again.
Next steps:
- Use create_service_principal to create the enterprise app
- Use create_role_assignment to grant it access to Azure resources"Put session hosts in drain mode for patching"
You: List session hosts in the 'hp-engineering' host pool and put the first two in drain mode
Agent: [Lists session hosts]
Session hosts in hp-engineering:
1. sh-eng-01 — Available, 3 active sessions
2. sh-eng-02 — Available, 1 active session
3. sh-eng-03 — Available, 5 active sessions
[Toggles drain mode]
sh-eng-01 is now in drain mode (no new sessions)
sh-eng-02 is now in drain mode (no new sessions)
Existing sessions on these hosts will continue until users log off.
When ready to patch, use disconnect_user_sessions to gracefully disconnect remaining users."Review the security posture of our subscription"
You: /security-review
Agent: [Fetches Secure Score, recommendations, alerts, compliance]
Secure Score: 72/100 (72%)
Top recommendations (by severity):
[HIGH] Enable MFA for all Azure management accounts (3 accounts without MFA)
[HIGH] Restrict SSH access — 5 NSGs allow 0.0.0.0/0 on port 22
[MEDIUM] Enable diagnostic logging on 12 storage accounts
[MEDIUM] Enable Azure Defender for SQL on 3 servers
Active alerts: 1
- Suspicious login attempt from unusual location (medium severity)
Policy compliance: 89% compliant
- 23 resources non-compliant (mainly missing diagnostic settings)
Priority actions:
1. Restrict SSH NSG rules immediately (security risk)
2. Enable MFA on management accounts
3. Enable Defender for SQL (data protection)Quick Start
Prerequisites
Node.js 20+
Azure CLI (
az) for the defaultaz-cliauth mode:macOS:
brew install azure-cli· Windows:winget install --id Microsoft.AzureCLI· Linux: see Install the Azure CLI
An Azure / Entra ID account with RBAC access to the subscriptions you want to manage. Your own role assignments govern what the server can do.
# 1. Clone and build
git clone https://github.com/nickmeron/Azure-MCP-Server.git
cd Azure-MCP-Server
npm install && npm run build
# 2. Add to your MCP client config (see below) — that's it!
# No need to run `az login` or edit config files manually.
# The server handles authentication and setup interactively.With Claude Code you can register it in one command:
claude mcp add azure -- node /full/path/to/Azure-MCP-Server/dist/index.jsFirst Run Experience
When you first use the server, just ask your AI assistant anything about Azure. If you're not authenticated yet, the setup tool will:
Automatically open your browser for Azure login (via
az login) — no credentials in chatDiscover your tenants — if you have one, it auto-selects it; if multiple, it asks you to pick
Discover your subscriptions — same: auto-select if one, ask if multiple
Save everything to
config.yaml— next time you restart, it just works
You: List my Azure resource groups
Agent: No subscription configured yet. Let me run setup.
[Calls setup tool]
Opening browser for Azure login...
Authenticated successfully.
Auto-selected tenant: Contoso (abc-123-...)
Found 3 subscriptions:
- Contoso Production: sub-111
- Contoso Staging: sub-222
- Contoso Dev: sub-333
Which subscription should I use as default?
You: Use Contoso Dev
Agent: [Calls setup with subscriptionId: "sub-333"]
Default subscription set to: Contoso Dev (sub-333) — saved to config.yaml
Setup complete! Now let me get those resource groups...After setup, you can switch tenants anytime with switch_tenant or subscriptions with set_subscription. All changes are saved automatically.
MCP Client Configuration
Claude Code (~/.claude.json or project .mcp.json)
{
"mcpServers": {
"azure": {
"command": "node",
"args": ["/path/to/Azure-MCP-Server/dist/index.js"]
}
}
}VS Code (Copilot MCP)
{
"mcp": {
"servers": {
"azure": {
"command": "node",
"args": ["/path/to/Azure-MCP-Server/dist/index.js"]
}
}
}
}Cursor
{
"mcpServers": {
"azure": {
"command": "node",
"args": ["/path/to/Azure-MCP-Server/dist/index.js"]
}
}
}How It Works
Dynamic Tool Loading
With 202 tools across 25 modules, loading everything at once would eat the LLM's context window. Instead, the server uses a two-tier system:
Tier 1 (always loaded, ~19 tools): Core navigation and discovery — setup, auth, subscriptions, list resources, Resource Graph queries, tool discovery, LRO tracking.
Tier 2 (loaded on demand, ~183 tools across 23 modules): Service-specific tools that the agent loads only when needed.
The agent calls discover_tools to browse what's available, then get_module_tools("compute") to load a specific module. This keeps context usage at ~30K tokens instead of ~200K.
Authentication — Fully Interactive
Authentication is seamless. The setup tool detects whether you have an active Azure session and, if not, automatically opens your browser for Azure login. No credentials ever pass through the chat — authentication happens directly between your browser and Azure's login page.
Mode | How | Best For |
| Auto-detects | Everyone (recommended) |
| Opens browser for Entra ID login directly | Alternative to az-cli |
| Prints code for aka.ms/devicelogin | SSH/remote sessions |
| Azure-assigned identity | Container Apps deployment |
| Client ID + secret | CI/CD pipelines |
Tokens are cached and encrypted via the OS keychain. After first login, you won't be prompted again for weeks. Tenant and subscription selections are saved to config.yaml automatically.
RBAC — Zero Custom Authorization
We never implement our own authorization. Your Entra ID identity carries your Azure RBAC assignments. If you don't have permission, Azure returns 403 and we surface a helpful message telling you which role you need.
Long-Running Operations
Azure operations like VM creation or AKS provisioning can take minutes. The server tracks these in the background:
Starts the operation, returns immediately with a tracking ID
Polls Azure in the background every 15 seconds
Agent can check status anytime via
list_active_operationsorget_operation_statusOperations can be cancelled via
cancel_operation
Org Knowledge & Guardrails
The server enforces your organization's standards automatically. They live in knowledge/*.yaml — the shipped files are examples, so edit them to match your own conventions (or point orgKnowledge in config.yaml at your own files):
Naming conventions: Resource groups must match
rg-{team}-{env}-{region}, VMs must matchvm-{team}-{purpose}-{env}-{index}, etc.Required tags: Every resource must have
team,environment, andcost-centertags.Approved SKUs: Only pre-approved VM sizes and storage SKUs can be used for creation.
Destructive operation confirmation: Deletes, role assignments, and other dangerous operations require explicit confirmation.
Production protection: Resources tagged
env=productioncannot be deleted even with confirmation.
Complete Feature Reference
Infrastructure Management
Capability | Tools | What You Can Do |
Subscriptions & Resource Groups |
| Navigate your Azure estate, create resource groups with enforced naming and tagging, switch between subscriptions |
Generic ARM |
| CRUD any Azure resource by ARM ID, run Resource Graph KQL queries across all subscriptions |
Virtual Machines |
| Full VM lifecycle — create with SKU validation and cost estimation, power operations, resize, instance view |
Storage |
| Storage accounts (name validation, HTTPS-only, TLS 1.2), blob containers |
Networking |
| VNets, subnets, NSGs with security rules, public IPs, NICs, VNet peering, private endpoints, private DNS zones with VNet linking |
Platform Services
Capability | Tools | What You Can Do |
Kubernetes (AKS) |
| Create clusters with networking config, scale node pools, download kubeconfig |
Containers (ACI/ACR) |
| Run containers on ACI, manage container registries, list image repositories |
App Service |
| Web apps, function apps, power operations, app settings management (sensitive values masked), deployment slot swaps |
Databases |
| Azure SQL, PostgreSQL Flexible Server, Cosmos DB — full server and database lifecycle |
Key Vault |
| Vault management, secret CRUD (values shown only on create), key listing |
Service Bus |
| Messaging namespaces, queues, topics, and subscriptions |
API Management |
| APIM instances, APIs, products, subscription keys |
CDN / Front Door |
| CDN and Front Door profiles, endpoints, cache purging |
AI Services |
| Azure OpenAI and Cognitive Services accounts, GPT/embedding model deployments |
Identity & Security
Capability | Tools | What You Can Do |
IAM (Role Assignments) |
| View and manage who has access to what, browse built-in and custom roles |
Managed Identities |
| User-assigned identities, workload identity federation (GitHub Actions, AKS), enable/disable system-assigned identity on any resource |
App Registrations (Entra ID) |
| Full app registration lifecycle via Microsoft Graph — create apps, generate secrets, manage service principals |
Entra ID (Directory & Sign-ins) |
| Look up users and groups (including transitive memberships), resolve object IDs from role assignments, read sign-in logs and Conditional Access policies via Microsoft Graph |
Security (Defender) |
| Defender for Cloud Secure Score, security recommendations by severity, active security alerts |
Policy & Compliance |
| Azure Policy assignments, compliance summaries, non-compliant resource details |
Observability & FinOps
Capability | Tools | What You Can Do |
Monitoring |
| Run KQL against Log Analytics and Application Insights, discover and query resource metrics, list metric/log alert rules and action groups, inspect diagnostic settings, view who-did-what in activity logs |
Cost Management |
| Cost breakdowns by resource group and service, budget creation with email alert thresholds |
Pricing & Research |
| Look up retail prices for any Azure service/SKU/region, estimate VM monthly costs, check quota usage, find Microsoft Learn guidance on any Azure topic |
VDI & Specialized Services
Capability | Tools | What You Can Do |
Azure Virtual Desktop |
| Full AVD lifecycle — host pools (personal/pooled), session host management with drain mode, app groups (Desktop/RemoteApp), workspaces, registration tokens for joining new hosts |
Backup & Recovery |
| Recovery Services vaults, protected items inventory, recovery point browsing |
Automation |
| Automation accounts, runbook execution with parameters, job status and output |
Advanced Capabilities
Capability | Tools | What You Can Do |
Template Export |
| Export any resource group as an ARM template for IaC adoption |
What-If Analysis |
| Preview what an ARM template deployment would create, modify, or delete — without actually deploying |
Environment Comparison |
| Side-by-side diff of two resource groups — find resource type mismatches, missing resources, configuration drift between dev/staging/prod |
Optimization Scanner |
| Automated scan for idle VMs, unattached disks, overly permissive NSG rules, missing required tags |
Org Standards |
| Query your org's naming conventions, approved SKUs, and required tags (from |
Guided Workflows (MCP Prompts)
Prompt | What It Does |
| Step-by-step guided deployment: checks org standards, estimates costs, validates SKUs, creates the resource, verifies success |
| Systematic debugging: checks resource status, activity logs, metrics, NSGs, security alerts, then suggests fixes |
| FinOps deep-dive: total spend, breakdown by resource group and service, budget status, optimization opportunities |
| Security posture review: Secure Score, Defender recommendations, active alerts, policy compliance, non-compliant resources |
| Diagnose AADSTS sign-in errors (e.g. Conditional Access blocks, MFA required): checks the user, sign-in logs, CA policies, group memberships, and role assignments, then pinpoints the fix |
| Well-Architected Framework assessment: tags, redundancy, security config, networking, backup, cost efficiency |
Configuration
Edit config.yaml in the project root:
server:
transport: stdio # stdio (local) or http (shared server)
logLevel: info
auth:
mode: az-cli # browser | az-cli | device-code | managed-identity | service-principal
tenantId: "your-tenant-id"
azure:
defaultSubscriptionId: "your-sub-id"
allowedSubscriptionIds: [] # empty = all subscriptions the user has access to
blockedResourceGroups: # prevent accidental ops on shared infra
- "rg-production-core"
- "rg-networking-hub"
modules:
enabled: [] # empty = all modules available
disabled: [] # explicitly disable specific modules
guardrails:
requireConfirmationFor:
- "delete_*"
- "arm_delete_resource"
- "create_role_assignment"
blockDestructiveOnProduction: true
maxResultsDefault: 50
orgKnowledge:
namingConventions: "./knowledge/naming-conventions.yaml"
approvedSkus: "./knowledge/approved-skus.yaml"
requiredTags: "./knowledge/required-tags.yaml"
audit:
enabled: true
destination: console # console | file | bothEnvironment variables override config.yaml: AZURE_TENANT_ID, AZURE_SUBSCRIPTION_ID, AUTH_MODE, TRANSPORT, LOG_LEVEL. See .env.example for the full list.
setup,switch_tenant, andset_subscriptionwrite your tenant and subscription IDs intoconfig.yaml. If you fork this repo, avoid committing those local values.
MCP Resources (Read-Only Data)
URI | Description |
| Org naming conventions, approved SKUs, required tags |
| Current server configuration (non-sensitive) |
| Full module and tool catalog with load status |
Development
npm run build # Compile TypeScript
npm run dev # Watch mode
npm test # Run tests
npm run typecheck # Type check without buildingSee docs/ADDING_MODULES.md for how to add new Azure service modules.
Security Model
Authentication: All auth via
@azure/identitycredential chain — no hardcoded credentials anywhere. Tokens cached and encrypted via OS keychain.Authorization: Azure RBAC enforced natively. We never implement custom authorization. If you don't have permission, Azure returns 403 and we tell you which role you need.
Audit logging: Every tool invocation logged with timestamp, tool name, parameters (secrets masked), subscription ID, duration, and status. Sensitive fields (
password,secret,key,connectionString,token) are automatically redacted.Guardrails: Destructive operations require explicit confirmation. Production resource groups (tagged
env=production) are protected from deletion. Subscription allowlisting prevents cross-tenant accidents.Org standards enforcement: Naming conventions, required tags, and approved SKUs are validated on every create operation. Non-compliant requests are rejected with clear guidance.
License
This server cannot be deployed
Maintenance
Related MCP Connectors
Your AI Agent's Infrastructure Layer. Connect Claude, Copilot, Codex, or ChatGPT to 200+ managed open source services. Start databases, pipelines, and applications through natural language.
Connect AI assistants to GitHub - manage repos, issues, PRs, and workflows through natural language.
- mcpOAuthcom.vibgrate
Query your team's drift, vulnerability, and upgrade data from any AI assistant. OAuth 2.1, 51 tools.
Deploy, monitor, and manage your OpenClaw AI assistants via natural language.
Related MCP Servers
- AlicenseBqualityDmaintenanceEnables natural language exploration of Azure environments by generating and executing KQL queries against Azure Resource Graph. Supports multi-tenant configurations, subscription scoping, and provides direct access to Azure resource information through conversational interactions.82Apache 2.0
- AlicenseCqualityDmaintenanceEnables AI assistants to manage multi-cloud resources (AWS, Azure, GCP) including resource operations, cost analysis, monitoring metrics, and security compliance checks through natural language commands.263 npm2MIT
- AlicenseBqualityDmaintenanceEnables intelligent interaction with Azure resources through natural language by translating requests into safe, auditable Azure CLI commands with plan/review workflows and direct access to 8 Azure services including Storage, Cosmos DB, Key Vault, and more.31MIT
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to interact with Azure DevOps to manage work items, Git repositories, branches, commits, and projects through natural language commands.863 npm5MIT