Skip to main content
Tools Reference

Microsoft Azure Tools

Written By Christopher Scaminaci

Last updated 7 days ago

Microsoft Azure Tools

azure_ · 545 tools · Free 304 · Pro 241Azure Resource Manager management plane, plus Log Analytics queries. You sign in with your own Microsoft work account, on StackJack's application or your organization's own registration, and Azure authorizes every call against your own RBAC - a 403 usually names your role rather than a connector fault. Each tool pins the api-version its resource provider needs. Pass entraTenant to act in a customer directory you administer. Paging follows ARM's nextLink as sent, and a multi-page walk stops at 1000 items or 10 pages; Resource Graph pages with its own skip token instead. Long-running writes answer 202 and nothing here polls them, so confirm the outcome by re-reading the resource. Key Vault coverage is vaults, policies and key or secret metadata only, never secret values; sovereign clouds and classic resources are out of scope.

All connector tools · Microsoft Azure setup guide

Microsoft Azure tool groups

Subscriptions

ToolPlanAccessSummary
azure_get_resource_providerFreeRead-onlyGet one resource provider's registration state and the full resourceTypes list it exposes in a subscription, including each type's supported locations and apiVersions.
azure_get_subscriptionFreeRead-onlyGet one Azure subscription's details: subscriptionId, displayName, state, tenantId, authorizationSource (the mechanism granting access, e.g. RoleBased or Legacy), managedByTenants (the partner…
azure_list_locationsFreeRead-onlyList the Azure regions available to a subscription.
azure_list_resource_providersFreeRead-onlyList the Azure resource providers in a subscription and their registration state.
azure_list_subscriptionsFreeRead-onlyList the Azure subscriptions the signed-in user can see — the ENTRY POINT for this connector.
azure_list_tenantsFreeRead-onlyList the Microsoft Entra directories (tenants) the signed-in user can access — their own plus every customer directory they hold a delegated relationship with.
azure_register_resource_providerProWriteRegister a resource provider in a subscription, making its resource types deployable there.
azure_unregister_resource_providerProDestructiveUnregister a resource provider from a subscription.

[Microsoft Azure] Get one resource provider's registration state and the full resourceTypes list it exposes in a subscription, including each type's supported locations and apiVersions. Useful for confirming a resource type is available in the region you intend to deploy to before a create fails.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
providerNamespacestringyesThe provider namespace, e.g. Microsoft.Compute — from azure_list_resource_providers.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one Azure subscription's details: subscriptionId, displayName, state, tenantId, authorizationSource (the mechanism granting access, e.g. RoleBased or Legacy), managedByTenants (the partner directories with delegated access — how you confirm a GDAP relationship exists) and subscriptionPolicies including its quota id and spending limit. Requires a subscription id from azure_list_subscriptions.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
subscriptionIdstringyesThe subscription id (a GUID), from azure_list_subscriptions.

[Microsoft Azure] List the Azure regions available to a subscription. Each item carries name (the value every create/update tool wants, e.g. eastus), displayName, regionalDisplayName, metadata (regionType Physical | Logical, regionCategory Recommended | Other, geographyGroup, physicalLocation, pairedRegion) and availabilityZoneMappings. Use it before creating a resource group or any regional resource — a region name that is valid in one subscription can be unavailable in another.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the Azure resource providers in a subscription and their registration state. Each item carries namespace (e.g. Microsoft.Compute), registrationState (Registered | NotRegistered | Registering | Unregistered) and resourceTypes with their locations and apiVersions. This is the tool to reach for when a create call fails with NoRegisteredProviderFound or MissingSubscriptionRegistration: the provider is simply not registered in that subscription yet, and azure_register_resource_provider fixes it.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the Azure subscriptions the signed-in user can see — the ENTRY POINT for this connector. Each item carries subscriptionId, displayName, state (Enabled | Warned | PastDue | Disabled | Deleted), tenantId and subscriptionPolicies. The subscriptionId returned here is required by nearly every other azure_* tool. Pass entraTenant to enumerate a CUSTOMER's subscriptions under your GDAP relationship instead of your own — CSP-provisioned customer subscriptions normally place the partner's Admin Agents group in the Owner role, so an MSP user usually has real access there. An EMPTY result is a valid answer, not an error: it means the user has consented but holds no Azure RBAC in the directory. Returns ARM's {value:[...]} envelope; up to 1000 items across 10 pages per call, with nextLink returned when more remain.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in — its tenant GUID or a verified domain such as contoso.onmicrosoft.com. Omit to use your own directory.

[Microsoft Azure] List the Microsoft Entra directories (tenants) the signed-in user can access — their own plus every customer directory they hold a delegated relationship with. Each item carries tenantId, displayName, domains, tenantCategory (Home | ProjectedBy | ManagedBy) and countryCode. Use this to DISCOVER the tenantId values to pass as entraTenant elsewhere; tenantCategory ManagedBy identifies a customer you administer. Pairs with graph_list_delegated_admin_customers on the Microsoft Graph connector, which reports the GDAP relationship's roles and expiry.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory — which is what you almost always want here, since this tool is how you find the others.

[Microsoft Azure] Register a resource provider in a subscription, making its resource types deployable there. This is ADDITIVE and idempotent — registering an already-registered provider is a no-op, and registration removes no resource and interrupts no workload, which is why it is not marked destructive. Registration is asynchronous: the response returns registrationState 'Registering', and azure_get_resource_provider reports when it reaches 'Registered' (usually under a minute). Use this after a deployment fails with NoRegisteredProviderFound or MissingSubscriptionRegistration.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
providerNamespacestringyesThe provider namespace to register, e.g. Microsoft.Compute.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Unregister a resource provider from a subscription. DESTRUCTIVE: while unregistering does not delete existing resources, it makes the provider's types UNDEPLOYABLE in the subscription and breaks any automation that creates them — and Azure refuses the call outright if resources of those types still exist. Treat it as a deliberate teardown step, not a cleanup nicety. Prefer leaving unused providers registered: registration costs nothing.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
providerNamespacestringyesThe provider namespace to unregister, e.g. Microsoft.Compute.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

Resource Graph

ToolPlanAccessSummary
azure_get_resource_change_detailsFreeRead-onlyGet the full BEFORE and AFTER snapshots for one resource change, plus the property-level diff.
azure_list_resource_graph_facetsFreeRead-onlyRun a KQL query and return FACET summaries — value counts for the columns you name — alongside the rows.
azure_query_resource_changesFreeRead-onlyList configuration CHANGES to Azure resources in a time window — the "what changed and when" surface, and usually the fastest route from an incident to its cause.
azure_query_resourcesFreeRead-onlyRun a KQL query across many subscriptions at once — the most powerful read in this connector.
azure_query_resources_countFreeRead-onlyRun a KQL query that returns only a COUNT, across many subscriptions at once.

[Microsoft Azure] Get the full BEFORE and AFTER snapshots for one resource change, plus the property-level diff. This is the tool that answers "what exactly did someone change on this NSG at 03:14" — the change list from azure_query_resource_changes tells you a change happened, this tells you what it was. Requires the resourceId and the changeId from that query.

ParamTypeRequiredDefaultDescription
changeIdstringyesThe change id, from azure_query_resource_changes.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceIdstringyesThe full ARM resource id of the changed resource, from azure_query_resource_changes.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Run a KQL query and return FACET summaries — value counts for the columns you name — alongside the rows. Use it to profile an estate before drilling in: faceting on 'type', 'location' or 'subscriptionId' answers "what is actually deployed here and where" in one call, which is the natural first question about a customer you have just gained access to. Supply the facet columns as a comma-separated list of column names that your query projects.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
facetColumnsstringyesComma-separated column names to facet on, e.g. "type,location". Each must be projected by the query.
querystringyesThe KQL query, e.g. "Resources | project name, type, location, subscriptionId".
subscriptionIdsstringnonullComma-separated subscription ids to scope the query to. Omit to query everything the user can see.
topintegernonullMaximum rows to return alongside the facets (1-1000).

[Microsoft Azure] List configuration CHANGES to Azure resources in a time window — the "what changed and when" surface, and usually the fastest route from an incident to its cause. Each change carries a changeId, the changeType (Create | Update | Delete), the timestamp, and which properties moved. Scope it to a single resource with resourceId, or to a subscription and window to sweep everything. Pass the returned changeId to azure_get_resource_change_details for the full before/after. Azure retains change history for 14 days.

ParamTypeRequiredDefaultDescription
endTimestringyesEnd of the window, ISO-8601 UTC (e.g. 2026-08-13T00:00:00Z).
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceIdstringnonullRestrict to ONE resource by its full ARM resource id (the /subscriptions/... string on every Azure object). Omit to sweep the whole subscription.
skipTokenstringnonullContinuation token from a previous response's $skipToken.
startTimestringyesStart of the window, ISO-8601 UTC (e.g. 2026-08-12T00:00:00Z).
subscriptionIdstringyesThe subscription id to search, from azure_list_subscriptions.
topintegernonullMaximum changes to return (1-1000).

[Microsoft Azure] Run a KQL query across many subscriptions at once — the most powerful read in this connector. Prefer it over fanning out per-subscription list calls: one query answers questions like "every VM without a backup", "all public IPs by region" or "resources missing an owner tag" across an entire estate, and Microsoft positions it as the mitigation for resource-provider throttling. Tables include Resources, ResourceContainers (subscriptions and resource groups), PolicyResources, SecurityResources, HealthResources and AdvisorResources. Example: "Resources | where type =~ 'microsoft.compute/virtualmachines' | project name, location, resourceGroup, subscriptionId". Pagination is BODY-level and unlike the rest of this connector: when the response carries $skipToken and resultTruncated is 'true', pass that token back as skipToken to get the next page. Scope with subscriptionIds (recommended: pass the customer's subscriptions from azure_list_subscriptions) or leave empty to query everything the user can see.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
managementGroupIdsstringnonullComma-separated management group ids to scope the query to instead of subscriptions.
querystringyesThe KQL query text, passed to Azure verbatim.
skipintegernonullRows to skip before returning results. Prefer skipToken for paging; this is for jumping to an offset.
skipTokenstringnonullContinuation token from a previous response's $skipToken, to fetch the next page.
subscriptionIdsstringnonullComma-separated subscription ids to scope the query to, from azure_list_subscriptions. Omit to query every subscription the signed-in user can see.
topintegernonullMaximum rows to return (1-1000). Omit for Azure's own default.

[Microsoft Azure] Run a KQL query that returns only a COUNT, across many subscriptions at once. A thin convenience over azure_query_resources: it appends a summarize to your query so you get a number rather than a truncated page of rows. Use it for "how many VMs are running across all customers" or "how many resources are missing the cost-centre tag" — questions where the rows themselves are noise and where returning them would hit the row cap and mislead. Supply the filter portion only, without a summarize of your own.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
managementGroupIdsstringnonullComma-separated management group ids to scope the query to instead of subscriptions.
querystringyesThe KQL filter to count, e.g. "Resources | where type =~ 'microsoft.compute/virtualmachines'". Do NOT include a summarize — one is appended for you.
subscriptionIdsstringnonullComma-separated subscription ids to scope the query to. Omit to count across everything the user can see.

Resource Groups

ToolPlanAccessSummary
azure_check_resource_group_existsFreeRead-onlyCheck whether a resource group exists WITHOUT retrieving it, returning {"exists": true|false}.
azure_create_resource_groupProWriteCreate a resource group, or update an existing one's tags.
azure_delete_resource_groupProDestructiveDelete a resource group AND EVERY RESOURCE INSIDE IT.
azure_export_resource_group_templateFreeRead-onlyExport a resource group as an ARM template — the JSON that would recreate its resources.
azure_get_resource_groupFreeRead-onlyGet one resource group: id, name, location, tags, managedBy and properties.provisioningState.
azure_list_resource_group_resourcesFreeRead-onlyList every resource inside one resource group.
azure_list_resource_groupsFreeRead-onlyList the resource groups in a subscription.
azure_update_resource_group_tagsProWriteUpdate a resource group's tags via PATCH, leaving everything else alone.

[Microsoft Azure] Check whether a resource group exists WITHOUT retrieving it, returning {"exists": true|false}. Cheaper and unambiguous compared with reading azure_get_resource_group and interpreting a 404 — use it as a precondition before a create, or to confirm a delete finished.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Create a resource group, or update an existing one's tags. Not destructive: creating adds an empty container, and updating an existing group changes only its tags — the resources inside are untouched, and Azure does not allow a group's location to move. Requires a region name from azure_list_locations. Tags are supplied as JSON, e.g. {"environment":"production","owner":"helpdesk"}. NOTE the tag semantics: this call REPLACES the group's tag set, so include every tag you want to keep — use azure_update_resource_group_tags for a merge instead.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations. Ignored when updating an existing group.
resourceGroupNamestringyesThe resource group name to create or update.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object, e.g. {"environment":"production"}. REPLACES the existing tag set.

[Microsoft Azure] Delete a resource group AND EVERY RESOURCE INSIDE IT. This is the single most destructive tool in the connector: Azure deletes the entire contents — virtual machines, disks, databases, storage accounts and their data — with no further confirmation and no undo. Call azure_list_resource_group_resources first and show the caller exactly what will be destroyed. The operation is ASYNCHRONOUS: this returns as soon as Azure accepts the request, the accepted response has no body and carries no tracking reference you can follow, and deletion continues for minutes afterwards; poll azure_check_resource_group_exists to confirm completion. A resource protected by a delete lock or a policy blocks the whole operation.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group name to DELETE, along with everything inside it.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Export a resource group as an ARM template — the JSON that would recreate its resources. Read-only despite being an HTTP POST: it produces a document and changes nothing. Use it to capture a working configuration before a risky change, or to clone an environment. Pass resource ids to export a subset, or omit them to export the whole group. Note that Azure's exporter is imperfect for some resource types and may emit parameters the caller must fill in; treat the result as a strong starting point rather than a guaranteed-deployable artifact.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
optionsstringnonullComma-separated export options, e.g. "IncludeParameterDefaultValue,IncludeComments".
resourceGroupNamestringyesThe resource group name.
resourceIdsstringnonullComma-separated ARM resource ids to export. Omit to export every resource in the group.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one resource group: id, name, location, tags, managedBy and properties.provisioningState. A 404 here is a legitimate empty answer — the group does not exist in that subscription — and is often a sign the caller meant a CUSTOMER's subscription and omitted entraTenant.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every resource inside one resource group. Each item carries id, name, type, location, sku, kind, managedBy and tags. Use this before azure_delete_resource_group to show exactly what a deletion would destroy — the delete removes all of this without a further prompt from Azure. Filter with an OData expression such as "resourceType eq 'Microsoft.Compute/virtualMachines'", and expand with "createdTime,changedTime,provisioningState" for lifecycle detail.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullComma-separated fields to expand, e.g. "createdTime,changedTime,provisioningState".
filterstringnonullOData filter, e.g. "resourceType eq 'Microsoft.Compute/virtualMachines'".
maxItemsintegerno1000Maximum resources to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the resource groups in a subscription. Each item carries id, name, location, tags, managedBy and properties.provisioningState. Filter with an OData expression, most usefully by tag: "tagName eq 'environment' and tagValue eq 'production'". Returns ARM's {value:[...]} envelope; up to 1000 items across 10 pages per call, with nextLink returned when more remain. Requires a subscription id from azure_list_subscriptions.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOData filter, e.g. "tagName eq 'environment' and tagValue eq 'production'". Omit for all groups.
maxItemsintegerno1000Maximum resource groups to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Update a resource group's tags via PATCH, leaving everything else alone. Not destructive: tags carry no access or workload semantics, and this is a partial update — tags you omit are preserved rather than cleared, which is the difference from azure_create_resource_group. Supply tags as a JSON object, e.g. {"costCentre":"CC-1042"}.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringyesTags to set as a JSON object, e.g. {"costCentre":"CC-1042"}. Omitted tags are preserved.

Resources & Tags

ToolPlanAccessSummary
azure_delete_resource_by_idProDestructiveDelete any Azure resource by its full ARM resource id.
azure_get_resource_by_idFreeRead-onlyGet any Azure resource by its full ARM resource id — the /subscriptions/...
azure_get_resource_tagsFreeRead-onlyGet the tags on any Azure resource, resource group or subscription by its ARM id.
azure_list_resourcesFreeRead-onlyList every resource in a subscription, of any type.
azure_move_resourcesProDestructiveMove resources to a different resource group or subscription.
azure_set_resource_tagsProWriteREPLACE the entire tag set on any Azure resource, resource group or subscription.
azure_update_resource_tagsProWriteMerge, replace or delete tags on any Azure resource, resource group or subscription.
azure_validate_move_resourcesProWriteValidate a resource move WITHOUT performing it — the safe preview for azure_move_resources.

[Microsoft Azure] Delete any Azure resource by its full ARM resource id. DESTRUCTIVE and generally irreversible: for a data-bearing resource such as a storage account or a managed disk, the data goes with it. You must supply the api-version that resource's provider expects — azure_get_resource_provider lists them. Prefer a dedicated family's delete tool where one exists: it pins the version and often surfaces type-specific safeguards. Deletion is asynchronous for most types; the 202 response carries the Location URL to poll.

ParamTypeRequiredDefaultDescription
apiVersionstringyesThe api-version this resource's provider expects — from azure_get_resource_provider.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceIdstringyesThe full ARM resource id to DELETE.

[Microsoft Azure] Get any Azure resource by its full ARM resource id — the /subscriptions/... string every Azure object carries and every list tool returns. Works for resource types this connector has no dedicated family for. You must supply the api-version that resource's PROVIDER expects; azure_get_resource_provider lists the supported apiVersions for each type. If you do not know it, prefer the dedicated family's get tool, which pins the version for you.

ParamTypeRequiredDefaultDescription
apiVersionstringyesThe api-version this resource's provider expects, e.g. 2023-05-01 — from azure_get_resource_provider.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceIdstringyesThe full ARM resource id, e.g. /subscriptions//resourceGroups//providers/Microsoft.Storage/storageAccounts/.

[Microsoft Azure] Get the tags on any Azure resource, resource group or subscription by its ARM id. Returns {properties:{tags:}}. Read this before azure_set_resource_tags, which REPLACES the whole tag set — merging by hand against a stale view is how tags get silently dropped.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceIdstringyesThe full ARM id of the resource, resource group or subscription.

[Microsoft Azure] List every resource in a subscription, of any type. Each item carries id, name, type, location, sku, kind, plan, managedBy and tags. Filter with an OData expression — by type ("resourceType eq 'Microsoft.Storage/storageAccounts'"), by tag ("tagName eq 'owner'"), or by group ("resourceGroup eq 'prod-rg'") — and expand "createdTime,changedTime,provisioningState" for lifecycle detail. For questions spanning MANY subscriptions, azure_query_resources is the better tool: it answers in one call where this would need one call per subscription and can trip ARM's throttling. Up to 1000 items across 10 pages per call, with nextLink when more remain.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullComma-separated fields to expand, e.g. "createdTime,changedTime,provisioningState".
filterstringnonullOData filter, e.g. "resourceType eq 'Microsoft.Storage/storageAccounts'" or "tagName eq 'owner'".
maxItemsintegerno1000Maximum resources to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Move resources to a different resource group or subscription. DESTRUCTIVE: a move changes every resource's ARM id, which silently breaks role assignments, policy assignments, locks, alert rules, diagnostic settings and any automation or template that references the old id — and while the move runs, the SOURCE and TARGET groups are both LOCKED against other write operations. Not every resource type supports moving, and Azure validates the whole set atomically: one unmovable resource fails the entire operation. Run azure_validate_move_resources first — it performs the same validation without moving anything. The operation is asynchronous; the 202 response carries the Location URL to poll.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe SOURCE resource group name.
resourceIdsstringyesComma-separated full ARM resource ids to move.
subscriptionIdstringyesThe SOURCE subscription id, from azure_list_subscriptions.
targetResourceGroupIdstringyesThe TARGET resource group's full ARM id, e.g. /subscriptions//resourceGroups/.

[Microsoft Azure] REPLACE the entire tag set on any Azure resource, resource group or subscription. Tags carry no access-control or workload semantics — nothing stops running and nothing is deleted — so this is not marked destructive, but note the replace semantics: any tag you omit is REMOVED. Read azure_get_resource_tags first and include everything you want to keep, or use azure_update_resource_tags to merge instead. Tags are a JSON object, e.g. {"environment":"production","costCentre":"CC-1042"}.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceIdstringyesThe full ARM id of the resource, resource group or subscription.
tagsJsonstringyesThe COMPLETE tag set as a JSON object. Omitted tags are removed.

[Microsoft Azure] Merge, replace or delete tags on any Azure resource, resource group or subscription. Additive by default and not destructive — tags carry no access or workload semantics. operation controls the semantics: Merge adds or overwrites the tags you supply and PRESERVES the rest (the safe default); Replace swaps the whole set, removing omitted tags; Delete removes exactly the tags you name. Prefer Merge unless you specifically intend to clear tags.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
operationstringno"Merge"Merge (add/overwrite, keep the rest — the default), Replace (swap the whole set), or Delete (remove the named tags).
resourceIdstringyesThe full ARM id of the resource, resource group or subscription.
tagsJsonstringyesTags as a JSON object, e.g. {"costCentre":"CC-1042"}.

[Microsoft Azure] Validate a resource move WITHOUT performing it — the safe preview for azure_move_resources. Runs Azure's full move validation and reports which resources would fail and why. Explicitly NOT destructive: marking a safe-preview tool destructive would defeat its purpose, since the whole point is that an agent can run it freely before asking a human about the real move. The check is asynchronous; a 202 with no errors means validation passed.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe SOURCE resource group name.
resourceIdsstringyesComma-separated full ARM resource ids to validate for the move.
subscriptionIdstringyesThe SOURCE subscription id, from azure_list_subscriptions.
targetResourceGroupIdstringyesThe TARGET resource group's full ARM id.

Virtual Machines

ToolPlanAccessSummary
azure_assess_vm_patchesProWriteAssess which operating-system patches are available for a virtual machine.
azure_attach_vm_data_disksProWriteAttach one or more EXISTING managed disks to a virtual machine as data disks.
azure_convert_vm_to_managed_disksProDestructiveConvert a legacy virtual machine's unmanaged (page-blob) disks to managed disks.
azure_create_or_update_vmProWriteCreate a virtual machine, or replace an existing one's model wholesale.
azure_create_or_update_vm_extensionProWriteInstall an extension on a virtual machine, or update one already installed.
azure_deallocate_vmProDestructiveDeallocate a virtual machine — shut it down AND release its compute resources, which is what stops the compute bill.
azure_delete_vmProDestructiveDELETE a virtual machine.
azure_delete_vm_extensionProDestructiveUninstall an extension from a virtual machine.
azure_detach_vm_data_disksProDestructiveDetach one or more data disks from a virtual machine.
azure_get_vmFreeRead-onlyGet one virtual machine's full model: size, OS profile, image reference, OS and data disks with their LUNs and managed-disk ids, network interface ids, boot-diagnostics settings, identity, zones and…
azure_get_vm_boot_diagnostics_dataProDestructiveMint time-limited SAS URIs for a virtual machine's boot diagnostics — consoleScreenshotBlobUri (a bitmap of the console at the moment of capture) and serialConsoleLogBlobUri (the boot serial log).
azure_get_vm_extensionFreeRead-onlyGet one extension on one virtual machine by its instance name — the name the extension was DEPLOYED under, which is often not the same as its publisher type (azure_list_vm_extensions returns both).
azure_get_vm_instance_viewFreeRead-onlyGet a virtual machine's RUNTIME state — this is the tool that answers "is this machine on?".
azure_get_vm_run_commandFreeRead-onlyGet one managed run command on a virtual machine, and with expand="instanceView" its RESULT — executionState (Running, Succeeded, Failed, TimedOut), exitCode, startTime, endTime, and the captured…
azure_get_vm_run_command_documentFreeRead-onlyGet one built-in run command document by its command id — the full definition, including the script Azure will execute and the parameters array naming every value the command expects and which of them…
azure_install_vm_patchesProDestructiveInstall operating-system patches on a virtual machine now.
azure_list_vm_extensionsFreeRead-onlyList the extensions installed on one virtual machine — the in-guest agents Azure manages, such as the Monitor agent, the Dependency agent, Custom Script, the antimalware extension and the domain-join…
azure_list_vm_image_offersFreeRead-onlyList one publisher's image offers in a region — the second rung of the image coordinate.
azure_list_vm_image_publishersFreeRead-onlyList the image publishers available in one region — the first rung of the four-part image coordinate (publisher, offer, SKU, version) that azure_create_or_update_vm needs.
azure_list_vm_image_skusFreeRead-onlyList the SKUs under one publisher/offer in a region — the third rung of the image coordinate, and the one that names the actual edition: 2022-datacenter-azure-edition, 22_04-lts-gen2, and so on.
azure_list_vm_image_versionsFreeRead-onlyList the published versions of one publisher/offer/SKU image in a region — the fourth and last rung of the image coordinate.
azure_list_vm_resize_optionsFreeRead-onlyList the sizes THIS virtual machine can actually be resized to.
azure_list_vm_run_command_documentsFreeRead-onlyList the BUILT-IN run command documents Azure publishes for a region — the vetted scripts an agent can invoke by id instead of writing its own.
azure_list_vm_run_commandsFreeRead-onlyList the MANAGED run commands deployed on one virtual machine.
azure_list_vm_sizesFreeRead-onlyList every virtual machine size Azure offers in one region, with each size's numberOfCores, memoryInMB, maxDataDiskCount, osDiskSizeInMB and resourceDiskSizeInMB.
azure_list_vmsFreeRead-onlyList every virtual machine in a subscription, across all resource groups.
azure_list_vms_in_resource_groupFreeRead-onlyList the virtual machines inside one resource group.
azure_perform_vm_maintenanceProDestructiveTrigger Azure's pending host maintenance on a virtual machine NOW, instead of waiting for the platform's self-service window to close and the maintenance to be applied automatically.
azure_power_off_vmProDestructivePower off (stop) a virtual machine, leaving it ALLOCATED.
azure_reapply_vmProDestructiveReapply a virtual machine's ARM model to the platform — Azure re-pushes the stored configuration to the machine's host.
azure_redeploy_vmProDestructiveRedeploy a virtual machine — shut it down, MOVE it to a new Azure host, and power it back on.
azure_reimage_vmProDestructiveReimage a virtual machine — reset its OS disk back to the original image.
azure_restart_vmProDestructiveRestart a virtual machine.
azure_run_vm_commandProDestructiveRun a command INSIDE a customer's virtual machine, through the Azure guest agent.
azure_set_vm_tagsProWriteSet the tags on a virtual machine, leaving every other property untouched.
azure_simulate_vm_evictionProDestructiveSimulate the eviction of a SPOT virtual machine, so an owner can test that their workload survives being evicted.
azure_start_vmProWriteStart (power on) a stopped or deallocated virtual machine.
azure_update_vmProWriteUpdate an existing virtual machine with a PATCH — the tool to use for a resize, a boot-diagnostics change, an identity change or a licence-type change.

[Microsoft Azure] Assess which operating-system patches are available for a virtual machine. Not destructive: nothing is installed, nothing reboots, and the guest is only inspected — this is the safe half of the patching pair and the right thing to run before proposing azure_install_vm_patches. An assessment takes a few minutes and reports the count of patches by classification (Critical, Security, Other), the reboot requirement and the assessment's own status. The machine must be RUNNING with a healthy guest agent; a stopped or deallocated machine cannot be assessed. The operation is ASYNCHRONOUS — the result also lands on the machine's instance view, so azure_get_vm_instance_view shows the latest assessment afterwards.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe running virtual machine to assess. Nothing is installed.

[Microsoft Azure] Attach one or more EXISTING managed disks to a virtual machine as data disks. Not destructive: it only adds storage, and nothing already on the machine is changed or removed. The disks must already exist in the same region as the machine — this does not create them — and each LUN must be unique on the machine; omit lun to let Azure assign one. Read azure_get_vm first to see the LUNs already in use and the machine's maxDataDiskCount for its size (azure_list_vm_sizes reports that limit). Attaching makes the volume visible to Azure; the guest OS still has to initialise, partition and mount it. Set deleteOption to "Delete" only when the disk should be destroyed along with the machine — the default "Detach" leaves it behind. The operation is ASYNCHRONOUS and returns immediately with the machine's updated storage profile.

ParamTypeRequiredDefaultDescription
dataDisksToAttachJsonstringyesThe disks to attach, as a JSON array of objects: [{"diskId":"/subscriptions/.../disks/mydisk","lun":1,"caching":"ReadOnly","deleteOption":"Detach"}]. Only diskId is required.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine name.

[Microsoft Azure] Convert a legacy virtual machine's unmanaged (page-blob) disks to managed disks. Destructive and IRREVERSIBLE: there is no supported conversion back, the machine's disk resource ids all change — breaking any script, backup policy, role assignment or template that referenced the old blob URIs — and the source VHD blobs are left behind in their storage account still costing money. The machine MUST already be stop-deallocated (azure_deallocate_vm) or the call fails, so this is inherently an outage. Snapshot the disks first. The operation is ASYNCHRONOUS and can run for a long time on large disks; poll azure_get_vm for the new managedDisk ids.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe stop-deallocated virtual machine to CONVERT. The conversion cannot be undone.

[Microsoft Azure] Create a virtual machine, or replace an existing one's model wholesale. Not marked destructive because the normal use is additive — it stands a new machine up — but read the replace semantics before pointing it at a name that already exists: this is a PUT, so the properties document you send REPLACES the stored one, and a data disk, NIC or extension setting you leave out is removed from the machine. For a change to an existing machine prefer azure_update_vm, which patches. Before creating: pick a region with azure_list_locations, a size with azure_list_vm_sizes, and a publisher/offer/SKU/version with the azure_list_vm_image_* tools; the network interface must already exist, since ARM will not create one for you. The operation is ASYNCHRONOUS — this returns as soon as ARM accepts the request, the accepted response has no body and carries no tracking reference you can follow, and provisioning continues for several minutes; poll azure_get_vm_instance_view for the outcome. Costs begin as soon as the machine allocates.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
identityJsonstringnonullManaged identity as a JSON object, e.g. {"type":"SystemAssigned"}.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations. A machine's region cannot be changed later.
planJsonstringnonullMarketplace purchase plan as a JSON object ({"name":...,"publisher":...,"product":...}). Required for marketplace images whose terms must be accepted.
propertiesJsonstringyesThe VM properties document as JSON — hardwareProfile, storageProfile (imageReference and osDisk), osProfile and networkProfile at minimum. REPLACES the stored properties on an existing machine.
resourceGroupNamestringyesThe resource group to create the machine in. It must already exist.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object, e.g. {"environment":"production"}. REPLACES the machine's tag set.
vmNamestringyesThe virtual machine name.
zonesJsonstringnonullAvailability zones as a JSON array of strings, e.g. ["1"]. A machine's zone cannot be changed later.

[Microsoft Azure] Install an extension on a virtual machine, or update one already installed. Not marked destructive: installing an agent is additive and Azure does not restart the machine to do it. Note two real consequences anyway — an extension runs code in the guest with high privilege, so it deserves the same scrutiny as a script; and because this is a PUT, reusing an EXISTING instance name replaces that extension's settings wholesale rather than merging them, which for an agent like the Monitor agent can change what it collects. Read azure_list_vm_extensions first to see what is installed and under which instance names. Secrets belong in properties.protectedSettings, which Azure encrypts and never returns on a read. The operation is ASYNCHRONOUS — this returns immediately and installation continues for a few minutes; poll azure_get_vm_extension with expand="instanceView" for the outcome.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
extensionNamestringyesThe extension INSTANCE name to create or replace. Reusing an existing name replaces that extension's settings.
locationstringyesThe Azure region of the machine, e.g. eastus. It must match the machine's own location.
propertiesJsonstringyesThe extension properties as JSON — publisher, type, typeHandlerVersion, autoUpgradeMinorVersion, settings and (for secrets) protectedSettings.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object. REPLACES the extension resource's tag set.
vmNamestringyesThe virtual machine name.

[Microsoft Azure] Deallocate a virtual machine — shut it down AND release its compute resources, which is what stops the compute bill. Destructive: the machine stops serving, sessions drop, in-memory work is lost, the contents of the temporary/resource disk (D: on Windows, /mnt on Linux) are DISCARDED, and because the machine leaves its host a dynamically-assigned public IP is released and will differ on next start. Managed OS and data disks and their data survive and continue to be billed for storage. This is the correct tool for "stop this VM to save money"; azure_power_off_vm keeps billing it. Set hibernate=true to preserve the running memory state instead of discarding it — the machine must have been created with hibernation enabled. The operation is ASYNCHRONOUS and returns immediately.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
hibernatebooleannofalseHibernate instead of discarding memory state. Only valid on a machine created with hibernation enabled.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine to DEALLOCATE. Temporary-disk contents are discarded and a dynamic IP is released.

[Microsoft Azure] DELETE a virtual machine. What is lost depends on each attached resource's deleteOption, which the caller should read from azure_get_vm BEFORE calling this: a disk, NIC or public IP marked "Delete" is destroyed with the machine and its data is unrecoverable, while one marked "Detach" is left behind in the resource group still costing money. There is no recycle bin and no undo — a machine without a backup or a snapshot cannot be brought back. Confirm the identity of the machine with azure_get_vm first; a name is easy to mistake between environments. Set forceDeletion only for a machine that is already broken: it skips Azure's graceful shutdown, so in-flight guest writes are lost. The operation is ASYNCHRONOUS — this returns immediately with a 202 and deletion continues for minutes; a delete lock or a policy on the machine blocks it outright.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
forceDeletionbooleannofalseSkip the graceful shutdown and force the delete. Only for an already-broken machine — in-flight guest writes are lost.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine to DELETE.

[Microsoft Azure] Uninstall an extension from a virtual machine. Destructive: the in-guest agent is removed and whatever it was doing stops — removing the Monitor agent blindly ends log and metric collection for that machine, removing an antimalware or backup extension ends protection, and removing a domain-join or disk-encryption extension can leave the machine in a state that needs manual repair. The extension's own configuration is gone with it and would have to be redeployed from scratch. Read azure_get_vm_extension first and tell the caller what the extension is before removing it. Some extensions run an uninstall script in the guest, so a brief disruption is possible. The operation is ASYNCHRONOUS and returns immediately.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
extensionNamestringyesThe extension INSTANCE name to UNINSTALL, from azure_list_vm_extensions. Whatever the agent was doing stops.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine name.

[Microsoft Azure] Detach one or more data disks from a virtual machine. Destructive: the volume disappears from a running guest, so anything reading or writing it fails immediately, and an application or database whose files live on that disk will break until the disk is reattached. The disk resource itself SURVIVES with its data intact and keeps costing storage — this removes the attachment, not the disk. Dismount the volume inside the guest before calling. detachOption="ForceDetach" is a last resort for a disk a previous detach left stuck: it does not wait for outstanding writes to flush, so data in flight IS lost. Read azure_get_vm first to confirm which diskId sits on which LUN. The operation is ASYNCHRONOUS and returns immediately with the machine's updated storage profile.

ParamTypeRequiredDefaultDescription
dataDisksToDetachJsonstringyesThe disks to DETACH, as a JSON array of objects: [{"diskId":"/subscriptions/.../disks/mydisk"}]. Add "detachOption":"ForceDetach" only for a disk a previous detach left stuck — unflushed writes are lost.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine name.

[Microsoft Azure] Get one virtual machine's full model: size, OS profile, image reference, OS and data disks with their LUNs and managed-disk ids, network interface ids, boot-diagnostics settings, identity, zones and tags. Pass expand="instanceView" to append the runtime view (power state, extension health, disk status) in the same call, or expand="userData" to include the base64 user-data blob. A 404 is a legitimate empty answer — no such machine in that group — and is frequently a sign the caller meant a CUSTOMER's subscription and omitted entraTenant. A 403 means the signed-in user's Azure RBAC does not grant read on this machine; StackJack cannot widen that.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullOptional expansion: "instanceView" for runtime state, or "userData" for the user-data blob.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine name.

[Microsoft Azure] Mint time-limited SAS URIs for a virtual machine's boot diagnostics — consoleScreenshotBlobUri (a bitmap of the console at the moment of capture) and serialConsoleLogBlobUri (the boot serial log). TREAT THE RESPONSE AS A CREDENTIAL: whoever holds either URL can fetch that content from anywhere on the internet, with no Entra sign-in and no conditional access, until it expires — and a console screenshot can show whatever was on screen, including an unlocked session or an error dump. This is the first thing to fetch for a machine that reports PowerState/running but is unreachable: the screenshot usually shows the blue screen, the fsck prompt or the GRUB menu that explains it. Marked destructive despite changing nothing on the machine, because it DISCLOSES access (the disk-grant rule, one family over). Boot diagnostics must already be ENABLED on the machine (properties.diagnosticsProfile.bootDiagnostics.enabled on azure_get_vm); if it is not, expect a 409 rather than empty URIs. The URIs expire, by default after 120 minutes; choose the shortest expiry that can possibly work.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
sasUriExpirationTimeInMinutesintegernonullHow long the returned SAS URIs stay valid, in minutes (1-1440). Omit for Azure's 120-minute default.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine name.

[Microsoft Azure] Get one extension on one virtual machine by its instance name — the name the extension was DEPLOYED under, which is often not the same as its publisher type (azure_list_vm_extensions returns both). Returns publisher, type, typeHandlerVersion, settings and provisioningState; pass expand="instanceView" for the live status and the substatuses that carry an extension's own stdout/stderr. Protected settings are never returned by Azure — a secret passed to an extension cannot be read back through this tool or any other. A 404 means no extension with that instance name is deployed on the machine.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullSet to "instanceView" to include the extension's live status and substatuses.
extensionNamestringyesThe extension INSTANCE name, from azure_list_vm_extensions — not the publisher type.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine name.

[Microsoft Azure] Get a virtual machine's RUNTIME state — this is the tool that answers "is this machine on?". Returns the statuses array whose PowerState/* code is one of PowerState/running, PowerState/stopped (still allocated and still billed), PowerState/deallocated (compute released, not billed) or PowerState/starting|stopping|deallocating, alongside per-extension health, per-disk status, the OS name and version, the hypervisor generation and any boot-diagnostics blob URIs. Do NOT read properties.provisioningState from azure_get_vm for this — that field describes the last ARM write, not the power state. This is also the tool to poll after any of the asynchronous power actions to confirm the outcome.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine name.

[Microsoft Azure] Get one managed run command on a virtual machine, and with expand="instanceView" its RESULT — executionState (Running, Succeeded, Failed, TimedOut), exitCode, startTime, endTime, and the captured standard output and standard error. This is how the outcome of a long-running managed command is collected: the deployment returns as soon as Azure accepts it, and the output lands here afterwards. Where a command was configured with outputBlobUri the large output goes to that blob instead and only a summary appears here. A 404 means no managed run command with that name exists on the machine — check azure_list_vm_run_commands for the deployed names.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullSet to "instanceView" to include the execution state, exit code and captured output.
resourceGroupNamestringyesThe resource group the machine lives in.
runCommandNamestringyesThe managed run command's name, from azure_list_vm_run_commands.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine name.

[Microsoft Azure] Get one built-in run command document by its command id — the full definition, including the script Azure will execute and the parameters array naming every value the command expects and which of them are required. This is the tool to call BEFORE azure_run_vm_command with a built-in id: it turns a guessed parameter set into a checked one, and the resulting script text is exactly what the caller can be shown before they approve running it on a customer machine. Requires a command id and region from azure_list_vm_run_command_documents; a 404 means no such id in that region.

ParamTypeRequiredDefaultDescription
commandIdstringyesThe command id, e.g. RunPowerShellScript — from azure_list_vm_run_command_documents.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Install operating-system patches on a virtual machine now. Destructive: patching changes the guest, cannot be rolled back through this API, and with rebootSetting "IfRequired" or "Always" it REBOOTS the machine — dropping every session and interrupting the service on it. Run azure_assess_vm_patches first and show the caller what would be installed. rebootSetting must be one of "IfRequired", "Never" or "Always"; choosing "Never" leaves the machine in a pending-reboot state that some patches need before they take effect. maximumDuration is an ISO-8601 duration (for example PT4H) after which Azure stops starting new patch installs. Supply windowsParametersJson OR linuxParametersJson to match the guest OS — classificationsToInclude, kbNumbersToExclude and the like. The operation is ASYNCHRONOUS and can run for hours; the outcome lands on the machine's instance view.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
linuxParametersJsonstringnonullLinux patch selection as JSON, e.g. {"classificationsToInclude":["Security"],"packageNameMasksToExclude":["kernel*"]}. Use on a Linux guest.
maximumDurationstringnonullISO-8601 duration after which Azure stops starting new installs, e.g. PT4H. Omit for Azure's default.
rebootSettingstringyesOne of "IfRequired", "Never" or "Always". Anything but "Never" can reboot the machine mid-operation.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe running virtual machine to PATCH. It may reboot.
windowsParametersJsonstringnonullWindows patch selection as JSON, e.g. {"classificationsToInclude":["Critical","Security"],"kbNumbersToExclude":["KB5000001"]}. Use on a Windows guest.

[Microsoft Azure] List the extensions installed on one virtual machine — the in-guest agents Azure manages, such as the Monitor agent, the Dependency agent, Custom Script, the antimalware extension and the domain-join extension. Each item carries publisher, type, typeHandlerVersion, autoUpgradeMinorVersion, settings and provisioningState. Pass expand="instanceView" to include each extension's live status and its last message, which is where an agent that installed but failed to run reports why. This is the inventory to read before azure_delete_vm_extension so the caller sees exactly what is installed.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullSet to "instanceView" to include each extension's live status and last message.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine name.

[Microsoft Azure] List one publisher's image offers in a region — the second rung of the image coordinate. Under MicrosoftWindowsServer the offer is WindowsServer; under Canonical it is one of the ubuntu-* offers. Requires an exact publisher name from azure_list_vm_image_publishers: the value is case-sensitive and a near-miss returns a 404 rather than a suggestion. Returns a bare JSON array, not the {value:[...]} envelope.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
publisherNamestringyesThe exact publisher name, from azure_list_vm_image_publishers (case-sensitive).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the image publishers available in one region — the first rung of the four-part image coordinate (publisher, offer, SKU, version) that azure_create_or_update_vm needs. Familiar values are MicrosoftWindowsServer, Canonical, RedHat and MicrosoftWindowsDesktop. Note that publishers are REGIONAL: an image present in one region may be absent from another, so always ask for the region the machine will be created in. Returns a bare JSON array, not the usual {value:[...]} envelope, and it is a long list — narrow it by name rather than reading it all back to the caller.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the SKUs under one publisher/offer in a region — the third rung of the image coordinate, and the one that names the actual edition: 2022-datacenter-azure-edition, 22_04-lts-gen2, and so on. The gen1/gen2 distinction lives here and matters, because a gen2 image will not boot on a VM size that only supports gen1. Requires exact publisher and offer names from azure_list_vm_image_publishers and azure_list_vm_image_offers. Returns a bare JSON array, not the {value:[...]} envelope.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
offerstringyesThe exact offer name, from azure_list_vm_image_offers (case-sensitive).
publisherNamestringyesThe exact publisher name, from azure_list_vm_image_publishers (case-sensitive).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the published versions of one publisher/offer/SKU image in a region — the fourth and last rung of the image coordinate. Versions are Major.Minor.Build strings and are ordered by Azure, not by the array position, so pass orderby="name desc" with top=1 when you only want the newest. When creating a machine you can usually skip this and set version to "latest" in the image reference, but note that "latest" is resolved once at deployment time and the machine does NOT track later releases. Returns a bare JSON array, not the {value:[...]} envelope.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
offerstringyesThe exact offer name, from azure_list_vm_image_offers (case-sensitive).
orderbystringnonullSort expression, e.g. "name desc" for newest first.
publisherNamestringyesThe exact publisher name, from azure_list_vm_image_publishers (case-sensitive).
skustringyesThe exact SKU name, from azure_list_vm_image_skus (case-sensitive).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
topintegernonullMaximum versions to return, e.g. 1 with orderby="name desc" for just the newest.

[Microsoft Azure] List the sizes THIS virtual machine can actually be resized to. The answer is narrower than azure_list_vm_sizes because Azure only offers sizes supported by the physical cluster the machine is currently allocated on. A size missing from this list is not necessarily unavailable in the region — deallocating the machine first (azure_deallocate_vm) frees it from its cluster and usually widens the set. Read this before issuing a size change through azure_update_vm, so the update does not fail after the machine has already been taken down.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine name.

[Microsoft Azure] List the BUILT-IN run command documents Azure publishes for a region — the vetted scripts an agent can invoke by id instead of writing its own. Each item carries $schema, id (e.g. RunPowerShellScript, RunShellScript, EnableRemotePS, IPConfig, ifconfig), osType, label and description. Prefer one of these over an ad-hoc script wherever it fits: a named document is auditable and its behaviour is fixed, where free-form script text is not. Read azure_get_vm_run_command_document next to learn what parameters an id takes before calling azure_run_vm_command.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the MANAGED run commands deployed on one virtual machine. These are persistent child resources (created by a template, the portal, the CLI or PowerShell) and are a different thing from the one-shot azure_run_vm_command action: each has a name, a source script, a timeout and a provisioningState, and it survives until it is deleted. Pass expand="instanceView" to include each one's execution state, exit code and captured output. This is the tool that answers "what has been scheduled to run on this machine?". Returns ARM's {value:[...]} envelope, paged.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullSet to "instanceView" to include each command's execution state, exit code and output.
maxItemsintegerno1000Maximum run commands to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine name.

[Microsoft Azure] List every virtual machine size Azure offers in one region, with each size's numberOfCores, memoryInMB, maxDataDiskCount, osDiskSizeInMB and resourceDiskSizeInMB. Use this when CHOOSING a size for a new machine. It is NOT the right tool for resizing an existing one — availability there is constrained by the cluster the machine already sits on, which is what azure_list_vm_resize_options answers. Requires a region name from azure_list_locations. Note this reports capability, not price or current regional capacity: a size listed here can still fail to allocate.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every virtual machine in a subscription, across all resource groups. Each item carries id, name, location, zones, tags, properties.hardwareProfile.vmSize, properties.storageProfile (OS and data disks), properties.networkProfile and properties.provisioningState. Note that provisioningState describes the last ARM write, NOT whether the machine is powered on — pass expand="instanceView" to get the PowerState/* status codes inline, or call azure_get_vm_instance_view for one machine. Requires a subscription id from azure_list_subscriptions. Returns ARM's {value:[...]} envelope; up to 1000 items across 10 pages per call, with nextLink returned when more remain.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullSet to "instanceView" to include each machine's runtime power state and per-extension status. Costs extra time on large subscriptions; omit when you only need configuration.
filterstringnonullOData filter, e.g. "'virtualMachineScaleSet/id' eq '/subscriptions//resourceGroups//providers/Microsoft.Compute/virtualMachineScaleSets/'". Omit for all machines.
maxItemsintegerno1000Maximum virtual machines to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the virtual machines inside one resource group. Same item shape as azure_list_vms but scoped to a single group, which is the cheaper call when the caller already knows where the machines live. Pass expand="instanceView" to include runtime power state. A 404 here means the resource GROUP does not exist in that subscription; an empty {"value":[]} means the group exists and holds no virtual machines — the two are different answers and worth distinguishing for the caller.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullSet to "instanceView" to include each machine's runtime power state and per-extension status.
maxItemsintegerno1000Maximum virtual machines to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name, from azure_list_resource_groups.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Trigger Azure's pending host maintenance on a virtual machine NOW, instead of waiting for the platform's self-service window to close and the maintenance to be applied automatically. Destructive: applying maintenance interrupts the machine — expect a reboot or a live migration pause — and in-memory work is lost. The point of running it deliberately is to choose WHEN that interruption happens. It fails with a 409 on a machine that has no maintenance pending, which is a legitimate answer rather than a fault; check maintenanceRedeployStatus in azure_get_vm_instance_view first. The operation is ASYNCHRONOUS and returns immediately.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine to apply pending host maintenance to. Expect an interruption.

[Microsoft Azure] Power off (stop) a virtual machine, leaving it ALLOCATED. Destructive: the machine stops serving, every session drops and in-memory work is lost. Understand the billing difference before choosing this over azure_deallocate_vm — a powered-off machine keeps its host reservation and its dynamic IP, and you are STILL CHARGED for its compute. Choose this when the machine must keep its IP or must be able to start again immediately; choose deallocate to stop the compute bill. skipShutdown issues a hard power cut with no guest shutdown at all, which risks filesystem corruption and unflushed application writes — reserve it for a machine that is already hung. The operation is ASYNCHRONOUS and returns immediately.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
skipShutdownbooleannofalseCut power without a guest shutdown. Risks filesystem corruption — only for a machine that is already hung.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine to POWER OFF. It stays allocated and stays billed.

[Microsoft Azure] Reapply a virtual machine's ARM model to the platform — Azure re-pushes the stored configuration to the machine's host. This is the remedy for a machine stuck in a failed provisioningState after an update that Azure recorded but never finished applying. Marked destructive out of caution rather than certainty: the operation is a platform-level re-application whose effect can include a service interruption on a running machine, and the safe assumption for an agent is that the machine may bounce. It changes no stored configuration of its own — whatever is in the model is simply applied again. The operation is ASYNCHRONOUS and returns immediately.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine whose stored model should be REAPPLIED. Assume a possible interruption.

[Microsoft Azure] Redeploy a virtual machine — shut it down, MOVE it to a new Azure host, and power it back on. This is the standard remedy for a machine that is unreachable for reasons on the platform side rather than in the guest. Destructive: it is a full outage of several minutes, in-memory work is lost, and the contents of the temporary/resource disk are DISCARDED because the machine lands on different hardware. Managed disks and their data follow the machine. Try azure_restart_vm first — it is the cheaper interruption — and reach for this only when a restart has not helped. The operation is ASYNCHRONOUS and returns immediately; confirm with azure_get_vm_instance_view.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine to REDEPLOY onto a new host. Temporary-disk contents are discarded.

[Microsoft Azure] Reimage a virtual machine — reset its OS disk back to the original image. THIS IS DATA LOSS BY DESIGN: every change made to the operating system disk since the machine was created is destroyed, including installed software, configuration, local user profiles and anything an application wrote outside a data disk. Attached DATA disks are not touched. On a machine with an ephemeral OS disk the reset is the only way to recover it; on an ordinary machine treat this as a last resort and confirm with a human first. Set tempDisk=true to also reset the temporary/resource disk (ephemeral OS disks only). The operation is ASYNCHRONOUS — this returns immediately and the machine is unavailable for several minutes.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
exactVersionbooleannofalseReimage to the image's exact resolved version rather than the newest one. Set true to avoid an unintended OS upgrade when the machine was created with version "latest".
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tempDiskbooleannofalseAlso reset the temporary disk. Valid only for a machine with an ephemeral OS disk.
vmNamestringyesThe virtual machine to REIMAGE. Everything on its OS disk is destroyed.

[Microsoft Azure] Restart a virtual machine. Destructive because it is a service interruption on a live customer machine: every session on it drops, anything running in memory is lost, and an application that does not survive a reboot cleanly may not come back. Confirm with a human before restarting production. The machine's disks, IP configuration and identity are unaffected. The operation is ASYNCHRONOUS — this returns immediately and the machine is unavailable for a minute or more; poll azure_get_vm_instance_view for PowerState/running.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine to RESTART. Every session on it drops.

[Microsoft Azure] Run a command INSIDE a customer's virtual machine, through the Azure guest agent. The script executes as SYSTEM on Windows and as root on Linux, with no prompt, no sandbox and no review by Azure — this is arbitrary code execution on a live machine, which is why it is marked destructive regardless of what the script happens to do. Always show the caller the exact script text and get explicit approval before calling. Prefer a built-in commandId from azure_list_vm_run_command_documents over free-form script where one fits, and read azure_get_vm_run_command_document first to learn which parameters it takes. The machine must be running with a healthy guest agent, output is truncated by Azure at roughly 4096 bytes per stream, and the call can take up to 90 minutes — use a managed run command instead for anything long. Returns ARM's value array of statuses carrying the combined stdout/stderr.

ParamTypeRequiredDefaultDescription
commandIdstringyesThe command id, e.g. RunPowerShellScript or RunShellScript — from azure_list_vm_run_command_documents.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
parametersJsonstringnonullParameters as a JSON array of {"name":...,"value":...} objects, matching the command document's parameter list.
resourceGroupNamestringyesThe resource group the machine lives in.
scriptstringnonullThe script text to execute, as the caller approved it. Newlines separate lines; Azure runs them as one script. Omit when the commandId is a built-in that needs no script.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine to RUN CODE ON, as SYSTEM or root.

[Microsoft Azure] Set the tags on a virtual machine, leaving every other property untouched. Not destructive: tags carry no access-control or workload semantics, nothing stops running and no data is lost. Note the REPLACE semantics — Microsoft.Compute treats the tags map as a single value, so any tag you omit is removed. Read the machine with azure_get_vm first and include everything you want to keep, or use the provider-agnostic azure_update_resource_tags with operation="Merge" when you only want to add one tag without knowing the rest.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringyesThe COMPLETE tag set as a JSON object, e.g. {"environment":"production","costCentre":"CC-1042"}. Omitted tags are removed.
vmNamestringyesThe virtual machine name.

[Microsoft Azure] Simulate the eviction of a SPOT virtual machine, so an owner can test that their workload survives being evicted. Destructive: this is not a dry run — the machine is really evicted, which means it is deallocated or deleted according to its own evictionPolicy, and in-memory work and temporary-disk contents are lost. Only valid on a spot machine (properties.priority == "Spot" on azure_get_vm); a regular machine returns an error. Check the machine's evictionPolicy before calling: an evictionPolicy of "Delete" means the simulated eviction DELETES it. The operation is ASYNCHRONOUS and returns immediately.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe SPOT virtual machine to really evict. If its evictionPolicy is "Delete", this deletes it.

[Microsoft Azure] Start (power on) a stopped or deallocated virtual machine. Not destructive — starting is purely additive: nothing on the machine is lost and no in-flight work is interrupted. The one consequence worth telling a caller about is cost: a deallocated machine is not billed for compute, and starting it resumes that billing. Starting a deallocated machine also reallocates it on a fresh host, so a dynamically-assigned public IP normally CHANGES; a static IP does not. The operation is ASYNCHRONOUS — this returns immediately and the machine takes up to a few minutes to reach PowerState/running; confirm with azure_get_vm_instance_view.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vmNamestringyesThe virtual machine name.

[Microsoft Azure] Update an existing virtual machine with a PATCH — the tool to use for a resize, a boot-diagnostics change, an identity change or a licence-type change. Not marked destructive: a property you omit at the TOP level is left alone, so this cannot silently wipe a machine's configuration the way a full replace can. Be aware that ARM merges only at the top level — a nested COLLECTION you do send, such as storageProfile.dataDisks, replaces the stored one entirely, so use azure_attach_vm_data_disks rather than patching the disk list by hand. A resize is the common case and has a real side effect: changing hardwareProfile.vmSize RESTARTS the machine, and if the new size is not on the current cluster Azure deallocates and reallocates it, which changes the dynamic IP. Confirm the size is offered by azure_list_vm_resize_options first. The operation is ASYNCHRONOUS: it returns immediately and continues in the background.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
identityJsonstringnonullManaged identity as a JSON object, e.g. {"type":"SystemAssigned"}.
propertiesJsonstringnonullThe properties to change, as a JSON object, e.g. {"hardwareProfile":{"vmSize":"Standard_D4s_v5"}}. Top-level properties you omit are preserved; a nested collection you send replaces the stored one.
resourceGroupNamestringyesThe resource group the machine lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object. REPLACES the machine's tag set — see azure_set_vm_tags.
vmNamestringyesThe virtual machine name.

Storage

ToolPlanAccessSummary
azure_check_storage_account_name_availabilityFreeRead-onlyCheck whether a storage account name is free BEFORE trying to create it.
azure_create_blob_containerProWriteCreate a blob container in a storage account.
azure_create_file_shareProWriteCreate an Azure Files share in a storage account.
azure_create_storage_accountProWriteCreate a new storage account.
azure_create_storage_queueProWriteCreate a Storage queue in an account.
azure_create_storage_tableProWriteCreate a Storage table in an account.
azure_delete_blob_containerProDestructiveDelete a blob container AND EVERY BLOB INSIDE IT.
azure_delete_file_shareProDestructiveDelete an Azure Files share AND EVERY FILE AND FOLDER INSIDE IT.
azure_delete_storage_accountProDestructiveDelete a storage account AND EVERYTHING INSIDE IT.
azure_delete_storage_queueProDestructiveDelete a Storage queue AND EVERY MESSAGE STILL IN IT.
azure_delete_storage_tableProDestructiveDelete a Storage table AND EVERY ROW IN IT.
azure_get_blob_containerFreeRead-onlyGet one blob container's ARM properties: publicAccess (None, Blob or Container — anything other than None means anonymous internet reads are possible), metadata, leaseStatus/leaseState/leaseDuration,…
azure_get_blob_service_propertiesFreeRead-onlyGet the account-wide Blob service settings: deleteRetentionPolicy (blob soft delete and its retention in days), containerDeleteRetentionPolicy (container soft delete — this is what decides whether…
azure_get_file_service_propertiesFreeRead-onlyGet the account-wide Azure Files settings: shareDeleteRetentionPolicy (share soft delete and its retention in days — this decides whether azure_delete_file_share is recoverable), protocolSettings.smb…
azure_get_file_shareFreeRead-onlyGet one Azure Files share's ARM properties: shareQuota (provisioned GiB), accessTier, enabledProtocols, rootSquash, leaseStatus, metadata, lastModifiedTime and etag.
azure_get_storage_accountFreeRead-onlyGet one storage account's full configuration: kind, sku, location, tags, accessTier, primaryEndpoints, encryption, minimumTlsVersion, allowBlobPublicAccess, allowSharedKeyAccess, publicNetworkAccess…
azure_get_storage_lifecycle_policyFreeRead-onlyGet the account's lifecycle management policy — the rule set that automatically tiers blobs to Cool or Archive and DELETES them after an age threshold.
azure_lease_blob_containerProDestructiveAcquire, renew, change, release or break a LEASE on a blob container.
azure_list_blob_containersFreeRead-onlyList the blob containers in a storage account, as ARM resources.
azure_list_file_sharesFreeRead-onlyList the Azure Files shares in a storage account, as ARM resources.
azure_list_storage_account_keysProDestructiveReturn the storage account's ROOT ACCESS KEYS in plain text.
azure_list_storage_account_usageFreeRead-onlyReport how many storage accounts the subscription has used against its per-region quota, as {value:[{unit, currentValue, limit, name:{value, localizedValue}}]}.
azure_list_storage_accountsFreeRead-onlyList every storage account in a subscription.
azure_list_storage_accounts_in_resource_groupFreeRead-onlyList the storage accounts inside ONE resource group, with the same fields as azure_list_storage_accounts.
azure_list_storage_queuesFreeRead-onlyList the Storage queues in an account.
azure_list_storage_skusFreeRead-onlyList the storage SKUs the subscription may deploy: each item carries name (Standard_LRS, Standard_GRS, Standard_ZRS, Premium_LRS, ...), tier, kind, the locations it is offered in, and a restrictions…
azure_list_storage_tablesFreeRead-onlyList the Storage tables in an account.
azure_regenerate_storage_account_keyProDestructiveRegenerate one of the storage account's root access keys.
azure_revoke_storage_user_delegation_keysProDestructiveRevoke ALL of the account's user delegation keys, invalidating every Microsoft Entra-signed shared access signature issued against it.
azure_set_blob_service_propertiesProWriteSet the account-wide Blob service settings — soft delete, container soft delete, versioning, change feed, point-in-time restore and CORS.
azure_set_file_service_propertiesProWriteSet the account-wide Azure Files settings — share soft delete and its retention, the SMB protocol settings (accepted versions, authentication methods, kerberos ticket encryption, channel encryption)…
azure_set_storage_account_network_rulesProWriteReplace the storage account's firewall (networkAcls) via PATCH.
azure_set_storage_lifecycle_policyProWriteSet the account's lifecycle management policy — the rules that automatically tier blobs to Cool or Archive and delete them past an age threshold.
azure_update_blob_containerProWriteUpdate an existing blob container's anonymous-access level or metadata via PATCH.
azure_update_file_shareProWriteUpdate an existing Azure Files share's quota, access tier or metadata via PATCH.
azure_update_storage_accountProWriteUpdate an existing storage account's SKU, tags or settings via PATCH.

[Microsoft Azure] Check whether a storage account name is free BEFORE trying to create it. Returns or {nameAvailable:false, reason, message} — reason is AccountNameInvalid for a name that breaks the rules (3-24 characters, lower-case letters and digits only, no hyphens) or AlreadyExists for a name someone else has already taken. Storage account names are globally unique across ALL of Azure, not just the tenant, so a perfectly reasonable name is often taken by a stranger. Read-only despite being an HTTP POST: it reserves nothing and changes nothing. Run this before azure_create_storage_account so a name clash is a clean answer rather than a failed create.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe candidate storage account name to test.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Create a blob container in a storage account. Not destructive: it adds an empty container and cannot overwrite an existing one — ARM answers 409 if the name is taken. Container names are 3-63 characters, lower-case letters, digits and hyphens, and must start with a letter or digit. publicAccess controls ANONYMOUS internet access and defaults to None, which is the safe value: "Blob" lets anyone who knows a blob's URL read that blob without credentials, and "Container" additionally lets anyone LIST the container's contents. Only choose either deliberately, and note they are ignored anyway if the account has allowBlobPublicAccess set to false. metadataJson attaches user-defined name/value pairs, e.g. {"owner":"helpdesk"}.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
containerNamestringyesThe new container name: 3-63 lower-case letters, digits and hyphens.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
metadataJsonstringnonullMetadata as a JSON object, e.g. {"owner":"helpdesk"}.
publicAccessstringno"None"Anonymous access level: None (default and safe), Blob (anonymous blob reads), or Container (anonymous reads AND listing).
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Create an Azure Files share in a storage account. Not destructive: it adds an empty share and cannot overwrite an existing one — ARM answers 409 if the name is taken. Share names are 3-63 characters, lower-case letters, digits and hyphens. quotaGiB is the share's maximum size in GiB: up to 5120 on a standard account (or up to 102400 if the account has large file shares enabled), and on a premium FileStorage account it is the PROVISIONED size that you are billed for whether or not it is used, so pick it deliberately. accessTier applies to standard accounts and trades cost against transaction price: TransactionOptimized, Hot or Cool. enabledProtocols is SMB (the default) or NFS; NFS requires a premium FileStorage account and cannot be changed after creation.

ParamTypeRequiredDefaultDescription
accessTierstringnonullStandard-account tier: TransactionOptimized, Hot or Cool.
accountNamestringyesThe storage account name.
enabledProtocolsstringnonullSMB (default) or NFS. NFS requires a premium FileStorage account and cannot be changed later.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
metadataJsonstringnonullMetadata as a JSON object, e.g. {"department":"finance"}.
quotaGiBintegernonullShare size in GiB. On a premium account this is provisioned capacity and is billed whether used or not.
resourceGroupNamestringyesThe resource group name that holds the account.
shareNamestringyesThe new share name: 3-63 lower-case letters, digits and hyphens.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Create a new storage account. Not destructive: it adds an empty account and cannot overwrite an existing one's data — ARM answers 409 if the name is taken. Check the name with azure_check_storage_account_name_availability first (names are globally unique across all of Azure, 3-24 lower-case letters and digits) and the sku/region pairing with azure_list_storage_skus. skuName is the redundancy setting and is the decision that matters most: Standard_LRS keeps three copies in one datacentre, Standard_ZRS spreads them across availability zones, Standard_GRS and Standard_RAGRS replicate to a paired region. kind should almost always be StorageV2. propertiesJson passes advanced settings through verbatim, e.g. {"minimumTlsVersion":"TLS1_2","allowBlobPublicAccess":false,"supportsHttpsTrafficOnly":true}. The create is ASYNCHRONOUS: this returns as soon as ARM accepts the request, the accepted response has no body and carries no tracking reference you can follow, and the account takes up to a minute to appear — confirm it with azure_get_storage_account.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe new account name: 3-24 characters, lower-case letters and digits only, globally unique.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
kindstringno"StorageV2"The account kind: StorageV2 (recommended), BlobStorage, BlockBlobStorage, FileStorage or Storage.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
propertiesJsonstringnonullAdvanced settings as a JSON object, e.g. {"minimumTlsVersion":"TLS1_2","allowBlobPublicAccess":false}.
resourceGroupNamestringyesThe resource group to create the account in. It must already exist.
skuNamestringyesThe redundancy SKU, e.g. Standard_LRS, Standard_ZRS, Standard_GRS, Premium_LRS — from azure_list_storage_skus.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object, e.g. {"environment":"production"}.

[Microsoft Azure] Create a Storage queue in an account. Not destructive: it adds an empty queue and cannot overwrite an existing one — ARM answers 409 if the name is taken. Queue names are 3-63 characters, lower-case letters, digits and hyphens, and must start and end with a letter or digit. This creates the queue only; sending and receiving MESSAGES is a data-plane operation and is deliberately outside this connector, so an application still needs its own credentials to use the queue. metadataJson attaches user-defined name/value pairs.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
metadataJsonstringnonullMetadata as a JSON object, e.g. {"app":"invoicing"}.
queueNamestringyesThe new queue name: 3-63 lower-case letters, digits and hyphens.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Create a Storage table in an account. Not destructive: it adds an empty table and cannot overwrite an existing one — ARM answers 409 if the name is taken. Table names are 3-63 alphanumeric characters and must start with a letter; hyphens are NOT allowed, which is the usual reason a name that works for a container is rejected here. This creates the table only; reading and writing ROWS is a data-plane operation and is deliberately outside this connector.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tableNamestringyesThe new table name: 3-63 alphanumeric characters, starting with a letter. No hyphens.

[Microsoft Azure] Delete a blob container AND EVERY BLOB INSIDE IT. DESTRUCTIVE: the whole container's contents go at once, and this connector cannot show you what they were — blob listing is on the data plane and deliberately out of scope, so nothing here can tell you how many blobs or how many gigabytes are about to be lost. Whether the deletion is recoverable depends entirely on the account: check azure_get_blob_service_properties, and if containerDeleteRetentionPolicy.enabled is false the delete is PERMANENT the moment it succeeds. A container under a legal hold or a locked immutability policy cannot be deleted at all and the call fails — azure_get_blob_container reports both flags. Ask a human before calling this on any container you did not just create.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
containerNamestringyesThe container to DELETE, along with every blob inside it.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete an Azure Files share AND EVERY FILE AND FOLDER INSIDE IT. DESTRUCTIVE: a share is usually a mapped network drive somebody depends on, so this both destroys data and breaks users mid-session, and this connector cannot show you what is inside — file listing is on the data plane and deliberately out of scope. Whether it is recoverable depends on the account: check azure_get_file_service_properties, and if shareDeleteRetentionPolicy.enabled is false the delete is PERMANENT immediately. azure_get_file_share with includeUsage true reports shareUsageBytes, which is the best available signal of how much data is at stake. Ask a human before calling this on any share you did not just create.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group name that holds the account.
shareNamestringyesThe file share to DELETE, along with every file and folder inside it.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a storage account AND EVERYTHING INSIDE IT. DESTRUCTIVE and normally irreversible: every blob, every file share and its files, every queue and its messages, and every table and its rows go with the account, and account-level soft delete is OFF unless someone explicitly enabled it. Container and blob soft-delete policies do NOT protect you here — they only cover deletions inside a surviving account. Before calling this, show the caller what will be lost: azure_list_blob_containers, azure_list_file_shares, azure_list_storage_queues and azure_list_storage_tables together enumerate the account's top-level contents, though none of them can see the data inside. The delete is asynchronous; a resource lock or an Azure Policy deny assignment blocks it outright.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account to DELETE, along with all blobs, files, queues and tables inside it.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a Storage queue AND EVERY MESSAGE STILL IN IT. DESTRUCTIVE and irreversible: queues have no soft delete, so the messages are gone the moment the call succeeds, and any application still writing to the queue starts failing. This connector CANNOT SEE the messages — queue contents are on the data plane and deliberately out of scope — so it cannot tell you whether the queue is empty or holds a backlog of unprocessed work. That blindness is the reason to be careful: confirm with whoever owns the application before deleting a queue you did not just create.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
queueNamestringyesThe queue to DELETE, along with every message still in it.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a Storage table AND EVERY ROW IN IT. DESTRUCTIVE and irreversible: tables have no soft delete, so every entity is gone the moment the call succeeds. This connector CANNOT SEE the rows — table contents are on the data plane and deliberately out of scope — so it cannot tell you whether the table is empty or holds years of application records, and azure_list_storage_tables reports names only. Storage tables are frequently used as an application's primary datastore, so treat a delete here as equivalent to dropping a database table in production: confirm with whoever owns the application first.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tableNamestringyesThe table to DELETE, along with every row in it.

[Microsoft Azure] Get one blob container's ARM properties: publicAccess (None, Blob or Container — anything other than None means anonymous internet reads are possible), metadata, leaseStatus/leaseState/leaseDuration, hasImmutabilityPolicy, hasLegalHold, immutableStorageWithVersioning, lastModifiedTime and etag. Returns no blobs and no blob content. Read this before azure_delete_blob_container: a container carrying a legal hold or a locked immutability policy cannot be deleted at all, and the delete will fail rather than partially succeed. A 404 means either the account or the container does not exist.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
containerNamestringyesThe blob container name, from azure_list_blob_containers.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get the account-wide Blob service settings: deleteRetentionPolicy (blob soft delete and its retention in days), containerDeleteRetentionPolicy (container soft delete — this is what decides whether azure_delete_blob_container is recoverable), isVersioningEnabled, changeFeed, restorePolicy (point-in-time restore), cors and defaultServiceVersion. Read this BEFORE deleting a container or a blob-bearing account: if containerDeleteRetentionPolicy.enabled is false, a delete is permanent immediately. These are settings only — no blob content is returned or reachable from this connector.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get the account-wide Azure Files settings: shareDeleteRetentionPolicy (share soft delete and its retention in days — this decides whether azure_delete_file_share is recoverable), protocolSettings.smb (the SMB versions, authentication methods, kerberos ticket encryption and channel encryption the account will accept) and cors. The SMB protocol settings are the usual cause of a client that can mount a share from one machine but not another. Settings only — no file content is returned or reachable from this connector.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one Azure Files share's ARM properties: shareQuota (provisioned GiB), accessTier, enabledProtocols, rootSquash, leaseStatus, metadata, lastModifiedTime and etag. Set includeUsage to true to also return shareUsageBytes — the actual consumed capacity, which is the number you need before shrinking a quota, because Azure refuses a quota below current usage. Returns no files and no file content. A 404 means either the account or the share does not exist; a soft-deleted share is not returned here at all — use azure_list_file_shares with expand "deleted" to see it.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
includeUsagebooleannofalseTrue to also return shareUsageBytes, the share's actual consumed capacity.
resourceGroupNamestringyesThe resource group name that holds the account.
shareNamestringyesThe file share name, from azure_list_file_shares.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one storage account's full configuration: kind, sku, location, tags, accessTier, primaryEndpoints, encryption, minimumTlsVersion, allowBlobPublicAccess, allowSharedKeyAccess, publicNetworkAccess and the networkAcls firewall rules. This is also how you READ the account's network rules — there is no separate get-network-rules tool, because ARM returns them inside properties.networkAcls here. Set expand to geoReplicationStats for the geo-redundancy lag of a GRS account, or blobRestoreStatus for an in-flight point-in-time restore. Returns NO keys and NO account contents. A 404 means no account of that name exists in that resource group; storage account names are globally unique, lower-case letters and digits only, 3-24 characters.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name (3-24 lower-case letters and digits).
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullOptional extra detail: "geoReplicationStats" or "blobRestoreStatus".
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get the account's lifecycle management policy — the rule set that automatically tiers blobs to Cool or Archive and DELETES them after an age threshold. Returns properties.policy.rules, each with a filter (blob prefixes and blob types) and actions (tierToCool, tierToArchive, delete, with daysAfterModificationGreaterThan / daysAfterLastAccessTimeGreaterThan). Read this before investigating "our files vanished": a delete action here removes data on a schedule with no further prompt, and it is the single most common cause of unexplained blob loss in a healthy account. A 404 is a legitimate empty answer meaning no policy is configured, not an error.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Acquire, renew, change, release or break a LEASE on a blob container. A lease is an exclusive write lock: while one is held, only the holder of the lease id may delete the container, and Acquire will fail for anyone else. Marked DESTRUCTIVE because two of its actions interfere with something already running — Break forcibly ends a lease another process is holding, and Release drops it — which can let a delete or a reconfiguration through that the lease existed precisely to prevent, or make the holder's next operation fail. action must be Acquire, Renew, Change, Release or Break. Acquire returns the leaseId you must supply for Renew, Change and Release; leaseDuration is 15-60 seconds, or -1 for an infinite lease. Break takes an optional breakPeriod in seconds. Note this is the CONTAINER lease, not a blob lease — blob leases live on the data plane and are out of scope here.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
actionstringyesThe lease action: Acquire, Renew, Change, Release or Break.
breakPeriodintegernonullFor Break only: seconds to let the existing lease run before it ends.
containerNamestringyesThe blob container name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
leaseDurationintegernonullLease length in seconds for Acquire: 15-60, or -1 for infinite.
leaseIdstringnonullThe current lease id (a GUID). Required for Renew, Change and Release.
proposedLeaseIdstringnonullThe new lease id to propose, for Acquire or Change.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the blob containers in a storage account, as ARM resources. Each item carries name, etag and a properties block with publicAccess, lastModifiedTime, leaseStatus, leaseState, leaseDuration, hasImmutabilityPolicy, hasLegalHold and metadata. It does NOT list the blobs inside a container — blob content is on the data plane and is deliberately outside this connector. namePrefix filters to containers whose name starts with that string (it is a prefix match, not a substring search); set includeDeleted to true to also see soft-deleted containers still inside their retention window, which is how you confirm whether a deleted container can still be restored. A 404 means the storage account does not exist; an empty {value:[]} means it has no containers.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
includeDeletedbooleannofalseTrue to also return soft-deleted containers still within their retention window.
maxItemsintegerno1000Maximum containers to return (1-1000, default 1000).
namePrefixstringnonullReturn only containers whose name STARTS WITH this string. Omit for all containers.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the Azure Files shares in a storage account, as ARM resources. Each item carries name, etag and a properties block with shareQuota (the provisioned size in GiB), accessTier, enabledProtocols (SMB or NFS), leaseStatus, lastModifiedTime and metadata. It does NOT list the files inside a share — file content is on the data plane and is deliberately outside this connector. namePrefix is a prefix match on the share name. Set expand to "deleted" to include soft-deleted shares still inside their retention window, "snapshots" to include share snapshots, or "deleted,snapshots" for both. An empty {value:[]} on a real account simply means it has no file shares — many blob-only accounts do not.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullExtra items to include: "deleted", "snapshots", or "deleted,snapshots".
maxItemsintegerno1000Maximum shares to return (1-1000, default 1000).
namePrefixstringnonullReturn only shares whose name STARTS WITH this string. Omit for all shares.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Return the storage account's ROOT ACCESS KEYS in plain text. Understand exactly what this hands the caller: each key grants FULL read, write and delete access to every blob, every file, every queue and every table in the account, from anywhere the account firewall allows, with no Microsoft Entra sign-in, no role assignment, no MFA and no per-user audit trail. A leaked key is equivalent to handing over the whole account, and it stays valid until someone regenerates it. Marked DESTRUCTIVE even though it mutates nothing, because it DISCLOSES a credential — that classification is deliberate and must not be "fixed" to read-only. Do not include the key in a chat transcript, a ticket or a log. Prefer Entra-based access (a role assignment) wherever the consumer supports it; if a key really must be shared, plan the rotation before you disclose it. Set includeKerberosKeys to also return kerb1/kerb2 on an account with Active Directory authentication enabled.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account whose ROOT KEYS will be disclosed.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
includeKerberosKeysbooleannofalseTrue to also return the Kerberos keys (kerb1/kerb2) on an AD-joined account.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Report how many storage accounts the subscription has used against its per-region quota, as {value:[{unit, currentValue, limit, name:{value, localizedValue}}]}. This is the QUOTA surface, not a consumption or capacity report — it answers "can we still create a storage account in this region?", not "how many gigabytes are stored". Check it when azure_create_storage_account fails with a SubscriptionMaximumStorageAccountsExceeded-style error. Requires a region name from azure_list_locations.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every storage account in a subscription. Each item carries id, name, location, kind (StorageV2, BlobStorage, FileStorage), sku.name (the redundancy setting, e.g. Standard_LRS or Standard_GRS), tags and a properties block with primaryEndpoints, accessTier, provisioningState, allowBlobPublicAccess, minimumTlsVersion, supportsHttpsTrafficOnly and networkAcls. This is the account INVENTORY — it never touches account contents. Requires a subscription id from azure_list_subscriptions; a 403 means the signed-in user has no Reader role on that subscription. Returns ARM's {value:[...]} envelope, up to 1000 accounts across 10 pages per call, with nextLink when more remain.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum storage accounts to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the storage accounts inside ONE resource group, with the same fields as azure_list_storage_accounts. Prefer this when the caller already knows the group — it is a single narrow call, where the subscription-wide list can return hundreds of accounts. A 404 means the resource group itself does not exist in that subscription (often a sign the caller meant a CUSTOMER's directory and omitted entraTenant); an empty {value:[]} means the group exists but holds no storage accounts.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum storage accounts to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name, from azure_list_resource_groups.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the Storage queues in an account. METADATA ONLY: each item carries the queue's name, ARM id and user-defined metadata key/value pairs. It does NOT return queue MESSAGES, message counts or message content — those are on the data plane and are deliberately outside this connector, so this tool cannot tell you whether a queue is backed up. Use it to inventory queues, to find one an application is misconfigured against, or to identify orphaned queues before deleting them. namePrefix is a prefix match on the queue name.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum queues to return (1-1000, default 1000).
namePrefixstringnonullReturn only queues whose name STARTS WITH this string. Omit for all queues.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the storage SKUs the subscription may deploy: each item carries name (Standard_LRS, Standard_GRS, Standard_ZRS, Premium_LRS, ...), tier, kind, the locations it is offered in, and a restrictions array explaining any region or quota block. Read this before azure_create_storage_account so the sku and region you pick are actually available to this subscription — a wrong pairing fails the create with an unhelpful 400. The list runs to several hundred entries; lower maxItems when you only need to confirm one SKU.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum SKUs to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the Storage tables in an account. METADATA ONLY: each item carries the table's name, ARM id and any stored access policies (signedIdentifiers). It does NOT return table ROWS, entities, row counts or any customer data — those are on the data plane and are deliberately outside this connector. Use it to inventory tables and to identify orphaned ones before deleting them; note that this tool cannot tell you whether a table still holds data, so confirm with the owning application before calling azure_delete_storage_table.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum tables to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Regenerate one of the storage account's root access keys. DESTRUCTIVE on two counts. First, it BREAKS every existing consumer of that key IMMEDIATELY and without warning — applications, backup jobs, Functions and Logic Apps holding connection strings, mounted SMB drives, and every shared access signature that was signed with it. Failures appear as 403 AuthenticationFailed from that moment, and there is no undo: the old key value is gone for good. Second, the response CONTAINS both keys in plain text, so this discloses a credential exactly as azure_list_storage_account_keys does. The safe procedure is the two-key rotation: confirm every consumer is using key1, regenerate key2, move the consumers to key2, then regenerate key1. Inventory the consumers before you call this — Azure will not tell you who was using the key. keyName must be key1, key2, kerb1 or kerb2; kerb1/kerb2 exist only on an account with Active Directory authentication enabled.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account whose key will be replaced.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
keyNamestringyesWhich key to regenerate: key1, key2, kerb1 or kerb2. Every current consumer of that key stops working.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Revoke ALL of the account's user delegation keys, invalidating every Microsoft Entra-signed shared access signature issued against it. DESTRUCTIVE: this is a blunt, account-wide instrument with no way to revoke a single SAS — every identity-based SAS anyone has handed out for this account stops working at once, and any application or partner relying on one starts failing with 403. It is the correct emergency response to a leaked user delegation SAS, and the wrong tool for routine cleanup. Note what it does NOT do: account-key-signed SAS tokens are unaffected, because they derive from the root keys — for those, use azure_regenerate_storage_account_key instead. Returns an empty body on success.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account whose Entra-signed SAS tokens will ALL be invalidated.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Set the account-wide Blob service settings — soft delete, container soft delete, versioning, change feed, point-in-time restore and CORS. Not destructive: this is a settings change and deletes no data. It is normally used to make an account SAFER, by turning soft delete on. Read the current settings with azure_get_blob_service_properties first, because this PUT replaces the properties object: omitting deleteRetentionPolicy on an account that had soft delete enabled TURNS IT OFF, which quietly removes the safety net protecting future deletions. Example propertiesJson: {"deleteRetentionPolicy":{"enabled":true,"days":30},"containerDeleteRetentionPolicy":{"enabled":true,"days":30},"isVersioningEnabled":true}.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
propertiesJsonstringyesThe COMPLETE Blob service properties object as JSON, e.g. {"deleteRetentionPolicy":{"enabled":true,"days":30}}. Omitted settings revert to their defaults.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Set the account-wide Azure Files settings — share soft delete and its retention, the SMB protocol settings (accepted versions, authentication methods, kerberos ticket encryption, channel encryption) and CORS. Not destructive: this is a settings change and deletes no file data. It is normally used to make an account SAFER, by turning share soft delete on. Read the current settings with azure_get_file_service_properties first, because this PUT replaces the properties object: omitting shareDeleteRetentionPolicy on an account that had share soft delete enabled TURNS IT OFF, which is what decides whether a later azure_delete_file_share is recoverable — the safety net disappears silently and nothing reports it. Be equally careful with protocolSettings.smb: narrowing the accepted SMB versions or authentication methods can disconnect clients that mount these shares today, which looks like an outage rather than a settings change. Example propertiesJson: {"shareDeleteRetentionPolicy":{"enabled":true,"days":30}}.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
propertiesJsonstringyesThe COMPLETE File service properties object as JSON, e.g. {"shareDeleteRetentionPolicy":{"enabled":true,"days":30}}. Omitted settings revert to their defaults.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Replace the storage account's firewall (networkAcls) via PATCH. Not destructive — nothing is deleted and no data is touched — but treat it with the same care as one: a wrong rule set CUTS OFF ACCESS to a live account for every application, backup job and user outside the addresses you allow, and it takes effect within a minute. The most common way to lock yourself out is setting defaultAction to Deny without listing the caller's own public IP, or without bypass "AzureServices" for the Azure platform services that need in. Read the current rules with azure_get_storage_account (properties.networkAcls) first: this call REPLACES the whole networkAcls object, so any ipRules or virtualNetworkRules you omit are removed. Example networkAclsJson: {"defaultAction":"Deny","bypass":"AzureServices,Logging,Metrics","ipRules":[{"value":"203.0.113.4","action":"Allow"}],"virtualNetworkRules":[]}.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
networkAclsJsonstringyesThe COMPLETE networkAcls object as JSON, e.g. {"defaultAction":"Deny","bypass":"AzureServices","ipRules":[{"value":"203.0.113.4","action":"Allow"}]}. Anything omitted is removed.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Set the account's lifecycle management policy — the rules that automatically tier blobs to Cool or Archive and delete them past an age threshold. The call itself is a settings write and deletes nothing, so it is not marked destructive, but READ THE CONSEQUENCE: a rule containing a delete action will permanently remove matching blobs on Azure's schedule, starting within about 24 hours, with no further prompt and no per-blob confirmation. Get the current policy with azure_get_storage_lifecycle_policy first — this PUT REPLACES the entire rule set. Confirm the account's soft-delete settings with azure_get_blob_service_properties before adding any delete action, so a mistaken filter is recoverable. Example policyJson: {"rules":[{"enabled":true,"name":"archive-logs","type":"Lifecycle","definition":{"filters":{"blobTypes":["blockBlob"],"prefixMatch":["logs/"]},"actions":{"baseBlob":{"tierToCool":{"daysAfterModificationGreaterThan":30}}}}}]}.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
policyJsonstringyesThe COMPLETE policy object as JSON, e.g. {"rules":[...]}. It REPLACES every existing rule.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Update an existing blob container's anonymous-access level or metadata via PATCH. Not destructive: no blobs are touched and the container is not replaced. The common and important use is REMEDIATION — setting publicAccess to None on a container that was left open to anonymous internet reads. Going the other way (None to Blob or Container) exposes the container's blobs to anyone on the internet who knows or can guess the URL, so make that change only on explicit instruction. Supplying metadataJson replaces the container's metadata set; omit it to leave metadata alone.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
containerNamestringyesThe blob container name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
metadataJsonstringnonullMetadata as a JSON object. Supplying it REPLACES the container's metadata set.
publicAccessstringnonullNew anonymous access level: None, Blob or Container. Omit to leave it unchanged.
resourceGroupNamestringyesThe resource group name that holds the account.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Update an existing Azure Files share's quota, access tier or metadata via PATCH. Not destructive: it is a partial update, no files are touched, and the share is not replaced. Growing a quota is safe and takes effect immediately. SHRINKING one is where care is needed: Azure refuses a quota below the share's current usage, so read shareUsageBytes with azure_get_file_share (includeUsage true) first — and a quota set just above current usage will start failing writes for users as soon as the share grows into it. Changing accessTier on a standard account re-rates both storage and transaction costs and can trigger a one-off charge. enabledProtocols cannot be changed after creation.

ParamTypeRequiredDefaultDescription
accessTierstringnonullNew standard-account tier: TransactionOptimized, Hot or Cool. Omit to leave it unchanged.
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
metadataJsonstringnonullMetadata as a JSON object. Supplying it REPLACES the share's metadata set.
quotaGiBintegernonullNew share size in GiB. Azure refuses a value below the share's current usage.
resourceGroupNamestringyesThe resource group name that holds the account.
shareNamestringyesThe file share name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Update an existing storage account's SKU, tags or settings via PATCH. Not destructive: it is a partial update — anything you omit is left alone, no data is touched, and an account's location and name can never change. Common uses are retiering (accessTier Hot to Cool via propertiesJson), tightening TLS, or turning off anonymous blob access. Be aware that some settings have real blast radius even though nothing is deleted: setting allowSharedKeyAccess to false immediately breaks every application authenticating with an account key, and lowering minimumTlsVersion requirements can break older clients. Pass propertiesJson verbatim, e.g. {"accessTier":"Cool","allowBlobPublicAccess":false}. To change the firewall specifically, prefer azure_set_storage_account_network_rules.

ParamTypeRequiredDefaultDescription
accountNamestringyesThe storage account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
propertiesJsonstringnonullSettings to change as a JSON object, e.g. {"accessTier":"Cool","minimumTlsVersion":"TLS1_2"}.
resourceGroupNamestringyesThe resource group name that holds the account.
skuNamestringnonullA new redundancy SKU, e.g. Standard_GRS. Omit to leave the SKU unchanged.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object. On this PATCH the supplied tag object REPLACES the account's tag set.

Networking

ToolPlanAccessSummary
azure_check_vnet_ip_availabilityFreeRead-onlyCheck whether a specific private IP address is free in a virtual network, and get suggested alternatives when it is not.
azure_create_network_security_groupProWriteCreate an empty network security group, or update its tags.
azure_create_nsg_ruleProDestructiveCreate or replace a security rule in a network security group.
azure_create_public_ip_addressProWriteCreate a public IP address resource, or replace an existing one's definition.
azure_create_routeProDestructiveCreate or replace a route in a route table.
azure_create_route_tableProWriteCreate an empty route table, or update its tags and BGP setting.
azure_create_subnetProWriteCreate a subnet in a virtual network, or replace an existing one.
azure_create_virtual_networkProWriteCreate a virtual network, or replace an existing one's definition.
azure_create_vnet_peeringProWriteCreate a peering from this virtual network to another.
azure_delete_network_interfaceProDestructiveDelete a network interface.
azure_delete_network_security_groupProDestructiveDelete a network security group and every rule in it.
azure_delete_nsg_ruleProDestructiveDelete a security rule from a network security group.
azure_delete_public_ip_addressProDestructiveDelete a public IP address resource.
azure_delete_routeProDestructiveDelete a route from a route table.
azure_delete_subnetProDestructiveDelete a subnet from a virtual network.
azure_delete_virtual_networkProDestructiveDelete a virtual network and every subnet inside it.
azure_delete_vnet_peeringProDestructiveDelete a peering.
azure_get_application_gatewayFreeRead-onlyGet one application gateway in full, including every listener, rule, backend setting, probe, rewrite rule set and certificate's metadata.
azure_get_application_gateway_backend_healthFreeRead-onlyAsk an application gateway how it currently sees each of its backend servers: per pool and per HTTP setting, every server's address with a health status of Healthy, Unhealthy, Partial, Draining or…
azure_get_azure_firewallFreeRead-onlyGet one Azure Firewall in full, including every inline rule collection with its priority and action, the private IP the firewall answers on, and its provisioning state.
azure_get_load_balancerFreeRead-onlyGet one load balancer in full: frontends, backend pools, rules, health probes, NAT rules and outbound rules.
azure_get_network_interfaceFreeRead-onlyGet one network interface in full: every IP configuration with its private address and allocation method, the subnet and public IP resource ids, the NSG attached to the NIC itself, applied DNS…
azure_get_network_security_groupFreeRead-onlyGet one network security group with every rule and every attachment.
azure_get_nsg_ruleFreeRead-onlyGet one security rule by name.
azure_get_public_ip_addressFreeRead-onlyGet one public IP address resource: its SKU and tier, allocation method, the assigned ipAddress, idleTimeoutInMinutes, DNS label and FQDN, availability zones, and the ipConfiguration it is attached…
azure_get_route_tableFreeRead-onlyGet one route table with its full routes array and the list of subnets it is attached to.
azure_get_subnetFreeRead-onlyGet one subnet: its address prefix, attached network security group and route table, service endpoints, delegations and private-endpoint policies.
azure_get_virtual_networkFreeRead-onlyGet one virtual network in full: address space, every subnet with its prefix, attached network security group, route table, service endpoints and delegations, plus peerings, DNS servers and DDoS…
azure_get_virtual_network_gatewayFreeRead-onlyGet one virtual network gateway in full: type, SKU and generation, active-active state, BGP settings including the ASN and the peering addresses, the gateway subnet's IP configurations, and any…
azure_get_vnet_peeringFreeRead-onlyGet one peering by name, including its peeringState and the four traffic flags.
azure_list_application_gatewaysFreeRead-onlyList every application gateway in a subscription: its sku and capacity or autoscale range, operationalState, frontend IP and port configurations, HTTP listeners, backend pools and settings, request…
azure_list_azure_firewallsFreeRead-onlyList every Azure Firewall in a subscription: its sku tier (Standard, Premium or Basic), threatIntelMode, the firewallPolicy it draws rules from when policy-managed, its ipConfigurations and…
azure_list_bastion_hostsFreeRead-onlyList every Azure Bastion host in a subscription, with its sku, scaleUnits, the AzureBastionSubnet and public IP it uses, and the feature flags — enableTunneling, enableIpConnect, enableShareableLink…
azure_list_express_route_circuitsFreeRead-onlyList every ExpressRoute circuit in a subscription, with its serviceProviderProperties (the carrier, peering location and bandwidth), the sku tier and family, and — the two fields to read first —…
azure_list_load_balancer_backend_poolsFreeRead-onlyList a load balancer's backend address pools with their full membership — every NIC ip configuration or explicit IP address in each pool.
azure_list_load_balancersFreeRead-onlyList every load balancer in a subscription with its sku (Basic or Standard), frontendIPConfigurations (the addresses it answers on, public or private), backendAddressPools, loadBalancingRules, probes,…
azure_list_network_interfacesFreeRead-onlyList every network interface (NIC) in a subscription.
azure_list_network_interfaces_in_resource_groupFreeRead-onlyList the network interfaces inside one resource group.
azure_list_network_security_groupsFreeRead-onlyList every network security group in a subscription.
azure_list_network_security_groups_in_resource_groupFreeRead-onlyList the network security groups inside one resource group.
azure_list_network_watchersFreeRead-onlyList the Network Watcher resources in a subscription.
azure_list_nic_effective_nsg_rulesFreeRead-onlyShow the security rules that are ACTUALLY in force on one network interface — Azure's own evaluation of the NIC's NSG combined with the subnet's NSG, in priority order, including the built-in default…
azure_list_nic_effective_routesFreeRead-onlyShow the routing table that is ACTUALLY in force on one network interface: Azure's system routes, routes learned over BGP from a VPN or ExpressRoute gateway, and any user-defined routes from an…
azure_list_nsg_rulesFreeRead-onlyList the ADMIN-DEFINED security rules in a network security group.
azure_list_public_ip_addressesFreeRead-onlyList every public IP address resource in a subscription, with its sku (Basic or Standard), publicIPAllocationMethod (Static or Dynamic), the ipAddress currently assigned, the dnsSettings FQDN if one…
azure_list_route_tablesFreeRead-onlyList every route table in a subscription, each with its routes array (address prefix, next hop type, next hop IP), the subnets it is attached to, and disableBgpRoutePropagation.
azure_list_routesFreeRead-onlyList the individual routes in one route table, each with addressPrefix, nextHopType and, for a virtual-appliance hop, nextHopIpAddress.
azure_list_subnetsFreeRead-onlyList the subnets in a virtual network.
azure_list_virtual_network_gatewaysFreeRead-onlyList the virtual network gateways in one resource group — the VPN and ExpressRoute gateways that connect a virtual network to on-premises or to other networks.
azure_list_virtual_network_usageFreeRead-onlyReport how many private IP addresses each subnet in a virtual network has consumed, with currentValue and limit per subnet.
azure_list_virtual_networksFreeRead-onlyList every virtual network in a subscription, across all resource groups.
azure_list_virtual_networks_in_resource_groupFreeRead-onlyList the virtual networks inside one resource group.
azure_list_vnet_peeringsFreeRead-onlyList the peerings on a virtual network — the links that let two networks route to each other directly.
azure_list_vpn_connectionsFreeRead-onlyList the gateway connections in one resource group — the site-to-site VPN tunnels, VNet-to-VNet links and ExpressRoute circuit connections.
azure_run_connectivity_checkFreeRead-onlyActually TEST reachability from a virtual machine to another Azure resource or to any address and port, and get the full hop-by-hop path back with latency and, at each hop, what allowed or blocked the…
azure_run_ip_flow_verifyFreeRead-onlyAsk Azure whether a specific packet would be allowed or denied to a specific virtual machine, and WHICH security rule decides it.
azure_run_next_hopFreeRead-onlyAsk Azure where traffic from a virtual machine to a given destination address would actually go NEXT, and which route decides it.
azure_start_application_gatewayProWriteStart a stopped application gateway.
azure_stop_application_gatewayProDestructiveStop an application gateway.
azure_update_network_security_group_tagsProWriteUpdate a network security group's tags via PATCH, leaving every rule and attachment untouched.
azure_update_virtual_network_tagsProWriteUpdate a virtual network's tags via PATCH, leaving its address space, subnets and peerings untouched.

[Microsoft Azure] Check whether a specific private IP address is free in a virtual network, and get suggested alternatives when it is not. Returns {available:true|false, availableIPAddresses:[...]}. Use it before pinning a static IP on a NIC or a load balancer front end — Azure rejects a duplicate at write time with an error that does not say which resource already holds the address, and this call answers that question in advance. Note it reports availability within the VNET's address space, so an address outside every subnet prefix reports unavailable rather than raising an error.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
ipAddressstringyesThe private IPv4 address to test, e.g. 10.0.1.15.
resourceGroupNamestringyesThe resource group the network lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
virtualNetworkNamestringyesThe virtual network name.

[Microsoft Azure] Create an empty network security group, or update its tags. Not destructive as used here: a new NSG carries only Azure's default rules and is attached to nothing, so it filters no traffic until a subnet or NIC is pointed at it. Deliberately does NOT take a rules array — rules are managed one at a time through azure_create_nsg_rule so that each security-boundary change is an explicit, individually-reviewable call rather than a bulk replace that could silently drop existing rules. Creating an NSG changes nothing on its own; attaching it does, via azure_create_subnet.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
networkSecurityGroupNamestringyesThe network security group name to create.
resourceGroupNamestringyesThe resource group to create the NSG in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object, e.g. {"environment":"production"}.

[Microsoft Azure] Create or replace a security rule in a network security group. DESTRUCTIVE DESPITE CREATING NOTHING DESTRUCTIVE-SOUNDING: this is a security-boundary change that takes effect within seconds across every subnet and NIC the NSG is attached to, and Azure raises no alert about it. An Allow rule with sourceAddressPrefix "*" or "Internet" on port 3389 or 22 exposes every machine in scope to the whole internet — the single most damaging call in this family. It is also a PUT: replacing an existing rule name discards every field you do not send, so read azure_get_nsg_rule first. Priority is 100-4096 and lower wins; a new rule at a lower priority than an existing deny silently overrides it. Confirm the intent with a human before opening anything inbound from outside the customer's own address space.

ParamTypeRequiredDefaultDescription
accessstringyesAccess: Allow or Deny.
descriptionstringnonullFree-text description of why this rule exists — worth setting, it is the only audit trail on a rule.
destinationAddressPrefixstringno"*"Destination address prefix: a CIDR, an IP, a service tag, or * for any.
destinationPortRangestringno"*"Destination port range, e.g. 443, 80-8080, or * for any.
directionstringyesDirection: Inbound or Outbound.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
networkSecurityGroupNamestringyesThe network security group name.
priorityintegeryesPriority, 100-4096. LOWER WINS and the first match ends evaluation.
protocolstringyesProtocol: Tcp, Udp, Icmp, Esp, Ah or * for any.
resourceGroupNamestringyesThe resource group the NSG lives in.
ruleNamestringyesThe rule name to create or replace.
sourceAddressPrefixstringno"*"Source address prefix: a CIDR, an IP, a service tag such as Internet or VirtualNetwork, or * for ANY. Defaults to * — be explicit.
sourcePortRangestringno"*"Source port range, e.g. * or 1024-65535.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Create a public IP address resource, or replace an existing one's definition. Not destructive when creating: a new address is attached to nothing and routes no traffic until something references it. Two constraints Azure enforces and reports badly: a Standard-SKU address MUST be Static (Dynamic is rejected), and the dnsSettings label must be globally unique within the region, so a taken label fails with a conflict rather than a name suggestion. Standard is the right default — it is zone-redundant and Basic is retired for new deployments. This is a PUT, so replacing an existing resource discards fields you do not send, and changing the allocation method of an in-use address is what actually releases and reassigns it.

ParamTypeRequiredDefaultDescription
addressVersionstringno"IPv4"IP version: IPv4 or IPv6.
allocationMethodstringno"Static"Allocation: Static or Dynamic. Standard SKU requires Static.
domainNameLabelstringnonullOptional DNS label, e.g. contoso-vpn — becomes label.region.cloudapp.azure.com and must be globally unique in the region.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
idleTimeoutInMinutesintegerno4Idle timeout in minutes, 4-30.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
publicIpAddressNamestringyesThe public IP address resource name to create or replace.
resourceGroupNamestringyesThe resource group to create the address in.
skustringno"Standard"SKU: Standard (recommended, must be Static) or Basic (retired for new deployments).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object, e.g. {"environment":"production"}.

[Microsoft Azure] Create or replace a route in a route table. DESTRUCTIVE DESPITE CREATING SOMETHING, for the same reason an NSG rule write is: this redirects live traffic across every subnet the table is attached to, within seconds, with no alert anywhere in Azure. A 0.0.0.0/0 route with nextHopType "None" black-holes ALL outbound traffic from those subnets — including the management path you are using — and one pointing at a virtual appliance that is down does the same thing less obviously. Adding a route that covers the subnet you are connected from can lock you out of the machines in it. nextHopIpAddress is only valid, and is required, when nextHopType is VirtualAppliance. Azure matches the longest prefix, so a /32 overrides a broader route regardless of order.

ParamTypeRequiredDefaultDescription
addressPrefixstringyesDestination CIDR this route applies to, e.g. 0.0.0.0/0 or 10.50.0.0/16.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
nextHopIpAddressstringnonullThe appliance's private IP. Required for VirtualAppliance, rejected for every other next hop type.
nextHopTypestringyesNext hop: VirtualAppliance, VirtualNetworkGateway, VnetLocal, Internet or None.
resourceGroupNamestringyesThe resource group the route table lives in.
routeNamestringyesThe route name to create or replace.
routeTableNamestringyesThe route table name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Create an empty route table, or update its tags and BGP setting. Not destructive as used here: a new table holds no routes and is attached to no subnet, so it changes nothing until azure_create_route adds an entry and a subnet is pointed at it through azure_create_subnet. Deliberately does NOT take a routes array — routes are added one at a time so each traffic-path change is individually reviewable rather than hidden inside a bulk replace. Setting disableBgpRoutePropagation to true on an EXISTING table is the one sharp edge here: it immediately stops every attached subnet from learning on-premises routes over VPN or ExpressRoute.

ParamTypeRequiredDefaultDescription
disableBgpRoutePropagationbooleannofalseSet true to stop attached subnets learning routes over BGP from a VPN or ExpressRoute gateway. Leave false unless that is the intent.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
resourceGroupNamestringyesThe resource group to create the route table in.
routeTableNamestringyesThe route table name to create or replace.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object, e.g. {"environment":"production"}.

[Microsoft Azure] Create a subnet in a virtual network, or replace an existing one. Not destructive when CREATING: it carves an unused range out of the network's address space. UPDATING carries the connector's sharpest silent trap and is why azure_get_subnet exists — this is a PUT that REPLACES the properties object, so omitting networkSecurityGroupId DETACHES the NSG and leaves the subnet with no filtering, and omitting routeTableId removes forced tunnelling, sending traffic that was going through a firewall straight out instead. Neither raises an error; both take effect immediately. Always read the subnet first and pass back every value you are not deliberately changing. The address prefix must sit inside the virtual network's address space and must not overlap another subnet.

ParamTypeRequiredDefaultDescription
addressPrefixstringyesThe subnet CIDR, e.g. 10.0.1.0/24. Must sit inside the VNet address space and not overlap another subnet.
delegationsJsonstringnonullDelegations as a JSON array, e.g. [{"name":"aks","properties":{"serviceName":"Microsoft.ContainerService/managedClusters"}}].
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
networkSecurityGroupIdstringnonullFull ARM resource id of the NSG to attach. OMITTING THIS ON AN UPDATE DETACHES the existing NSG.
resourceGroupNamestringyesThe resource group the network lives in.
routeTableIdstringnonullFull ARM resource id of the route table to attach. OMITTING THIS ON AN UPDATE DETACHES the existing one.
serviceEndpointsJsonstringnonullService endpoints as a JSON array, e.g. [{"service":"Microsoft.Storage"}].
subnetNamestringyesThe subnet name to create or replace.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
virtualNetworkNamestringyesThe virtual network name.

[Microsoft Azure] Create a virtual network, or replace an existing one's definition. Not destructive when CREATING: a new network is an empty container. UPDATING is a different matter and the reason to read azure_get_virtual_network first — this is a PUT with no partial-update option, so the properties object you send REPLACES what is there. Omitting the subnets array from an existing network is rejected while resources occupy it, but omitting a subnet's networkSecurityGroup or routeTable silently DETACHES them, removing a firewall or a forced-tunnel route without any error. Supply addressPrefixes as a JSON array, e.g. ["10.0.0.0/16"], and subnets as a JSON array, e.g. [{"name":"web","properties":{"addressPrefix":"10.0.1.0/24"}}]. Address space cannot overlap a network this one is peered with.

ParamTypeRequiredDefaultDescription
addressPrefixesJsonstringyesAddress prefixes as a JSON array, e.g. ["10.0.0.0/16"].
dnsServersJsonstringnonullDNS server IPs as a JSON array, e.g. ["10.0.0.4"]. Omit to use Azure-provided DNS.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
resourceGroupNamestringyesThe resource group to create the network in.
subnetsJsonstringnonullSubnets as a JSON array, e.g. [{"name":"web","properties":{"addressPrefix":"10.0.1.0/24"}}]. REPLACES the existing set.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object, e.g. {"environment":"production"}.
virtualNetworkNamestringyesThe virtual network name to create or replace.

[Microsoft Azure] Create a peering from this virtual network to another. Not destructive: it adds a route between two networks and removes nothing. THE CRITICAL DETAIL — a peering is ONE-DIRECTIONAL as an object and must be created on BOTH networks before any traffic flows. Creating only this side leaves peeringState=Initiated and nothing works, which reads like a broken peering rather than a half-finished one, so plan the second call before making the first. The two address spaces must NOT overlap; Azure rejects an overlapping peering. allowGatewayTransit belongs on the HUB side and useRemoteGateways on the SPOKE side — setting both on one side is a common misconfiguration that Azure accepts and that then fails to route.

ParamTypeRequiredDefaultDescription
allowForwardedTrafficbooleannofalseAllow traffic FORWARDED by the remote network (not originating there) — needed for hub-and-spoke through an appliance. Default false.
allowGatewayTransitbooleannofalseLet the remote network use THIS network's gateway. Set on the HUB side only. Default false.
allowVirtualNetworkAccessbooleannotrueAllow traffic from the remote network to reach this one. Default true.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
peeringNamestringyesThe peering name to create or replace.
remoteVirtualNetworkIdstringyesFull ARM resource id of the REMOTE virtual network to peer with.
resourceGroupNamestringyesThe resource group the LOCAL network lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
useRemoteGatewaysbooleannofalseUse the REMOTE network's gateway. Set on the SPOKE side only, and only when the hub sets allowGatewayTransit. Default false.
virtualNetworkNamestringyesThe LOCAL virtual network name — the side this peering is created on.

[Microsoft Azure] Delete a network interface. Azure refuses while the NIC is attached to a virtual machine, so this only succeeds on an interface that is already detached — which is exactly the case where it is easy to delete the wrong one, because a detached NIC gives no hint of what it used to serve. Deleting it RELEASES its private IP address: a machine rebuilt later gets a different address unless the configuration was static and is recreated by hand, and anything pinned to the old address (firewall rules, DNS records, application config) silently points at nothing. Read azure_get_network_interface first and keep the ipConfigurations block if the address matters.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
networkInterfaceNamestringyesThe network interface name to DELETE.
resourceGroupNamestringyesThe resource group the interface lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a network security group and every rule in it. Destructive: this REMOVES FILTERING. Azure refuses while the NSG is still attached to a subnet or NIC, so a success means it was already detached — but that is exactly the dangerous case to think about, because whatever it used to protect has been running unfiltered since it was detached. The rules are not recoverable; read azure_get_network_security_group first if there is any chance the caller wants them rebuilt. Deleting an NSG never blocks traffic — it can only ever allow more.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
networkSecurityGroupNamestringyesThe network security group name to DELETE, along with every rule in it.
resourceGroupNamestringyesThe resource group the NSG lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a security rule from a network security group. Destructive in BOTH directions, which is why it is flagged regardless of what the rule did: removing a Deny rule OPENS whatever it was blocking, and removing an Allow rule BREAKS an application that was depending on it. The change is live within seconds and nothing in Azure announces it. There is no undo — read azure_get_nsg_rule first and keep the definition if there is any chance it needs rebuilding. Note that deleting a rule does not restore a "default" for that traffic: evaluation simply falls through to the next matching rule, which may be one of Azure's built-in defaults.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
networkSecurityGroupNamestringyesThe network security group name.
resourceGroupNamestringyesThe resource group the NSG lives in.
ruleNamestringyesThe rule name to DELETE.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a public IP address resource. THE ADDRESS ITSELF IS LOST, not just the resource: a static address goes back into Azure's regional pool the moment this succeeds and cannot be reclaimed, so anything the customer's partners, firewalls or DNS records pinned to it breaks permanently. That is the whole risk here, and it is invisible in the API's response. Azure refuses while the address is attached to a NIC, load balancer or gateway, so success means it was already detached — which is also when its history is least obvious. Confirm with a human before deleting any static address that has ever been published.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
publicIpAddressNamestringyesThe public IP address resource name to DELETE.
resourceGroupNamestringyesThe resource group the address lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a route from a route table. Destructive in both directions, like deleting an NSG rule: removing a route does not restore a neutral state, it falls back to Azure's system route or a BGP-learned one for that prefix — so deleting a route that forced traffic through a firewall appliance sends that traffic STRAIGHT OUT to the internet instead, unfiltered and unlogged, which is the opposite of an outage and much harder to notice. The change is live within seconds across every subnet the table is attached to. Read azure_list_routes first and keep the definition if there is any chance it needs rebuilding.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the route table lives in.
routeNamestringyesThe route name to DELETE.
routeTableNamestringyesThe route table name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a subnet from a virtual network. Destructive: it removes an address range that live workloads may be addressed within, and recreating it does NOT restore what was there — the subnet's resource id changes, so NSG associations, route tables, private endpoints and any template referencing the old id break. Azure refuses while a NIC, gateway, private endpoint or delegated service still occupies it, so read azure_get_subnet with expand="ipConfigurations" first and show the caller what is in the way rather than letting the call fail. An emptied subnet that was carrying a delegation for a managed service is the case to be most careful with: the service can recreate resources into it at any moment.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the network lives in.
subnetNamestringyesThe subnet name to DELETE.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
virtualNetworkNamestringyesThe virtual network name.

[Microsoft Azure] Delete a virtual network and every subnet inside it. Destructive and not undoable: recreating the network does NOT restore anything that referenced it, because every resource is bound to a subnet by resource id and those ids change. Azure refuses while any NIC, gateway, private endpoint or delegated service still occupies a subnet, so a success here means the network was already empty — but peerings from OTHER networks are removed with it, silently severing traffic those networks were relying on. Read azure_get_virtual_network with expand="subnets/ipConfigurations" and azure_list_vnet_peerings first, and show the caller both. The operation is ASYNCHRONOUS: this returns a 202 immediately and deletion continues afterwards.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the network lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
virtualNetworkNamestringyesThe virtual network name to DELETE, along with every subnet inside it.

[Microsoft Azure] Delete a peering. Destructive, and unusually abrupt: unlike most network deletes Azure does NOT refuse because something is using it — the call succeeds immediately and traffic between the two networks stops, breaking applications that were routing across it with no warning and no error anywhere. It also leaves the REMOTE network's matching peering stranded in Disconnected, which cannot be repaired and must itself be deleted and recreated. Confirm with the caller what crosses this link before removing it, and plan to delete both sides. There is no undo: recreating requires both peerings again.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
peeringNamestringyesThe peering name to DELETE.
resourceGroupNamestringyesThe resource group the network lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
virtualNetworkNamestringyesThe virtual network name.

[Microsoft Azure] Get one application gateway in full, including every listener, rule, backend setting, probe, rewrite rule set and certificate's metadata. Certificate EXPIRY is the read worth doing on a schedule: sslCertificates carries the public data of each certificate, and an expired one takes every HTTPS site behind the gateway offline at once with a browser error rather than an Azure alert. Private key material is never returned by this API, which is why this is a Free read.

ParamTypeRequiredDefaultDescription
applicationGatewayNamestringyesThe application gateway name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the gateway lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Ask an application gateway how it currently sees each of its backend servers: per pool and per HTTP setting, every server's address with a health status of Healthy, Unhealthy, Partial, Draining or Unknown, and for an unhealthy one the reason — a failed probe, a certificate the gateway does not trust, or a connection refused. Changes nothing. This is the first call for "the site returns 502": a 502 from an application gateway almost always means it has no healthy backend, and the reason string here names why far more precisely than the gateway's own logs. It is a long-running operation, so Azure can accept the request before the result is ready; an accepted answer arrives as an empty with no tracking reference you can follow, so call the tool again.

ParamTypeRequiredDefaultDescription
applicationGatewayNamestringyesThe application gateway name, from azure_list_application_gateways.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the gateway lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one Azure Firewall in full, including every inline rule collection with its priority and action, the private IP the firewall answers on, and its provisioning state. The private IP is the value you match against route tables: a user-defined route sending 0.0.0.0/0 to a virtual appliance should point at THIS address, and a mismatch after a firewall was rebuilt is the classic cause of a subnet losing all outbound connectivity. Rule collections are evaluated by priority with network rules before application rules, so a broad network Allow can make an application rule below it irrelevant.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
firewallNamestringyesThe Azure Firewall name.
resourceGroupNamestringyesThe resource group the firewall lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one load balancer in full: frontends, backend pools, rules, health probes, NAT rules and outbound rules. When traffic is not reaching the backends, the probes block is where to look first — a probe on the wrong port or path marks every machine unhealthy and the balancer then refuses ALL traffic rather than passing it through, which presents as a total outage rather than a degraded one. Match each loadBalancingRule's backendPort against what the application actually listens on, and check that the rule's probe is the one you think it is.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
loadBalancerNamestringyesThe load balancer name.
resourceGroupNamestringyesThe resource group the load balancer lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one network interface in full: every IP configuration with its private address and allocation method, the subnet and public IP resource ids, the NSG attached to the NIC itself, applied DNS servers, accelerated networking and IP forwarding flags, and the VM it belongs to. Remember that a NIC can carry an NSG of its own IN ADDITION to the one on its subnet — Azure evaluates BOTH, and a rule that looks correct on the subnet can still be blocked by the NIC's own group. When traffic is not flowing as the rules suggest, azure_list_nic_effective_nsg_rules is the call that resolves the combination rather than guessing at it.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullOptional expansion, e.g. "NetworkSecurityGroup" to inline the attached group.
networkInterfaceNamestringyesThe network interface name.
resourceGroupNamestringyesThe resource group the interface lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one network security group with every rule and every attachment. This is the security-posture read: work through securityRules by ascending priority, because the FIRST match wins and later rules never run — a permissive rule at priority 100 makes a careful deny at 200 dead code, which is the usual explanation for "we blocked that but it still gets through". Then read defaultSecurityRules to see what Azure allows implicitly, and the subnets and networkInterfaces arrays to confirm the NSG is actually attached to something.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
networkSecurityGroupNamestringyesThe network security group name.
resourceGroupNamestringyesThe resource group the NSG lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one security rule by name. Read this before changing a rule: azure_create_nsg_rule is a PUT that replaces the whole rule, so any field you do not send reverts to its default — most consequentially, omitting sourceAddressPrefix defaults it to "*", turning a rule scoped to one address into one open to everything. Fetch, change the single field you mean to change, and send the rest back unchanged.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
networkSecurityGroupNamestringyesThe network security group name.
resourceGroupNamestringyesThe resource group the NSG lives in.
ruleNamestringyesThe rule name, from azure_list_nsg_rules.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one public IP address resource: its SKU and tier, allocation method, the assigned ipAddress, idleTimeoutInMinutes, DNS label and FQDN, availability zones, and the ipConfiguration it is attached to. A Dynamic address is only present while the resource it serves is running — the ipAddress property is absent on a deallocated machine and a DIFFERENT address is assigned when it starts again, which is the usual explanation for "the IP changed on its own". Static is the fix, and it is set at creation or by replacing the resource, not toggled here.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
publicIpAddressNamestringyesThe public IP address resource name (not the address itself).
resourceGroupNamestringyesThe resource group the address lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one route table with its full routes array and the list of subnets it is attached to. Read this before any route change: what a table CONTAINS is only half the picture, and the subnets array is the other half — the same table attached to three subnets means one route edit changes the path for all three. To see what a specific machine is actually using once system, BGP and user-defined routes are combined, use azure_list_nic_effective_routes instead; this call shows the intent, that one shows the outcome.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the route table lives in.
routeTableNamestringyesThe route table name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one subnet: its address prefix, attached network security group and route table, service endpoints, delegations and private-endpoint policies. READ THIS BEFORE azure_create_subnet on an existing subnet — that call is a PUT and replaces the properties object, so omitting networkSecurityGroup or routeTable DETACHES them rather than leaving them alone, silently removing a firewall or a forced-tunnel route. Pass expand="ipConfigurations" to list what currently occupies the subnet, which is what tells you whether a delete will be refused.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullSet to "ipConfigurations" to include what currently occupies the subnet.
resourceGroupNamestringyesThe resource group the network lives in.
subnetNamestringyesThe subnet name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
virtualNetworkNamestringyesThe virtual network name.

[Microsoft Azure] Get one virtual network in full: address space, every subnet with its prefix, attached network security group, route table, service endpoints and delegations, plus peerings, DNS servers and DDoS settings. READ THIS BEFORE azure_create_virtual_network on an existing network — that call is a PUT and replaces the object, so anything you omit is removed. Pass expand="subnets/ipConfigurations" to see which resources actually occupy each subnet, which is what tells you whether a subnet is safe to delete.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullOptional expansion, e.g. "subnets/ipConfigurations" to include what occupies each subnet.
resourceGroupNamestringyesThe resource group the network lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
virtualNetworkNamestringyesThe virtual network name.

[Microsoft Azure] Get one virtual network gateway in full: type, SKU and generation, active-active state, BGP settings including the ASN and the peering addresses, the gateway subnet's IP configurations, and any point-to-site VPN client configuration. The SKU is the number to read when a customer reports a slow VPN — each SKU carries a hard aggregate throughput ceiling and a maximum tunnel count, and neither raises an alert when reached, so a tunnel that saturates is simply slow. Changing a SKU or converting to active-active recreates the gateway and drops every tunnel for the duration, which is why this connector reads gateways but does not rebuild them.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
gatewayNamestringyesThe virtual network gateway name.
resourceGroupNamestringyesThe resource group the gateway lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one peering by name, including its peeringState and the four traffic flags. Use it to diagnose a half-configured link: peeringState Initiated means the matching peering on the REMOTE network has not been created, and Disconnected means the remote side was deleted — in which case the surviving peering must be deleted and recreated, because Azure will not reconnect it. allowGatewayTransit on one side must be paired with useRemoteGateways on the other for a spoke to use a hub's VPN or ExpressRoute gateway.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
peeringNamestringyesThe peering name, from azure_list_vnet_peerings.
resourceGroupNamestringyesThe resource group the network lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
virtualNetworkNamestringyesThe virtual network name.

[Microsoft Azure] List every application gateway in a subscription: its sku and capacity or autoscale range, operationalState, frontend IP and port configurations, HTTP listeners, backend pools and settings, request routing rules, SSL certificates (metadata only — never the private key), and the webApplicationFirewallConfiguration when WAF is enabled. Two fields carry most of the diagnostic value: operationalState tells you whether the gateway is Running or Stopped, and the WAF block's mode says whether it is actually blocking (Prevention) or merely logging (Detection) — a WAF left in Detection is a common finding, because it looks enabled everywhere except in this field. Up to 1000 items across 10 pages per call.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum gateways to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every Azure Firewall in a subscription: its sku tier (Standard, Premium or Basic), threatIntelMode, the firewallPolicy it draws rules from when policy-managed, its ipConfigurations and hubIPAddresses, and — on older firewalls that still hold rules inline — the applicationRuleCollections, networkRuleCollections and natRuleCollections. Read threatIntelMode carefully: Alert only logs known-malicious traffic while Deny actually blocks it, and Off disables the feature entirely, so a firewall in Alert mode is reporting threats it is still passing through. A firewall whose rules live in a firewallPolicy shows empty rule collections here, which is expected and not a misconfiguration.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum firewalls to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every Azure Bastion host in a subscription, with its sku, scaleUnits, the AzureBastionSubnet and public IP it uses, and the feature flags — enableTunneling, enableIpConnect, enableShareableLink and disableCopyPaste. Bastion is the reason a customer's VMs can have no public IP and still be reachable, so its presence changes how you read an otherwise closed NSG. Two flags are worth calling out in a security review: enableShareableLink lets someone hand out access by URL without an Azure sign-in, and disableCopyPaste left false permits clipboard transfer into and out of the session.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum hosts to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every ExpressRoute circuit in a subscription, with its serviceProviderProperties (the carrier, peering location and bandwidth), the sku tier and family, and — the two fields to read first — circuitProvisioningState and serviceProviderProvisioningState. Those two are separate on purpose: Azure can show the circuit Enabled while the carrier still shows NotProvisioned, which means the customer is billing for a circuit that carries no traffic and is waiting on the provider, not on Azure. The peerings array shows which peering types are configured and their BGP state.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum circuits to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List a load balancer's backend address pools with their full membership — every NIC ip configuration or explicit IP address in each pool. The pool object embedded in azure_get_load_balancer is often truncated for large pools, so this is the reliable way to answer "is this machine actually in the pool?". An EMPTY pool is the answer to a surprising share of load balancer incidents: the balancer, its rules and its probes all look correct and there is simply nothing behind it, usually because a machine was rebuilt and its new NIC was never added back.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
loadBalancerNamestringyesThe load balancer name, from azure_list_load_balancers.
maxItemsintegerno1000Maximum pools to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the load balancer lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every load balancer in a subscription with its sku (Basic or Standard), frontendIPConfigurations (the addresses it answers on, public or private), backendAddressPools, loadBalancingRules, probes, inboundNatRules and outboundRules. The sku and the frontend type together tell you what a balancer is FOR: a Standard balancer with a public frontend is internet-facing, an internal one carries only a private frontend. Worth knowing while reading these: a Standard load balancer is secure by default, meaning its backend machines have NO outbound internet access unless an outbound rule or NAT gateway provides it — a surprisingly common cause of "the VM cannot reach Windows Update" behind an internal balancer. Up to 1000 items across 10 pages per call.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum load balancers to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every network interface (NIC) in a subscription. Each item carries the NIC's ipConfigurations (private IP, allocation method, the subnet it sits in and any public IP attached), the networkSecurityGroup applied directly to the NIC, dnsSettings, enableAcceleratedNetworking, macAddress and virtualMachine.id when it is attached to one. This is the join between a machine and its addresses: a VM object names its NICs by id but carries no IP of its own, so this is the call that answers "what is this VM's address?" and "what is on 10.0.1.7?". A NIC with no virtualMachine property is orphaned — it still costs nothing itself but it holds its private IP and any attached static public IP, which does bill. Up to 1000 items across 10 pages per call.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum interfaces to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the network interfaces inside one resource group. Same item shape as azure_list_network_interfaces, scoped to a single group — the cheaper call once the caller knows where the machine lives. Note that a NIC does not have to live in the same resource group as the VM it is attached to, so an empty result here does not mean the group's VMs have no interfaces; follow the networkProfile.networkInterfaces ids on the VM instead.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum interfaces to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name, from azure_list_resource_groups.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every network security group in a subscription. Each item carries its securityRules (the rules an admin wrote), defaultSecurityRules (Azure's built-ins, which allow VNet-internal traffic and deny all inbound from the Internet at priority 65500), and the subnets and networkInterfaces it is attached to. An NSG attached to NOTHING filters nothing — check the attachment arrays before reporting a customer as protected, because an orphaned NSG full of careful rules is a common and convincing-looking illusion. Returns ARM's {value:[...]} envelope; up to 1000 items across 10 pages.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum network security groups to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the network security groups inside one resource group. Same item shape as azure_list_network_security_groups, scoped to a single group — the cheaper call when the caller already knows where the NSG lives.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum network security groups to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name, from azure_list_resource_groups.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the Network Watcher resources in a subscription. Every diagnostic call in this family runs THROUGH a watcher, so this is the lookup that comes first: a watcher is regional, Azure normally auto-creates one per region in a resource group called NetworkWatcherRG, and the watcher you pass must be in the SAME REGION as the machine you are diagnosing — using one from another region fails with an error that does not mention the region. If a region has no watcher listed here, its diagnostics are simply unavailable until one is created.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum watchers to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Show the security rules that are ACTUALLY in force on one network interface — Azure's own evaluation of the NIC's NSG combined with the subnet's NSG, in priority order, including the built-in default rules that are invisible in azure_list_nsg_rules. This is the tool that answers "why is this port blocked when I created an Allow rule for it?", because the answer is almost always a lower-priority rule in the OTHER group or one of Azure's defaults. Changes nothing. The VM must be RUNNING — Azure computes this from the live host, and a stopped or deallocated machine returns an error rather than the rules. It is a long-running operation, so Azure can accept the request before the result is ready; an accepted answer arrives as an empty and carries no tracking reference you can follow, so treat as still running and call the tool again.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
networkInterfaceNamestringyesThe network interface name, from azure_get_network_interface.
resourceGroupNamestringyesThe resource group the interface lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Show the routing table that is ACTUALLY in force on one network interface: Azure's system routes, routes learned over BGP from a VPN or ExpressRoute gateway, and any user-defined routes from an attached route table, each with its source, address prefix, next hop type and next hop address. Changes nothing. Use it when traffic is leaving a machine by an unexpected path — a route with source "Default" and next hop "Internet" on a prefix you expected to reach on-premises means the user-defined route you thought was applied is not, and a route showing state "Invalid" means its next-hop virtual appliance no longer exists. The VM must be RUNNING, and like the effective-rules call this is a long-running operation: an accepted-but-not-ready answer arrives as an empty with no tracking reference you can follow, so call the tool again rather than waiting on one.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
networkInterfaceNamestringyesThe network interface name, from azure_get_network_interface.
resourceGroupNamestringyesThe resource group the interface lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the ADMIN-DEFINED security rules in a network security group. Each rule carries priority, direction (Inbound or Outbound), access (Allow or Deny), protocol, and the source/destination address prefixes and port ranges. Evaluate in ascending priority — the first match wins and nothing after it runs. Note this returns only the rules someone wrote: Azure's built-in defaults are a SEPARATE array visible through azure_get_network_security_group, and they are what allows VNet-to-VNet traffic and denies inbound Internet at priority 65500. A rule with sourceAddressPrefix "*" or "Internet" and access Allow is the pattern to flag to a caller reviewing exposure.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum rules to return (1-1000, default 1000).
networkSecurityGroupNamestringyesThe network security group name.
resourceGroupNamestringyesThe resource group the NSG lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every public IP address resource in a subscription, with its sku (Basic or Standard), publicIPAllocationMethod (Static or Dynamic), the ipAddress currently assigned, the dnsSettings FQDN if one is configured, and ipConfiguration.id naming what the address is attached to. Two things this answers that nothing else does: which addresses are ORPHANED — a Static address with no ipConfiguration is billing every hour while serving nothing — and what a customer's actual internet-facing footprint is, which is the list you check against an external scan. Basic-SKU addresses are worth flagging in any review: Microsoft retired that SKU for new deployments and existing ones need migrating to Standard. Up to 1000 items across 10 pages per call.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum addresses to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every route table in a subscription, each with its routes array (address prefix, next hop type, next hop IP), the subnets it is attached to, and disableBgpRoutePropagation. User-defined routes OVERRIDE Azure's system routes and BGP-learned routes for the prefixes they name, so a route table is the most common reason traffic takes a path the network diagram does not show — a 0.0.0.0/0 route pointing at a firewall appliance forces every outbound flow through it, and one pointing at "None" black-holes it silently. disableBgpRoutePropagation set to true on a subnet with a VPN or ExpressRoute gateway cuts off the on-premises routes it would otherwise learn, which breaks hybrid connectivity in a way that looks like a gateway fault. Up to 1000 items across 10 pages per call.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum route tables to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the individual routes in one route table, each with addressPrefix, nextHopType and, for a virtual-appliance hop, nextHopIpAddress. Azure matches the LONGEST prefix, not the first entry, so ordering in this list carries no meaning — a /32 always beats a /24 regardless of position. A nextHopType of "None" is a deliberate black hole rather than a misconfiguration; "VirtualAppliance" whose nextHopIpAddress no longer exists is the one that silently drops traffic.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum routes to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the route table lives in.
routeTableNamestringyesThe route table name, from azure_list_route_tables.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the subnets in a virtual network. Each item carries name, addressPrefix, the attached networkSecurityGroup and routeTable (as resource ids), serviceEndpoints, delegations, privateEndpointNetworkPolicies and provisioningState. The attached NSG id is the answer to "what is filtering traffic here?" — a subnet with no networkSecurityGroup has NO subnet-level filtering at all, and its VMs are protected only by whatever NSGs are attached to their individual NICs. A delegations entry means the subnet is reserved for a managed service (AKS, App Service, SQL Managed Instance) and cannot host ordinary VMs.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum subnets to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the network lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
virtualNetworkNamestringyesThe virtual network name.

[Microsoft Azure] List the virtual network gateways in one resource group — the VPN and ExpressRoute gateways that connect a virtual network to on-premises or to other networks. Each carries gatewayType (Vpn or ExpressRoute), vpnType (RouteBased or PolicyBased), sku, activeActive, enableBgp with its bgpSettings, and the ipConfigurations naming the gateway subnet and public IPs. NOTE this API has no subscription-wide list, unlike most Microsoft.Network types — resourceGroupName is required, so enumerate groups with azure_list_resource_groups if the gateway's location is unknown. A PolicyBased vpnType is worth flagging: it supports exactly one tunnel and no BGP, which is the ceiling behind many "we cannot add a second site" questions.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum gateways to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group to look in — this API has no subscription-wide list.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Report how many private IP addresses each subnet in a virtual network has consumed, with currentValue and limit per subnet. This is the capacity question behind most "why can't I add another VM / another AKS node?" failures: a subnet that looks large can be nearly full, and Azure reserves FIVE addresses in every subnet for its own use (network, gateway, two DNS, broadcast), so a /29 offers three usable addresses rather than eight. Read this before proposing a deployment into an existing subnet.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the network lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
virtualNetworkNamestringyesThe virtual network name.

[Microsoft Azure] List every virtual network in a subscription, across all resource groups. Each item carries id, name, location, tags and a properties block with addressSpace.addressPrefixes (the CIDR ranges the network owns), the full subnets array with each subnet's prefix and attached NSG or route table, virtualNetworkPeerings, dhcpOptions.dnsServers and enableDdosProtection. This is the starting point for any "how is this customer's network laid out?" question, and the addressSpace values are what you compare before proposing a peering — two networks with overlapping CIDRs CANNOT be peered, which is the most common reason a peering request fails. Returns ARM's {value:[...]} envelope; up to 1000 items across 10 pages per call.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum virtual networks to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the virtual networks inside one resource group. Same item shape as azure_list_virtual_networks but scoped to a single group, which is the cheaper call when the caller already knows where the network lives. A 404 means the resource GROUP does not exist in that subscription; an empty {"value":[]} means the group exists and holds no virtual networks — different answers, worth distinguishing for the caller.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum virtual networks to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name, from azure_list_resource_groups.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the peerings on a virtual network — the links that let two networks route to each other directly. Each item carries remoteVirtualNetwork.id, allowVirtualNetworkAccess, allowForwardedTraffic, allowGatewayTransit, useRemoteGateways and peeringState. READ peeringState CAREFULLY: a peering is only functional when it is Connected on BOTH networks, and a state of Initiated means only one side has been created — traffic does not flow, and this is the single most common cause of "the peering exists but nothing can reach anything". Also check this before deleting either network, because deleting one silently severs the link for the other.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum peerings to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the network lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
virtualNetworkNamestringyesThe virtual network name.

[Microsoft Azure] List the gateway connections in one resource group — the site-to-site VPN tunnels, VNet-to-VNet links and ExpressRoute circuit connections. THE FIELD THAT MATTERS IS connectionStatus: Connected, Connecting, NotConnected or Unknown, alongside egressBytesTransferred and ingressBytesTransferred and the time of the last connection. A tunnel sitting in Connecting is the signature of a mismatched shared key or a peer that is not answering, and one showing Connected with zero bytes in either direction usually means routing, not the tunnel, is the problem. Like gateways, connections have no subscription-wide list — resourceGroupName is required.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum connections to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group to look in — this API has no subscription-wide list.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Actually TEST reachability from a virtual machine to another Azure resource or to any address and port, and get the full hop-by-hop path back with latency and, at each hop, what allowed or blocked the traffic. Returns connectionStatus (Reachable, Unreachable, Degraded or Unknown) with probe counts, average and minimum latency, and an issues array naming the cause — an NSG rule, a user-defined route, a DNS resolution failure, or the target port being closed. Unlike azure_run_ip_flow_verify this sends real traffic from the machine and therefore needs the Network Watcher agent extension installed on it; where that is missing, ip flow verify plus next hop answer most of the same questions from configuration alone. Long-running: an accepted-but-not-ready answer arrives as an empty with no tracking reference you can follow, so call the tool again.

ParamTypeRequiredDefaultDescription
destinationAddressstringnonullDestination address — a hostname or IP, e.g. www.contoso.com or 10.0.2.4. Give this or destinationResourceId.
destinationPortintegernonullDestination port, e.g. 443.
destinationResourceIdstringnonullFull ARM resource id of the destination Azure resource. Give this or destinationAddress.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
networkWatcherNamestringyesThe network watcher name, from azure_list_network_watchers — must be in the source VM's region.
protocolstringnonullProtocol: Tcp, Http, Https or Icmp. Omit to let Azure choose from the port.
resourceGroupNamestringyesThe resource group holding the NETWORK WATCHER (often NetworkWatcherRG), not the VM's group.
sourcePortintegernonullOptional source port to send from.
sourceResourceIdstringyesFull ARM resource id of the SOURCE virtual machine. It needs the Network Watcher agent extension.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Ask Azure whether a specific packet would be allowed or denied to a specific virtual machine, and WHICH security rule decides it. Returns {access:"Allow"|"Deny", ruleName:"..."} after evaluating every NSG that applies to the machine, in the order Azure itself uses. Changes nothing — it evaluates rules rather than sending traffic. This is the definitive answer to "is the firewall blocking this?", and the ruleName it returns is what turns a guess into a fix: a deny attributed to DefaultOutboundDenyAll means no rule matched at all, while a named rule tells you exactly which one to edit. The VM must be RUNNING, and the network watcher must be in the same region as it. Long-running: Azure can accept the request before the answer is ready, and an accepted response arrives as an empty with no tracking reference you can follow, so call the tool again.

ParamTypeRequiredDefaultDescription
directionstringyesDirection of the packet from the VM's point of view: Inbound or Outbound.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
localIpAddressstringyesThe VM's own IP address for this flow.
localPortstringyesThe VM's own port for this flow, e.g. 3389.
networkWatcherNamestringyesThe network watcher name, from azure_list_network_watchers — must be in the VM's region.
protocolstringyesProtocol: TCP or UDP.
remoteIpAddressstringyesThe other end's IP address.
remotePortstringyesThe other end's port, e.g. 51000.
resourceGroupNamestringyesThe resource group holding the NETWORK WATCHER (often NetworkWatcherRG), not the VM's group.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
targetResourceIdstringyesFull ARM resource id of the target virtual machine, e.g. /subscriptions/.../providers/Microsoft.Compute/virtualMachines/web01.

[Microsoft Azure] Ask Azure where traffic from a virtual machine to a given destination address would actually go NEXT, and which route decides it. Returns the next hop type — Internet, VirtualAppliance, VirtualNetworkGateway, VnetLocal, VnetPeering, HyperNetGateway or None — with the hop's IP address and the resource id of the route table that produced it. Changes nothing. Two answers are diagnoses in themselves: "None" means the traffic is black-holed and will vanish without an error anywhere, and a routeTableId pointing at a table nobody expected is how an accidental forced-tunnel gets found. The VM must be RUNNING and the watcher must be in its region. Long-running: an accepted-but-not-ready answer arrives as an empty with no tracking reference you can follow, so call the tool again.

ParamTypeRequiredDefaultDescription
destinationIpAddressstringyesThe destination IP address to test the path to.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
networkWatcherNamestringyesThe network watcher name, from azure_list_network_watchers — must be in the VM's region.
resourceGroupNamestringyesThe resource group holding the NETWORK WATCHER (often NetworkWatcherRG), not the VM's group.
sourceIpAddressstringyesThe source IP address on that machine.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
targetNicResourceIdstringnonullOptional full ARM resource id of a specific NIC, when the machine has more than one.
targetResourceIdstringyesFull ARM resource id of the source virtual machine.

[Microsoft Azure] Start a stopped application gateway. Not destructive — it restores service rather than interrupting it — but it is not free either: a running gateway bills per hour plus per capacity unit whether or not any traffic reaches it, which is the whole reason one would have been stopped. Starting takes several minutes and the frontend does not answer until it completes; a public IP that was Dynamic may come back on a DIFFERENT address, so check azure_get_public_ip_address afterwards if anything external points at it. Long-running: the 202 response carries the operation URL to poll.

ParamTypeRequiredDefaultDescription
applicationGatewayNamestringyesThe application gateway name to start.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the gateway lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Stop an application gateway. DESTRUCTIVE: every website, API and service published through this gateway becomes unreachable the moment it stops — this is a full outage for everything behind it, not a maintenance-window action, and Azure asks for no confirmation. The gateway's configuration survives and azure_start_application_gateway brings it back, but startup takes several minutes and a Dynamic public IP may return on a different address. The legitimate use is cost control on a gateway serving a dev or test environment; on anything else, confirm with a human first and check azure_get_application_gateway_backend_health to see what is actually being served.

ParamTypeRequiredDefaultDescription
applicationGatewayNamestringyesThe application gateway name to STOP.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the gateway lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Update a network security group's tags via PATCH, leaving every rule and attachment untouched. Not destructive: tags carry no filtering semantics, and this is a genuine partial update. Supply tags as a JSON object, e.g. {"owner":"netops"}.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
networkSecurityGroupNamestringyesThe network security group name.
resourceGroupNamestringyesThe resource group the NSG lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringyesTags to set as a JSON object, e.g. {"owner":"netops"}.

[Microsoft Azure] Update a virtual network's tags via PATCH, leaving its address space, subnets and peerings untouched. Not destructive: tags carry no network or access semantics, and unlike azure_create_virtual_network this is a genuine partial update — it is the safe way to label a network without any risk of replacing its definition. Supply tags as a JSON object, e.g. {"costCentre":"CC-1042"}.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the network lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringyesTags to set as a JSON object, e.g. {"costCentre":"CC-1042"}.
virtualNetworkNamestringyesThe virtual network name.

Cost Management

ToolPlanAccessSummary
azure_create_budgetProWriteCreate a spend budget, or update an existing one.
azure_create_cost_exportProWriteCreate a scheduled cost export, or update an existing one.
azure_delete_budgetProDestructiveDelete a budget.
azure_delete_cost_exportProDestructiveDelete a scheduled cost export.
azure_dismiss_cost_alertProWriteDismiss a cost alert, marking it as handled so it stops appearing as active.
azure_forecast_costFreeRead-onlyForecast what a subscription (or resource group) WILL spend, using Azure's own projection from recent usage.
azure_get_budgetFreeRead-onlyGet one budget by name, including its current and forecast spend and its full notification set.
azure_get_cost_exportFreeRead-onlyGet one scheduled cost export by name: its schedule and recurrence, the dataset definition, the destination storage account and container, and the eTag.
azure_get_price_sheetFreeRead-onlyGet the price sheet for a subscription — the rate Azure actually charges this customer per meter, which for a CSP or enterprise agreement is not the public retail price.
azure_list_budgetsFreeRead-onlyList the spend budgets configured on a subscription or resource group.
azure_list_cost_alertsFreeRead-onlyList the cost alerts currently raised on a subscription — budget thresholds crossed, spend anomalies Azure detected, and invoice or credit warnings.
azure_list_cost_dimensionsFreeRead-onlyList the dimensions available for grouping and filtering cost, and the VALUES each one currently holds for this subscription — the resource groups that actually exist, the services actually in use,…
azure_list_cost_export_runsFreeRead-onlyList the recent execution history of one scheduled cost export.
azure_list_cost_exportsFreeRead-onlyList the scheduled cost exports configured on a subscription — the recurring jobs that write cost detail files to a storage account.
azure_list_reservation_recommendationsFreeRead-onlyList Azure's reserved-instance recommendations for a subscription — where committing to a one- or three-year reservation would cost less than pay-as-you-go, based on the customer's own recent usage.
azure_list_usage_detailsFreeRead-onlyList individual billing line items — one row per meter per resource per day, with the resource id, meter, quantity, unit price, effective price and cost.
azure_query_costFreeRead-onlyTHE cost question tool: what a subscription (or one resource group) spent, broken down however you ask.
azure_run_cost_exportProDestructiveTrigger a scheduled cost export to run immediately, without waiting for its next scheduled time.

[Microsoft Azure] Create a spend budget, or update an existing one. Not destructive: a budget only sends notifications — Azure never stops or throttles resources when one is exceeded, so this cannot interrupt a workload. NOTE the replace semantics: this is a PUT, so an existing budget of the same name is REPLACED wholesale. Read azure_get_budget first and pass every notification you want to keep, or they are silently dropped. Notifications are supplied as a JSON object keyed by your own label, e.g. {"Actual_GreaterThan_80_Percent":{"enabled":true,"operator":"GreaterThan","threshold":80,"thresholdType":"Actual","contactEmails":["helpdesk@contoso.com"]}} — threshold is a PERCENTAGE of the amount, not an absolute figure, and a budget accepts at most five. startDate must be the first of a month and no earlier than the current time grain's period.

ParamTypeRequiredDefaultDescription
amountnumberyesThe budget amount in the billing currency, e.g. 5000.
budgetNamestringyesThe budget name to create or replace.
endDatestringnonullBudget end date, e.g. 2027-07-31. Omit for Azure's default of ten years out.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
etagstringnonullThe eTag from azure_get_budget, for optimistic concurrency on an update. Omit when creating.
filterJsonstringnonullOptional filter as a JSON object, to budget a slice of the scope by dimension or tag.
notificationsJsonstringnonullNotifications as a JSON object keyed by your own label. Threshold is a PERCENTAGE of amount. At most five.
resourceGroupNamestringnonullScope the budget to one resource group. Omit for a subscription-scoped budget.
startDatestringyesBudget start date — must be the FIRST of a month, e.g. 2026-08-01.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
timeGrainstringyesReset period: Monthly, Quarterly, Annually, BillingMonth, BillingQuarter or BillingAnnual.

[Microsoft Azure] Create a scheduled cost export, or update an existing one. Not destructive: it writes new files into a storage container the caller nominates and touches no existing resource. NOTE the replace semantics — this is a PUT, so an existing export of the same name is REPLACED wholesale; read azure_get_cost_export first when changing one. The destination storage account is given as its full ARM resource id, and the signed-in user needs write access to it as well as to the cost scope. Recurrence is Daily, Weekly, Monthly or Annually, and the recurrence period must START in the future — Azure rejects a past start with an unhelpful 400. Set scheduleStatus to Inactive to define an export without running it, then enable it later.

ParamTypeRequiredDefaultDescription
costTypestringnonullCost type: ActualCost (default), AmortizedCost or Usage.
destinationContainerstringyesThe blob container to write into.
destinationResourceIdstringyesFull ARM resource id of the destination STORAGE ACCOUNT, e.g. /subscriptions//resourceGroups//providers/Microsoft.Storage/storageAccounts/.
destinationRootFolderPathstringnonullFolder path inside the container. Omit to write at the container root.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
exportNamestringyesThe export name to create or replace.
granularitystringnonullGranularity of the exported rows: Daily (default) or Monthly.
recurrencestringyesRecurrence: Daily, Weekly, Monthly or Annually.
recurrenceFromstringyesWhen the schedule starts — must be in the FUTURE, e.g. 2026-09-01T00:00:00Z.
recurrenceTostringyesWhen the schedule ends, e.g. 2027-09-01T00:00:00Z.
resourceGroupNamestringnonullScope the export to one resource group. Omit for a subscription-scoped export.
scheduleStatusstringnonullSchedule status: Active (default) or Inactive to define it without running.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
timeframestringnonullWhat to export: MonthToDate (default), BillingMonthToDate, TheLastMonth, TheLastBillingMonth, WeekToDate or Custom.

[Microsoft Azure] Delete a budget. Destructive: it removes a spend guardrail and every notification hanging off it, so nobody is told the next time this customer's spend crosses the threshold — and the loss is silent, because a missing budget raises no alert of its own. There is no undo; recreating it requires the full definition, so read azure_get_budget first if there is any chance the caller wants it back. Historical cost data is unaffected: a budget is only a notification rule over data Azure keeps regardless.

ParamTypeRequiredDefaultDescription
budgetNamestringyesThe budget name to DELETE, from azure_list_budgets.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullThe resource group, if the budget is scoped to one. Omit for a subscription-scoped budget.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a scheduled cost export. Destructive: the recurring delivery stops, and the loss is silent — downstream billing or reporting that reads those files simply stops receiving new ones, with no error anywhere in Azure. Files already written to the storage container are NOT deleted and remain readable. There is no undo; recreating the export needs its full definition, so read azure_get_cost_export first if the caller may want it back. To pause deliveries reversibly, prefer azure_create_cost_export with scheduleStatus=Inactive.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
exportNamestringyesThe export name to DELETE, from azure_list_cost_exports.
resourceGroupNamestringnonullThe resource group, if the export is scoped to one. Omit for a subscription-scoped export.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Dismiss a cost alert, marking it as handled so it stops appearing as active. Not destructive: it flips ONE status field on the alert, the alert itself stays readable through azure_list_cost_alerts, and a human can reactivate it from the Azure portal — so while this API offers no un-dismiss operation of its own, nothing is lost and nothing about spending, the budget, or any future alert changes. Dismiss only an alert the caller has explicitly acknowledged; never dismiss in bulk to tidy a list, because the status is the only record that somebody looked. Dismissing does not fix the underlying condition: if the budget is still exceeded, Azure raises a fresh alert on its next evaluation, so a repeatedly-returning alert means the spend problem is unaddressed rather than that the dismissal failed — delete or re-scope the budget instead of silencing it here.

ParamTypeRequiredDefaultDescription
alertIdstringyesThe alert id — the NAME segment of the alert's ARM id, from azure_list_cost_alerts.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullThe resource group, if the alert is scoped to one. Omit for a subscription-scoped alert.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Forecast what a subscription (or resource group) WILL spend, using Azure's own projection from recent usage. Read-only despite being an HTTP POST. Returns the same columns/rows table shape as azure_query_cost, so read properties.columns first. Set includeActualCost=true to get actuals and forecast in one series, which is what a "are we on track this month?" answer needs. The projection is a statistical extrapolation of recent usage, not a commitment: it does not know about a migration you are about to run or a VM someone is about to deallocate, and it is least reliable for a subscription whose usage changed in the last few days. For timeframe=Custom the period may extend into the FUTURE — that is the point of this tool, and it is the difference from azure_query_cost.

ParamTypeRequiredDefaultDescription
costTypestringnonullCost type: ActualCost (default), AmortizedCost or Usage.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterJsonstringnonullOptional filter as a JSON object in Azure's filter shape.
fromDatestringnonullStart date for timeframe=Custom, e.g. 2026-08-01.
granularitystringnonullGranularity: Daily or Monthly. Omit for a single total.
groupByDimensionsstringnonullComma-separated dimensions to group by, e.g. "ServiceName". At most two groupings in total.
groupByTagsstringnonullComma-separated TAG KEYS to group by. Counts toward the same limit of two.
includeActualCostbooleannotrueInclude actual costs alongside the forecast so one series covers the whole period. Default true.
includeFreshPartialCostbooleannotrueInclude the newest partial-day costs, which are incomplete but current. Default true.
resourceGroupNamestringnonullRestrict to one resource group. Omit for the whole subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
timeframestringnonullTimeframe: MonthToDate, BillingMonthToDate, TheLastMonth, TheLastBillingMonth, WeekToDate or Custom. Default MonthToDate.
toDatestringnonullEnd date for timeframe=Custom — may be in the FUTURE, e.g. 2026-08-31.

[Microsoft Azure] Get one budget by name, including its current and forecast spend and its full notification set. Fetch this before azure_create_budget when UPDATING an existing budget: that call replaces the whole resource, so the caller needs the current notifications to avoid dropping them. The response also carries the eTag, which the update can pass back for optimistic concurrency. A 404 means no budget of that name at that scope — note that a subscription-scoped budget and a resource-group-scoped one of the same name are different resources.

ParamTypeRequiredDefaultDescription
budgetNamestringyesThe budget name, from azure_list_budgets.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullThe resource group, if the budget is scoped to one. Omit for a subscription-scoped budget.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one scheduled cost export by name: its schedule and recurrence, the dataset definition, the destination storage account and container, and the eTag. Read this before azure_create_cost_export when changing an existing export — that call replaces the whole resource, so the caller needs the current definition to avoid silently altering what gets delivered. A 404 means no export of that name at that scope.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullSet to "runHistory" to include the export's recent runs.
exportNamestringyesThe export name, from azure_list_cost_exports.
resourceGroupNamestringnonullThe resource group, if the export is scoped to one. Omit for a subscription-scoped export.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get the price sheet for a subscription — the rate Azure actually charges this customer per meter, which for a CSP or enterprise agreement is not the public retail price. Use it to explain a charge ("why is this VM costing that much per hour") or to estimate a change before making it. Expand meterDetails to get each meter's name, category and unit of measure alongside the rate; without it the rows are meter GUIDs and hard to interpret. This is a LARGE document on a subscription with broad service usage, so set top when exploring. AVAILABILITY IS EFFECTIVELY EA-ONLY: this subscription-scoped price sheet is an Enterprise Agreement surface, and for a Microsoft Customer Agreement or CSP customer it commonly errors rather than returning data — their price sheet lives under the billing-profile scope, which this connector deliberately does not address. Treat a 404, 204 or a scope error here as "no subscription-scoped price sheet exists for this billing relationship" rather than a broken tool, and fall back to azure_list_usage_details, whose rows carry the effective price actually charged.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullSet to "meterDetails" to include each meter's name, category and unit — strongly recommended.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
topintegernonullMaximum price rows to return, e.g. 100 while exploring.

[Microsoft Azure] List the spend budgets configured on a subscription or resource group. Each item carries properties.amount, timeGrain (Monthly, Quarterly, Annually or their BillingMonth equivalents), timePeriod, the notification thresholds with their contact emails and action groups, and — most usefully for a status answer — properties.currentSpend and properties.forecastSpend, which say how much of the budget is already consumed without a second call. A budget is a NOTIFICATION guardrail, not a spending cap: Azure does not stop resources when one is exceeded, so never tell a caller a budget will prevent an overspend.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum budgets to return (1-1000, default 1000).
resourceGroupNamestringnonullRestrict to budgets scoped to one resource group. Omit for subscription-scoped budgets.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the cost alerts currently raised on a subscription — budget thresholds crossed, spend anomalies Azure detected, and invoice or credit warnings. Each item carries properties.definition.type, properties.status (Active, Overridden, Resolved or Dismissed), properties.costEntityId naming the budget that fired, and the threshold and current values. This is the tool that answers "is anything wrong with this customer's spend right now?" in one call, where azure_query_cost answers "what are they spending". Alerts are generated by Azure on its own schedule from cost data that lags roughly four hours, so a very recent overspend may not have surfaced yet.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullRestrict to alerts scoped to one resource group. Omit for the whole subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the dimensions available for grouping and filtering cost, and the VALUES each one currently holds for this subscription — the resource groups that actually exist, the services actually in use, the meter categories actually billed. Call this before composing an azure_query_cost filter when you are unsure of the exact spelling of a value: dimension values are case-sensitive in a filter and a near-miss returns an empty result rather than an error, which reads like "this customer spent nothing". Each item carries properties.data (the values), properties.total and properties.category.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOData filter over the dimensions themselves, e.g. "properties/category eq 'ResourceGroupName'".
resourceGroupNamestringnonullRestrict to one resource group. Omit for the whole subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
timeframestringnonullTimeframe whose values to report: MonthToDate (default), TheLastMonth, WeekToDate or Custom.
topintegernonullMaximum values returned per dimension (1-1000).

[Microsoft Azure] List the recent execution history of one scheduled cost export. Each run carries properties.status (Queued, InProgress, Completed, Failed, Timeout, NewDataNotAvailable or DataNotAvailable), the submitted and processing timestamps, the file name written, and the error when one failed. This is the tool that answers "why hasn't the customer's cost file arrived?" — and the answer is often NewDataNotAvailable, which is not a failure: it means Azure had no fresh cost data for the period, most commonly because the export ran twice in one refresh window.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
exportNamestringyesThe export name, from azure_list_cost_exports.
resourceGroupNamestringnonullThe resource group, if the export is scoped to one. Omit for a subscription-scoped export.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the scheduled cost exports configured on a subscription — the recurring jobs that write cost detail files to a storage account. Each item carries properties.schedule (status and recurrence), properties.definition (what data is exported) and properties.deliveryInfo.destination (the storage account, container and folder). Exports are the supported way to get LARGE or historical cost datasets: azure_query_cost is quota-metered and capped, while an export can move a whole year of line-item detail. Pass expand="runHistory" to see recent runs inline instead of calling azure_list_cost_export_runs per export.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullSet to "runHistory" to include each export's recent runs inline.
resourceGroupNamestringnonullRestrict to exports scoped to one resource group. Omit for the whole subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List Azure's reserved-instance recommendations for a subscription — where committing to a one- or three-year reservation would cost less than pay-as-you-go, based on the customer's own recent usage. Each item carries the recommended SKU and quantity, the look-back period it was computed from, the projected netSavings and the costWithNoReservedInstances baseline. This is the highest-value cost tool after azure_query_cost for an MSP conversation, because the saving is concrete and attributable. Two caveats to pass on: the projection assumes usage continues at the observed rate, so it is wrong for a workload about to be migrated or decommissioned; and a reservation is a genuine financial commitment with limited cancellation rights, so this is advice for a human to approve, never an action to take.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOData filter, e.g. "properties/scope eq 'Single' and properties/lookBackPeriod eq 'Last30Days'".
maxItemsintegerno1000Maximum recommendations to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List individual billing line items — one row per meter per resource per day, with the resource id, meter, quantity, unit price, effective price and cost. This is the LINE-ITEM detail behind the totals azure_query_cost aggregates: use it to answer "which exact resource caused this charge", and use the query tool for anything summarized. Filter by date with an OData expression such as "properties/usageStart ge '2026-08-01' and properties/usageEnd le '2026-08-07'", and set metric to ActualCost or AmortizedCost. Be deliberate about the range: a busy subscription produces tens of thousands of rows per month, and a scheduled export (azure_create_cost_export) is the supported path for anything larger than a few days.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullComma-separated fields to expand, e.g. "meterDetails,additionalInfo".
filterstringnonullOData filter, most usefully by date, e.g. "properties/usageStart ge '2026-08-01'".
maxItemsintegerno1000Maximum line items to return (1-1000, default 1000). Line-item data is large — narrow the filter rather than raising this.
metricstringnonullMetric: ActualCost (default) or AmortizedCost.
resourceGroupNamestringnonullRestrict to one resource group. Omit for the whole subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] THE cost question tool: what a subscription (or one resource group) spent, broken down however you ask. Read-only despite being an HTTP POST — it aggregates billing records and changes nothing. Group by up to two dimensions (ResourceGroupName, ServiceName, MeterCategory, ResourceLocation, ResourceId, ChargeType) and/or tag keys, over a timeframe of MonthToDate, BillingMonthToDate, TheLastMonth, TheLastBillingMonth, WeekToDate or Custom. The response is a columns/rows table, NOT a list of objects: read properties.columns to learn what each position in properties.rows means before interpreting any number. Two caveats worth passing to the caller: cost data refreshes roughly every four hours and the current period is re-rated until the invoice closes, so today's figure can legitimately change; and this API is quota-metered in query processing units, so prefer one grouped call over a loop of narrow ones. costType ActualCost bills reservations when purchased, AmortizedCost spreads them across the term — the two disagree by design for any customer holding reservations. PAGINATION HERE IS UNLIKE THE REST OF THIS CONNECTOR: because this is a POST it is not auto-paged, and the continuation token arrives as properties.nextLink INSIDE the response body rather than as the uniform top-level nextLink — when it is present, re-issue this same call with the $skiptoken value from that link passed as skipToken. A 403 almost always means a MISSING COST ROLE rather than a missing subscription: reading cost data needs Cost Management Reader or Billing Reader, and Contributor — even Owner — does not include it, which is a common gap for an engineer who can otherwise manage every resource in the subscription.

ParamTypeRequiredDefaultDescription
costTypestringnonullCost type: ActualCost (default), AmortizedCost or Usage.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterJsonstringnonullOptional filter as a JSON object in Azure's filter shape, e.g. {"dimensions":{"name":"ResourceGroupName","operator":"In","values":["prod-rg"]}}.
fromDatestringnonullStart date for timeframe=Custom, e.g. 2026-07-01. Required with Custom, ignored otherwise.
granularitystringnonullGranularity: Daily or Monthly. Omit for a single total over the whole timeframe.
groupByDimensionsstringnonullComma-separated dimensions to group by, e.g. "ResourceGroupName,ServiceName". Azure allows at most two groupings in total across dimensions and tags.
groupByTagsstringnonullComma-separated TAG KEYS to group by, e.g. "costCentre". Counts toward the same limit of two groupings.
resourceGroupNamestringnonullRestrict to one resource group. Omit to query the whole subscription.
skipTokenstringnonullContinuation token to fetch the next page: the $skiptoken value carried in a previous response's properties.nextLink.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
timeframestringnonullTimeframe: MonthToDate, BillingMonthToDate, TheLastMonth, TheLastBillingMonth, WeekToDate or Custom. Default MonthToDate.
toDatestringnonullEnd date for timeframe=Custom, e.g. 2026-07-31. Required with Custom, ignored otherwise.

[Microsoft Azure] Trigger a scheduled cost export to run immediately, without waiting for its next scheduled time. Flagged DESTRUCTIVE deliberately, even though it deletes nothing: it writes a file into a CUSTOMER's storage account on a cadence nobody agreed to, it can overwrite the blob the last scheduled run produced for the same period, it bills that customer for the storage and egress, and anything watching the container for new blobs will treat the out-of-band file as a real period boundary. None of that is undoable from here. Run it when you genuinely need data fresher than the schedule provides — after repairing a broken export, or to seed a new container — and read azure_list_cost_export_runs FIRST to find out why a file is missing rather than forcing another one. The run is ASYNCHRONOUS: this returns as soon as Azure accepts it and the file appears minutes later, so poll azure_list_cost_export_runs for the outcome instead of assuming success. A run that reports NewDataNotAvailable is not a failure — it means no fresh cost data existed for the period, the usual result of triggering twice inside one four-hour refresh window.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
exportNamestringyesThe export name to run now, from azure_list_cost_exports.
resourceGroupNamestringnonullThe resource group, if the export is scoped to one. Omit for a subscription-scoped export.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

Monitor

ToolPlanAccessSummary
azure_create_action_groupProWriteCreate an action group, or replace an existing one.
azure_create_diagnostic_settingProWriteCreate a diagnostic setting, or replace an existing one, so a resource ships its logs and metrics to a Log Analytics workspace, a storage account or an event hub.
azure_delete_action_groupProDestructiveDelete an action group.
azure_delete_autoscale_settingProDestructiveDelete an autoscale setting permanently.
azure_delete_diagnostic_settingProDestructiveDelete a diagnostic setting, stopping the export of that resource's logs and metrics.
azure_delete_log_alert_ruleProDestructiveDelete a log search alert rule permanently.
azure_delete_metric_alert_ruleProDestructiveDelete a metric alert rule permanently.
azure_get_action_groupFreeRead-onlyGet one action group with every receiver in full, including each one's enabled state and, for webhooks, the URI and whether the common alert schema is used.
azure_get_autoscale_settingFreeRead-onlyGet one autoscale setting in full: every profile with its capacity bounds and its recurrence or fixed-date schedule, and every scale rule with its metric trigger, threshold, direction, instance change…
azure_get_diagnostic_settingFreeRead-onlyGet one diagnostic setting by name, with its full logs and metrics arrays and every destination it writes to.
azure_get_log_alert_ruleFreeRead-onlyGet one log search alert rule in full, including the complete KQL query it runs.
azure_get_metric_alert_ruleFreeRead-onlyGet one metric alert rule in full: every criterion with its metric name, dimensions, threshold and operator, the auto-mitigate setting, the evaluation window and the action groups attached.
azure_get_metric_alert_rule_statusFreeRead-onlyGet the current firing STATE of a metric alert rule, per dimension combination: whether it is currently Fired or Resolved, when that state was entered, and the value that caused it.
azure_get_metricsFreeRead-onlyRead actual metric VALUES for one Azure resource over a time window — CPU, memory, disk, request counts, latency, whatever azure_list_metric_definitions says the resource emits.
azure_list_action_groupsFreeRead-onlyList every action group in a subscription with its short name and every receiver it notifies — email, SMS, voice, push, webhook, Logic App, Azure Function, ITSM connector and automation runbook.
azure_list_activity_logFreeRead-onlyRead the subscription's activity log — the control-plane audit trail of WHO changed WHAT and WHEN, including the caller's identity, the operation name, the status, the correlation id and the resource…
azure_list_activity_log_alert_rulesFreeRead-onlyList the activity log alert rules in a subscription — the rules that fire when a control-plane EVENT happens rather than when a metric crosses a threshold: a resource deleted, a service health…
azure_list_autoscale_settingsFreeRead-onlyList the autoscale settings in a subscription — the rules that add and remove instances on scale sets, App Service plans and other scalable resources.
azure_list_diagnostic_setting_categoriesFreeRead-onlyList the log and metric categories a specific resource is CAPABLE of exporting, with each category's type and, for logs, the category groups ("allLogs", "audit") it belongs to.
azure_list_diagnostic_settingsFreeRead-onlyList the diagnostic settings on a resource — where its platform logs and metrics are being SHIPPED, if anywhere: a Log Analytics workspace, a storage account, an event hub, or a marketplace partner.
azure_list_log_alert_rulesFreeRead-onlyList the log search alert rules in a subscription — the rules that run a KQL query against a Log Analytics workspace on a schedule and fire on the result.
azure_list_metric_alert_rulesFreeRead-onlyList every metric alert rule in a subscription, with its scopes (what it watches), criteria (the metric, aggregation, operator and threshold), evaluationFrequency and windowSize, severity 0-4, the…
azure_list_metric_definitionsFreeRead-onlyList the metrics that a specific Azure resource actually emits, with each metric's name, display name, unit, the aggregations it supports (Average, Minimum, Maximum, Total, Count), its supported time…
azure_list_metric_namespacesFreeRead-onlyList the metric namespaces available on a resource.
azure_set_autoscale_setting_enabledProDestructiveSwitch an autoscale setting on or off.
azure_set_log_alert_rule_enabledProDestructiveSwitch a log search alert rule on or off.
azure_set_metric_alert_rule_enabledProDestructiveSwitch a metric alert rule on or off.

[Microsoft Azure] Create an action group, or replace an existing one. Not destructive when creating: a new group notifies nobody until an alert rule references it. UPDATING replaces the whole group — every receivers array you omit is dropped, so read azure_get_action_group first. Two ARM rules that produce confusing errors otherwise: the group's location must be the literal "Global" (it is not a regional resource), and groupShortName is capped at 12 characters because it is what appears in an SMS. Give receivers as JSON arrays in ARM's own shape, e.g. emailReceiversJson [{"name":"oncall","emailAddress":"ops@contoso.com","useCommonAlertSchema":true}]. Adding an SMS or voice receiver starts BILLING per notification, and adding an email receiver sends that address a confirmation immediately.

ParamTypeRequiredDefaultDescription
actionGroupNamestringyesThe action group name to create or replace.
emailReceiversJsonstringnonullEmail receivers as a JSON array, e.g. [{"name":"oncall","emailAddress":"ops@contoso.com","useCommonAlertSchema":true}].
enabledbooleannotrueSet false to create the group without it notifying anything yet.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
groupShortNamestringyesShort name shown in SMS and push notifications. Maximum 12 characters.
resourceGroupNamestringyesThe resource group to create the action group in.
smsReceiversJsonstringnonullSMS receivers as a JSON array, e.g. [{"name":"oncall-sms","countryCode":"1","phoneNumber":"5551234567"}]. Billable per message.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object, e.g. {"environment":"production"}.
webhookReceiversJsonstringnonullWebhook receivers as a JSON array, e.g. [{"name":"psa","serviceUri":"https://...","useCommonAlertSchema":true}].

[Microsoft Azure] Create a diagnostic setting, or replace an existing one, so a resource ships its logs and metrics to a Log Analytics workspace, a storage account or an event hub. Not destructive when CREATING — it starts collection that was not happening. UPDATING is where the care is needed: this is a PUT with no partial update, so the logs and metrics arrays you send REPLACE what is there, and a category you omit stops being collected immediately with no error and no notification. Read azure_get_diagnostic_setting first. Give logsJson and metricsJson as JSON arrays in ARM's own shape, e.g. logsJson [{"categoryGroup":"audit","enabled":true}] and metricsJson [{"category":"AllMetrics","enabled":true}] — azure_list_diagnostic_setting_categories tells you what this resource type supports. At least one destination is required. Ingestion is BILLABLE per GB, so enabling allLogs on a chatty resource is a cost decision as much as a monitoring one.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
eventHubAuthorizationRuleIdstringnonullFull ARM resource id of an event hub authorization rule to send to.
eventHubNamestringnonullEvent hub name, when sending to an event hub.
logsJsonstringnonullLog categories as a JSON array, e.g. [{"categoryGroup":"audit","enabled":true}].
metricsJsonstringnonullMetric categories as a JSON array, e.g. [{"category":"AllMetrics","enabled":true}].
resourceIdstringyesFull ARM resource id to attach the setting to.
settingNamestringyesThe diagnostic setting name to create or replace.
storageAccountIdstringnonullFull ARM resource id of a storage account to send to.
workspaceIdstringnonullFull ARM resource id of a Log Analytics workspace to send to.

[Microsoft Azure] Delete an action group. DESTRUCTIVE WITH A BLAST RADIUS BEYOND THE GROUP ITSELF: every alert rule that referenced it keeps evaluating and keeps firing, and now tells nobody. Azure does not refuse the delete, does not warn that rules depend on it, and does not mark those rules as broken — they carry on looking healthy in azure_list_metric_alert_rules with a dangling action id. One deleted action group can silence an entire environment's monitoring. Check which rules reference it first, and confirm with a human.

ParamTypeRequiredDefaultDescription
actionGroupNamestringyesThe action group name to DELETE.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the action group lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete an autoscale setting permanently. The resource keeps running at whatever instance count it currently holds and never changes it again — same freeze as disabling, without the way back — and the profiles, thresholds and cooldowns someone tuned against real traffic are gone. Read azure_get_autoscale_setting and keep the definition first, and prefer azure_set_autoscale_setting_enabled with false if this is temporary. After deleting, set an explicit instance count on the target resource rather than leaving it wherever autoscale happened to stop.

ParamTypeRequiredDefaultDescription
autoscaleSettingNamestringyesThe autoscale setting name to DELETE.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the setting lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a diagnostic setting, stopping the export of that resource's logs and metrics. DESTRUCTIVE IN A WAY THAT DOES NOT SHOW UP FOR WEEKS: the resource keeps running perfectly, nothing errors, no alert fires, and log records simply stop arriving. The setting itself takes a minute to rebuild — the records that were never shipped during the gap do not exist anywhere and cannot be back-filled, so for a customer under a retention or audit obligation this deletes evidence rather than configuration. Read azure_get_diagnostic_setting and keep the definition first. The legitimate reason is almost always cost, and reducing the categories through azure_create_diagnostic_setting is the cheaper answer than removing collection entirely.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceIdstringyesFull ARM resource id the setting is attached to.
settingNamestringyesThe diagnostic setting name to DELETE.

[Microsoft Azure] Delete a log search alert rule permanently. The KQL query goes with it, and that query is usually the part someone spent real time getting right — rebuilding it means rediscovering which table, which fields and which threshold actually distinguish the condition from noise. No recycle bin. Read azure_get_log_alert_rule first and keep the query text, or use azure_set_log_alert_rule_enabled with false, which is reversible.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the rule lives in.
ruleNamestringyesThe log search alert rule name to DELETE.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a metric alert rule permanently. Same blindness as disabling one, without the easy undo: the rule's criteria, thresholds and action-group wiring are gone, and rebuilding them means re-deriving thresholds someone tuned over time. There is no recycle bin. Read azure_get_metric_alert_rule first and keep the definition — and consider azure_set_metric_alert_rule_enabled with false instead, which is reversible and leaves the tuning intact.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the rule lives in.
ruleNamestringyesThe metric alert rule name to DELETE.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one action group with every receiver in full, including each one's enabled state and, for webhooks, the URI and whether the common alert schema is used. Read this before azure_create_action_group on an existing name — that call is a PUT that replaces the whole group, so a receivers array you do not send is a receivers array that stops being notified. Webhook URIs returned here can contain secrets in their query string, which is worth remembering before pasting the response into a ticket.

ParamTypeRequiredDefaultDescription
actionGroupNamestringyesThe action group name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the action group lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one autoscale setting in full: every profile with its capacity bounds and its recurrence or fixed-date schedule, and every scale rule with its metric trigger, threshold, direction, instance change and cooldown. The cooldown and the scale-in threshold are where autoscale misbehaviour usually lives — a scale-out threshold and a scale-in threshold set too close together produce flapping, where the service scales up and down continuously and each cycle costs a full instance-hour. Multiple profiles are evaluated by schedule, so a setting that "ignores" its rules is often running a different profile than the one being read.

ParamTypeRequiredDefaultDescription
autoscaleSettingNamestringyesThe autoscale setting name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the setting lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one diagnostic setting by name, with its full logs and metrics arrays and every destination it writes to. READ THIS BEFORE azure_create_diagnostic_setting on an existing name — that call is a PUT that replaces the whole object, so any category you leave out stops being collected the moment it succeeds, silently and with no error. Fetch, change the one thing you mean to change, and send the rest back unchanged.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceIdstringyesFull ARM resource id the setting is attached to.
settingNamestringyesThe diagnostic setting name, from azure_list_diagnostic_settings.

[Microsoft Azure] Get one log search alert rule in full, including the complete KQL query it runs. The query is the rule — everything else is scheduling — so this is the call that answers "what does this alert actually look for?", and it is worth reading before trusting an alert's name. A rule whose query references a table that stopped being ingested (because a diagnostic setting was removed) returns no rows forever and therefore never fires, which looks identical to "nothing is wrong". Cross-check with azure_list_diagnostic_settings on the resources the query names.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the rule lives in.
ruleNamestringyesThe log search alert rule name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one metric alert rule in full: every criterion with its metric name, dimensions, threshold and operator, the auto-mitigate setting, the evaluation window and the action groups attached. Read this before changing anything about the rule — and read the criteria carefully when a customer says an alert "never fires": a threshold on the wrong aggregation (Average where Maximum was meant) is invisible in the portal summary and produces a rule that is technically working and practically useless.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the rule lives in.
ruleNamestringyesThe metric alert rule name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get the current firing STATE of a metric alert rule, per dimension combination: whether it is currently Fired or Resolved, when that state was entered, and the value that caused it. This is the difference between "the rule is configured" and "the rule is angry right now", and on a multi-dimensional rule it tells you WHICH instance is in trouble rather than just that something is. A rule whose status has been Fired for weeks is usually a threshold set too tight rather than a real long-running incident, and it is the reason the customer's team has learned to ignore that alert.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the rule lives in.
ruleNamestringyesThe metric alert rule name, from azure_list_metric_alert_rules.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Read actual metric VALUES for one Azure resource over a time window — CPU, memory, disk, request counts, latency, whatever azure_list_metric_definitions says the resource emits. This is the call behind "is this server actually busy?" and "was it busy at 3am on Tuesday?". Two traps worth knowing. First, an empty timeseries means the metric name did not match, NOT that the value was zero — Azure returns no error for an unknown metric name, so verify the name against the definitions first. Second, the interval you ask for must be one the metric supports and Azure silently coarsens it otherwise, so a PT1M request over a 30-day span comes back hourly. Platform metrics are retained for 93 days; anything older needs Log Analytics.

ParamTypeRequiredDefaultDescription
aggregationstringno"Average"Aggregation: Average, Minimum, Maximum, Total or Count. Comma-separate for more than one.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOptional dimension filter, e.g. "LUN eq '*'" to split a disk metric by disk.
intervalstringno"PT5M"Sample interval, e.g. PT1M, PT5M, PT1H, P1D. Must be one the metric supports.
metricNamesstringyesComma-separated metric names, exactly as azure_list_metric_definitions spells them, e.g. "Percentage CPU,Available Memory Bytes".
metricNamespacestringnonullOptional metric namespace, for custom or guest-OS metrics.
resourceIdstringyesFull ARM resource id of the resource to read metrics from.
timespanstringno"PT1H"ISO-8601 time window, e.g. PT1H for the last hour or 2026-08-01T00:00:00Z/2026-08-02T00:00:00Z for a fixed range.
topintegerno100Maximum records when splitting by a dimension.

[Microsoft Azure] List every action group in a subscription with its short name and every receiver it notifies — email, SMS, voice, push, webhook, Logic App, Azure Function, ITSM connector and automation runbook. An action group is WHO gets told when an alert fires, so this is the other half of any monitoring review: rules without action groups notify nobody, and action groups pointing at a former employee's address notify nobody who is listening. Check enabled on the group AND on each receiver — a receiver can be individually disabled, most often because the recipient clicked the unsubscribe link in an alert email, which silently removes them without changing anything visible on the group.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum groups to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Read the subscription's activity log — the control-plane audit trail of WHO changed WHAT and WHEN, including the caller's identity, the operation name, the status, the correlation id and the resource affected. This is the first call for "who deleted the VM?", "why did this restart?" and "what changed before the outage started?", and it is often the only record: deleting a resource removes the resource but not its activity log entries. A time filter is REQUIRED by the API and this tool builds one from startTime, so a request always has a bounded window. Retention is 90 DAYS and is not configurable — anything older exists only if a diagnostic setting was exporting the log to a workspace or storage account, which is exactly why azure_list_diagnostic_settings on the subscription is worth checking during onboarding rather than after an incident.

ParamTypeRequiredDefaultDescription
callerstringnonullOptional caller to restrict to — a user principal name or an object id.
endTimestringnonullOptional end of the window as ISO-8601 UTC. Omit for "up to now".
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno200Maximum events to return (1-1000, default 200). The log is dense; narrow the window rather than raising this.
resourceGroupNamestringnonullOptional resource group to restrict to.
resourceIdstringnonullOptional full ARM resource id to restrict to a single resource.
startTimestringyesStart of the window as ISO-8601 UTC, e.g. 2026-08-12T00:00:00Z. Must be within the last 90 days.
statusstringnonullOptional status, e.g. Succeeded, Failed, Started.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the activity log alert rules in a subscription — the rules that fire when a control-plane EVENT happens rather than when a metric crosses a threshold: a resource deleted, a service health advisory published, a policy assignment changed, an administrative operation failing. Each carries its scopes, its condition.allOf clauses, the action groups it notifies and whether it is enabled. Worth reading alongside azure_list_metric_alert_rules during a monitoring review, because the two answer different questions and a customer who has only metric alerts gets no notification at all when someone deletes the resource being monitored.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum rules to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the autoscale settings in a subscription — the rules that add and remove instances on scale sets, App Service plans and other scalable resources. Each carries its profiles with their capacity minimum, maximum and default, the scale rules with their metric triggers and cooldowns, the target resource, and whether it is enabled. Read minimum against maximum when a customer reports a cost surprise or a performance one: an autoscale maximum set high enough to be invisible in testing is how a runaway workload becomes a five-figure month, and a minimum of 1 on a production service is how a single instance restart becomes an outage.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum settings to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the log and metric categories a specific resource is CAPABLE of exporting, with each category's type and, for logs, the category groups ("allLogs", "audit") it belongs to. Categories are per resource type and are not guessable, so this is the lookup that comes before writing a diagnostic setting — naming a category the resource does not publish is rejected with an error that does not list the valid ones. The "audit" category group is the one to reach for when a customer needs security logging without paying to ingest every verbose operational log.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceIdstringyesFull ARM resource id to inspect.

[Microsoft Azure] List the diagnostic settings on a resource — where its platform logs and metrics are being SHIPPED, if anywhere: a Log Analytics workspace, a storage account, an event hub, or a marketplace partner. Each setting names the log categories and metric categories it is exporting. AN EMPTY RESULT IS THE FINDING, not a null answer: it means that resource's logs exist only in Azure's own 90-day activity window (or not at all, for resource logs, which are NOT retained anywhere by default) and cannot be queried later. Run this against a customer's key resources during onboarding — a security review that assumes logs exist because the resource is running is the most common gap this call closes.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceIdstringyesFull ARM resource id to inspect — any resource, or a subscription id path for the activity log itself.

[Microsoft Azure] List the log search alert rules in a subscription — the rules that run a KQL query against a Log Analytics workspace on a schedule and fire on the result. Each carries its scopes, the query text, evaluationFrequency and windowSize, severity, the threshold and operator, muteActionsDuration and its action groups. These are the rules that catch what metrics cannot: a specific error string appearing in application logs, a sign-in from an unexpected country, a backup job that logged a failure. Read the windowSize against the evaluationFrequency when reviewing — a window shorter than the frequency leaves blind gaps between evaluations, and a window much longer double-counts the same events into repeated alerts.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum rules to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every metric alert rule in a subscription, with its scopes (what it watches), criteria (the metric, aggregation, operator and threshold), evaluationFrequency and windowSize, severity 0-4, the action groups it notifies, and — the field to read first — whether it is ENABLED. Two findings this call produces on almost every monitoring review: rules that are disabled and nobody remembers switching off, and rules with an empty actions array, which evaluate and fire correctly and then tell absolutely nobody. A rule scoped to a resource that has since been deleted is the third; it stays in the list looking healthy forever.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum rules to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the metrics that a specific Azure resource actually emits, with each metric's name, display name, unit, the aggregations it supports (Average, Minimum, Maximum, Total, Count), its supported time grains and its dimensions. CALL THIS BEFORE azure_get_metrics: metric names are per resource type and are not guessable — a virtual machine exposes "Percentage CPU" while an App Service exposes "CpuPercentage", and asking for the wrong one returns an empty series rather than an error, which reads exactly like "the resource is idle". The dimensions listed here are also what you can split or filter a query by.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
metricNamespacestringnonullOptional metric namespace, from azure_list_metric_namespaces — needed for custom or guest-OS metrics.
resourceIdstringyesFull ARM resource id of the resource to inspect, e.g. /subscriptions/.../providers/Microsoft.Compute/virtualMachines/web01.

[Microsoft Azure] List the metric namespaces available on a resource. Most Azure resources publish everything under one implicit platform namespace and need this call at all — it matters when a resource has CUSTOM metrics, or guest-OS metrics collected by the Azure Monitor agent, which live in their own namespaces and are invisible to azure_list_metric_definitions until you name the namespace. If a customer insists a metric exists and the definitions call does not show it, this is where it is hiding.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceIdstringyesFull ARM resource id of the resource to inspect.
startTimestringnonullOptional ISO-8601 start time; namespaces are returned as of this moment.

[Microsoft Azure] Switch an autoscale setting on or off. DESTRUCTIVE because of what happens next rather than what happens now: disabling autoscale FREEZES the resource at its current instance count, so a service sitting at its scale-in floor when you disable it stays there through the next traffic peak and falls over under load that it would have handled. Nothing about the resource looks wrong in the meantime. Disabling is the right move when autoscale is flapping or during a controlled capacity test, and it should be paired with setting a manual instance count that can survive peak. Enabling hands capacity back to the rules, which will begin acting within one evaluation cycle. This sends a PATCH, so the profiles and rules are untouched.

ParamTypeRequiredDefaultDescription
autoscaleSettingNamestringyesThe autoscale setting name.
enabledbooleanyestrue to let the rules control capacity, false to freeze the current instance count.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the setting lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Switch a log search alert rule on or off. Flagged destructive for the same reason as the metric-alert equivalent: disabling stops every notification silently, the query stops running, and nothing in Azure says so. It matters slightly more here, because log search rules are usually the ones watching for security events and failed backups — the alerts nobody sees precisely because they normally do not fire. Enabling is safe. This sends a PATCH, so the query and schedule are untouched.

ParamTypeRequiredDefaultDescription
enabledbooleanyestrue to enable the rule, false to stop it running and notifying.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the rule lives in.
ruleNamestringyesThe log search alert rule name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Switch a metric alert rule on or off. DESTRUCTIVE IN ONE DIRECTION, which is why it is flagged regardless of which way you are going: disabling a rule stops every notification it would have sent, the monitored resource keeps running normally, and NOTHING in Azure announces that monitoring has stopped — the failure is discovered by the incident that should have paged someone. Disabling during a planned maintenance window is legitimate; leaving it disabled afterwards is the single most common monitoring gap in an inherited environment, so pair it with a reminder to re-enable. Enabling is safe and reversible. This sends a PATCH, so nothing else about the rule changes.

ParamTypeRequiredDefaultDescription
enabledbooleanyestrue to enable the rule, false to stop it notifying.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the rule lives in.
ruleNamestringyesThe metric alert rule name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

Log Analytics

ToolPlanAccessSummary
azure_create_log_analytics_saved_searchProWriteSave a KQL query into a workspace so the customer's team can reuse it, or update an existing one.
azure_create_log_analytics_workspaceProWriteCreate a Log Analytics workspace, or update an existing one's retention, SKU and access settings.
azure_delete_log_analytics_saved_searchProDestructiveDelete a saved search.
azure_delete_log_analytics_workspaceProDestructiveDelete a Log Analytics workspace and everything ingested into it.
azure_get_log_analytics_saved_searchFreeRead-onlyGet one saved search with its full query text, category, display name and — when it is defined as a function — its alias and parameter list.
azure_get_log_analytics_tableFreeRead-onlyGet one table's configuration: its plan, its effective retention and total retention, its schema with every column and type, and for a custom table its search-results or restored-logs origin.
azure_get_log_analytics_workspaceFreeRead-onlyGet one Log Analytics workspace in full.
azure_get_log_analytics_workspace_usageFreeRead-onlyReport a workspace's current data-ingestion usage against its quota, with the current value, the limit, the unit and the reset time.
azure_list_log_analytics_saved_searchesFreeRead-onlyList a workspace's saved searches — the stored KQL queries a customer's team has built up, each with its category, display name and query text.
azure_list_log_analytics_tablesFreeRead-onlyList the tables in a workspace with each one's plan (Analytics, Basic or Auxiliary), its own retentionInDays and totalRetentionInDays, and whether it is a built-in Microsoft table or a custom one.
azure_list_log_analytics_workspace_keysProDestructiveReturn a workspace's primary and secondary SHARED KEYS.
azure_list_log_analytics_workspacesFreeRead-onlyList every Log Analytics workspace in a subscription, each with its customerId (the GUID azure_query_log_analytics needs), sku, retentionInDays, provisioningState, publicNetworkAccess settings and the…
azure_list_log_analytics_workspaces_in_resource_groupFreeRead-onlyList the Log Analytics workspaces inside one resource group.
azure_query_log_analyticsFreeRead-onlyRun a KQL query against a Log Analytics workspace and get the result tables back.
azure_set_log_analytics_table_retentionProDestructiveSet how long one table keeps its data.

[Microsoft Azure] Save a KQL query into a workspace so the customer's team can reuse it, or update an existing one. Not destructive: a saved search stores query TEXT and runs nothing on its own — it neither ingests, deletes nor costs anything until someone opens it. Updating is a PUT that replaces the whole object, so send the category and any function alias back along with the query. Set functionAlias to make the query callable by name from other queries, which is how a customer's team builds a shared vocabulary; changing or removing an alias that other queries call breaks them silently, so read azure_get_log_analytics_saved_search first.

ParamTypeRequiredDefaultDescription
categorystringyesCategory the search is grouped under, e.g. Security.
displayNamestringyesDisplay name shown to the customer's team.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
functionAliasstringnonullOptional function alias, making the query callable by name from other queries.
functionParametersstringnonullOptional function parameters, e.g. "days:int = 7".
querystringyesThe KQL query text.
resourceGroupNamestringyesThe resource group the workspace lives in.
savedSearchIdstringyesThe saved search id to create or replace, e.g. failed-signins.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
workspaceNamestringyesThe workspace name.

[Microsoft Azure] Create a Log Analytics workspace, or update an existing one's retention, SKU and access settings. Not destructive when CREATING: a new workspace is empty and ingests nothing until a diagnostic setting or agent points at it. UPDATING deserves care for one reason — LOWERING retentionInDays deletes data older than the new value, permanently and without confirmation, so treat a retention reduction here exactly as seriously as azure_set_log_analytics_table_retention. Ingestion is BILLED PER GB and retention beyond the SKU's included period is billed per GB per month, so both numbers are cost decisions. PerGB2018 is the standard SKU; a capacity reservation is cheaper only above a sustained daily volume.

ParamTypeRequiredDefaultDescription
dailyQuotaGbnumbernonullOptional daily ingestion cap in GB. The workspace stops ingesting for the rest of the day when it is hit.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
resourceGroupNamestringyesThe resource group to create the workspace in.
retentionInDaysintegerno30Retention in days, 30-730. LOWERING this on an existing workspace DELETES older data.
skustringno"PerGB2018"SKU name, e.g. PerGB2018 (standard) or CapacityReservation.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object, e.g. {"environment":"production"}.
workspaceNamestringyesThe workspace name to create or update.

[Microsoft Azure] Delete a saved search. No log data is touched — what is lost is the query, which is often the more expensive artifact: someone worked out which table, which fields and which thresholds actually distinguish the condition from noise, and there is no version history to recover it from. If the search defined a functionAlias, every other query calling that alias breaks immediately and reports an unresolved name rather than pointing back here. Read azure_get_log_analytics_saved_search and keep the text first.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the workspace lives in.
savedSearchIdstringyesThe saved search id to DELETE.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
workspaceNamestringyesThe workspace name.

[Microsoft Azure] Delete a Log Analytics workspace and everything ingested into it. DESTRUCTIVE AT THE LARGEST SCALE IN THIS CONNECTOR: this is every log record the customer has, not a configuration object — sign-in history, security events, application traces, the evidence behind any retention obligation. It also breaks every diagnostic setting, alert rule and workbook pointing at the workspace, none of which are updated or flagged. By default the workspace is SOFT DELETED and can be recovered for 14 days by recreating it with the same name in the same resource group; passing force=true skips that entirely and is irreversible from the moment it returns. Never call this without an explicit human decision, and prefer reducing retention or ingestion if the goal is cost.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
forcebooleannofalsetrue to PERMANENTLY delete, skipping the 14-day soft-delete recovery window. Leave false unless a human has said otherwise.
resourceGroupNamestringyesThe resource group the workspace lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
workspaceNamestringyesThe workspace name to DELETE.

[Microsoft Azure] Get one saved search with its full query text, category, display name and — when it is defined as a function — its alias and parameter list. Fetch this before replacing one: azure_create_log_analytics_saved_search is a PUT that replaces the whole object, so a category or function alias you do not send is dropped, and dropping a functionAlias silently breaks every other query that calls it by name.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the workspace lives in.
savedSearchIdstringyesThe saved search id, from azure_list_log_analytics_saved_searches.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
workspaceNamestringyesThe workspace name.

[Microsoft Azure] Get one table's configuration: its plan, its effective retention and total retention, its schema with every column and type, and for a custom table its search-results or restored-logs origin. Read the schema when a query fails on a column name — Microsoft renames and adds columns in built-in tables over time, and a query copied from an older runbook can reference a column that no longer exists. Read retentionInDays before changing it, because azure_set_log_analytics_table_retention deletes anything older than the value you set.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the workspace lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tableNamestringyesThe table name, e.g. SigninLogs or Heartbeat — from azure_list_log_analytics_tables.
workspaceNamestringyesThe workspace name.

[Microsoft Azure] Get one Log Analytics workspace in full. THE FIELD YOU USUALLY CAME FOR IS customerId — the bare GUID that azure_query_log_analytics takes, which is deliberately not the same as the workspace's ARM resource id. Also carries retentionInDays (how far back a query can reach), the sku and its capacity reservation, workspaceCapping.dailyQuotaGb, the public network access settings for ingestion and query separately, and the soft-delete period. Read retentionInDays before promising a customer that last quarter's data is available: the default is 30 days on most SKUs, not the year people assume.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the workspace lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
workspaceNamestringyesThe workspace NAME (not its customer id).

[Microsoft Azure] Report a workspace's current data-ingestion usage against its quota, with the current value, the limit, the unit and the reset time. This is the cost and the availability question in one call: Log Analytics bills per GB ingested, so a workspace whose usage jumped is a bill that jumped, and a workspace at its daily cap has STOPPED ingesting until the reset — meaning the logs someone is about to go looking for do not exist for the rest of today. When usage is unexpectedly high, azure_query_log_analytics with a Usage table summary by DataType names the source in one query.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the workspace lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
workspaceNamestringyesThe workspace name.

[Microsoft Azure] List a workspace's saved searches — the stored KQL queries a customer's team has built up, each with its category, display name and query text. This is the fastest way to learn an unfamiliar environment: the saved searches ARE the institutional knowledge about what matters in these logs, usually written by whoever handled the last incident. Anything defined with a functionAlias is also callable as a function from inside other queries, which is worth knowing before deciding a query references a table that does not exist. Note this sub-resource uses its own api-version, not the workspace one.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum saved searches to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the workspace lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
workspaceNamestringyesThe workspace name.

[Microsoft Azure] List the tables in a workspace with each one's plan (Analytics, Basic or Auxiliary), its own retentionInDays and totalRetentionInDays, and whether it is a built-in Microsoft table or a custom one. This is what a KQL query can actually reach, so it answers "why does my query return nothing?" better than the query does: a table that is not listed here is not being ingested, which points back at a missing diagnostic setting rather than a broken query. Also read the plan — a table on the Basic plan is much cheaper to ingest but supports only a restricted query surface and no alert rules, so a log alert written against it will never work.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum tables to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the workspace lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
workspaceNamestringyesThe workspace name.

[Microsoft Azure] Return a workspace's primary and secondary SHARED KEYS. THESE ARE CREDENTIALS, which is why this is marked destructive and gated to Pro despite reading rather than writing: the workspace id plus either key is all anything needs to write arbitrary records into the customer's logs through the data collector API, from anywhere on the internet, with no further authorization. Fabricated log entries are worse than missing ones, because everything downstream — alert rules, security reviews, audit exports — treats them as real. The legitimate use is configuring an agent or a collector that cannot use managed identity. Never write a key into a ticket, a chat message or a document, and prefer a data collection endpoint with managed identity where the platform supports it.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the workspace lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
workspaceNamestringyesThe workspace name.

[Microsoft Azure] List every Log Analytics workspace in a subscription, each with its customerId (the GUID azure_query_log_analytics needs), sku, retentionInDays, provisioningState, publicNetworkAccess settings and the daily ingestion cap if one is set. Start here on any new customer: the number of workspaces is itself a finding — one per environment is normal, one per resource group usually means logs are scattered and no query can see the whole picture, and none at all means nothing is being retained anywhere. workspaceCapping.dailyQuotaGb is worth checking too, because a workspace that hits its cap silently STOPS ingesting for the rest of the day and resumes the next, leaving a daily hole in exactly the data someone is relying on.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum workspaces to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the Log Analytics workspaces inside one resource group. Same item shape as azure_list_log_analytics_workspaces, scoped to a single group — the cheaper call when the caller already knows where the workspace lives.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum workspaces to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name, from azure_list_resource_groups.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Run a KQL query against a Log Analytics workspace and get the result tables back. THIS IS THE MOST USEFUL DIAGNOSTIC CALL IN THE WHOLE AZURE CONNECTOR: sign-in logs, application errors, VM performance history, backup job outcomes, firewall flow logs and anything else a diagnostic setting has shipped are all queryable here, and it reaches back as far as the workspace's retention rather than the 90 days platform metrics keep. Takes the workspace's CUSTOMER ID — a bare GUID from the workspace's customerId property, NOT its resource id or name; azure_get_log_analytics_workspace returns it. The query runs read-only against ingested data and changes nothing. An empty result usually means the table is not being ingested at all rather than that nothing happened, so check azure_list_log_analytics_tables when a query you trust comes back empty. Queries have a service-side time limit, so scope with a timespan and a where clause before reaching for a longer window.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
kqlstringyesThe KQL query, e.g. SigninLogs | where ResultType != 0 | summarize count() by UserPrincipalName
timespanstringnonullOptional ISO-8601 duration or interval, e.g. PT1H or P7D. Omit for the query's own time filter.
workspaceIdstringyesThe workspace CUSTOMER ID — a bare GUID, from the customerId property in azure_get_log_analytics_workspace. Not the ARM resource id.

[Microsoft Azure] Set how long one table keeps its data. DESTRUCTIVE IN THE MOST LITERAL SENSE AVAILABLE IN THIS CONNECTOR: lowering retention DELETES every record in that table older than the new value, immediately, permanently and with no confirmation prompt — dropping SigninLogs from 365 days to 30 destroys eleven months of authentication history in one call, and no other tool here can get it back. Raising retention is safe and simply costs more (retention beyond the workspace's included period is billed per GB per month). Read azure_get_log_analytics_table first, and treat any REDUCTION as an evidence-destruction decision that needs a human, especially on a table a customer's compliance obligations depend on. Set retentionInDays to -1 to inherit the workspace default.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the workspace lives in.
retentionInDaysintegeryesInteractive retention in days (4-730), or -1 to inherit the workspace default. LOWERING deletes older data.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tableNamestringyesThe table name to reconfigure.
totalRetentionInDaysintegernonullOptional total retention in days including the cheaper long-term archive (4-4383). Must be at least retentionInDays.
workspaceNamestringyesThe workspace name.

App Service

ToolPlanAccessSummary
azure_create_app_service_planProWriteCreate an App Service plan.
azure_delete_app_service_planProDestructiveDelete an App Service plan.
azure_delete_web_appProDestructiveDelete a web app or Function App permanently.
azure_delete_web_app_slotProDestructiveDelete a deployment slot.
azure_get_app_service_planFreeRead-onlyGet one App Service plan: its tier and size, current instance capacity, worker count, the number of sites on it, per-site scaling, zone redundancy and maximum elastic worker count.
azure_get_web_appFreeRead-onlyGet one web app or Function App in full: state, hostnames and their SSL bindings, the App Service plan, httpsOnly, clientCertMode, the managed identity if one is assigned, VNet integration, and a…
azure_get_web_app_configurationFreeRead-onlyGet a web app's site configuration — the runtime stack and version, alwaysOn, minTlsVersion, ftpsState, http20Enabled, remoteDebuggingEnabled, the health check path, IP restrictions and CORS.
azure_get_web_app_publishing_credentialsProDestructiveReturn a web app's publishing username and password.
azure_get_web_app_slotFreeRead-onlyGet one deployment slot in full — the same shape as azure_get_web_app, for the slot rather than production.
azure_get_web_app_source_controlFreeRead-onlyGet a web app's source control configuration — the repository URL, the branch, and whether continuous deployment is enabled.
azure_list_app_service_plan_web_appsFreeRead-onlyList the web apps running on one App Service plan.
azure_list_app_service_plansFreeRead-onlyList every App Service plan in a subscription with its sku (tier, size and CAPACITY — the instance count), numberOfSites, whether it is Linux (reserved), and its zone redundancy.
azure_list_web_app_connection_stringsProDestructiveReturn a web app's connection strings, with their type (SQLAzure, PostgreSQL, Custom and so on).
azure_list_web_app_deploymentsFreeRead-onlyList a web app's deployment history — each deployment's id, status, author, message, start and end time, and whether it is the currently active one.
azure_list_web_app_functionsFreeRead-onlyList the individual functions inside a Function App, each with its trigger configuration, script href, language and whether it is disabled.
azure_list_web_app_hostname_bindingsFreeRead-onlyList a web app's custom domain bindings, each with its SSL state, certificate thumbprint, hostname type and whether the domain is verified.
azure_list_web_app_instancesFreeRead-onlyList the running instances of a web app — the individual workers serving it, with each one's name and state.
azure_list_web_app_settingsProDestructiveReturn a web app's application settings — the environment variables the app runs with.
azure_list_web_app_slotsFreeRead-onlyList a web app's deployment slots — the parallel copies (staging, testing, blue) that a release is warmed up in before being swapped into production.
azure_list_web_appsFreeRead-onlyList every App Service web app and Function App in a subscription, each with its state (Running or Stopped), defaultHostName, the serverFarmId of the plan it runs on, its enabled hostnames, httpsOnly,…
azure_list_web_apps_in_resource_groupFreeRead-onlyList the web apps and Function Apps inside one resource group.
azure_restart_web_appProDestructiveRestart a web app.
azure_scale_app_service_planProDestructiveChange an App Service plan's tier, size or instance count.
azure_set_web_app_configurationProDestructiveUpdate a web app's site configuration.
azure_set_web_app_settingsProDestructiveReplace a web app's ENTIRE application settings collection.
azure_start_web_appProWriteStart a stopped web app.
azure_stop_web_appProDestructiveStop a web app.
azure_swap_web_app_slotsProDestructiveSwap a deployment slot into production.

[Microsoft Azure] Create an App Service plan. Not destructive when creating: a new plan hosts nothing until an app is placed on it — but it BEGINS BILLING IMMEDIATELY on every tier except Free, whether or not anything runs on it, so an abandoned plan is a bill nobody notices. Choose the tier deliberately: Free and Shared have no alwaysOn, no custom SSL and no slots; Basic adds those but no autoscale; Standard and above add slots, autoscale and staging. The reserved flag decides Linux (true) or Windows (false) and CANNOT be changed afterwards — getting it wrong means creating a second plan and moving every app. To change an existing plan's size or instance count, use azure_scale_app_service_plan instead.

ParamTypeRequiredDefaultDescription
capacityintegerno1Instance count. Every app on the plan shares these instances.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
linuxbooleannofalsetrue for Linux, false for Windows. CANNOT be changed after creation.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
planNamestringyesThe App Service plan name to create.
resourceGroupNamestringyesThe resource group to create the plan in.
skuNamestringno"B1"SKU name, e.g. B1, S1, P1v3.
skuTierstringno"Basic"SKU tier, e.g. Basic, Standard, PremiumV3.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object, e.g. {"environment":"production"}.

[Microsoft Azure] Delete an App Service plan. Azure refuses while any app is still on it, so this only succeeds on an empty plan — which is exactly the case worth deleting, since an empty plan bills hourly for nothing on every tier above Free. Confirm it is genuinely empty with azure_list_app_service_plan_web_apps rather than trusting numberOfSites alone, because that count includes deployment slots and a plan can look occupied by a slot belonging to an app that has already moved. Deleting is permanent; recreating a plan with the same name does not bring back anything that was on it.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
planNamestringyesThe App Service plan name to DELETE.
resourceGroupNamestringyesThe resource group the plan lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a web app or Function App permanently. This removes the app, its configuration, its app settings, its deployment slots and the code deployed to it, with no recycle bin — and it RELEASES the azurewebsites.net hostname, so anyone can claim that name afterwards. Custom domains stop resolving to anything and any integration calling the app starts failing immediately. The App Service plan and any linked database survive and keep billing unless deleted separately. Read azure_get_web_app and azure_list_web_app_settings first if there is any chance the app needs rebuilding; the settings are usually the part nobody has written down.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name to DELETE.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a deployment slot. The slot's code, its own app settings and its configuration go with it, permanently — and if the slot holds the PREVIOUS production release (which is exactly what it holds after a swap), deleting it removes the rollback path that a swap-back would have used. That is the risk worth naming: the slot usually looks idle precisely because it is the safety net. Production itself is untouched. Read azure_get_web_app_slot first.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name.
slotNamestringyesThe slot name to DELETE.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one App Service plan: its tier and size, current instance capacity, worker count, the number of sites on it, per-site scaling, zone redundancy and maximum elastic worker count. Read the tier before promising a feature — deployment slots, custom domains with SSL, alwaysOn, VNet integration and autoscale each have a minimum tier, and "the setting is missing" is usually the tier answering rather than a bug. Capacity here is the ceiling every app on the plan shares.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
planNamestringyesThe App Service plan name.
resourceGroupNamestringyesThe resource group the plan lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one web app or Function App in full: state, hostnames and their SSL bindings, the App Service plan, httpsOnly, clientCertMode, the managed identity if one is assigned, VNet integration, and a siteConfig summary. Two fields carry most of the diagnostic value. availabilityState says whether Azure itself considers the app healthy, which distinguishes "the app is broken" from "the platform is degraded". And hostNameSslStates lists each custom domain with its certificate thumbprint and SSL state — a binding showing Disabled is a custom domain serving a certificate warning to every visitor, which is invisible from the app's own logs.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get a web app's site configuration — the runtime stack and version, alwaysOn, minTlsVersion, ftpsState, http20Enabled, remoteDebuggingEnabled, the health check path, IP restrictions and CORS. This is the security review of an App Service in one call: minTlsVersion below 1.2 is a finding, ftpsState of AllAllowed permits plaintext FTP credentials over the internet, remoteDebuggingEnabled left true after a debugging session is an open door, and an empty ipSecurityRestrictions list means the site accepts traffic from anywhere. Contains no secrets, which is why it is a Free read — app settings and connection strings are separate calls for exactly that reason.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Return a web app's publishing username and password. THIS IS A DEPLOYMENT CREDENTIAL: anyone holding it can push arbitrary code to the site over FTP, Web Deploy or Git, and the site then runs that code with whatever managed identity and network access it has. That is a far larger grant than it appears, which is why it is destructive and Pro. The legitimate use is configuring a deployment pipeline that cannot use a service principal or federated identity. Prefer disabling basic publishing credentials entirely and using an Entra identity where the customer's tooling supports it; if you do retrieve these, treat them as burned the moment they leave a secure channel.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one deployment slot in full — the same shape as azure_get_web_app, for the slot rather than production. READ THIS BEFORE azure_swap_web_app_slots. A swap makes whatever is in the slot live within seconds, and the two facts worth checking first are in here: the slot's state (a stopped slot swapped into production is an outage) and its lastModifiedTimeUtc, which tells you whether the thing about to go live is the release someone believes it is or something left over from weeks ago.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name.
slotNamestringyesThe slot name, e.g. staging — from azure_list_web_app_slots.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get a web app's source control configuration — the repository URL, the branch, and whether continuous deployment is enabled. This answers "where does this app's code come from?", which is the question an inherited environment never has documented. A repoUrl pointing at a personal account or a repository nobody currently has access to is a real operational risk worth surfacing. If continuous deployment is on, note that changes pushed to that branch reach the app without anyone using Azure at all, so an unexplained deployment in azure_list_web_app_deployments has its explanation here.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the web apps running on one App Service plan. This is the blast-radius call: everything returned here shares the plan's CPU, memory and instance count, so one app looping on a thread starves the others, and any change to the plan's tier or capacity affects every app in this list at once. Run it before scaling or deleting a plan — a plan that looks like it belongs to one customer's app often turns out to be carrying three, and the plan's own numberOfSites field counts slots as well as apps.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum apps to return (1-1000, default 1000).
planNamestringyesThe App Service plan name, from azure_list_app_service_plans.
resourceGroupNamestringyesThe resource group the plan lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every App Service plan in a subscription with its sku (tier, size and CAPACITY — the instance count), numberOfSites, whether it is Linux (reserved), and its zone redundancy. THE PLAN IS WHAT BILLS, not the apps on it, which makes this the first call for any App Service cost question. Two findings appear routinely: a plan with numberOfSites of zero, which is pure waste billing hourly for nothing, and a Premium-tier plan carrying a single low-traffic app, where the tier was chosen for a feature that a cheaper tier now includes. Capacity is also the shared ceiling — every app and every running slot on the plan competes for the same instances.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum plans to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Return a web app's connection strings, with their type (SQLAzure, PostgreSQL, Custom and so on). THESE ARE CREDENTIALS BY DEFINITION — a connection string normally embeds a username and password, or an account key, for a database that usually holds the customer's actual data. Marked destructive and Pro for that reason, like the storage-account keys. Read it to diagnose a connection failure and quote the SERVER and DATABASE, never the whole string. Entries pointing at Key Vault references or using managed identity carry no secret and are the better pattern to recommend.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List a web app's deployment history — each deployment's id, status, author, message, start and end time, and whether it is the currently active one. This is the "what changed?" call for an app that started misbehaving: correlate the active deployment's timestamp against when the problem began, and the answer is usually right there. A failed deployment left at the top of the list while an older one stays active explains an app that is stubbornly serving code the customer thinks they replaced.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno100Maximum deployments to return (1-1000, default 100).
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the individual functions inside a Function App, each with its trigger configuration, script href, language and whether it is disabled. Only meaningful on a site whose kind includes functionapp — on an ordinary web app this returns an empty collection rather than an error, which is worth knowing so an empty result is not read as "the functions are missing". The isDisabled flag is the one that explains a timer or queue trigger that has quietly stopped running while the app itself looks perfectly healthy.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum functions to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the Function App lives in.
siteNamestringyesThe Function App name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List a web app's custom domain bindings, each with its SSL state, certificate thumbprint, hostname type and whether the domain is verified. This is where an expiring certificate shows up before the customer's users find it: a binding whose thumbprint points at a certificate nearing expiry will start serving browser warnings on a specific date with no Azure alert attached. A binding in a Disabled SSL state is already doing that. Also useful when a customer reports "the site works on azurewebsites.net but not on our domain" — an unverified or missing binding is the usual answer.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum bindings to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the running instances of a web app — the individual workers serving it, with each one's name and state. Useful for two questions. "Is it actually scaled out?" — an app the customer believes runs three instances but shows one is running on a plan whose capacity was never raised. And "is one instance bad?" — intermittent errors that only some users see are the classic signature of a single unhealthy worker, and a health check path set through azure_set_web_app_configuration is what lets Azure take it out of rotation automatically.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum instances to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Return a web app's application settings — the environment variables the app runs with. TREAT THE RESPONSE AS CREDENTIALS, which is why this is marked destructive and gated to Pro despite only reading: app settings are exactly where real applications keep database passwords, third-party API keys, storage account keys and signing secrets, because that is what the mechanism is for. A settings dump pasted into a ticket is a credential leak that outlives the ticket. Values shown as @Microsoft.KeyVault(...) are Key Vault REFERENCES and safe to share — the secret itself is not returned. Use this to diagnose a misconfigured app, then quote the KEY that is wrong rather than the value.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List a web app's deployment slots — the parallel copies (staging, testing, blue) that a release is warmed up in before being swapped into production. Each carries its own state, hostname and configuration. Slots are the mechanism behind zero-downtime deployment on App Service, so their presence tells you how the customer releases; their ABSENCE on a production app tells you every deployment is a live cutover with a cold start attached. A slot left running for months is also worth flagging, because slots consume the plan's compute alongside production.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum slots to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every App Service web app and Function App in a subscription, each with its state (Running or Stopped), defaultHostName, the serverFarmId of the plan it runs on, its enabled hostnames, httpsOnly, kind (app, functionapp, app,linux) and the outbound IP addresses it uses. The outboundIpAddresses field is the answer to "what should the customer's partner allow-list?", and possibleOutboundIpAddresses is the fuller set the app can move to on a scale operation — allow-listing only the current ones is a very common cause of an integration breaking after an unrelated restart. Note that a Stopped app still bills for its App Service plan, because the plan is what carries the compute. Up to 1000 items across 10 pages per call.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum apps to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the web apps and Function Apps inside one resource group. Same item shape as azure_list_web_apps, scoped to a single group — the cheaper call once the caller knows where the app lives.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum apps to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name, from azure_list_resource_groups.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Restart a web app. Destructive in the honest sense that it interrupts service: in-flight requests are dropped, any in-memory session state is lost, and the app is unavailable for the seconds-to-minutes its cold start takes — which on a large .NET or Java app is longer than people expect. It is nonetheless the standard first remedy for a hung worker, a leaked connection pool or a setting change that needs a fresh process. On an app with alwaysOn disabled the next request also pays the cold start, so restarting a low-traffic app during business hours is more visible than restarting a busy one.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name to restart.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Change an App Service plan's tier, size or instance count. DESTRUCTIVE IN BOTH DIRECTIONS, and it affects EVERY app on the plan at once — run azure_list_app_service_plan_web_apps first, because plans are shared far more often than people remember. Scaling DOWN removes capacity from live apps and can drop a tier-gated feature: moving below Standard disables deployment slots and autoscale, and any staging slot on the plan stops working. Scaling UP is an immediate and open-ended cost increase, billed per instance per hour until someone changes it back. A tier change also RECYCLES the workers, so every app on the plan restarts and loses in-memory state. Check the current values with azure_get_app_service_plan and confirm a capacity increase with whoever owns the bill.

ParamTypeRequiredDefaultDescription
capacityintegeryesInstance count, shared by every app on the plan.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
planNamestringyesThe App Service plan name.
resourceGroupNamestringyesThe resource group the plan lives in.
skuNamestringyesSKU name, e.g. B1, S1, P1v3.
skuTierstringyesSKU tier, e.g. Basic, Standard, PremiumV3.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Update a web app's site configuration. This is a PATCH, so unlike the settings call it does not delete what you omit — it is destructive because of WHAT it changes: these are the app's security and availability posture, live, on the next request. Lowering minTlsVersion weakens transport security for every visitor; setting ftpsState to AllAllowed permits plaintext FTP credentials over the internet; enabling remoteDebuggingEnabled opens a debugger to a running production process and is routinely left on afterwards. Turning alwaysOn off makes a low-traffic app cold-start on every visit, and turning it on is not available on the Free and Shared tiers. Read azure_get_web_app_configuration first, and change one thing at a time.

ParamTypeRequiredDefaultDescription
alwaysOnbooleannonullKeep the app warm between requests. Not available on Free or Shared tiers.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
ftpsStatestringnonullFTPS state: AllAllowed, FtpsOnly or Disabled. Disabled is the right default.
healthCheckPathstringnonullHealth check path, e.g. /healthz. Azure removes an unhealthy instance from rotation when set.
http20EnabledbooleannonullEnable HTTP/2.
minTlsVersionstringnonullMinimum TLS version: 1.0, 1.1 or 1.2. Never lower this below 1.2 without an explicit reason.
remoteDebuggingEnabledbooleannonullEnable remote debugging. Leave false in production and turn it back off after any session.
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Replace a web app's ENTIRE application settings collection. DESTRUCTIVE AND THE MOST COMMONLY MISUSED CALL IN THIS FAMILY: this is a PUT, so whatever you send becomes the complete set and every key you leave out is DELETED. An app that loses its database connection setting starts failing on the next request with an error that names nothing useful, and there is no undo. The safe sequence is always: azure_list_web_app_settings, take the whole object, change the one key, send it all back. Changing settings also RESTARTS the app. Values of the form @Microsoft.KeyVault(SecretUri=...) are Key Vault references and are the right way to carry a secret here.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the app lives in.
settingsJsonstringyesThe COMPLETE settings collection as a JSON object, e.g. {"WEBSITE_TIME_ZONE":"UTC","ApiKey":"@Microsoft.KeyVault(SecretUri=...)"}. Anything omitted is deleted.
siteNamestringyesThe web app name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Start a stopped web app. Not destructive — it restores service. Worth knowing that stopping an app never saved the customer any money on its own: the App Service PLAN is what bills, so a stopped app on a running plan costs exactly the same as a started one. That means there is rarely a cost reason not to start an app back up, and it also means "we stopped it to save money" is usually a misunderstanding worth correcting.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name to start.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Stop a web app. DESTRUCTIVE: the site goes offline immediately and every visitor gets an error page — this is a full outage for whatever the app serves, and Azure asks for no confirmation. It also does NOT reduce the bill, because the App Service plan is what carries the cost, so "stop it to save money" is not a reason that works here (scaling or deleting the plan is). Legitimate uses are containing a compromised app or stopping a runaway background job. Confirm with a human on anything customer-facing, and use azure_restart_web_app instead if the goal is to clear a stuck process.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name to STOP.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Swap a deployment slot into production. THIS IS A PRODUCTION DEPLOYMENT, which is the whole reason it is destructive: whatever code and configuration currently sit in the slot become live within seconds, with no build, no test gate and no confirmation, and what was in production moves into the slot. The risk is rarely the mechanism and almost always the contents — a slot nobody has looked at in a month contains a release nobody remembers. Check azure_get_web_app_slot for the slot's state and last modified time first, and confirm with a human. A swap CAN be reversed by swapping again, but the sessions dropped and any database migration the new code ran on start-up cannot. Settings marked as slot settings stay with their slot; everything else travels with the code, which is how a staging connection string reaches production.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
preserveVnetbooleannotrueKeep each slot's VNet integration where it is rather than swapping it too.
resourceGroupNamestringyesThe resource group the app lives in.
siteNamestringyesThe web app name.
sourceSlotNamestringyesThe slot to swap INTO production, e.g. staging.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
targetSlotstringno"production"The slot to swap into — "production" unless swapping between two non-production slots.

SQL

ToolPlanAccessSummary
azure_create_sql_databaseProWriteCreate an empty database on a SQL logical server.
azure_create_sql_elastic_poolProWriteCreate an elastic pool, or update an existing pool's capacity and per-database limits.
azure_create_sql_firewall_ruleProDestructiveCreate or replace an IP firewall rule on a SQL logical server.
azure_create_sql_serverProWriteCreate an Azure SQL logical server, or update an existing one's TLS floor and public network access.
azure_create_sql_virtual_network_ruleProDestructiveAllow a subnet to reach a SQL logical server, or replace an existing rule of the same name.
azure_delete_sql_databaseProDestructiveDelete a database.
azure_delete_sql_elastic_poolProDestructiveDelete an elastic pool.
azure_delete_sql_firewall_ruleProDestructiveDelete an IP firewall rule from a SQL logical server.
azure_delete_sql_serverProDestructiveDelete an Azure SQL logical server AND EVERY DATABASE AND ELASTIC POOL UNDER IT.
azure_delete_sql_virtual_network_ruleProDestructiveRemove a subnet's access to a SQL logical server.
azure_failover_sql_databaseProDestructiveForce a failover of a database to another replica.
azure_get_sql_databaseFreeRead-onlyGet one database in full: sku and tier, status, maxSizeBytes, currentBackupStorageRedundancy, zoneRedundant, readScale, autoPauseDelay and minCapacity for serverless, the elastic pool it belongs to,…
azure_get_sql_database_backup_retentionFreeRead-onlyRead a database's SHORT-TERM backup retention — retentionDays, which is how far back a point-in-time restore can reach, and diffBackupIntervalInHours.
azure_get_sql_database_encryptionFreeRead-onlyReport whether Transparent Data Encryption is enabled on a database — the state of encryption at rest, which is what a compliance questionnaire is asking about.
azure_get_sql_database_long_term_retentionFreeRead-onlyRead a database's LONG-TERM retention policy: weeklyRetention, monthlyRetention, yearlyRetention and weekOfYear, as ISO-8601 durations such as P4W, P12M or P7Y.
azure_get_sql_elastic_poolFreeRead-onlyGet one elastic pool in full: sku and capacity, perDatabaseSettings, maxSizeBytes, licenseType, zoneRedundant and creationDate.
azure_get_sql_serverFreeRead-onlyGet one Azure SQL logical server in full: fullyQualifiedDomainName (the host a connection string points at), administratorLogin, administrators (the Entra admin and whether Entra-only authentication…
azure_get_sql_server_auditing_settingsFreeRead-onlyRead a SQL logical server's auditing policy: whether auditing is Enabled, which action groups are captured, how many days of audit records are retained, whether events go to Azure Monitor, and the…
azure_list_sql_database_restore_pointsFreeRead-onlyList a database's discrete restore points, each with its restorePointType, earliestRestoreDate and creation time.
azure_list_sql_databasesFreeRead-onlyList every database on a SQL logical server, each with its sku (tier and capacity), status, maxSizeBytes, collation, zoneRedundant flag, elasticPoolId when it is pooled, and the earliestRestoreDate…
azure_list_sql_elastic_poolsFreeRead-onlyList a SQL logical server's elastic pools with each one's sku and capacity, perDatabaseSettings (the minimum and maximum capacity any single database may take), maxSizeBytes and zoneRedundant flag.
azure_list_sql_firewall_rulesFreeRead-onlyList a SQL logical server's IP firewall rules, each with its start and end address.
azure_list_sql_server_entra_adminsFreeRead-onlyList the Microsoft Entra administrators configured on a SQL logical server — the login name, the object id of the user or group, and the directory the principal comes from.
azure_list_sql_serversFreeRead-onlyList every Azure SQL logical server in a subscription, with each one's fully qualified domain name, administrator login, version, minimalTlsVersion, publicNetworkAccess and state.
azure_list_sql_servers_in_resource_groupFreeRead-onlyList the Azure SQL logical servers inside one resource group.
azure_list_sql_virtual_network_rulesFreeRead-onlyList a SQL logical server's virtual network rules — each one naming a subnet that is allowed to reach the server without any IP firewall rule.
azure_pause_sql_databaseProDestructivePause a Data Warehouse / dedicated SQL pool database so it stops billing for compute.
azure_restore_sql_databaseProDestructiveRestore a database to a point in time, as a NEW database alongside the original.
azure_resume_sql_databaseProWriteResume a paused Data Warehouse / dedicated SQL pool database.
azure_scale_sql_databaseProDestructiveChange a database's service tier, compute size or maximum size.
azure_set_sql_database_backup_retentionProDestructiveSet a database's short-term backup retention in days.
azure_set_sql_server_admin_passwordProDestructiveReset the SQL administrator password on a logical server.

[Microsoft Azure] Create an empty database on a SQL logical server. Not destructive: a new database contains no data and affects nothing that already exists. IT DOES START BILLING IMMEDIATELY at the chosen sku, which is the thing to be deliberate about — a provisioned tier bills per hour whether or not anything connects, while a serverless tier (GP_S_Gen5_2 and similar) pauses after autoPauseDelay minutes and bills only storage while paused. Pass elasticPoolName instead of a sku to place the database in an existing pool, where it shares the pool's already-paid capacity and adds no compute cost. To change an EXISTING database's size or tier use azure_scale_sql_database, which is a separate tool because it is disruptive and this one is not.

ParamTypeRequiredDefaultDescription
collationstringnonullOptional collation, e.g. SQL_Latin1_General_CP1_CI_AS. Cannot be changed after creation.
databaseNamestringyesThe database name to create.
elasticPoolNamestringnonullOptional elastic pool name to create the database inside. Mutually exclusive with skuName.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus. Must match the server's region.
maxSizeBytesintegernonullOptional maximum size in bytes, e.g. 268435456000 for 250 GB.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
skuNamestringnonullOptional sku name, e.g. S0, GP_Gen5_2 or GP_S_Gen5_2 (serverless). Omit when using elasticPoolName.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object, e.g. {"environment":"production"}.

[Microsoft Azure] Create an elastic pool, or update an existing pool's capacity and per-database limits. Not destructive: creating a pool moves no databases and breaks nothing, and updating capacity on a pool is an online operation for the databases inside it. It DOES bill from the moment it exists, at the pool's own sku, whether or not any database is in it — an empty pool left behind after a migration is a common recurring charge. Lowering perDatabaseSettings.maxCapacity on a live pool throttles every database in it, so change that number knowing what runs there.

ParamTypeRequiredDefaultDescription
capacityintegernonullOptional pool capacity (eDTUs or vCores, depending on the sku).
elasticPoolNamestringyesThe elastic pool name to create or update.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus. Must match the server's region.
perDatabaseMaxCapacitynumbernonullOptional maximum capacity any one database may take. Throttles every database when lowered.
perDatabaseMinCapacitynumbernonullOptional minimum capacity any one database may take.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
skuNamestringyesThe pool sku name, e.g. StandardPool, GP_Gen5 or BC_Gen5.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object, e.g. {"environment":"production"}.

[Microsoft Azure] Create or replace an IP firewall rule on a SQL logical server. DESTRUCTIVE BECAUSE IT CHANGES WHO CAN REACH THE DATA, in the same sense as creating a network security group rule: the change is live within seconds, nothing in Azure alerts on it, and a range that is one digit too wide is indistinguishable from a correct rule in a later listing. Never use 0.0.0.0 to 255.255.255.255 — that opens the databases to the internet — and understand that the special 0.0.0.0 to 0.0.0.0 rule allows every Azure IP in the world rather than just this customer's. Prefer the narrowest range that works, and prefer a private endpoint or a virtual network rule over any public range. Creating a rule with an existing name REPLACES it, so read azure_list_sql_firewall_rules first.

ParamTypeRequiredDefaultDescription
endIpAddressstringyesLast IP address in the allowed range. Use the same value as startIpAddress for a single host.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
ruleNamestringyesThe rule name to create or replace. An existing name is overwritten.
serverNamestringyesThe server name.
startIpAddressstringyesFirst IP address in the allowed range, e.g. 203.0.113.10.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Create an Azure SQL logical server, or update an existing one's TLS floor and public network access. Not destructive: a new server holds no databases and costs nothing until one is created under it. THE ADMINISTRATOR PASSWORD IS AN ARGUMENT, so it will appear in this conversation's transcript wherever that is stored — prefer creating the server with Entra-only authentication and setting an Entra administrator instead, which needs no password at all. When a password is unavoidable, treat it as burned and rotate it with azure_set_sql_server_admin_password from a secure channel afterwards. Set publicNetworkAccess to Disabled unless a private endpoint is not an option; the default leaves the server reachable from the internet with only firewall rules in the way.

ParamTypeRequiredDefaultDescription
administratorLoginstringnonullOptional SQL administrator login name. Required when creating a server that is not Entra-only.
administratorLoginPasswordstringnonullOptional SQL administrator password. Appears in this transcript — prefer Entra-only authentication.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
minimalTlsVersionstringno"1.2"Minimum TLS version the server accepts: 1.0, 1.1 or 1.2. Use 1.2.
publicNetworkAccessstringno"Enabled"Public network access: Enabled or Disabled. Disabled requires a private endpoint to reach the server.
resourceGroupNamestringyesThe resource group to create the server in.
serverNamestringyesThe server name to create or update. Must be globally unique and lowercase.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object, e.g. {"environment":"production"}.

[Microsoft Azure] Allow a subnet to reach a SQL logical server, or replace an existing rule of the same name. DESTRUCTIVE FOR THE SAME REASON AS THE IP FIREWALL RULE: it widens who can reach the customer's data, takes effect within seconds, and grants access to EVERY resource in that subnet — present and future — rather than to a named application. The subnet is identified by its resource group, virtual network and subnet name, which this tool composes into the subnet id ARM expects. Leave ignoreMissingVnetServiceEndpoint false so Azure refuses a rule pointing at a subnet that has no Microsoft.Sql service endpoint, rather than accepting a rule that quietly does nothing.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
ignoreMissingVnetServiceEndpointbooleannofalsetrue to create the rule even when the subnet has no Microsoft.Sql service endpoint. Leave false.
resourceGroupNamestringyesThe resource group the SQL server lives in.
ruleNamestringyesThe rule name to create or replace.
serverNamestringyesThe server name.
subnetNamestringyesThe subnet name inside that virtual network.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
virtualNetworkNamestringyesThe virtual network name, from azure_list_virtual_networks.
virtualNetworkResourceGroupNamestringyesThe resource group holding the VIRTUAL NETWORK (often different from the server's).

[Microsoft Azure] Delete a database. DESTRUCTIVE AND EFFECTIVELY IMMEDIATE: every application using it fails on its next connection. Azure keeps the automated backups for the remainder of the retention period, so a deleted database can be restored from Azure's restorable-dropped-databases surface within that window — but that surface is not exposed by this connector, the window is whatever azure_get_sql_database_backup_retention reports (7 days by default), and a database deleted after its retention lapses is gone permanently. Never delete a database to 'save cost' without checking whether azure_pause_sql_database or a smaller sku answers the same question reversibly.

ParamTypeRequiredDefaultDescription
databaseNamestringyesThe database name to DELETE.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete an elastic pool. Azure refuses while any database is still in it, so this cannot silently take databases with it — but that refusal is the whole reason to be careful about the step BEFORE this one: emptying a pool means moving each database to its own sku, and every one of those moves is an azure_scale_sql_database with the disconnection and the standalone hourly cost that carries. Deleting an empty pool is the cheap, correct end of a migration; deleting a pool as the FIRST step is a plan that ends with a much larger bill. Read azure_list_sql_databases and check elasticPoolId first.

ParamTypeRequiredDefaultDescription
elasticPoolNamestringyesThe elastic pool name to DELETE. Must already be empty.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete an IP firewall rule from a SQL logical server. DESTRUCTIVE IN THE OTHER DIRECTION FROM THE CREATE: removing a rule cuts off every client in that range on its next connection, and the applications that break report a generic connection failure that names nothing about firewalls, so the cause is usually found last. Closing an over-broad rule is often the right thing to do — do it knowing which range is being closed and having told a human, because there is no grace period and no staged rollout.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
ruleNamestringyesThe rule name to DELETE, from azure_list_sql_firewall_rules.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete an Azure SQL logical server AND EVERY DATABASE AND ELASTIC POOL UNDER IT. This is the resource-group delete of the SQL family: the databases are not listed, not confirmed and not recoverable through this connector once the operation completes, and every application whose connection string names this server fails immediately. Deleted servers can sometimes be recovered through Azure's own deleted-servers surface within a short window, but that is a support path rather than an undo and it is not exposed here. Run azure_list_sql_databases first and read the result to a human before calling this.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name to DELETE, with every database under it.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Remove a subnet's access to a SQL logical server. DESTRUCTIVE: every application running in that subnet loses its connection to the databases on the next attempt, with a generic connection error that says nothing about virtual network rules. Applications hosted in Azure very often depend on exactly one of these rules and on no IP firewall rule at all, so removing what looks like a redundant entry is the classic way to take a customer's production application down. Read azure_list_sql_virtual_network_rules and confirm what runs in the subnet first.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
ruleNamestringyesThe rule name to DELETE, from azure_list_sql_virtual_network_rules.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Force a failover of a database to another replica. DESTRUCTIVE: every connection is dropped at the switchover and in-flight transactions roll back — this is a deliberate, visible interruption, not a transparent one. Its legitimate uses are testing that an application actually reconnects the way its owner believes, and clearing a stuck primary replica. replicaType Primary fails over the primary replica (Business Critical and Premium tiers, and Hyperscale); ReadableSecondary fails over a read replica only. Databases with no secondary replica return an ARM error rather than failing over. Never run this as a diagnostic step on a production database without saying so first.

ParamTypeRequiredDefaultDescription
databaseNamestringyesThe database name to FAIL OVER.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
replicaTypestringnonullWhich replica to fail over: Primary or ReadableSecondary. Omit for the service default.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one database in full: sku and tier, status, maxSizeBytes, currentBackupStorageRedundancy, zoneRedundant, readScale, autoPauseDelay and minCapacity for serverless, the elastic pool it belongs to, creationDate and earliestRestoreDate. Read currentBackupStorageRedundancy before promising geo-recovery — Local means the backups do not leave the region and a regional outage takes them with the database. Read earliestRestoreDate before promising a restore point: it is set by the retention policy, and azure_get_sql_database_backup_retention explains why it is where it is.

ParamTypeRequiredDefaultDescription
databaseNamestringyesThe database name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Read a database's SHORT-TERM backup retention — retentionDays, which is how far back a point-in-time restore can reach, and diffBackupIntervalInHours. THIS IS THE REAL ANSWER TO 'HOW FAR BACK CAN WE RECOVER', and the default of 7 days surprises people who assume a month. It is also the number that decides whether a ransomware event is recoverable: encryption that is noticed on day 9 cannot be undone from a 7-day window. Pair it with azure_get_sql_database_long_term_retention, which covers the weekly, monthly and yearly copies, and with currentBackupStorageRedundancy on the database, which says whether those backups survive losing the region.

ParamTypeRequiredDefaultDescription
databaseNamestringyesThe database name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Report whether Transparent Data Encryption is enabled on a database — the state of encryption at rest, which is what a compliance questionnaire is asking about. TDE is on by default for databases created since 2017 and is frequently OFF on databases migrated in from an on-premises SQL Server, which is the case worth catching. This returns the STATE only: it never returns a key, and the encryption protector (whether the key is Microsoft-managed or the customer's own Key Vault key) is a server-level setting that this connector does not read, in keeping with its Key Vault management-plane-only rule.

ParamTypeRequiredDefaultDescription
databaseNamestringyesThe database name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Read a database's LONG-TERM retention policy: weeklyRetention, monthlyRetention, yearlyRetention and weekOfYear, as ISO-8601 durations such as P4W, P12M or P7Y. This is the archive layer that lives beyond the short-term window, and it is OFF by default — all four fields empty (PT0S) means the only recovery available is the short-term point-in-time window, which is the finding for any customer with a multi-year retention obligation. weekOfYear only matters when yearlyRetention is set: it picks which weekly backup becomes the yearly one, and an unset value means no yearly copy is kept regardless of the duration.

ParamTypeRequiredDefaultDescription
databaseNamestringyesThe database name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one elastic pool in full: sku and capacity, perDatabaseSettings, maxSizeBytes, licenseType, zoneRedundant and creationDate. Read this before moving a database into the pool with azure_create_sql_database, because a pool at its capacity slows every database in it at once rather than only the newest — the failure mode of an over-packed pool is a general slowdown nobody can attribute, which is why it is usually diagnosed late.

ParamTypeRequiredDefaultDescription
elasticPoolNamestringyesThe elastic pool name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one Azure SQL logical server in full: fullyQualifiedDomainName (the host a connection string points at), administratorLogin, administrators (the Entra admin and whether Entra-only authentication is on), version, minimalTlsVersion, publicNetworkAccess, restrictOutboundNetworkAccess and any assigned managed identity. Read administrators.azureADOnlyAuthentication before advising on credentials — when it is true the SQL administrator password is not usable at all, and a password reset would be the wrong fix for a login failure.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe logical server NAME, without the .database.windows.net suffix.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Read a SQL logical server's auditing policy: whether auditing is Enabled, which action groups are captured, how many days of audit records are retained, whether events go to Azure Monitor, and the storage endpoint they are written to. This is the compliance question for the whole server, because a server-level policy applies to every database under it — and 'state: Disabled' means there is no record of who queried what, which is a finding on its own for any customer with a retention obligation. When isAzureMonitorTargetEnabled is true the records land in a Log Analytics workspace and azure_query_log_analytics can read them; when only storageEndpoint is set they are blobs and this connector cannot query them.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List a database's discrete restore points, each with its restorePointType, earliestRestoreDate and creation time. THIS IS NOT THE POINT-IN-TIME WINDOW and the difference matters: on a normal Azure SQL database, point-in-time restore works to ANY second inside the retention period (see azure_get_sql_database_backup_retention and the earliestRestoreDate on the database itself), while this list holds explicit snapshots — which for Data Warehouse / dedicated SQL pools are the only restore points that exist. An empty list on a normal database is therefore not a finding. Read this before azure_restore_sql_database when the database is a dedicated SQL pool.

ParamTypeRequiredDefaultDescription
databaseNamestringyesThe database name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum restore points to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every database on a SQL logical server, each with its sku (tier and capacity), status, maxSizeBytes, collation, zoneRedundant flag, elasticPoolId when it is pooled, and the earliestRestoreDate that bounds any point-in-time restore. THIS IS THE COST AND THE RISK PICTURE FOR THE SERVER IN ONE CALL: the sku is what bills, status Paused means a serverless database is not running (and not billing for compute), and earliestRestoreDate is the real answer to 'how far back can we recover', which is usually shorter than people assume. Every server also returns a 'master' database — it is the system database, cannot be dropped, and is not a customer database.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum databases to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List a SQL logical server's elastic pools with each one's sku and capacity, perDatabaseSettings (the minimum and maximum capacity any single database may take), maxSizeBytes and zoneRedundant flag. An elastic pool is a block of capacity SHARED by many databases, so this is the cost answer for a multi-tenant application: the pool bills whether it holds one database or two hundred, and adding a database to a pool that has headroom costs nothing extra. perDatabaseSettings.maxCapacity is the throttle worth reading during a performance complaint — one database can never exceed it however idle the rest of the pool is.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum pools to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List a SQL logical server's IP firewall rules, each with its start and end address. READ THIS BEFORE ANY OTHER SECURITY QUESTION ABOUT A SQL SERVER, because these rules are the entire perimeter when publicNetworkAccess is Enabled. Two patterns are findings, not settings: a rule spanning 0.0.0.0 to 255.255.255.255 exposes the databases to the whole internet, and the special rule with start AND end 0.0.0.0 (usually named AllowAllWindowsAzureIps) allows every Azure IP address in the world — including virtual machines in other companies' subscriptions — which is far broader than the name suggests to most people. Wide ranges left over from a migration are the usual cause.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum rules to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the Microsoft Entra administrators configured on a SQL logical server — the login name, the object id of the user or group, and the directory the principal comes from. THIS IS AN ACCESS-CONTROL ANSWER, not a configuration detail: whoever is named here holds full administrative rights over every database on the server, and when the principal is a GROUP the real answer is that group's membership, which this call does not expand. A stale Entra admin group is a common finding on an inherited environment, and it is invisible from the database side. Pair with azure_get_sql_server, whose administrators.azureADOnlyAuthentication field says whether SQL logins still work alongside these.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum administrators to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every Azure SQL logical server in a subscription, with each one's fully qualified domain name, administrator login, version, minimalTlsVersion, publicNetworkAccess and state. START A SQL REVIEW HERE, because two fields on this list are findings on their own: publicNetworkAccess set to Enabled means the server answers on the public internet and only its firewall rules decide who reaches it, and a minimalTlsVersion below 1.2 means the server still accepts connections a modern security baseline rejects. A logical server is a container and an endpoint, not a machine — it has no size or cost of its own; the databases and elastic pools underneath it are what bill.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum servers to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the Azure SQL logical servers inside one resource group. Same item shape as azure_list_sql_servers, scoped to a single group — the cheaper call when the caller already knows where the server lives.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum servers to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name, from azure_list_resource_groups.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List a SQL logical server's virtual network rules — each one naming a subnet that is allowed to reach the server without any IP firewall rule. This is the other half of the perimeter and it is easy to miss: a server whose IP firewall list looks tight can still be reachable from several subnets listed only here. Check ignoreMissingVnetServiceEndpoint on each rule, because true means the rule was created without verifying the subnet actually has the Microsoft.Sql service endpoint enabled, which is a rule that silently does nothing until someone enables it later.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum rules to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Pause a Data Warehouse / dedicated SQL pool database so it stops billing for compute. DESTRUCTIVE BECAUSE IT INTERRUPTS A LIVE WORKLOAD: every open connection is terminated, running queries are cancelled, and the database refuses new connections until azure_resume_sql_database completes — which itself takes minutes, not seconds. Storage keeps billing while paused. This is the right lever for a reporting warehouse nobody uses at night and the wrong one for anything an application connects to on demand. Note that SERVERLESS databases pause themselves after their autoPauseDelay and resume on the next connection; this tool is not how you manage those, and calling it on a database that does not support pausing returns an ARM error rather than doing nothing.

ParamTypeRequiredDefaultDescription
databaseNamestringyesThe database name to PAUSE.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Restore a database to a point in time, as a NEW database alongside the original. THE SOURCE IS NEVER TOUCHED — this tool cannot overwrite it, because Azure refuses a restore onto an existing database name, and that is deliberate: recovery is done by restoring beside the original and switching over once the data has been checked. It is still marked destructive, because it provisions a full second copy of the database that bills at its own service objective from the moment it exists, the operation cannot be cancelled once accepted, and a restore left running as 'a quick check' becomes a duplicate production-sized cost nobody is watching. restorePointInTime must fall between the database's earliestRestoreDate (azure_get_sql_database) and now, in UTC. ARM answers 202 Accepted: poll azure_get_sql_database on the TARGET name until status is Online.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus. Must match the server's region.
resourceGroupNamestringyesThe resource group the server lives in.
restorePointInTimestringyesThe UTC point in time to restore to, ISO-8601, e.g. 2026-08-13T09:30:00Z. Must be within the retention window.
serverNamestringyesThe server name. The restored copy lands on the same server.
sourceDatabaseNamestringyesThe SOURCE database name to restore FROM. It is left untouched.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
targetDatabaseNamestringyesThe NEW database name to restore INTO. Must not already exist.

[Microsoft Azure] Resume a paused Data Warehouse / dedicated SQL pool database. Not destructive — starting is additive, and the data is exactly as it was left. It does restart compute BILLING at the database's configured service objective from the moment it comes online, and the resume takes minutes, so an application retried too early still sees connection failures that are not a fault. ARM answers 202 Accepted with no body: the operation is running, not finished. Poll azure_get_sql_database and wait for status Online before telling anyone the database is back.

ParamTypeRequiredDefaultDescription
databaseNamestringyesThe database name to RESUME.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Change a database's service tier, compute size or maximum size. DESTRUCTIVE IN BOTH DIRECTIONS, which is why it is separate from azure_create_sql_database. Scaling copies the database to new capacity and then switches over: connections are dropped at the switchover, in-flight transactions roll back, and on a large database the operation can run for a long time before that happens. Scaling DOWN can also fail outright — or lose capability — when the target tier's maximum size is smaller than the data already stored, or when the current tier's features (zone redundancy, read scale-out, long-term retention) are not available below it. Scaling UP is an open-ended hourly cost the customer has not agreed to. Read azure_get_sql_database first, and treat a tier change as a maintenance-window decision rather than a tuning knob.

ParamTypeRequiredDefaultDescription
databaseNamestringyesThe database name to scale.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxSizeBytesintegernonullOptional new maximum size in bytes. Must be at least the space already used.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
skuNamestringnonullThe target sku name, e.g. S3, GP_Gen5_4, BC_Gen5_8. Omit to change only maxSizeBytes.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Set a database's short-term backup retention in days. DESTRUCTIVE WHEN LOWERED, in the most literal sense this connector has: reducing retention DELETES every backup older than the new value immediately and permanently, so dropping 35 days to 7 destroys four weeks of recovery points in one call and no other tool here can get them back. That is the recovery path a customer's ransomware and accidental-deletion plans depend on. Raising retention is safe and simply costs more — backup storage beyond the included allocation bills per GB per month, which is usually a small number next to what the shorter window risks. Read azure_get_sql_database_backup_retention first, and treat any REDUCTION as a decision that needs a named human.

ParamTypeRequiredDefaultDescription
databaseNamestringyesThe database name.
diffBackupIntervalInHoursintegernonullOptional differential backup interval in hours: 12 or 24.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
retentionDaysintegeryesRetention in days, 1-35. LOWERING this DELETES backups older than the new value.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Reset the SQL administrator password on a logical server. DESTRUCTIVE BECAUSE IT BREAKS EVERY EXISTING CONSUMER: any application, scheduled job, reporting tool or backup script whose connection string embeds the old password starts failing on its next connection, and nothing in Azure lists what those are — the failures surface as unrelated application outages minutes or hours later. The new password is an argument and therefore appears in this conversation's transcript. This is the right call for a confirmed credential compromise and the wrong one for a single user who cannot sign in; check azure_get_sql_server first, because when azureADOnlyAuthentication is true the SQL password is not in use at all and resetting it changes nothing.

ParamTypeRequiredDefaultDescription
administratorLoginPasswordstringyesThe NEW administrator password. Appears in this transcript — rotate through a secure channel where possible.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the server lives in.
serverNamestringyesThe server name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

AKS

ToolPlanAccessSummary
azure_delete_aks_clusterProDestructiveDelete an AKS cluster and everything AKS created for it — every node pool, and the entire auto-generated node resource group with its virtual machines, managed disks, load balancers and public IPs.
azure_delete_aks_node_poolProDestructiveDelete a node pool and every node in it.
azure_get_aks_clusterFreeRead-onlyGet one AKS cluster in full: both version fields, every agent pool profile inline, the network profile (plugin, policy, service and pod CIDRs, outbound type), identity and RBAC configuration,…
azure_get_aks_cluster_upgrade_profileFreeRead-onlyReport what a cluster's control plane can upgrade TO: its current version, whether that version is still supported, and every available upgrade with its isPreview flag.
azure_get_aks_command_resultFreeRead-onlyFetch the result of a command started by azure_run_aks_command: its provisioningState, exitCode, startedAt and finishedAt, and the command's combined output as text.
azure_get_aks_node_poolFreeRead-onlyGet one node pool in full: count and the autoscaler's min and max, vmSize, both orchestrator version fields, nodeImageVersion, os disk size and type, maxPods, node labels and taints,…
azure_get_aks_node_pool_upgrade_profileFreeRead-onlyReport what one node pool can upgrade to: its current Kubernetes and node image versions, its OS type, and the available upgrade versions with their isPreview flags.
azure_list_aks_cluster_admin_credentialsProDestructiveReturn a cluster's ADMIN kubeconfig, base64-encoded.
azure_list_aks_cluster_monitoring_credentialsProDestructiveReturn the MONITORING user's kubeconfig for a cluster, base64-encoded.
azure_list_aks_cluster_user_credentialsProDestructiveReturn a cluster's USER kubeconfig, base64-encoded.
azure_list_aks_clustersFreeRead-onlyList every AKS cluster in a subscription with its kubernetesVersion, currentKubernetesVersion, provisioningState, powerState, node resource group, SKU tier and API-server access profile.
azure_list_aks_clusters_in_resource_groupFreeRead-onlyList the AKS clusters inside one resource group.
azure_list_aks_kubernetes_versionsFreeRead-onlyList the Kubernetes versions AKS offers in one Azure region, each with its patch versions, support plan, isPreview flag and whether it is the default.
azure_list_aks_node_poolsFreeRead-onlyList a cluster's node pools with each one's count, vmSize, mode (System or User), orchestratorVersion, currentOrchestratorVersion, nodeImageVersion, osType, osSKU, autoscaling settings, spot priority…
azure_rotate_aks_cluster_certificatesProDestructiveRotate a cluster's certificates and, with them, every kubeconfig ever issued for it.
azure_run_aks_commandProDestructiveRun a kubectl or helm command inside a cluster through the AKS run-command channel.
azure_start_aks_clusterProWriteStart a stopped AKS cluster.
azure_stop_aks_clusterProDestructiveStop an AKS cluster: the control plane is preserved and every node is DEALLOCATED.
azure_update_aks_cluster_tagsProWriteReplace an AKS cluster's tags.
azure_upgrade_aks_node_pool_imageProDestructiveUpgrade a node pool to the latest node IMAGE — the OS and runtime patches — without changing its Kubernetes version.

[Microsoft Azure] Delete an AKS cluster and everything AKS created for it — every node pool, and the entire auto-generated node resource group with its virtual machines, managed disks, load balancers and public IPs. NO UNDO AT ANY LEVEL: there is no soft delete, no recycle bin and no Azure-side backup of what was running. Persistent volumes backed by managed disks in the node resource group go with it, which is how cluster deletions destroy data people believed was outside the cluster. Anything the cluster did NOT create — an external database, a storage account, a Key Vault — survives. Run azure_list_aks_node_pools and read the cluster's nodeResourceGroup to a human first.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name to DELETE, with every node pool and its node resource group.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a node pool and every node in it. DESTRUCTIVE: the nodes are drained and removed, and the pods that were running on them are rescheduled ONLY if the cluster's remaining pools have room — otherwise they sit Pending indefinitely and the application is down with no error that names this deletion. Check azure_list_aks_node_pools for the capacity that will be left. A pool with mode System hosts the cluster's own components and Azure refuses to delete the last one, which is a guard rather than a plan: deleting a System pool while another exists can still displace critical add-ons. Persistent volumes bound to nodes in this pool are detached, and anything using local ephemeral storage loses it.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
nodePoolNamestringyesThe node pool name to DELETE, with every node in it.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one AKS cluster in full: both version fields, every agent pool profile inline, the network profile (plugin, policy, service and pod CIDRs, outbound type), identity and RBAC configuration, apiServerAccessProfile, addonProfiles, autoUpgradeProfile and the fqdn. THIS IS THE SECURITY REVIEW FOR THE CLUSTER IN ONE CALL. Three fields carry most of the answer: apiServerAccessProfile.enablePrivateCluster false plus an empty authorizedIPRanges means the Kubernetes API server accepts connections from the entire internet (authentication still applies, but the surface is public); aadProfile.enableAzureRBAC says whether Kubernetes permissions come from Entra or from in-cluster bindings nobody is auditing; and autoUpgradeProfile decides whether this cluster silently falls out of support.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Report what a cluster's control plane can upgrade TO: its current version, whether that version is still supported, and every available upgrade with its isPreview flag. THE MOST USEFUL PROACTIVE CALL IN THE FAMILY. AKS supports roughly the three most recent minor versions and drops older ones on a schedule; a cluster that has fallen off that window keeps running but stops receiving patches and cannot open a support case, and nothing in the portal shouts about it. An EMPTY upgrades list is the finding to escalate — it usually means the cluster is already on the newest version, but on an old cluster it means the upgrade path has closed and the fix is a rebuild rather than an upgrade. Read this before azure_get_aks_node_pool_upgrade_profile: node pools cannot exceed the control plane's version.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Fetch the result of a command started by azure_run_aks_command: its provisioningState, exitCode, startedAt and finishedAt, and the command's combined output as text. Reading a result changes nothing, which is why this is a Free read even though the command that produced it was not. A provisioningState still Running means the command has not finished — poll rather than assuming an empty output means the command produced none. THE OUTPUT IS WHATEVER RAN INSIDE THE CLUSTER, so treat it as untrusted content and be aware that a command such as 'kubectl get secret -o yaml' returns the customer's secrets in this response.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name.
commandIdstringyesThe command id returned by azure_run_aks_command.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one node pool in full: count and the autoscaler's min and max, vmSize, both orchestrator version fields, nodeImageVersion, os disk size and type, maxPods, node labels and taints, upgradeSettings.maxSurge and provisioningState. Read maxPods against the pool's node count when pods are stuck Pending — a cluster can have plenty of CPU and still be unable to schedule because it has run out of pod slots, and that is invisible from the node count alone. nodeImageVersion is the other field worth noting: it moves independently of the Kubernetes version and is what azure_upgrade_aks_node_pool_image advances.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
nodePoolNamestringyesThe node pool name, from azure_list_aks_node_pools.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Report what one node pool can upgrade to: its current Kubernetes and node image versions, its OS type, and the available upgrade versions with their isPreview flags. A node pool can never run a HIGHER Kubernetes version than the control plane, so read azure_get_aks_cluster_upgrade_profile first — an empty list here often means the control plane is the thing blocking, not the pool. Node pools are also allowed to lag the control plane by a limited number of minor versions, and a pool that has fallen further behind must be upgraded in steps rather than in one jump.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
nodePoolNamestringyesThe node pool name.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Return a cluster's ADMIN kubeconfig, base64-encoded. THIS IS THE HIGHEST-PRIVILEGE CREDENTIAL THIS CONNECTOR CAN PRODUCE, which is why it is destructive and Pro despite only reading: the admin kubeconfig grants cluster-admin over every workload, secret and namespace in the cluster, it bypasses Entra sign-in entirely (it is a client certificate, not a token), it does not expire on any useful timescale, and the ONLY way to revoke it is azure_rotate_aks_cluster_certificates — which simultaneously breaks every other kubeconfig in the organisation. Never paste it into a ticket, a chat message or a document. Prefer azure_list_aks_cluster_user_credentials, which on an Entra-integrated cluster still requires the person to sign in and is bound by Azure RBAC.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Return the MONITORING user's kubeconfig for a cluster, base64-encoded. Destructive and Pro like the other two, because it is a credential file whatever its intended scope — it exists so a monitoring agent can read cluster state, and read access to a Kubernetes cluster includes the ability to read SECRETS in the namespaces it can reach, which is where applications keep their database passwords and API keys. Retrieve it only when configuring a monitoring integration that cannot use a managed identity, and treat it exactly as carefully as the admin config.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Return a cluster's USER kubeconfig, base64-encoded. Still a credential and still destructive and Pro, but meaningfully safer than the admin one: on an Entra-integrated cluster this config carries no certificate — it tells kubectl to sign the user in, and what they can then do is decided by Azure RBAC or by Kubernetes role bindings. On a cluster WITHOUT Entra integration it is an embedded certificate with full rights, exactly like the admin config, so read aadProfile on azure_get_aks_cluster before treating it as the safe option. This is the right call for giving an engineer legitimate access; treat the file as sensitive either way.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every AKS cluster in a subscription with its kubernetesVersion, currentKubernetesVersion, provisioningState, powerState, node resource group, SKU tier and API-server access profile. THE TWO VERSION FIELDS ARE NOT THE SAME THING and the difference is the whole point of reading this: kubernetesVersion is what was ASKED for and currentKubernetesVersion is what is RUNNING, so they diverge during an upgrade and after a failed one. powerState.code Stopped means the cluster's nodes are deallocated — the control plane is still there and nothing is billing for compute, which looks alarming and usually is not. Check the SKU tier too: Free tier clusters have no control-plane SLA, which matters before promising availability to a customer.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum clusters to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the AKS clusters inside one resource group. Same item shape as azure_list_aks_clusters, scoped to a single group. Note that every AKS cluster ALSO owns a second, auto-generated resource group (nodeResourceGroup, usually named MC_*) holding its virtual machines, disks and load balancers — that group is managed by AKS and should never be edited directly, which is worth knowing before anyone tidies it.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum clusters to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name, from azure_list_resource_groups.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the Kubernetes versions AKS offers in one Azure region, each with its patch versions, support plan, isPreview flag and whether it is the default. Use this to answer 'what should we be on?' independently of any particular cluster — the answer varies by region, and a version available in one region is not guaranteed in another. capabilities.supportPlan distinguishes standard support from long-term support, which is the difference between an upgrade being urgent and being merely due.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List a cluster's node pools with each one's count, vmSize, mode (System or User), orchestratorVersion, currentOrchestratorVersion, nodeImageVersion, osType, osSKU, autoscaling settings, spot priority and provisioningState. THIS IS WHERE AKS COST LIVES — the control plane is nearly free and the nodes are the bill, so count × vmSize per pool is the number to bring to a cost conversation. Two things to read carefully: a pool with mode System runs the cluster's own components and cannot simply be deleted, and scaleSetPriority Spot means Azure can evict those nodes at any time, which is the usual explanation for workloads that 'randomly restart at night'.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum node pools to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Rotate a cluster's certificates and, with them, every kubeconfig ever issued for it. DESTRUCTIVE AND FAR-REACHING: this is the ONLY way to revoke a leaked admin kubeconfig, and it revokes ALL of them — every engineer, every CI pipeline, every tool holding a downloaded config stops working simultaneously and must fetch a new one. The cluster's API server and nodes are also restarted during the rotation, so workloads see disruption. Use it when a credential from azure_list_aks_cluster_admin_credentials has leaked, and understand that recovering afterwards means redistributing credentials to everyone who legitimately had one. Not a routine hygiene task.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name whose certificates are ROTATED, invalidating every kubeconfig.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Run a kubectl or helm command inside a cluster through the AKS run-command channel. DESTRUCTIVE BECAUSE IT EXECUTES ARBITRARY CODE INSIDE THE CUSTOMER'S CLUSTER, in the same class as azure_run_vm_command: the command runs with the caller's cluster permissions, nothing on the Azure side inspects what it does, and a 'kubectl delete' typed here is as final as one typed anywhere else. Its legitimate use is real and valuable — it reaches a PRIVATE cluster whose API server is not routable from here, which is often the only way to diagnose one. Prefer read-only commands (get, describe, logs) and say what you are about to run before running it. ARM answers 202 Accepted with an operation id: pass that id to azure_get_aks_command_result for the exit code and output.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name to run the command INSIDE.
commandstringyesThe command, e.g. "kubectl get pods -A" or "helm list -A". Runs with your cluster permissions.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Start a stopped AKS cluster. Not destructive — starting is additive and the cluster comes back with its workloads as they were. It DOES restart billing for every node in every pool from the moment they allocate, and the operation takes minutes rather than seconds: ARM answers 202 Accepted and the cluster is not usable until powerState.code reads Running, so poll azure_get_aks_cluster before telling anyone it is back. Pods do not all become ready at the same moment as the nodes do, so an application check that fails immediately after this is usually early rather than broken.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name to START.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Stop an AKS cluster: the control plane is preserved and every node is DEALLOCATED. DESTRUCTIVE BECAUSE EVERY WORKLOAD IN THE CLUSTER STOPS AT ONCE — every pod, every ingress, every scheduled job, with no drain and no per-workload confirmation. Anything holding state only in a pod's local storage loses it. This is the right lever for a development or test cluster nobody uses overnight and a serious outage on anything else, and the cluster is unreachable until azure_start_aks_cluster finishes minutes later. Node compute stops billing while stopped; disks, public IPs and the control plane keep billing.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name to STOP. Every workload in it stops.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Replace an AKS cluster's tags. Not destructive — tags carry no behaviour, and this is the ONLY property-level write this connector exposes on a cluster. Everything else about a cluster (version, node configuration, network, add-ons) is changed through a full create-or-update PUT that would drop any property the call did not send, so those are deliberately not exposed here; use the portal, Bicep or the CLI for a real cluster change. Note this REPLACES the tag collection rather than merging into it — send the tags you want to keep.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringyesThe complete tag set as a JSON object, e.g. {"environment":"production","owner":"platform"}.

[Microsoft Azure] Upgrade a node pool to the latest node IMAGE — the OS and runtime patches — without changing its Kubernetes version. DESTRUCTIVE BECAUSE IT REPLACES EVERY NODE IN THE POOL: AKS cordons and drains each node in turn and brings up a replacement, so every pod on the pool is evicted and rescheduled at some point during the operation. Workloads with a correct PodDisruptionBudget and more than one replica ride it out; single-replica workloads and anything with local state do not. It is genuinely important — node image updates are where OS-level CVEs get fixed — but it is a maintenance-window operation on production. ARM answers 202 Accepted and the rollout continues afterwards; poll azure_get_aks_node_pool until provisioningState is Succeeded.

ParamTypeRequiredDefaultDescription
clusterNamestringyesThe AKS cluster name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
nodePoolNamestringyesThe node pool name whose nodes are REPLACED one at a time.
resourceGroupNamestringyesThe resource group the cluster lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

RBAC

ToolPlanAccessSummary
azure_create_custom_role_definitionProDestructiveCreate a custom role, or REPLACE an existing one with the same GUID.
azure_create_role_assignmentProDestructiveGrant a role to an Entra principal at a scope.
azure_delete_role_assignmentProDestructiveRemove a role assignment.
azure_delete_role_definitionProDestructiveDelete a custom role definition.
azure_find_role_definition_by_nameFreeRead-onlyFind a role definition by its exact display name, e.g. Contributor, Reader, Storage Blob Data Reader.
azure_get_role_assignmentFreeRead-onlyGet one role assignment by its name (a GUID) at a scope.
azure_get_role_definitionFreeRead-onlyGet one role definition by its GUID, with the full permissions arrays and assignableScopes.
azure_list_deny_assignmentsFreeRead-onlyList the deny assignments at a scope, each with the actions it blocks, the principals it applies to and any it excludes.
azure_list_deny_assignments_for_principalFreeRead-onlyList the deny assignments that apply to one user or service principal.
azure_list_role_assignmentsFreeRead-onlyList the role assignments at a scope: who (principalId and principalType) holds which role (roleDefinitionId) over what (scope), plus createdOn and createdBy and any ABAC condition.
azure_list_role_assignments_for_principalFreeRead-onlyList every role assignment held by one Entra principal — a user, group, service principal or managed identity — at, above or below a scope.
azure_list_role_assignments_for_resourceFreeRead-onlyList the role assignments that apply to ONE specific resource — a storage account, a key vault, a virtual machine — including everything inherited from its resource group and subscription.
azure_list_role_definitionsFreeRead-onlyList the role definitions available at a scope — every built-in Azure role plus any custom roles defined at or above it — with each one's roleName, description, type, permissions (actions, notActions,…

[Microsoft Azure] Create a custom role, or REPLACE an existing one with the same GUID. DESTRUCTIVE FOR A NON-OBVIOUS REASON: this is a create-or-update PUT, so writing to a GUID that already exists silently changes what EVERY principal already assigned to that role can do — widening it grants access nobody reviewed, and narrowing it breaks running automation with 403s that point at the automation rather than at this change. Actions are matched as patterns and a trailing wildcard is much broader than it looks: 'Microsoft.Storage/*' includes deleting every storage account. notActions subtract from actions and are the safer way to build a near-Contributor role. dataActions grant access to the CONTENTS of resources — blobs, secrets, queue messages — and should be empty unless data access is the explicit intent. Read azure_get_role_definition first when updating.

ParamTypeRequiredDefaultDescription
actionsstringyesComma-separated control-plane actions, e.g. Microsoft.Compute/virtualMachines/read, Microsoft.Compute/virtualMachines/start/action.
descriptionstringnonullOptional description — say what the role is for and who asked for it.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
notActionsstringnonullOptional comma-separated actions to SUBTRACT from the allowed set.
resourceGroupNamestringnonullOptional resource group to make the role assignable in. Omit for the whole subscription.
roleDefinitionIdstringyesThe role definition GUID to create or REPLACE. Reusing an existing GUID rewrites that role.
roleNamestringyesThe role display name, e.g. Backup Operator (Custom).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Grant a role to an Entra principal at a scope. DESTRUCTIVE BECAUSE IT MOVES THE ACCESS BOUNDARY: the grant is standing access that persists until someone removes it, it applies to everything beneath the scope, and granting at subscription scope when a resource group was meant is a mistake that looks identical in every later listing. Read the role's actual permissions with azure_get_role_definition first — Owner and User Access Administrator additionally allow the holder to grant roles to anyone including themselves, which makes them qualitatively different from Contributor. principalType matters: set it correctly, because a freshly created service principal can otherwise fail replication validation. The assignment name is a GUID; leave it blank and one is generated. Re-running the same grant returns a conflict rather than a duplicate, so a retry is safe.

ParamTypeRequiredDefaultDescription
descriptionstringnonullOptional description recorded on the assignment — say why this access exists.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
principalIdstringyesThe Entra principal OBJECT ID (a GUID) receiving the role.
principalTypestringno"User"Principal type: User, Group, ServicePrincipal, ForeignGroup or Device.
resourceGroupNamestringnonullOptional resource group to scope the grant to. Omit to grant over the WHOLE subscription.
roleAssignmentNamestringnonullOptional assignment name (a GUID). Leave blank to generate one.
roleDefinitionIdstringyesThe role definition GUID to grant, from azure_find_role_definition_by_name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Remove a role assignment. DESTRUCTIVE AND ABLE TO LOCK PEOPLE OUT: revoking the wrong assignment can remove the customer's own administrators from their subscription, and if the removed role was the last User Access Administrator or Owner at that scope, nobody left can grant it back — recovery becomes an Azure support case. Removing access from a SERVICE PRINCIPAL is the quieter version of the same mistake: an automation that has run nightly for two years fails at 2am with a 403 and nothing connects it to this call. Read azure_get_role_assignment first and confirm the principal, the role and the scope. This is also the correct, immediate action when an account is compromised.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullOptional resource group the assignment lives at. Must match the assignment's own scope.
roleAssignmentNamestringyesThe role assignment NAME (a GUID) to REMOVE, from azure_list_role_assignments.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a custom role definition. DESTRUCTIVE BEYOND THE ROLE ITSELF: every existing assignment of that role stops granting anything, so everyone and everything holding it loses access at once, and the assignments are left behind pointing at a role that no longer exists — which reads in a later listing as an assignment that should be working. Azure refuses to delete BUILT-IN roles, so this only ever affects the customer's own. Run azure_list_role_assignments and look for the role's id before deleting, and prefer narrowing a role's actions to deleting it when the goal is reducing permissions.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullOptional resource group scope the role was defined at.
roleDefinitionIdstringyesThe custom role definition GUID to DELETE.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Find a role definition by its exact display name, e.g. Contributor, Reader, Storage Blob Data Reader. USE THIS BEFORE azure_create_role_assignment: an assignment is made against a role definition GUID, not a name, and this is the call that turns one into the other. The match is exact and case-sensitive at the service, so 'contributor' returns nothing while 'Contributor' returns the role. An empty result usually means the name is slightly off rather than that the role does not exist — azure_list_role_definitions is the way to see the real spelling.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullOptional resource group to scope to. Omit for the whole subscription.
roleNamestringyesThe exact role display name, e.g. Contributor.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one role assignment by its name (a GUID) at a scope. Useful mainly to confirm exactly what azure_delete_role_assignment is about to remove — read the roleDefinitionId, principalId and scope back before deleting, because the assignment NAME is a meaningless GUID that carries no hint of what it grants, and deleting the wrong one is not distinguishable from deleting the right one until someone loses access.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullOptional resource group to scope to. Omit for the whole subscription.
roleAssignmentNamestringyesThe role assignment NAME (a GUID), from azure_list_role_assignments.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one role definition by its GUID, with the full permissions arrays and assignableScopes. READ THIS BEFORE GRANTING A ROLE YOU HAVE NOT GRANTED BEFORE — role names are marketing, the actions array is the truth, and several innocuous-sounding built-in roles carry far more than their name suggests. Two patterns are worth spotting: a wildcard in actions means every control-plane operation on the resource type, and any entry under dataActions grants access to the CONTENTS (blobs, secrets, messages) rather than just the resource's configuration, which is the distinction most access reviews miss.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullOptional resource group to scope to. Omit for the whole subscription.
roleDefinitionIdstringyesThe role definition GUID, from azure_find_role_definition_by_name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the deny assignments at a scope, each with the actions it blocks, the principals it applies to and any it excludes. DENY BEATS ALLOW, ALWAYS — a deny assignment overrides every role assignment including Owner, which makes this the answer to the most confusing class of Azure ticket: 'I am an Owner and I still get 403.' Deny assignments are created by Azure itself, most often by a Blueprint or a managed application, and isSystemProtected is true on all of them, meaning they cannot be edited or deleted directly and this connector deliberately offers no write here. The fix is to remove whatever created them, not to remove the deny.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum deny assignments to return (1-1000, default 1000).
resourceGroupNamestringnonullOptional resource group to scope to. Omit for the whole subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the deny assignments that apply to one user or service principal. Unlike the role-assignment principal filter, this one IS transitive through groups: a deny reaching the principal through nested group membership is returned, which is exactly what you want when explaining an unexpected 403. It accepts an object id for a USER or a SERVICE PRINCIPAL only — passing a group's object id returns nothing rather than an error, which reads like 'no deny assignments' and is not.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum deny assignments to return (1-1000, default 1000).
principalIdstringyesThe Entra object id (a GUID) of a USER or SERVICE PRINCIPAL. A group id returns nothing.
resourceGroupNamestringnonullOptional resource group to scope to. Omit for the whole subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the role assignments at a scope: who (principalId and principalType) holds which role (roleDefinitionId) over what (scope), plus createdOn and createdBy and any ABAC condition. THE HEADLINE ACCESS REVIEW FOR A SUBSCRIPTION. Read three things: principalType ServicePrincipal entries are applications and automation, which nobody remembers to remove and which never leave the company; the scope field shows whether the grant is here or INHERITED from above, and an inherited Owner cannot be removed at this level; and by default this returns assignments at, above AND below the scope, so set atScopeOnly to see only what is granted exactly here. The principalId is an Entra object id — this connector returns the id, not the person's name.

ParamTypeRequiredDefaultDescription
atScopeOnlybooleannofalsetrue to return only assignments at this scope and above, excluding sub-scopes.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum assignments to return (1-1000, default 1000).
resourceGroupNamestringnonullOptional resource group to scope to. Omit for the whole subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every role assignment held by one Entra principal — a user, group, service principal or managed identity — at, above or below a scope. THE 'WHAT CAN THIS ACCOUNT DO?' ANSWER, and the call to reach for during an offboarding or a suspected compromise. Two limits worth knowing: principalId is an Entra OBJECT ID, not an email address (this connector cannot look one up from a name), and the filter matches the principal DIRECTLY, so access this account inherits through GROUP membership is not listed here. An account that appears to have nothing can still be an Owner through a group.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum assignments to return (1-1000, default 1000).
principalIdstringyesThe Entra principal OBJECT ID (a GUID) — user, group, service principal or managed identity.
resourceGroupNamestringnonullOptional resource group to scope to. Omit for the whole subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the role assignments that apply to ONE specific resource — a storage account, a key vault, a virtual machine — including everything inherited from its resource group and subscription. This is the other direction from azure_list_role_assignments_for_principal and the one an incident usually needs: not 'what can this account reach' but 'who can reach this thing'. Takes a full ARM resource id, which every list and get tool in this connector returns on each object. Most entries will be INHERITED rather than granted here, which is the finding as often as not: a storage account nobody granted access to is still readable by every Contributor on the subscription.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum assignments to return (1-1000, default 1000).
resourceIdstringyesThe full ARM resource id, e.g. /subscriptions/.../resourceGroups/rg/providers/Microsoft.Storage/storageAccounts/acct.

[Microsoft Azure] List the role definitions available at a scope — every built-in Azure role plus any custom roles defined at or above it — with each one's roleName, description, type, permissions (actions, notActions, dataActions, notDataActions) and assignableScopes. This is the reference you need before creating any assignment, because an assignment takes a role definition GUID rather than a name. Set customOnly to see ONLY the customer's own custom roles, which is the more interesting half of the answer on an inherited environment: a custom role is where over-permissive access usually hides, since nobody reviews it the way they review 'Owner'. There are several hundred built-in roles, so filter or page rather than reading the whole list.

ParamTypeRequiredDefaultDescription
customOnlybooleannofalsetrue to return only custom roles, excluding every built-in Azure role.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum role definitions to return (1-1000, default 1000).
resourceGroupNamestringnonullOptional resource group to scope to. Omit for the whole subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

Policy

ToolPlanAccessSummary
azure_create_policy_assignmentProDestructiveAssign a policy definition or initiative to a scope.
azure_delete_policy_assignmentProDestructiveRemove a policy assignment.
azure_get_policy_assignmentFreeRead-onlyGet one policy assignment in full: the definition or initiative it assigns, every parameter value, its scope and notScopes, enforcementMode, nonComplianceMessages and any managed identity it runs…
azure_get_policy_definitionFreeRead-onlyGet one policy definition with its full policyRule — the if/then that decides which resources match and what happens when they do.
azure_get_policy_initiativeFreeRead-onlyGet one policy initiative with every policy definition it contains, each with its policyDefinitionReferenceId and the parameter values the initiative passes down.
azure_list_policy_assignmentsFreeRead-onlyList the policy assignments in effect at a scope, each with the definition or initiative it assigns, its parameters, enforcementMode, notScopes and any managed identity.
azure_list_policy_assignments_for_resourceFreeRead-onlyList the policy assignments that apply to ONE specific resource, including everything inherited from its resource group, subscription and management groups.
azure_list_policy_definitionsFreeRead-onlyList the policy definitions available to a subscription — every built-in Azure policy plus the customer's own custom ones — with each definition's displayName, policyType, mode, description,…
azure_list_policy_initiativesFreeRead-onlyList the policy INITIATIVES (policy set definitions) available to a subscription — named bundles of policy definitions assigned as one unit.
azure_set_policy_assignment_enforcementProDestructiveSwitch a policy assignment between Default (enforcing) and DoNotEnforce (report-only).

[Microsoft Azure] Assign a policy definition or initiative to a scope. DESTRUCTIVE BECAUSE AN ASSIGNMENT ACTS, NOT JUST OBSERVES: a definition whose effect is Deny starts BLOCKING deployments across the whole scope within minutes, and DeployIfNotExists or Modify effects CHANGE existing resources during their first evaluation rather than only governing new ones — which is how a well-meant tagging policy rewrites production. Read the definition with azure_get_policy_definition and check its effect BEFORE assigning. Assigning at subscription scope when a resource group was meant is the common mistake and looks identical afterwards. Set enforcementMode to DoNotEnforce to land the assignment in report-only mode first, which is the safe way to introduce any Deny policy. Note this connector does not create the managed identity that DeployIfNotExists effects require, so those assignments need one configured elsewhere before they can remediate.

ParamTypeRequiredDefaultDescription
descriptionstringnonullOptional description — say who asked for this guardrail and why.
displayNamestringnonullDisplay name shown in the portal and in compliance reports.
enforcementModestringno"Default"Enforcement: Default enforces the effect, DoNotEnforce evaluates and reports without blocking or remediating.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
isInitiativebooleannofalsetrue when policyDefinitionName names an INITIATIVE (policy set) rather than a single definition.
parametersJsonstringnonullOptional parameter values as a JSON object, e.g. {"listOfAllowedLocations":{"value":["eastus"]}}.
policyAssignmentNamestringyesThe assignment name to create, e.g. require-tags-prod.
policyDefinitionNamestringyesThe policy definition or initiative NAME to assign, from azure_list_policy_definitions or azure_list_policy_initiatives.
resourceGroupNamestringnonullOptional resource group to assign at. Omit to assign over the WHOLE subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Remove a policy assignment. DESTRUCTIVE AND SILENT: nothing breaks, nothing errors, and the resources that were being governed simply stop being checked — the customer's compliance data for that policy disappears from the next evaluation and the gap is invisible until someone runs an audit. If the assignment carried a Deny effect, deployments that were being blocked start succeeding immediately, which is exactly what someone under deadline pressure wants and exactly the decision that should not be made by an agent alone. Read azure_get_policy_assignment first and keep its parameter values: recreating an assignment is easy, but reconstructing which regions or SKUs it allowed is not.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
policyAssignmentNamestringyesThe policy assignment NAME to DELETE.
resourceGroupNamestringnonullOptional resource group the assignment lives at. Must match the assignment's own scope.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one policy assignment in full: the definition or initiative it assigns, every parameter value, its scope and notScopes, enforcementMode, nonComplianceMessages and any managed identity it runs remediation as. Read this before changing or deleting an assignment — the parameter values are the difference between a policy that allows three regions and one that allows thirty, and they exist only here rather than in the definition. An assignment with an identity is one whose effects WRITE to resources (DeployIfNotExists or Modify), which is worth knowing before assuming it only audits.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
policyAssignmentNamestringyesThe policy assignment NAME, from azure_list_policy_assignments.
resourceGroupNamestringnonullOptional resource group the assignment lives at. Must match the assignment's own scope.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one policy definition with its full policyRule — the if/then that decides which resources match and what happens when they do. READ THE EFFECT BEFORE ASSIGNING ANYTHING: Audit only records, Deny BLOCKS non-conforming deployments outright, and DeployIfNotExists and Modify CHANGE resources on their own, including existing ones during the assignment's first evaluation. The parameters block tells you what the assignment must supply; an assignment missing a required parameter fails at creation rather than silently. mode matters too — Indexed policies only evaluate resource types that support tags and location, so a policy that appears not to be working may simply not apply to the resource type in question.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
policyDefinitionNamestringyesThe policy definition NAME (often a GUID for built-ins), from azure_list_policy_definitions.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one policy initiative with every policy definition it contains, each with its policyDefinitionReferenceId and the parameter values the initiative passes down. The reference ids are the part worth having: they are how an exemption or a non-compliance message targets ONE policy inside the initiative rather than the whole thing, and they do not appear anywhere else. Read the definitions list before assigning — an initiative containing a Deny effect blocks deployments the moment it is assigned, and the initiative's own name rarely says so.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
initiativeNamestringyesThe initiative NAME, from azure_list_policy_initiatives.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the policy assignments in effect at a scope, each with the definition or initiative it assigns, its parameters, enforcementMode, notScopes and any managed identity. THIS IS THE GOVERNANCE ANSWER FOR A SUBSCRIPTION, and two fields carry most of it. enforcementMode DoNotEnforce means the assignment evaluates and reports but never blocks or remediates anything — an assignment in that state looks identical to a working one in most summaries and is the usual explanation for a policy 'not doing anything'. notScopes lists the exclusions someone carved out, which is where the exceptions to a customer's own rules are recorded and nowhere else. By default this returns assignments at, above and below the scope; set atScopeOnly to exclude the ones inherited from a management group.

ParamTypeRequiredDefaultDescription
atScopeOnlybooleannofalsetrue to return only assignments at this scope and above.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum assignments to return (1-1000, default 1000).
resourceGroupNamestringnonullOptional resource group to scope to. Omit for the whole subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the policy assignments that apply to ONE specific resource, including everything inherited from its resource group, subscription and management groups. This is the call that answers 'why was this deployment blocked?' and 'which rules is this resource actually being judged against?', neither of which the resource's own properties reveal. Takes a full ARM resource id, which every list and get tool in this connector returns on each object. Almost every entry will be inherited rather than assigned here — that is normal and is exactly the point of reading it from the resource's side.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum assignments to return (1-1000, default 1000).
resourceIdstringyesThe full ARM resource id, e.g. /subscriptions/.../resourceGroups/rg/providers/Microsoft.Storage/storageAccounts/acct.

[Microsoft Azure] List the policy definitions available to a subscription — every built-in Azure policy plus the customer's own custom ones — with each definition's displayName, policyType, mode, description, parameters and the policyRule itself. Set customOnly to see just the custom definitions, which is the interesting half on an inherited environment: built-ins are Microsoft's and are the same everywhere, while a custom definition is something someone in this organisation wrote and probably nobody has reviewed since. There are well over a thousand built-in definitions, so page or filter rather than reading the whole list. Note that definitions exist at subscription or management-group scope only — there is no resource-group-level definition, which is why this tool takes no resource group.

ParamTypeRequiredDefaultDescription
customOnlybooleannofalsetrue to return only the customer's own custom definitions, excluding every built-in.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum definitions to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the policy INITIATIVES (policy set definitions) available to a subscription — named bundles of policy definitions assigned as one unit. Initiatives are what real governance is built from, because a compliance standard is dozens of individual policies and nobody assigns those one at a time: the regulatory standards a customer claims to meet almost always arrive as one of these. Read the category in metadata to tell a compliance initiative from an operational one, and remember that assigning an initiative assigns EVERY definition inside it, so its size is the blast radius.

ParamTypeRequiredDefaultDescription
customOnlybooleannofalsetrue to return only the customer's own custom initiatives.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum initiatives to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Switch a policy assignment between Default (enforcing) and DoNotEnforce (report-only). DESTRUCTIVE IN THE DoNotEnforce DIRECTION, and this is the subtlest write in the family: the assignment stays in every listing, keeps evaluating, keeps producing compliance data — and stops blocking anything. A guardrail turned off this way is far harder to notice than one deleted, because every summary that counts assignments still counts it. Turning enforcement back ON is the safe direction but is not free either: a Deny policy re-enforced over an environment that drifted while it was off starts blocking deployments that had been succeeding. This is the right lever for a controlled maintenance window and the wrong one for making an error message go away.

ParamTypeRequiredDefaultDescription
enforcementModestringyesDefault to enforce the policy's effect, DoNotEnforce to evaluate and report only.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
policyAssignmentNamestringyesThe policy assignment NAME to reconfigure.
resourceGroupNamestringnonullOptional resource group the assignment lives at. Must match the assignment's own scope.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

Resource Health

ToolPlanAccessSummary
azure_get_resource_healthFreeRead-onlyGet the CURRENT health of one Azure resource as Azure's own platform probes see it, not as its configuration claims.
azure_get_service_health_eventFreeRead-onlyGet one service health event in full by its tracking id, including the complete communication history Microsoft has posted against it.
azure_list_emerging_issuesFreeRead-onlyList Azure's EMERGING issues — problems Microsoft has noticed and published on the Azure status page but has not yet turned into a per-subscription service health event.
azure_list_resource_group_resource_healthFreeRead-onlyList the current health of every probed resource inside ONE resource group.
azure_list_resource_health_historyFreeRead-onlyList the health TRANSITIONS for one resource over time, newest first — every move between Available, Unavailable, Degraded and Unknown, each with its reason and timestamp.
azure_list_service_health_eventsFreeRead-onlyList Microsoft's own declared service health events for a subscription — active incidents, planned maintenance, health advisories and security advisories, each with a tracking id, the affected regions…
azure_list_service_health_impacted_resourcesFreeRead-onlyList the customer's own resources that Microsoft has identified as impacted by a specific service health event.
azure_list_subscription_resource_healthFreeRead-onlyList the current health of EVERY resource in a subscription that Azure health-probes, in one call.

[Microsoft Azure] Get the CURRENT health of one Azure resource as Azure's own platform probes see it, not as its configuration claims. Returns an availabilityState of Available, Unavailable, Degraded or Unknown, plus the reason, a human-readable summary, and the time the state last changed. This is the first call to make when a customer reports something is down, because it distinguishes the three cases an engineer otherwise burns an hour separating: the resource is genuinely broken, the resource is fine and the problem is elsewhere (network, DNS, the application itself), or Azure has not probed it recently enough to say. Note that Unknown is not a failure — it usually means the resource is stopped or was recently created. A resource can read Available during a declared Azure incident; that is not a contradiction, it means this particular instance is not among the affected ones, and the service health tools are where that question is answered.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceIdstringyesFull ARM resource id, from the 'id' field of any Azure list tool's output.

[Microsoft Azure] Get one service health event in full by its tracking id, including the complete communication history Microsoft has posted against it. The listing gives the headline; this gives the running commentary an engineer actually needs — what Microsoft currently believes the cause is, what has been mitigated so far, and when the next update is due. Quote the tracking id to the customer rather than paraphrasing the summary: it is the identifier their own support conversations and any post-incident review will be indexed by, and it is the one piece of this response that stays valid after the event closes.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
eventTrackingIdstringyesThe event TRACKING ID, from the 'name' field of azure_list_service_health_events.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List Azure's EMERGING issues — problems Microsoft has noticed and published on the Azure status page but has not yet turned into a per-subscription service health event. This is deliberately the widest and least certain of the health reads, and that is what makes it useful in the first ten minutes of an incident: it is where a developing problem appears before the targeted notifications catch up, so it explains an outage the subscription-scoped tools are still silent about. Because it is not scoped to a subscription, everything it returns is Azure-wide and most of it will be irrelevant to any one customer — match it against the customer's regions and services before reporting it as their cause, and never quote an emerging issue to a customer as a confirmed incident.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum issues to return (1-1000, default 1000).

[Microsoft Azure] List the current health of every probed resource inside ONE resource group. Use this instead of the subscription-wide sweep when the customer's workloads are separated by resource group, which is the usual MSP arrangement — it scopes the answer to the application that is actually being reported as broken rather than returning the whole estate and making the agent filter it. The same caveat applies as at subscription scope: resource types Azure does not health-probe never appear, so an empty result means nothing here is monitored, not that everything is well.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOptional OData filter, for example "properties/availabilityState ne 'Available'".
maxItemsintegerno1000Maximum status records to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name, from azure_list_resource_groups.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the health TRANSITIONS for one resource over time, newest first — every move between Available, Unavailable, Degraded and Unknown, each with its reason and timestamp. This is the evidence tool: the current-health call says what is true now, and this one says whether it has been flapping, when it first broke, and whether the customer's account of 'it has been bad all week' matches what Azure recorded. Azure retains roughly 30 days of this history, so a question about an older incident has to be answered from the customer's own monitoring instead. Reason codes matter more than the states: a transition Azure attributes to PlatformInitiated (host maintenance, a hardware fault Azure recovered from) is a different conversation with the customer than one attributed to UserInitiated, which means somebody on their side stopped or reconfigured it.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOptional OData filter over the returned statuses, for example "properties/availabilityState eq 'Unavailable'".
maxItemsintegerno1000Maximum status records to return (1-1000, default 1000).
resourceIdstringyesFull ARM resource id, from the 'id' field of any Azure list tool's output.

[Microsoft Azure] List Microsoft's own declared service health events for a subscription — active incidents, planned maintenance, health advisories and security advisories, each with a tracking id, the affected regions and services, and Microsoft's current status update. This is the tool that ends an outage call early: if Azure has already declared an incident covering the customer's region and service, the answer is a tracking id and an ETA rather than an afternoon of investigation, and the tracking id is what the customer's own management wants to hear. Filter by eventType to separate the four kinds, because they demand opposite responses — a ServiceIssue is happening to the customer now, while PlannedMaintenance is something to schedule around and SecurityAdvisory usually needs action on the customer's side rather than Microsoft's. Note that events are scoped to what Azure believes could affect THIS subscription, so an incident absent here may still be real for a different subscription in the same directory.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOptional OData filter, for example "properties/eventType eq 'ServiceIssue'" or "properties/status eq 'Active'".
maxItemsintegerno1000Maximum events to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the customer's own resources that Microsoft has identified as impacted by a specific service health event. This is the call that converts a regional incident notice into a concrete blast radius — the difference between telling a customer 'there is an Azure incident in West Europe' and telling them exactly which four of their virtual machines are in it. Treat the list as a floor rather than a ceiling: Microsoft populates it as the investigation proceeds, so an empty or short list early in an incident means the analysis is incomplete, not that nothing of the customer's is affected. Pair it with the per-resource health reads for anything the customer names that does not appear here.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
eventTrackingIdstringyesThe event TRACKING ID, from the 'name' field of azure_list_service_health_events.
maxItemsintegerno1000Maximum impacted resources to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the current health of EVERY resource in a subscription that Azure health-probes, in one call. This is the estate-wide sweep — the call that answers 'what is unhealthy at this customer right now' without knowing in advance what to look at, and the natural thing to run at the start of a shift or after a regional incident is declared. Filter to the interesting half rather than reading it all: a filter of "properties/availabilityState ne 'Available'" turns a thousand-row inventory into the handful of rows worth acting on. Be aware that only resource types Azure actively probes appear here at all, so an absent resource means 'not health-monitored by the platform', not 'healthy' — check the resource itself before reporting an all-clear.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOptional OData filter, for example "properties/availabilityState ne 'Available'" to see only the resources with a problem.
maxItemsintegerno1000Maximum status records to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

Defender for Cloud

ToolPlanAccessSummary
azure_create_jit_network_access_policyProDestructiveCreate or replace a just-in-time VM access policy.
azure_delete_jit_network_access_policyProDestructiveDelete a just-in-time access policy.
azure_delete_security_contactProDestructiveRemove a security contact configuration from a subscription.
azure_get_defender_planFreeRead-onlyGet one Defender plan in full, including the extensions array that the list view summarises.
azure_get_jit_network_access_policyFreeRead-onlyGet one just-in-time access policy in full: every protected virtual machine, every port rule on it, and every currently open request with its requestor, source address, mapped port and expiry.
azure_get_security_alertFreeRead-onlyGet one security alert with everything the list view truncates — the full entities array, extendedProperties, supportingEvidence and extendedLinks to any threat-intelligence report behind it.
azure_get_security_assessmentFreeRead-onlyGet ONE Defender for Cloud assessment for ONE specific resource — the answer to "is this particular VM, storage account or SQL database passing this particular recommendation, and if not, what exactly…
azure_list_defender_plansFreeRead-onlyList every Microsoft Defender for Cloud plan on a subscription with its pricingTier (Free or Standard), subPlan, enabled extensions, enablementTime and freeTrialRemainingTime.
azure_list_jit_network_access_policiesFreeRead-onlyList the just-in-time VM access policies in a subscription or resource group.
azure_list_regulatory_compliance_assessmentsFreeRead-onlyList the assessments that decide one regulatory control's outcome, each with the underlying Defender recommendation it maps to, its state, and counts of passed, failed and skipped RESOURCES.
azure_list_regulatory_compliance_controlsFreeRead-onlyList the individual controls inside one regulatory standard — the numbered clauses an auditor works through, such as PCI DSS 1.2.1 or ISO 27001 A.9.2.3 — each with its description, state and counts of…
azure_list_regulatory_compliance_standardsFreeRead-onlyList the regulatory compliance standards Defender for Cloud is tracking for a subscription — PCI DSS, ISO 27001, SOC 2, NIST SP 800-53, CIS and whatever else has been applied — each with a state of…
azure_list_security_alertsFreeRead-onlyList the Defender for Cloud security alerts on a subscription or resource group — the actual detections, not the recommendations: brute-force attempts, suspicious process execution, crypto-mining,…
azure_list_security_assessment_metadataFreeRead-onlyList the DEFINITIONS of every recommendation available to a subscription — every built-in Microsoft one plus any the customer added — with displayName, description, severity, remediationDescription,…
azure_list_security_assessmentsFreeRead-onlyList every Defender for Cloud assessment in a subscription — one row PER RESOURCE PER RECOMMENDATION, each with the assessed resource's id, the recommendation's displayName and a status of Healthy,…
azure_list_security_contactsFreeRead-onlyList the security contact configurations on a subscription — who Defender for Cloud emails when it detects something, at what minimum severity, and whether the notification is on at all.
azure_list_security_locationsFreeRead-onlyGet the ASC location for a subscription — the single home region where Defender for Cloud stores that subscription's alerts and just-in-time policies.
azure_list_security_secure_score_controlsFreeRead-onlyList the security CONTROLS behind a secure score — each one a themed group of recommendations such as "Enable MFA", "Remediate vulnerabilities" or "Restrict unauthorized network access" — with its…
azure_list_security_secure_scoresFreeRead-onlyList the Defender for Cloud secure scores for a subscription — for each security initiative, the current score, the maximum available and the percentage between them.
azure_list_security_sub_assessmentsFreeRead-onlyList the INDIVIDUAL FINDINGS behind Defender's assessments — the actual CVEs on a machine, the specific container image vulnerabilities, the SQL vulnerability-assessment rule failures — each with its…
azure_request_jit_accessProDestructiveRequest just-in-time access to a virtual machine's management ports.
azure_set_defender_planProDestructiveTurn a Defender for Cloud plan on or off for a subscription.
azure_set_security_alert_stateProWriteMove a security alert between the four states Defender for Cloud defines: activate (back to Active), inProgress (someone is working it), resolve (handled, a true positive that was dealt with) and…
azure_set_security_contactProDestructiveSet who Defender for Cloud emails about security alerts on a subscription.

[Microsoft Azure] Create or replace a just-in-time VM access policy. DESTRUCTIVE FOR THE SAME REASON azure_create_nsg_rule IS: this decides who may reach a machine's management ports and for how long, so a wrong allowedSourceAddressPrefix here is an internet-exposed RDP port and a wrong maxRequestAccessDuration is one that stays exposed for a day. It is also a create-or-REPLACE of the WHOLE policy, which is the trap: a resource group's default policy usually covers many VMs, and sending one machine silently drops JIT protection from every other machine in it — nothing errors, and those machines simply stop being gated. Always read azure_get_jit_network_access_policy first and send the full existing virtualMachines array with your change merged into it. Each port rule needs number, protocol, maxRequestAccessDuration (ISO-8601, minimum PT5M and maximum P1D) and either allowedSourceAddressPrefix or allowedSourceAddressPrefixes — never both. Removing a machine from the array does NOT close ports that are already open; it only stops future requests being gated.

ParamTypeRequiredDefaultDescription
ascLocationstringyesThe ASC location — Defender's home region for this subscription, from azure_list_security_locations.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
policyNamestringno"default"The policy NAME, almost always "default" — one policy per resource group per location.
resourceGroupNamestringyesThe resource group holding the protected virtual machines.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
virtualMachinesJsonstringyesThe COMPLETE virtualMachines array as JSON, e.g. [{"id":"/subscriptions/.../virtualMachines/vm1","ports":[{"number":3389,"protocol":"TCP","allowedSourceAddressPrefix":"203.0.113.4","maxRequestAccessDuration":"PT3H"}]}].

[Microsoft Azure] Delete a just-in-time access policy. DESTRUCTIVE AND SILENT, in the shape that is easiest to get wrong: it does not close anything and it does not open anything — it removes the GATE. The network security group rules JIT was managing revert to whatever they were, every VM the policy covered stops requiring an approved request before its management ports can be reached, and no alert anywhere says the control is gone. If the underlying rules were Deny, the machines become unreachable and someone notices; if they were permissive, the ports are simply open from now on and nobody does. Read azure_get_jit_network_access_policy first and keep the definition — the port rules, durations and source prefixes are not recoverable, and reconstructing which addresses were allowed on which VM is far harder than recreating the policy shell. Access already open under this policy stays open until its own expiry.

ParamTypeRequiredDefaultDescription
ascLocationstringyesThe ASC location — Defender's home region for this subscription, from azure_list_security_locations.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
policyNamestringno"default"The policy NAME to DELETE, almost always "default".
resourceGroupNamestringyesThe resource group holding the protected virtual machines.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Remove a security contact configuration from a subscription. DESTRUCTIVE AND INVISIBLE: nothing breaks, no error is raised, Defender for Cloud carries on detecting exactly as before — and the next time it finds an intrusion, nobody is emailed. There is no Azure notification that notification has stopped, and no dashboard shows a subscription as unmonitored because of it, so the gap survives until an incident is missed or somebody thinks to run azure_list_security_contacts. This is almost never the right call: to change who is notified use azure_set_security_contact with the new list, and to pause notifications during a noisy migration set isEnabled false there instead, which at least leaves a record of the recipients to restore. Read azure_list_security_contacts first and keep the addresses and roles — they are not recoverable from anywhere else.

ParamTypeRequiredDefaultDescription
contactNamestringno"default"The contact NAME to DELETE, almost always "default".
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one Defender plan in full, including the extensions array that the list view summarises. READ THIS BEFORE CHANGING A PLAN: the write is a create-or-replace, so the extensions and subPlan you do not send are the ones that get turned off. The extensions are where the expensive and the important options live — on-upload malware scanning and sensitive-data discovery for StorageAccounts, agentless scanning and vulnerability assessment for VirtualMachines — and each has its own additionalExtensionProperties, such as the per-storage-account monthly GB cap for malware scanning. subPlan matters just as much: the same plan name at PerTransaction and at PerStorageAccount bills on completely different curves.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
planNamestringyesThe plan NAME, e.g. VirtualMachines, StorageAccounts, CloudPosture — from azure_list_defender_plans.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one just-in-time access policy in full: every protected virtual machine, every port rule on it, and every currently open request with its requestor, source address, mapped port and expiry. READ THIS BEFORE ANY JIT WRITE — azure_create_jit_network_access_policy is a create-or-REPLACE, so the machines and port rules you do not send back are the ones that stop being protected, and a policy typically covers many VMs at once. The policy name is almost always the literal string default, because Defender keeps one policy per resource group per location. Needs the ascLocation, which is Defender's home region for the SUBSCRIPTION rather than the VM's region — azure_list_security_locations returns it, and it also appears in the policy's own id.

ParamTypeRequiredDefaultDescription
ascLocationstringyesThe ASC location — Defender's home region for this subscription, from azure_list_security_locations.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
policyNamestringno"default"The policy NAME, almost always "default", from azure_list_jit_network_access_policies.
resourceGroupNamestringyesThe resource group holding the protected virtual machines.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one security alert with everything the list view truncates — the full entities array, extendedProperties, supportingEvidence and extendedLinks to any threat-intelligence report behind it. This is what an analyst reads before deciding whether a detection is real, and supportingEvidence is the part that decides it: it carries the actual observed rows, such as the exact command line that ran or the specific sign-ins that failed. Needs the ascLocation, which is the region Defender stores this SUBSCRIPTION's data in rather than the alerted resource's own region — read it from azure_list_security_locations, or take it straight out of the alert's id, which always contains /locations//. Note the entities and extendedProperties routinely contain user names, IP addresses, hostnames and file paths, which is exactly the point and is also personal data.

ParamTypeRequiredDefaultDescription
alertNamestringyesThe alert NAME — the last segment of the alert's id, from azure_list_security_alerts.
ascLocationstringyesThe ASC location — Defender's home region for this subscription, from azure_list_security_locations or the alert's own id.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullOptional resource group, when the alert's id contains one. Omit to address it at subscription level.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get ONE Defender for Cloud assessment for ONE specific resource — the answer to "is this particular VM, storage account or SQL database passing this particular recommendation, and if not, what exactly should be done about it?". Returns the status with its cause and description, the links.azurePortalUri deep link, and with includeMetadata the full remediationDescription. Takes a full ARM resource id because an assessment is an EXTENSION resource: it does not live in the subscription's own namespace, it hangs off whatever was assessed, so there is no way to address one without naming that resource — every list and get tool in this connector returns the id on each object, and azure_list_security_assessments returns it as properties.resourceDetails.id. The assessmentName is the recommendation's GUID from azure_list_security_assessments or azure_list_security_assessment_metadata, not its display name.

ParamTypeRequiredDefaultDescription
assessmentNamestringyesThe assessment NAME — a GUID, from azure_list_security_assessments.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
includeMetadatabooleannofalsetrue to expand the result with its metadata — severity, remediation steps, effort and user impact.
resourceIdstringyesThe full ARM resource id of the ASSESSED resource, e.g. /subscriptions/.../resourceGroups/rg/providers/Microsoft.Compute/virtualMachines/vm1.

[Microsoft Azure] List every Microsoft Defender for Cloud plan on a subscription with its pricingTier (Free or Standard), subPlan, enabled extensions, enablementTime and freeTrialRemainingTime. THIS IS THE FIRST CALL FOR BOTH SECURITY AND COST QUESTIONS about a customer's Defender posture, because the two are the same question: every plan on Standard is billed per resource per month, and every plan on Free means that resource type has NO threat detection at all — no alerts will ever fire for it and nothing anywhere says so. A subscription showing all-Free is not a healthy one, it is an unprotected one. Read freeTrialRemainingTime before recommending anything: a plan in trial flips to full price silently when the trial ends, which is the single most common surprise on an MSP's Azure invoice. Plan names are stable strings such as VirtualMachines, StorageAccounts, SqlServers, KeyVaults, Containers, CloudPosture, Arm, Dns and Api.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the just-in-time VM access policies in a subscription or resource group. Each policy names the virtual machines it protects and, per machine, the ports it will open on request with their protocol, maxRequestAccessDuration and allowedSourceAddressPrefix — plus a requests array showing any access that is OPEN RIGHT NOW, with the requestor's identity, the source address and the endTimeUtc it closes. THIS IS THE MANAGEMENT-PORT EXPOSURE ANSWER for a customer's VMs, and it reads in two halves: the policy is what COULD be opened and by whom, and requests is what IS open at this moment. A machine with no JIT policy is not protected by JIT at all, which usually means RDP or SSH is governed only by its network security group — cross-check with azure_list_nsg_rules rather than assuming a short list here means a small attack surface. maxRequestAccessDuration is the ceiling per request, so a policy allowing PT24H from source * is a JIT policy in name only.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum policies to return (1-1000, default 1000).
resourceGroupNamestringnonullOptional resource group to scope to. Omit for the whole subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the assessments that decide one regulatory control's outcome, each with the underlying Defender recommendation it maps to, its state, and counts of passed, failed and skipped RESOURCES. This is the bottom of the compliance tree and the only place the two halves join up: it is what turns "PCI DSS control 1.2.1 is failing" into the specific recommendation to fix, whose assessmentDetailsLink leads to the actual non-compliant resources through azure_list_security_assessments. Work this way round rather than starting from the assessment list, because the same recommendation feeds many controls across many standards and fixing it moves all of them at once — which is the argument that gets remediation work approved.

ParamTypeRequiredDefaultDescription
controlNamestringyesThe control NAME, e.g. 1.2.1, from azure_list_regulatory_compliance_controls.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum assessments to return (1-1000, default 1000).
standardNamestringyesThe standard NAME, from azure_list_regulatory_compliance_standards.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the individual controls inside one regulatory standard — the numbered clauses an auditor works through, such as PCI DSS 1.2.1 or ISO 27001 A.9.2.3 — each with its description, state and counts of passed, failed and skipped assessments. This is the middle layer between "are we PCI compliant" and "which resource is wrong", and it is the layer a remediation plan is written at, because a control is the unit an auditor asks about. Pay attention to the SKIPPED counts as well as the failed ones: a skipped assessment is one Azure could not evaluate, usually because the resource type is not present or the recommendation was turned off, and it is neither a pass nor a failure — presenting a standard as compliant while several controls were skipped is how a compliance report becomes wrong.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum controls to return (1-1000, default 1000).
standardNamestringyesThe standard NAME, e.g. PCI-DSS-v4, ISO-27001-2013, from azure_list_regulatory_compliance_standards.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the regulatory compliance standards Defender for Cloud is tracking for a subscription — PCI DSS, ISO 27001, SOC 2, NIST SP 800-53, CIS and whatever else has been applied — each with a state of Passed, Failed, Skipped or Unsupported and counts of passed, failed and skipped controls. THIS IS THE AUDIT ANSWER an MSP is asked for by name, and it comes with one caveat worth repeating to whoever reads it: these states reflect the technical controls Azure can evaluate, which is a subset of any real standard, so "Passed" here means Azure found nothing wrong rather than that the customer is certified. A standard appears in this list only once it has been assigned — an empty result means nothing is being tracked, not that everything passes. Note that failedControls counts CONTROLS, not resources, so one misconfigured storage account can fail several controls across several standards at once.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum standards to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the Defender for Cloud security alerts on a subscription or resource group — the actual detections, not the recommendations: brute-force attempts, suspicious process execution, crypto-mining, malware uploads, anomalous data access. Each alert carries severity, status (Active, InProgress, Resolved or Dismissed), intent (the MITRE kill-chain stage), compromisedEntity, remediationSteps, the MITRE techniques and subTechniques, and an entities array of the accounts, IPs, files, processes and hosts involved. THIS IS THE "IS ANYTHING ACTUALLY HAPPENING RIGHT NOW" CALL. Two properties decide triage: isIncident true means Defender correlated several alerts into one attack story and that story is what matters rather than any single alert, and correlationKey groups alerts that belong together across resources. Alerts only exist for resource types whose Defender plan is on — a quiet subscription may simply be an unmonitored one, which azure_list_defender_plans settles. Alerts are retained for two years.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum alerts to return (1-1000, default 1000).
resourceGroupNamestringnonullOptional resource group to scope to. Omit for the whole subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the DEFINITIONS of every recommendation available to a subscription — every built-in Microsoft one plus any the customer added — with displayName, description, severity, remediationDescription, categories, threats, implementationEffort, userImpact, assessmentType and the policyDefinitionId that switches each one on. This is the dictionary that turns the GUIDs in azure_list_security_assessments into something a human can read, and it is the only place the remediation text lives if you did not expand it there. Read assessmentType to tell Microsoft's own recommendations (BuiltIn) from CustomPolicy and CustomerManaged ones, which are what somebody in this organisation wrote and nobody has reviewed since. The preview flag marks recommendations that do not yet count towards the secure score, which explains a recommendation that is failing while the score does not move.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum definitions to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every Defender for Cloud assessment in a subscription — one row PER RESOURCE PER RECOMMENDATION, each with the assessed resource's id, the recommendation's displayName and a status of Healthy, Unhealthy or NotApplicable. This is the security to-do list in its rawest form, and it is LARGE: a modest subscription produces thousands of rows, so filter on status.code Unhealthy on your side and expect to page. Read status.cause and status.description on the NotApplicable rows before treating them as fine — the most common cause is OffByPolicy, which means the recommendation was turned off rather than that it passed, and it looks identical to a clean result in any count. Set includeMetadata to attach each row's severity, remediationDescription, implementationEffort and userImpact, which is what turns a list of failures into a plan.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
includeMetadatabooleannofalsetrue to expand each assessment with its metadata — severity, remediation steps, effort and user impact.
maxItemsintegerno1000Maximum assessments to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the security contact configurations on a subscription — who Defender for Cloud emails when it detects something, at what minimum severity, and whether the notification is on at all. Returns emails (a semicolon-separated list), phone, isEnabled, notificationsSources (per source type: Alert with its minimalSeverity, AttackPath with its minimalRiskLevel) and notificationsByRole, which emails everyone holding a named RBAC role on the subscription rather than a fixed address. THIS IS THE FIRST THING TO CHECK ON AN INHERITED TENANT and the most commonly wrong: a subscription with no contact, or with only a departed employee's address, detects breaches perfectly and tells nobody, and there is no symptom until an incident is missed. notificationsByRole set to Owner is the usual healthy answer for a customer who manages themselves; an MSP normally wants its own monitored mailbox in emails as well. Note the returned addresses and phone numbers are personal data.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum contacts to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get the ASC location for a subscription — the single home region where Defender for Cloud stores that subscription's alerts and just-in-time policies. There is exactly ONE per subscription and it is chosen by Azure, not by the customer; it is NOT the region a resource lives in, and assuming they match is the usual reason a get or state-change call answers 404. Every alert and JIT tool below that addresses one object by name needs this value, so this is the lookup call for the whole family. The value also appears inside every alert and policy id after /locations/, so an agent that already has an id does not need this call — it needs it when starting from a subscription id alone.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the security CONTROLS behind a secure score — each one a themed group of recommendations such as "Enable MFA", "Remediate vulnerabilities" or "Restrict unauthorized network access" — with its current and maximum score, its weight, and how many resources are healthy, unhealthy or not applicable. THIS IS THE PRIORITISED WORK LIST: the controls are what actually move the score, and the gap between current and max multiplied by weight is the remediation order, which is not obvious from the recommendation list alone because a control scores all-or-nothing per resource. Set includeDefinitions to also return each control's description and the assessment ids it contains, which is how you get from a control to the specific recommendations to fix. Omit secureScoreName for every control in the subscription across all initiatives, or pass ascScore for the built-in benchmark only.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
includeDefinitionsbooleannofalsetrue to expand each control with its definition — description, max score and the assessments it contains.
maxItemsintegerno1000Maximum controls to return (1-1000, default 1000).
secureScoreNamestringnonullOptional initiative name, e.g. ascScore, from azure_list_security_secure_scores. Omit for every control in the subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the Defender for Cloud secure scores for a subscription — for each security initiative, the current score, the maximum available and the percentage between them. THIS IS THE ONE NUMBER AN MSP REPORTS TO A CUSTOMER, and the entry named ascScore is the built-in Microsoft Cloud Security Benchmark score that the Azure portal shows; any other entry is a custom initiative someone added. Two things make the raw number misleading on its own and are worth saying out loud in any report: the percentage moves when Microsoft adds or retires a recommendation, so a score can fall without anything in the environment changing, and the maximum only counts controls that APPLY to what is deployed, so a subscription with almost nothing in it scores well by having nothing to get wrong. Use azure_list_security_secure_score_controls to turn the number into the list of things to fix.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum scores to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the INDIVIDUAL FINDINGS behind Defender's assessments — the actual CVEs on a machine, the specific container image vulnerabilities, the SQL vulnerability-assessment rule failures — each with its id, displayName, description, severity, impact, remediation text and additionalData carrying the CVE list, CVSS scores and patchable status. THIS IS THE VULNERABILITY REPORT, and it is the layer azure_list_security_assessments does not reach: there, a whole machine is one Unhealthy row, and here that same machine expands into every finding on it. Expect very large results and page accordingly. Omit assessmentName for every finding in the subscription, or pass one to scope to a single recommendation's findings. Requires the relevant Defender plan to be on and a scan to have run — an empty result on an unscanned estate means "nothing has looked", not "nothing is wrong", and azure_list_defender_plans is how you tell those apart.

ParamTypeRequiredDefaultDescription
assessmentNamestringnonullOptional assessment NAME (a GUID) to scope to one recommendation's findings. Omit for every finding in the subscription.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum findings to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Request just-in-time access to a virtual machine's management ports. DESTRUCTIVE BECAUSE IT OPENS PORTS FOR REAL: within seconds this rewrites the machine's network security group to admit the given source address on the given port, and RDP or SSH is reachable from that address until the request expires. The whole point of JIT is that this decision is made by a person with a reason, and the request is recorded against the CALLING IDENTITY — an agent doing it on its own puts an MSP engineer's name on an access grant nobody asked for. Two details decide the blast radius. Omitting allowedSourceAddressPrefix does NOT mean "nobody" — it defaults to the source IP of this API call, which for a hosted agent is a datacentre address rather than the technician's. And duration is capped by the policy's own maxRequestAccessDuration, so a request is silently shortened rather than refused. There is no revoke operation in this API: once opened, access stays open until endTimeUtc, so ask for the shortest duration that works. Requires an existing policy covering the machine — azure_get_jit_network_access_policy tells you which ports it will accept.

ParamTypeRequiredDefaultDescription
ascLocationstringyesThe ASC location — Defender's home region for this subscription, from azure_list_security_locations.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
justificationstringyesWhy access is being opened, and for whom. Recorded on the request and visible to the customer — write it for an auditor.
policyNamestringno"default"The policy NAME covering the machine, almost always "default".
resourceGroupNamestringyesThe resource group holding the virtual machine.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
virtualMachinesJsonstringyesThe virtualMachines array as JSON, e.g. [{"id":"/subscriptions/.../virtualMachines/vm1","ports":[{"number":3389,"duration":"PT1H","allowedSourceAddressPrefix":"203.0.113.4"}]}].

[Microsoft Azure] Turn a Defender for Cloud plan on or off for a subscription. DESTRUCTIVE IN BOTH DIRECTIONS, which is why it is flagged whichever way it is used. Setting Free REMOVES THREAT PROTECTION for every resource of that type: detection stops within minutes, no alert will ever fire for those resources again, nothing errors, and no Azure notification announces it — the gap is invisible until an incident is missed. Setting Standard starts UNBOUNDED METERED SPEND against the customer's invoice, priced per server, per storage account or per transaction depending on the plan, across every existing resource and every one created afterwards. Never do either without an explicit human decision naming the plan. This is also a create-or-REPLACE: read azure_get_defender_plan first and send back the subPlan and extensions you want kept, because anything omitted reverts to the plan default and silently disables features like malware scanning that someone deliberately enabled.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
extensionsJsonstringnonullOptional extensions array as JSON, e.g. [{"name":"OnUploadMalwareScanning","isEnabled":"True"}]. Omit and every extension reverts to its default.
planNamestringyesThe plan NAME to change, e.g. VirtualMachines, StorageAccounts, CloudPosture.
pricingTierstringyesStandard to enable protection and billing, Free to disable both.
subPlanstringnonullOptional sub-plan when the plan offers more than one, e.g. P1 or P2 for VirtualMachines, PerTransaction or DefenderForStorageV2 for StorageAccounts. Omit for the full plan.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Move a security alert between the four states Defender for Cloud defines: activate (back to Active), inProgress (someone is working it), resolve (handled, a true positive that was dealt with) and dismiss (a false positive). NOT DESTRUCTIVE, and the case here is stronger than for a cost alert: this flips one status field, the alert stays fully readable through azure_list_security_alerts and azure_get_security_alert, detection is unaffected, and activate is reachable from THIS SAME TOOL — every state it can set, it can also undo. What it does NOT do is fix anything: the state is only a record that a human looked, so dismissing an alert whose underlying condition persists means Defender raises a fresh one on the next detection. Never sweep a list to Dismissed to tidy it, because the status field is the only place an MSP's triage history for that customer is written down, and resolve and dismiss mean different things to whoever reads it next. Needs the ascLocation, which is in the alert's own id after /locations/.

ParamTypeRequiredDefaultDescription
alertNamestringyesThe alert NAME — the last segment of the alert's id, from azure_list_security_alerts.
ascLocationstringyesThe ASC location — Defender's home region for this subscription, from azure_list_security_locations or the alert's own id.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullOptional resource group, when the alert's id contains one. Omit to address it at subscription level.
statestringyesOne of activate, dismiss, resolve or inProgress.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Set who Defender for Cloud emails about security alerts on a subscription. DESTRUCTIVE FOR THE REASON A POLICY SET TO DoNotEnforce IS: this is a create-or-REPLACE of the whole contact, so any address, role or notification source you do not send is removed, and the failure is completely silent — detection keeps working, the subscription keeps looking healthy in every summary, and Defender simply stops telling anyone about intrusions. Setting isEnabled false is the same removal with the contact left in place looking configured, which is worse for whoever reads the configuration next. Read azure_list_security_contacts first and send back the full address list with your change merged in; adding an MSP mailbox by replacing the customer's own is the mistake this tool makes easiest. Raising minimalAlertSeverity is a quieter version of the same thing: setting High means Medium-severity detections — which is where lateral movement and credential access usually land — are never mailed to anyone.

ParamTypeRequiredDefaultDescription
contactNamestringno"default"The contact NAME. Azure recognises exactly one, "default"; any other name is accepted and then ignored.
emailsstringyesThe COMPLETE recipient list, semicolon-separated, e.g. soc@msp.example;it@customer.example. Replaces the existing list entirely.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
isEnabledbooleannotruefalse to keep the contact on file but stop every notification from it. Leave true unless the intent really is silence.
minimalAlertSeveritystringnonullMinimum alert severity to email: High, Medium or Low. Low sends everything. Omit to leave the alert notification source unset.
notifyRolesstringnonullOptional comma-separated RBAC roles to notify as well as the addresses — any of Owner, Contributor, ServiceAdmin, AccountAdmin.
phonestringnonullOptional phone number for the contact record. Azure does not call it; it is for the customer's own records.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

Deployments

ToolPlanAccessSummary
azure_cancel_deploymentProDestructiveCancel a deployment that is still running.
azure_create_deploymentProDestructiveDeploy an ARM or Bicep-compiled template to a resource group, or to the subscription itself when resourceGroupName is omitted.
azure_delete_deploymentProDestructiveDelete a deployment from the history.
azure_export_deployment_templateFreeRead-onlyExport the template EXACTLY AS IT WAS DEPLOYED, from the deployment history.
azure_get_deploymentFreeRead-onlyGet one deployment in full: its mode, provisioningState, timestamp and duration, the templateLink or templateHash it ran from, every parameter value it was given, its outputs, the providers and…
azure_get_deployment_operationFreeRead-onlyGet ONE operation from a deployment by its operation id, when azure_list_deployment_operations returned too much to read or the interesting entry was truncated.
azure_list_deployment_operationsFreeRead-onlyList the individual resource operations that made up one deployment.
azure_list_deploymentsFreeRead-onlyList the deployment history at a scope — every ARM or Bicep template deployment recorded against a resource group, or against the subscription itself when resourceGroupName is omitted.
azure_validate_deploymentFreeRead-onlyValidate a template without deploying it: ARM parses the template, resolves its parameters, variables and functions, hands each resource declaration to its resource provider for semantic checks, and…
azure_whatif_deploymentFreeRead-onlyPredict what a template WOULD do, without deploying it.

[Microsoft Azure] Cancel a deployment that is still running. DESTRUCTIVE BECAUSE STOPPING HALFWAY IS ITS OWN STATE, not a return to the previous one: ARM stops scheduling the remaining resources but does NOT roll back the ones it already created or modified, so the scope is left matching neither the old configuration nor the new — partially migrated, with the template's dependency ordering broken in the middle. A virtual network created without the subnets that were to follow it, or a database server without its firewall rules, is the usual shape of the result. Only a deployment whose provisioningState is still Accepted or Running can be cancelled; Azure refuses anything already terminal with a 409. Because cancelling does not undo, the realistic next step is to redeploy a known-good template rather than to assume the environment reverted — check azure_list_deployment_operations first to see exactly how far it got.

ParamTypeRequiredDefaultDescription
deploymentNamestringyesThe NAME of the running deployment to stop mid-flight.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullResource group the deployment is running at. Omit for a SUBSCRIPTION-scoped deployment.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Deploy an ARM or Bicep-compiled template to a resource group, or to the subscription itself when resourceGroupName is omitted. DESTRUCTIVE, AND THE MODE IS WHY: in COMPLETE mode ARM DELETES every resource in the target scope that the template does not declare — a template listing one storage account, deployed Complete over a production resource group, removes everything else in it, with no confirmation and no undo. INCREMENTAL mode (the default here) deletes nothing, but still OVERWRITES the live properties of every resource the template names, so a stale SKU, a smaller disk or a missing firewall rule in the template silently reverts a change someone made by hand. This tool cannot know which of those a caller's template implies until ARM runs it, so CALL azure_whatif_deployment FIRST and show the caller the predicted change list. Two further edges: the deployment NAME is a live handle, and reusing an existing name overwrites that history entry; and deployments are ASYNCHRONOUS — this returns as soon as ARM accepts the template while resources continue to be created for minutes afterwards, so poll azure_get_deployment and read provisioningState rather than assuming success. A subscription-scoped deployment (no resourceGroupName) REQUIRES location, and a deployment name's location is immutable once used. This tool deliberately offers no debug-logging switch: ARM's debug setting would write every resource's request and response body, secrets included, into a history that azure_list_deployment_operations reads back.

ParamTypeRequiredDefaultDescription
deploymentNamestringyesThe deployment name to create or overwrite, e.g. web-tier-2026-08-13.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringnonullAzure region storing the deployment record, e.g. eastus. REQUIRED when resourceGroupName is omitted.
modestringno"Incremental"Deployment mode: Incremental (default, deletes nothing) or Complete (DELETES anything the template omits).
parametersJsonstringnonullParameter values as a JSON object, e.g. {"vmName":{"value":"web01"}}.
parametersUristringnonullLocation of a parameters JSON file ARM should fetch. Supply this OR parametersJson.
resourceGroupNamestringnonullResource group to deploy into. Omit for a SUBSCRIPTION-scoped deployment, which then REQUIRES location.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
templateJsonstringnonullThe full ARM/Bicep-compiled template as a JSON object. Supply this OR templateUri, not both.
templateUristringnonullLocation of a template JSON file ARM should fetch, e.g. an https URL. Supply this OR templateJson.

[Microsoft Azure] Delete a deployment from the history. DESTRUCTIVE IN A WAY THAT IS EASY TO MISREAD: the deployed RESOURCES are untouched and keep running — what is destroyed is the RECORD of what was deployed. That record is the only place the template, its parameter values, its outputs and its per-resource operations are kept, and it is what an audit reads, what a rollback is reconstructed from, and what azure_export_deployment_template serves. Once it is gone there is no copy anywhere else, and nothing about the running environment shows that it ever existed. Delete a history entry to remove one that leaked a secret through its outputs or parameters, or to clear room in a resource group that has hit Azure's history cap — not to 'undo' a deployment, which this does not do. Azure refuses to delete a deployment that is still running; cancel it with azure_cancel_deployment first. The call is asynchronous and answers with no body.

ParamTypeRequiredDefaultDescription
deploymentNamestringyesThe deployment NAME whose history entry to DELETE. The deployed resources are not affected.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullResource group the deployment ran at. Omit for a SUBSCRIPTION-scoped deployment.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Export the template EXACTLY AS IT WAS DEPLOYED, from the deployment history. Read-only despite being an HTTP POST: it serves a stored document and changes nothing. This is deliberately NOT the same as azure_export_resource_group_template, which reverse-engineers a template from the resource group's CURRENT state — this one returns the historical artifact, so the two disagree the moment anything drifted since the deployment, and that disagreement is often the answer you actually want. Use it to recover a template nobody kept, to diff what was intended against what is running, or to redeploy a known-good configuration after a bad change. Note that the template comes back with its parameter DEFINITIONS but not the values it was run with; those are in azure_get_deployment under properties.parameters.

ParamTypeRequiredDefaultDescription
deploymentNamestringyesThe deployment NAME, from azure_list_deployments.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullResource group the deployment ran at. Omit for a SUBSCRIPTION-scoped deployment.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one deployment in full: its mode, provisioningState, timestamp and duration, the templateLink or templateHash it ran from, every parameter value it was given, its outputs, the providers and resource ids it touched, and its error object when it failed. This is also how you poll a deployment started by azure_create_deployment — that call returns as soon as ARM accepts the template, and provisioningState here moves through Accepted and Running to Succeeded, Failed or Canceled. READ THE RESULT WITH THE SAME CARE AS A CREDENTIAL: properties.outputs is stored exactly as the template emitted it, so a template that outputs a connection string, account key or password has put that value in the deployment history permanently; properties.parameters records what was passed in; and properties.templateLink.uri can itself carry a SAS token in its query string. When provisioningState is Failed the error object here usually names only the first failure — azure_list_deployment_operations is where the per-resource detail lives.

ParamTypeRequiredDefaultDescription
deploymentNamestringyesThe deployment NAME, from azure_list_deployments.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringnonullResource group the deployment ran at. Omit for a SUBSCRIPTION-scoped deployment.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get ONE operation from a deployment by its operation id, when azure_list_deployment_operations returned too much to read or the interesting entry was truncated. Returns that operation's targetResource, provisioningOperation, provisioningState, statusCode and the full statusMessage — the last of which is where a resource provider's real complaint lives, often several sentences that the list view abbreviates. The same secret hazard applies as to the list form: if the deployment ran with ARM's debug setting on, this response carries that resource's request and response bodies, which can contain passwords or listKeys output. Operation ids come from azure_list_deployment_operations and are meaningful only within their own deployment.

ParamTypeRequiredDefaultDescription
deploymentNamestringyesThe deployment NAME, from azure_list_deployments.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
operationIdstringyesThe operation id, from azure_list_deployment_operations.
resourceGroupNamestringnonullResource group the deployment ran at. Omit for a SUBSCRIPTION-scoped deployment.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the individual resource operations that made up one deployment. THIS IS THE MOST USEFUL READ IN THE FAMILY WHEN A DEPLOYMENT FAILS: the deployment's own error usually says only that something went wrong, while each operation here names ONE resource — its targetResource, provisioningState, timestamp, duration, statusCode and statusMessage — so the single resource that blocked everything else is immediately visible, along with every resource that had already succeeded before it. SECRET HAZARD, and it is a real one: when a deployment was submitted with ARM's debug setting enabled, each operation also carries the full request and response body for that resource, which Microsoft warns 'can potentially log and expose secrets like passwords used in the resource property or listKeys operations'. StackJack never enables that setting on a deployment it starts, but a deployment created by a pipeline, the portal or the CLI may have it on, so treat this response as sensitive rather than assuming it is metadata.

ParamTypeRequiredDefaultDescription
deploymentNamestringyesThe deployment NAME, from azure_list_deployments.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum operations to return (1-1000, default 1000).
resourceGroupNamestringnonullResource group the deployment ran at. Omit for a SUBSCRIPTION-scoped deployment.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the deployment history at a scope — every ARM or Bicep template deployment recorded against a resource group, or against the subscription itself when resourceGroupName is omitted. Each entry carries the deployment name, timestamp, duration, mode (Incremental or Complete), provisioningState, correlationId, the parameters it was given, its outputs and the resource ids it touched. THIS IS THE CHANGE LOG NOBODY ELSE KEEPS: on an inherited environment it is usually the only record of how the infrastructure reached its current shape, and a Complete-mode entry is the first place to look when resources 'disappeared'. Filter with "provisioningState eq 'Failed'" to jump straight to the deployments worth investigating, then read azure_list_deployment_operations to find WHICH resource failed. Note that Azure prunes this history automatically once a resource group accumulates several hundred deployments, so old entries are genuinely gone rather than hidden.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOData filter, e.g. "provisioningState eq 'Failed'". Omit for every deployment.
maxItemsintegerno1000Maximum deployments to return (1-1000, default 1000).
resourceGroupNamestringnonullResource group whose deployments to list. Omit for SUBSCRIPTION-scoped deployments.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Validate a template without deploying it: ARM parses the template, resolves its parameters, variables and functions, hands each resource declaration to its resource provider for semantic checks, and confirms the caller has permission to create what the template declares. Nothing is deployed and no deployment record is created, which is why this is read-only and free. VALIDATE AND WHAT-IF ANSWER DIFFERENT QUESTIONS and are worth running in that order: validate says the template is well-formed, its parameters are complete and the caller is allowed to run it, while azure_whatif_deployment says what it would actually DO. A template that validates perfectly can still delete a production resource group in Complete mode, so validating is not a substitute for previewing. A validation failure returns ARM's error object naming the offending resource and property, which is usually a far more precise message than the same template produces when it fails halfway through a real deployment.

ParamTypeRequiredDefaultDescription
deploymentNamestringyesA name for the validation run. Nothing is written under it.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringnonullAzure region storing the run record, e.g. eastus. REQUIRED when resourceGroupName is omitted.
modestringno"Incremental"Deployment mode to validate: Incremental (default) or Complete.
parametersJsonstringnonullParameter values as a JSON object, e.g. {"vmName":{"value":"web01"}}.
parametersUristringnonullLocation of a parameters JSON file ARM should fetch. Supply this OR parametersJson.
resourceGroupNamestringnonullResource group to validate against. Omit for a SUBSCRIPTION-scoped validation, which then REQUIRES location.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
templateJsonstringnonullThe full ARM/Bicep-compiled template as a JSON object. Supply this OR templateUri, not both.
templateUristringnonullLocation of a template JSON file ARM should fetch, e.g. an https URL. Supply this OR templateJson.

[Microsoft Azure] Predict what a template WOULD do, without deploying it. Returns a changes array in which every affected resource carries a changeType — Create, Delete, Modify, Deploy, NoChange, Ignore or Unsupported — plus a per-property delta showing the before and after values. THIS IS THE TOOL THAT ANSWERS THE COMPLETE-MODE QUESTION: run it with mode set to Complete and every resource ARM would DELETE appears as changeType Delete, which is the only cheap way to see that list before it is irreversible. Run it before every azure_create_deployment and show the caller the result — a template that looks additive routinely turns out to Modify a live resource back to a stale value. It changes nothing itself, which is why it is read-only and free. Two limits worth knowing: what-if stops expanding nested templates after a few hundred, marking the remainder Ignore rather than failing; and a large template can answer 202 Accepted with no body, in which case this returns an empty object rather than a change list — narrow the template and retry, because this connector does not poll long-running operations.

ParamTypeRequiredDefaultDescription
deploymentNamestringyesA name for the what-if run. Reusing a real deployment's name is fine — nothing is written.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringnonullAzure region storing the run record, e.g. eastus. REQUIRED when resourceGroupName is omitted.
modestringno"Incremental"Deployment mode to simulate: Incremental (default) or Complete. COMPLETE PREDICTS DELETIONS.
parametersJsonstringnonullParameter values as a JSON object, e.g. {"vmName":{"value":"web01"}}.
parametersUristringnonullLocation of a parameters JSON file ARM should fetch. Supply this OR parametersJson.
resourceGroupNamestringnonullResource group to simulate against. Omit for a SUBSCRIPTION-scoped preview, which then REQUIRES location.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
templateJsonstringnonullThe full ARM/Bicep-compiled template as a JSON object. Supply this OR templateUri, not both.
templateUristringnonullLocation of a template JSON file ARM should fetch, e.g. an https URL. Supply this OR templateJson.

Management Groups

ToolPlanAccessSummary
azure_add_subscription_to_management_groupProDestructiveAttach an existing subscription to a management group.
azure_check_management_group_name_availabilityFreeRead-onlyCheck whether a management group id is valid and still free BEFORE creating one.
azure_create_management_groupProWriteCreate a management group, optionally under a named parent.
azure_delete_management_groupProDestructiveDelete a management group.
azure_get_management_groupFreeRead-onlyGet one management group: name, displayName, tenantId and details — the parent group, a version number and who last changed it.
azure_get_management_group_descendantsFreeRead-onlyList EVERY entity descending from a management group — child management groups and subscriptions, at any depth — as one flat, PAGED list.
azure_list_management_group_entitiesFreeRead-onlyList every entity — management groups AND subscriptions — the signed-in user can see across a directory, with the fields the plain listings do not carry: parentNameChain and parentDisplayNameChain…
azure_list_management_group_subscriptionsFreeRead-onlyList the subscriptions attached DIRECTLY to one management group — the ones this group's own policy and role assignments reach first-hand, as opposed to the whole subtree that…
azure_list_management_groupsFreeRead-onlyList the management groups in a directory — the containers ABOVE subscriptions, and the scope at which Azure Policy assignments and RBAC role assignments are INHERITED by everything beneath them.
azure_move_management_groupProDestructiveMove a management group to a different parent.
azure_remove_subscription_from_management_groupProDestructiveDetach a subscription from a management group.

[Microsoft Azure] Attach an existing subscription to a management group. DESTRUCTIVE, WHICH THE WORD 'ADD' HIDES: a subscription has exactly ONE management group parent in ARM, so this silently DETACHES it from whichever group it was under — it is a move, not an addition, and the response never says where it came from. The subscription immediately inherits every policy assigned at the new group and its ancestors, including any Deny effect, which starts refusing deployments in a live customer environment, and any DeployIfNotExists or Modify effect, which rewrites EXISTING resources on first evaluation rather than only governing new ones. It also inherits every role assignment on the new chain while losing every one from the old, so this changes who can access a customer's subscription in both directions at once. To see what the destination will impose, run azure_list_policy_assignments against a subscription ALREADY under that group — that listing includes assignments inherited from above. Record the current parent from azure_get_subscription first, because undoing this means knowing it.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
groupIdstringyesThe management group id to attach the subscription to.
subscriptionIdstringyesThe subscription id to attach, from azure_list_subscriptions. It LEAVES its current management group.

[Microsoft Azure] Check whether a management group id is valid and still free BEFORE creating one. Worth the extra call because a management group's id is IMMUTABLE — only its displayName can be changed afterwards, so a typo is corrected by deleting the group and recreating it, which throws away every policy assignment and role assignment made at that scope in the meantime. Returns nameAvailable, plus when it is false a reason of AlreadyExists (someone in this directory already holds the id, possibly in a branch of the hierarchy this user cannot see, which is why a listing may look clear when the id is not) or Invalid (it breaks ARM's naming rules), and a message saying which. This call has no side effect of any kind — it creates nothing and reserves nothing, so the id can still be taken between this answer and your create.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
groupIdstringyesThe management group id to test, e.g. contoso-prod. Not the display name.

[Microsoft Azure] Create a management group, optionally under a named parent. NOT DESTRUCTIVE, and here is the reasoning rather than an assertion: a brand-new management group is EMPTY. It holds no subscription and no child group, so it governs nothing until something is moved into it or a policy is assigned at it, and undoing it is a single delete that loses nothing. Two things to know before calling. First, ARM treats this as create-or-update, so naming a groupId that ALREADY exists updates that group rather than failing — supplying displayName renames it, and omitting parentGroupId leaves its position in the hierarchy untouched, so a repeated call can never move a group by accident. Moving an existing group is a separate, deliberately destructive tool, azure_move_management_group. Second, the FIRST management group created in a directory can take up to 15 minutes while Azure initialises the service, and creating directly under the tenant root needs permission at the root that a delegated administrator often does not hold — name a parentGroupId you already have access to instead. The id you pass is permanent; check it with azure_check_management_group_name_availability first.

ParamTypeRequiredDefaultDescription
displayNamestringnonullFriendly name shown in the portal. Defaults to the groupId when omitted.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
groupIdstringyesThe management group id to create. Permanent and case-sensitive — only the display name can be changed later.
parentGroupIdstringnonullOptional parent management group id to create this group under. Omit to create under the tenant root, which requires root permissions. On an EXISTING group this MOVES it — prefer azure_move_management_group, which is flagged for that.

[Microsoft Azure] Delete a management group. DESTRUCTIVE. ARM refuses while the group still has children — child groups and attached subscriptions must be moved out first — and that refusal is a mercy rather than an obstacle, because deleting an EMPTY group is still not harmless: every policy assignment and every role assignment made AT that scope goes with it, and neither is recoverable from this response. Whatever used to sit beneath it keeps running and simply stops being governed by those rules, which is invisible until someone runs an audit. Capture what was assigned at the group before deleting: from a subscription that was under it, azure_list_policy_assignments and azure_list_role_assignments report inherited entries, and once the group is gone that record is the only one left. The id is released for reuse, but a recreated group is a new object and inherits none of the old assignments. The call is asynchronous — expect a 202 and confirm with azure_list_management_groups.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
groupIdstringyesThe management group id to DELETE. Must already be empty of child groups and subscriptions.

[Microsoft Azure] Get one management group: name, displayName, tenantId and details — the parent group, a version number and who last changed it. expand takes one of exactly three values. children includes its direct children, both child groups and the subscriptions attached to it, and adding recurse then walks the ENTIRE subtree in one response; ARM only honours recurse alongside expand=children, so this tool refuses that pair rather than letting ARM answer an opaque 400. path returns the chain from the tenant root down to this group, and ancestors returns the same chain reversed, from the immediate parent upward, as managementGroupAncestorsChain. Either of those two is the answer to 'where does this group's governance come from', because that chain is exactly the route every inherited policy assignment and role assignment arrives through — read it before assuming a rule was set here rather than above. WATCH THE SIZE LIMIT: ARM refuses to return more than 15 MB and answers 'the response of the message was too large', which a recursive read of a real customer hierarchy will hit — use azure_get_management_group_descendants, which pages, instead. excludeSubscriptions drops subscriptions from the children so you see only the group skeleton.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
excludeSubscriptionsbooleannofalsetrue to exclude subscriptions from the children, leaving only child management groups.
expandstringnonullOptional: children for direct children, path for the chain from the tenant root down, or ancestors for that chain reversed. Omit for none of them.
groupIdstringyesThe management group id (its immutable name, not its display name), from azure_list_management_groups.
recursebooleannofalsetrue to expand the WHOLE subtree rather than one level. Requires expand to be children, and can exceed ARM's 15 MB response limit on a large hierarchy.

[Microsoft Azure] List EVERY entity descending from a management group — child management groups and subscriptions, at any depth — as one flat, PAGED list. This is the scalable alternative to azure_get_management_group with recurse, and it is Microsoft's own documented fix when that call fails with 'the response of the message was too large' on a big hierarchy. Each item carries id, name, displayName, type (Microsoft.Management/managementGroups or /subscriptions) and its immediate parent, which is enough to rebuild the tree locally. This is the call that answers 'what would be affected if I assigned a policy here?' — everything in this list inherits anything assigned at the group you named, so its length is the blast radius of any governance change made at that scope.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
groupIdstringyesThe management group id whose descendants to list, from azure_list_management_groups.
maxItemsintegerno1000Maximum descendants to return (1-1000, default 1000).

[Microsoft Azure] List every entity — management groups AND subscriptions — the signed-in user can see across a directory, with the fields the plain listings do not carry: parentNameChain and parentDisplayNameChain (the full path from the tenant root to each node), numberOfChildren, numberOfChildGroups, numberOfDescendants, and this user's own permissions and inheritedPermissions on each node (noaccess, view, edit or delete). Read that permissions field before planning ANY change: it is the only call in this family that reports what the caller may actually do at each node, so it is how you find out a restructure will half-succeed before you attempt it. Set search to AllowedParents or AllowedChildren, naming a group in filter, to ask ARM directly where that group may legally be moved to or what may be moved under it — the safe way to plan a move before running azure_move_management_group. Returns ONE page; when the response carries a nextLink, the $skiptoken value inside it goes into skipToken to fetch the next one.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOptional OData filter on name or display name, e.g. name eq 'contoso-prod' or contains(displayName, 'Contoso').
groupNamestringnonullOptional management group id to focus the results on.
maxItemsintegerno1000Maximum entities to return in this page (1-1000, default 1000).
searchstringnonullOptional ARM $search mode: AllowedParents, AllowedChildren, ParentAndFirstLevelChildren, ParentOnly or ChildrenOnly. Used together with filter to name the entity being asked about.
skipTokenstringnonullContinuation token from a previous response's nextLink, to fetch the following page.

[Microsoft Azure] List the subscriptions attached DIRECTLY to one management group — the ones this group's own policy and role assignments reach first-hand, as opposed to the whole subtree that azure_get_management_group_descendants returns. Each item carries the subscription id, displayName, state and its parent group. Read it before azure_remove_subscription_from_management_group so you know exactly what is attached and what is about to lose its inherited governance, and read it again after azure_add_subscription_to_management_group to confirm the move landed where you meant. An empty result is a normal answer: a management group whose children are all other management groups holds no subscriptions of its own.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
groupIdstringyesThe management group id whose attached subscriptions to list.
maxItemsintegerno1000Maximum subscriptions to return (1-1000, default 1000).

[Microsoft Azure] List the management groups in a directory — the containers ABOVE subscriptions, and the scope at which Azure Policy assignments and RBAC role assignments are INHERITED by everything beneath them. That inheritance is why an MSP reads them: a subscription's effective governance is the union of what is assigned to it and what is assigned at every management group between it and the tenant root, and none of that upper half appears in the subscription's own properties. Each item carries name (the group's immutable id, the value every other tool here wants), displayName and tenantId. This is a FLAT list, not the tree — use azure_get_management_group with expand set to children for one group's shape, or azure_list_management_group_entities for the whole directory with parent chains. Pass entraTenant to read a CUSTOMER's hierarchy; a hierarchy belongs to a directory, so without it you only ever see your own.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum groups to return (1-1000, default 1000).

[Microsoft Azure] Move a management group to a different parent. DESTRUCTIVE, AND THE MOST FAR-REACHING CALL IN THIS FAMILY: nothing is deleted and nothing errors, but every group and every subscription in the moved subtree instantly stops inheriting the policy assignments and role assignments of its old ancestor chain and starts inheriting the new one. A Deny policy assigned above the new parent begins refusing deployments across the whole subtree within minutes; a DeployIfNotExists or Modify effect starts rewriting EXISTING resources on its first evaluation; and roles people were relying on quietly vanish while roles they never had appear. None of that is visible from the subscriptions themselves. Read azure_get_management_group with expand set to path FIRST and keep the old chain, because this call does not report where the group came from and the move is not reversible from its own response. Use azure_list_management_group_entities with search set to AllowedParents to confirm the destination is one this user may legally move to. Uses PATCH so only the parent changes — the group's display name and everything under it are left alone.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
groupIdstringyesThe management group id to MOVE.
newParentGroupIdstringyesThe management group id to move it UNDER. Verify with azure_list_management_group_entities using search AllowedParents.

[Microsoft Azure] Detach a subscription from a management group. DESTRUCTIVE AND SILENT — the same argument that makes deleting a policy assignment dangerous, applied to a whole subscription at once. Nothing errors, the subscription keeps running and every resource in it stays exactly where it was, but it stops inheriting every policy assignment and every role assignment that reached it through that group and its ancestors: guardrails stop being evaluated, the compliance data behind them disappears from the next scan, and anyone whose access came from an inherited role loses it without being told. The subscription is not left unparented — it falls back to the directory's root management group — so it is still governed, just by a far thinner chain, and the gap looks like nothing at all until an audit. Prefer azure_add_subscription_to_management_group to move it somewhere deliberate rather than detaching it into the root, and read azure_list_management_group_subscriptions first so you know what you are giving up.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
groupIdstringyesThe management group id to detach the subscription from.
subscriptionIdstringyesThe subscription id to DETACH. It falls back to the directory's root management group.

Disks & Snapshots

ToolPlanAccessSummary
azure_create_or_update_diskProWriteCreate a managed disk, or replace an existing one's model wholesale.
azure_create_or_update_imageProWriteCreate a custom managed image from a generalized virtual machine, from managed disks or from snapshots, or replace an existing image's model.
azure_create_or_update_snapshotProWriteTake a point-in-time snapshot of a managed disk, or replace an existing snapshot's model.
azure_delete_diskProDestructiveDELETE a managed disk.
azure_delete_imageProDestructiveDELETE a custom managed image.
azure_delete_snapshotProDestructiveDELETE a disk snapshot.
azure_get_diskFreeRead-onlyGet one managed disk in full: sku, diskSizeGB, diskIOPSReadWrite and diskMBpsReadWrite, osType, hyperVGeneration, encryption and encryptionSettingsCollection, networkAccessPolicy and…
azure_get_imageFreeRead-onlyGet one custom managed image in full: hyperVGeneration, sourceVirtualMachine, provisioningState and the complete storageProfile — the OS disk with its osType, osState, diskSizeGB and storage account…
azure_get_snapshotFreeRead-onlyGet one disk snapshot in full: sku, diskSizeGB, osType, hyperVGeneration, encryption, incremental, diskState, networkAccessPolicy and the creationData block naming the source disk and how the snapshot…
azure_grant_disk_accessProDestructiveMint a time-limited SAS URI that allows the raw contents of a managed disk to be downloaded or uploaded over the internet.
azure_grant_snapshot_accessProDestructiveMint a time-limited SAS URI that allows the raw contents of a disk snapshot to be downloaded over the internet.
azure_list_disksFreeRead-onlyList every managed disk in a subscription, across all resource groups.
azure_list_disks_in_resource_groupFreeRead-onlyList the managed disks inside one resource group.
azure_list_imagesFreeRead-onlyList the customer's OWN managed images in a subscription — the gold builds captured from their machines, not Microsoft's marketplace catalogue.
azure_list_snapshotsFreeRead-onlyList every disk snapshot in a subscription — the point-in-time copies that are a customer's cheapest and most immediate restore path when one exists.
azure_resize_diskProDestructiveGrow a managed disk to a new size in gibibytes.
azure_revoke_disk_accessProWriteRevoke every SAS URI previously granted over a managed disk, immediately.
azure_revoke_snapshot_accessProWriteRevoke every SAS URI previously granted over a disk snapshot, immediately.
azure_set_disk_skuProDestructiveChange a managed disk's performance SKU, and optionally its performance tier.

[Microsoft Azure] Create a managed disk, or replace an existing one's model wholesale. Not marked destructive because a disk's DATA is safe from this call in both directions — Azure rejects a change to creationData after the disk exists and rejects any shrink, so a mistaken replace cannot blank or truncate the volume. What a replace CAN change is everything around the data: networkAccessPolicy, publicNetworkAccess, the diskAccessId, encryption settings and maxShares are all replaced by the properties document you send, so a disk locked to a private endpoint can be quietly reopened to the internet by a properties block that simply omits the restriction. Read azure_get_disk first and send back what you mean to keep. The properties block is where createOption decides what the disk is made FROM: "Empty" for a blank data disk (diskSizeGB required), "Copy" from a snapshot or disk via sourceResourceId, "Restore", "Import" from a VHD blob, or "FromImage". The operation is ASYNCHRONOUS — a copy of a large disk continues for minutes after this returns; poll azure_get_disk for provisioningState and completionPercent. Billing begins as soon as the disk is provisioned, whether or not anything ever attaches it.

ParamTypeRequiredDefaultDescription
diskNamestringyesThe managed disk name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus. A disk cannot be moved between regions later, and it must match the region of any machine that will attach it.
propertiesJsonstringyesThe disk properties as JSON — creationData is required, e.g. {"creationData":{"createOption":"Empty"},"diskSizeGB":128}. REPLACES the stored properties on an existing disk.
resourceGroupNamestringyesThe resource group to create the disk in. It must already exist.
skuJsonstringnonullPerformance SKU as a JSON object, e.g. {"name":"Premium_LRS"}. Known names include Standard_LRS, StandardSSD_LRS, StandardSSD_ZRS, Premium_LRS, Premium_ZRS, PremiumV2_LRS and UltraSSD_LRS.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object, e.g. {"environment":"production"}. REPLACES the disk's tag set.
zonesJsonstringnonullAvailability zones as a JSON array of strings, e.g. ["1"]. A disk's zone cannot be changed later and must match the machine that attaches it.

[Microsoft Azure] Create a custom managed image from a generalized virtual machine, from managed disks or from snapshots, or replace an existing image's model. Not destructive: capturing an image reads its sources and creates a new resource, changing nothing that already exists. THE DANGEROUS STEP IS THE ONE THIS TOOL DOES NOT DO. Capturing from a running machine requires that machine to have been GENERALIZED first — sysprep on Windows, waagent -deprovision on Linux — and generalizing is a one-way operation that leaves the source machine permanently unbootable as itself. It must be treated as sacrificing the machine, and it is not performed here. If the source machine must survive, capture from a SNAPSHOT of its disks instead, using storageProfile.osDisk.snapshot. Set properties.storageProfile.osDisk.osState to "Generalized" for an image meant to be deployed repeatedly, or "Specialized" to preserve the original identity — deploying more than one machine from a specialized image puts duplicate hostnames and security identifiers onto the network. Worth mentioning to any customer still building this way: managed images are superseded by Azure Compute Gallery image versions, which add versioning and cross-region replication these do not have.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
imageNamestringyesThe managed image name.
locationstringyesThe Azure region, e.g. eastus. A managed image does not replicate to other regions on its own.
propertiesJsonstringyesThe image properties as JSON — either {"sourceVirtualMachine":{"id":"..."}} to capture a generalized machine, or a full storageProfile, e.g. {"storageProfile":{"osDisk":{"osType":"Windows","osState":"Generalized","snapshot":{"id":"..."}},"zoneResilient":false},"hyperVGeneration":"V2"}.
resourceGroupNamestringyesThe resource group to create the image in. It must already exist.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object. REPLACES the image's tag set — record the build date and what is inside it.

[Microsoft Azure] Take a point-in-time snapshot of a managed disk, or replace an existing snapshot's model. Not destructive, and it is the tool to reach for BEFORE anything in this family that is: a snapshot is the only thing standing between a mistaken azure_delete_disk and permanent data loss, and Azure creates none of them automatically. The source disk is not disturbed and the machine holding it keeps running. Set creationData to {"createOption":"Copy","sourceResourceId":"<the disk's ARM id from azure_get_disk>"}. Set incremental true for the usual case — an incremental snapshot bills only for the blocks that changed since the last one in its family, which is dramatically cheaper on a series, though it depends on its predecessors and cannot outlive them. A full snapshot is a standalone copy at full price. TWO WARNINGS WORTH PASSING ON. A snapshot is crash-consistent, not application-consistent: it captures the disk as if the power had been cut, so a database mid-write may need its own recovery on restore, and a machine with several disks needs each snapshotted separately with no guarantee they align. And a snapshot inherits none of the source disk's network restrictions, so it is a fresh copy of the data whose own networkAccessPolicy should be set deliberately. The operation is ASYNCHRONOUS; poll azure_get_snapshot for completionPercent.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus. Normally the source disk's own region.
propertiesJsonstringyesThe snapshot properties as JSON — creationData is required, e.g. {"creationData":{"createOption":"Copy","sourceResourceId":"/subscriptions/.../disks/mydisk"},"incremental":true}.
resourceGroupNamestringyesThe resource group to create the snapshot in. It must already exist.
skuJsonstringnonullStorage SKU as a JSON object, e.g. {"name":"Standard_ZRS"}. Standard_LRS is the cheapest and the default for most snapshots.
snapshotNamestringyesThe snapshot name to create.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullTags as a JSON object. REPLACES the snapshot's tag set — record what this snapshot is FOR, since nothing else will.

[Microsoft Azure] DELETE a managed disk. Destructive and UNRECOVERABLE: there is no recycle bin, no soft delete and no undo for managed disks, and everything on the volume is gone the moment the operation completes. The only route back is a snapshot or a backup that already existed BEFORE this call — check azure_list_snapshots for one first, and if there is none, say so to the caller rather than proceeding. Azure will refuse to delete a disk that is currently ATTACHED to a machine (its managedBy field names the owner), and note that this protection is about the ATTACHMENT and not about the machine's power state: a stop-deallocated machine still holds its disks, so a disk belonging to a machine someone shut down months ago is still protected, while the moment it is detached it becomes deletable with no further warning. That is the trap in orphaned-disk cleanup — an "Unattached" disk is often exactly the disk a deallocated machine's owner is planning to reattach. The operation is ASYNCHRONOUS; a delete lock or a policy on the resource blocks it outright.

ParamTypeRequiredDefaultDescription
diskNamestringyesThe managed disk to DELETE. Its contents cannot be recovered without a pre-existing snapshot.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the disk lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] DELETE a custom managed image. Destructive and unrecoverable: the image cannot be restored, and rebuilding one means standing up a machine, configuring it exactly as before, generalizing it and capturing again — which for a gold build maintained over years is not realistically reproducible at all. Machines ALREADY DEPLOYED from the image keep running and are unaffected; what is lost is the ability to deploy any more of them. That is why nothing appears to break when this is called and why the consequence surfaces weeks later, when a scale-out or a rebuild fails. Check first whether anything still references the image — a scale set's model, a template, a deployment pipeline or a Compute Gallery version can all point at it — because a reference to a deleted image fails only when it is next used. Read azure_get_image first and tell the caller what the image contains and when it was built.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
imageNamestringyesThe managed image to DELETE. No more machines can be deployed from it afterwards.
resourceGroupNamestringyesThe resource group the image lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] DELETE a disk snapshot. Destructive and UNRECOVERABLE, and worse than it looks because of WHAT a snapshot is: it is frequently the only restore point a customer has for the disk it came from, so deleting one can silently remove the recovery path for a volume that is still in production. Nothing about the live disk changes and nothing breaks today — the loss only becomes visible at the moment someone needs to restore, which is the worst moment to discover it. There is no recycle bin. INCREMENTAL SNAPSHOTS ARE A CHAIN: members of one family share stored blocks, so deleting one is not a straightforward tidy-up and the space freed is usually far less than its reported size suggests. Read azure_get_snapshot first and tell the caller which disk it was taken from and when — properties.creationData.sourceResourceId and properties.timeCreated — because after this call that pairing is unrecorded anywhere. Deleting old snapshots is a legitimate and often necessary cost measure; it just should not be done from the name alone.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the snapshot lives in.
snapshotNamestringyesThe snapshot to DELETE. It may be the only restore point for its source disk.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one managed disk in full: sku, diskSizeGB, diskIOPSReadWrite and diskMBpsReadWrite, osType, hyperVGeneration, encryption and encryptionSettingsCollection, networkAccessPolicy and publicNetworkAccess, maxShares, zones, tags and diskState. READ THIS BEFORE ANY WRITE IN THIS FAMILY, and read three fields in particular. managedBy names the virtual machine currently holding the disk, and it is what decides whether a delete will be refused or will succeed instantly. diskState of "ActiveSAS" means a download URL for this disk IS LIVE RIGHT NOW — someone has called azure_grant_disk_access and not revoked it, which is the fastest way to spot an export in progress or one that was forgotten. encryption.type tells you whether the customer's own key protects it, which changes what a copy of this disk is worth to whoever obtains one. A 404 is a legitimate empty answer and is often a sign the caller meant a CUSTOMER's subscription and omitted entraTenant.

ParamTypeRequiredDefaultDescription
diskNamestringyesThe managed disk name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the disk lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one custom managed image in full: hyperVGeneration, sourceVirtualMachine, provisioningState and the complete storageProfile — the OS disk with its osType, osState, diskSizeGB and storage account type, plus every data disk with its LUN. osState is the field to read first: "Generalized" means the image was properly sysprepped or deprovisioned and can be deployed repeatedly, while "Specialized" means it still carries the original machine's identity, hostname and security identifiers, so deploying more than one copy onto a domain causes collisions that are painful to unpick. storageProfile also tells you the machine size a deployment needs, since a gen2 image will not boot on a gen1-only size. A 404 means no image of that name in the group.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
imageNamestringyesThe managed image name.
resourceGroupNamestringyesThe resource group the image lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one disk snapshot in full: sku, diskSizeGB, osType, hyperVGeneration, encryption, incremental, diskState, networkAccessPolicy and the creationData block naming the source disk and how the snapshot was made. creationData.sourceResourceId is the field that matters most — it is the only record of WHICH disk this snapshot came from, and after that disk is deleted it is the only record that the pairing ever existed. completionPercent on a recent incremental snapshot tells you whether the background copy has finished; restoring from one that is still copying produces a disk that is not yet usable. A diskState of "ActiveSAS" means a download URL for this snapshot is live right now.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the snapshot lives in.
snapshotNamestringyesThe snapshot name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Mint a time-limited SAS URI that allows the raw contents of a managed disk to be downloaded or uploaded over the internet. TREAT THE RESPONSE AS A CREDENTIAL, NOT AS A LINK. The accessSAS value in the result grants whoever holds it the ability to pull a byte-for-byte copy of the customer's entire volume — every document, every database file, every cached credential, every private key and every password stored on that disk — with no Entra sign-in, no multi-factor prompt, no conditional access evaluation and no further authorization of any kind. It works from any network, for anyone the URL reaches, including anyone it is forwarded to by accident. Do not paste it into a ticket, a chat, a log or a summary. This is the strongest disclosure in the entire Azure connector after the AKS admin kubeconfig, which is why it is marked destructive despite writing nothing. Prefer taking a snapshot and granting access to that instead, so the live volume is never the thing exposed. Once granted, THE ONLY WAY to withdraw the URL before it expires on its own is azure_revoke_disk_access — deleting nothing, changing no role assignment and rotating no key will invalidate it, so choose the shortest duration that can possibly work. access="Read" is for export; access="Write" additionally allows the disk to be OVERWRITTEN and should be used only for a genuine upload. A disk attached to a running machine usually cannot be granted read access at all; snapshot it first.

ParamTypeRequiredDefaultDescription
accessstringno"Read""Read" to allow download, or "Write" to additionally allow the disk to be OVERWRITTEN. Use Read unless a real upload is intended.
diskNamestringyesThe managed disk whose RAW CONTENTS are being exposed. Confirm this is the disk the caller meant.
durationInSecondsintegerno3600How long the URL stays valid, in seconds (1-86400). Keep it as short as the transfer allows — the URL cannot be recalled except by revoking.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the disk lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Mint a time-limited SAS URI that allows the raw contents of a disk snapshot to be downloaded over the internet. TREAT THE RESPONSE AS A CREDENTIAL, NOT AS A LINK, exactly as for azure_grant_disk_access — and understand that a snapshot is not a lesser target. It is a full copy of a disk as it stood at a point in time, so the accessSAS in the result gives whoever holds it every file, credential and key that was on the source volume at the moment the snapshot was taken, downloadable from anywhere with no Entra sign-in and no further authorization. A snapshot of a domain controller's disk is a copy of the customer's password database. Never paste the value into a ticket, chat, log or summary. Granting on a snapshot rather than on the live disk is nonetheless the RIGHT pattern for an export, because the running volume is never the thing exposed and the machine is never disturbed. Choose the shortest duration the transfer allows: once granted, azure_revoke_snapshot_access is the ONLY way to withdraw the URL before it expires on its own. access="Read" is for export; "Write" additionally allows the snapshot to be overwritten.

ParamTypeRequiredDefaultDescription
accessstringno"Read""Read" to allow download, or "Write" to additionally allow the snapshot to be overwritten. Use Read unless a real upload is intended.
durationInSecondsintegerno3600How long the URL stays valid, in seconds (1-86400). Keep it as short as the transfer allows — the URL cannot be recalled except by revoking.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the snapshot lives in.
snapshotNamestringyesThe snapshot whose RAW CONTENTS are being exposed. This is a full copy of the source disk.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every managed disk in a subscription, across all resource groups. Each item carries id, name, location, zones, tags, sku.name (the performance tier the customer pays for), properties.diskSizeGB, properties.diskState and properties.managedBy. THE TWO FIELDS THAT EARN THIS CALL ARE managedBy AND diskState: a disk whose managedBy is null and whose diskState is "Unattached" is an ORPHAN — nothing is using it, and the customer has been billed for it every hour since whatever machine it belonged to was deleted. Orphaned disks are the single most common avoidable line on an Azure invoice and they are invisible from the virtual machine side, which is why this is a subscription-wide list rather than a per-machine one. properties.timeCreated tells you how long the waste has been running. Returns ARM's {value:[...]} envelope, up to 1000 items across 10 pages per call.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum disks to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the managed disks inside one resource group. Same item shape as azure_list_disks but scoped to a single group, which is the cheaper call when the caller already knows where to look — a large subscription can hold thousands of disks, because every machine has at least an OS disk and orphans accumulate behind every deletion. A 404 means the resource GROUP does not exist in that subscription; an empty {"value":[]} means the group exists and holds no disks, and the two are different answers worth distinguishing for the caller.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum disks to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name, from azure_list_resource_groups.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the customer's OWN managed images in a subscription — the gold builds captured from their machines, not Microsoft's marketplace catalogue. If you want Windows Server or Ubuntu, that is azure_list_vm_image_publishers and its siblings; this tool returns nothing Microsoft published. Each item carries id, name, location, tags, properties.hyperVGeneration, properties.sourceVirtualMachine (the machine the image was captured from, if it still exists) and properties.storageProfile with the OS disk and every data disk baked in. Worth knowing when reading the result: a managed image here is the OLDER capture mechanism, superseded by Azure Compute Gallery image versions, which replicate across regions and carry versioning that these do not. An estate still deploying from plain managed images is a finding rather than a detail. Returns ARM's {value:[...]} envelope, paged.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum images to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every disk snapshot in a subscription — the point-in-time copies that are a customer's cheapest and most immediate restore path when one exists. Each item carries id, name, location, tags, sku.name, properties.diskSizeGB, properties.incremental, properties.timeCreated and properties.creationData.sourceResourceId, which names the disk it was taken from. Read properties.incremental before quoting cost or restore behaviour: an incremental snapshot bills only for changed blocks and depends on the ones before it, while a full snapshot is a standalone copy at full price. This is also the inventory that answers "is there anything to restore?" before an agent proposes anything destructive, and the honest answer is often no — snapshots are not automatic and nothing in Azure creates them for you. Returns ARM's {value:[...]} envelope, paged.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum snapshots to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Grow a managed disk to a new size in gibibytes. Destructive because of what it requires rather than what it writes: AZURE ONLY EXPANDS, NEVER SHRINKS — a value smaller than the current diskSizeGB is refused outright, and there is no supported way to make a managed disk smaller other than creating a new one and copying the data across. Expanding is itself an outage on most disks: for anything but a premium SSD on a supported size the machine must be STOP-DEALLOCATED first (azure_deallocate_vm), so plan the window before calling. Two further consequences worth telling the caller. Growing past a tier boundary re-prices the disk immediately, because Azure bills managed disks by the provisioned size band rather than the bytes used, so 129 GiB costs the same as 256. And the guest OS does NOT see the new space on its own — someone still has to extend the partition and the filesystem inside the machine, which this API cannot do. Read azure_get_disk for the current size and managedBy first. The operation is ASYNCHRONOUS.

ParamTypeRequiredDefaultDescription
diskNamestringyesThe managed disk to RESIZE. The machine holding it usually has to be deallocated first.
diskSizeGBintegeryesThe new size in GiB. Must be LARGER than the current diskSizeGB — Azure refuses every shrink.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the disk lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Revoke every SAS URI previously granted over a managed disk, immediately. This is the remediation for azure_grant_disk_access and it is the ONLY thing that withdraws a granted URL before its own expiry — no role change, key rotation, network rule or resource lock will invalidate one. Not marked destructive on purpose: it removes exposure rather than creating it, and a safety lever that prompts as hard as the disclosure it undoes is a lever nobody pulls in time. Reach for it whenever a URL was shared further than intended, whenever a duration was set longer than the work needed, and as the closing step of any export. Be aware of the one real cost, which is interruption rather than loss: a download or upload genuinely in flight is cut off mid-transfer, so a partially-uploaded VHD is left invalid and must be restarted from the beginning. The disk's own data is never touched. A disk must also be revoked before it can be attached to a machine again, so this is a normal part of finishing an export rather than only an emergency action. Confirm the result with azure_get_disk — diskState should leave "ActiveSAS".

ParamTypeRequiredDefaultDescription
diskNamestringyesThe managed disk whose granted download URLs should be withdrawn now.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the disk lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Revoke every SAS URI previously granted over a disk snapshot, immediately. This is the remediation for azure_grant_snapshot_access and the ONLY thing that withdraws a granted URL before its own expiry. Not marked destructive on purpose: it removes exposure rather than creating it, and a safety lever should not prompt as hard as the disclosure it undoes. Use it whenever a URL travelled further than intended, whenever the duration was longer than the work needed, and as the closing step of every export — an export that is never revoked leaves a downloadable copy of the customer's data reachable for as long as the grant lasts. The one real cost is interruption rather than loss: a transfer genuinely in flight is cut off and must restart from the beginning. The snapshot's own contents are untouched. Confirm with azure_get_snapshot that diskState has left "ActiveSAS".

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the snapshot lives in.
snapshotNamestringyesThe snapshot whose granted download URLs should be withdrawn now.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Change a managed disk's performance SKU, and optionally its performance tier. Destructive on both axes an MSP cares about. PERFORMANCE: this changes the IOPS and throughput a live workload is getting, and moving DOWN — Premium_LRS to Standard_LRS is the usual cost-cutting move — can take a database or a busy file server from adequate to unusable within seconds of the change landing, with no error anywhere to explain it. BILLING: the disk re-prices immediately, and Standard_LRS bills per transaction where premium SKUs do not, so a chatty workload moved to standard to save money can cost more. Changing between the LRS and ZRS families, or to or from UltraSSD_LRS, is not a live conversion at all: those require the disk be detached from a stop-deallocated machine, so confirm the current sku with azure_get_disk before assuming this is an online change. The optional tier sets a performance band independent of size — that is how a small disk gets premium performance without being grown — and it bills for the band, not the bytes.

ParamTypeRequiredDefaultDescription
diskNamestringyesThe managed disk whose performance and price are being CHANGED.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the disk lives in.
skuNamestringyesThe SKU name, e.g. Premium_LRS. Known values: Standard_LRS, StandardSSD_LRS, StandardSSD_ZRS, Premium_LRS, Premium_ZRS, PremiumV2_LRS, UltraSSD_LRS.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tierstringnonullOptional performance tier, e.g. P30, to set performance independently of size. Omit to leave the tier alone.

Virtual Machine Scale Sets

ToolPlanAccessSummary
azure_deallocate_vm_scale_setProDestructiveDeallocate EVERY INSTANCE in a scale set — shut them all down AND release their compute, which is what stops the compute bill for the whole fleet.
azure_deallocate_vm_scale_set_instanceProDestructiveDeallocate ONE instance in a scale set — shut it down AND release its compute, which stops that instance's compute bill.
azure_delete_vm_scale_setProDestructiveDELETE an entire scale set and EVERY instance in it.
azure_delete_vm_scale_set_instancesProDestructiveDELETE the named instances from a scale set, permanently.
azure_get_vm_scale_setFreeRead-onlyGet one scale set's full MODEL — the desired state the fleet is built from: sku (VM size, tier and capacity), orchestrationMode, upgradePolicy (Manual, Automatic or Rolling, plus the rolling-upgrade…
azure_get_vm_scale_set_instanceFreeRead-onlyGet ONE instance inside a scale set by its instance id — that machine's own model: its resolved hardware profile, storage profile with the managed-disk ids actually attached to it, network profile…
azure_get_vm_scale_set_instance_statusFreeRead-onlyGet ONE instance's RUNTIME state — this is the tool that answers "is this particular node up?".
azure_get_vm_scale_set_instance_viewFreeRead-onlyGet the WHOLE SET's runtime rollup — ARM's instanceView on the scale set itself.
azure_get_vm_scale_set_rolling_upgradeFreeRead-onlyGet the status of the most recent ROLLING UPGRADE on a scale set — the batch-by-batch roll-out Azure performs when upgradePolicy.mode is Rolling or when an automatic OS upgrade runs.
azure_list_vm_scale_set_instancesFreeRead-onlyList the individual virtual machines INSIDE one scale set.
azure_list_vm_scale_set_os_upgrade_historyFreeRead-onlyList the history of AUTOMATIC OS IMAGE UPGRADES on a scale set — one entry per upgrade Azure has run, with properties.runningStatus (code, startTime, endTime), properties.progress (successful, failed,…
azure_list_vm_scale_set_skusFreeRead-onlyList the SKUs available to THIS scale set, each with a capacity block giving minimum, maximum and defaultCapacity.
azure_list_vm_scale_setsFreeRead-onlyList every virtual machine scale set in a subscription, across all resource groups.
azure_list_vm_scale_sets_in_resource_groupFreeRead-onlyList the virtual machine scale sets inside one resource group.
azure_power_off_vm_scale_setProDestructivePower off (stop) EVERY INSTANCE in a scale set, leaving them ALLOCATED.
azure_power_off_vm_scale_set_instanceProDestructivePower off (stop) ONE instance in a scale set, leaving it ALLOCATED and leaving every other instance running.
azure_reimage_vm_scale_setProDestructiveReimage EVERY INSTANCE in a scale set — reset every machine's OS disk back to the original image.
azure_reimage_vm_scale_set_instanceProDestructiveReimage ONE instance in a scale set — reset that machine's OS disk back to the original image.
azure_restart_vm_scale_setProDestructiveRestart EVERY INSTANCE in a scale set at once.
azure_restart_vm_scale_set_instanceProDestructiveRestart ONE instance in a scale set.
azure_scale_vm_scale_setProDestructiveSet a scale set's instance count.
azure_set_vm_scale_set_tagsProWriteSet the tags on a scale set, leaving every other property untouched.
azure_start_vm_scale_setProWriteStart (power on) EVERY instance in a scale set.
azure_start_vm_scale_set_instanceProWriteStart (power on) ONE instance in a scale set, leaving every other instance alone.

[Microsoft Azure] Deallocate EVERY INSTANCE in a scale set — shut them all down AND release their compute, which is what stops the compute bill for the whole fleet. Destructive and fleet-wide: the set stops serving, every session drops, in-memory work is lost, the contents of each instance's temporary/resource disk (D: on Windows, /mnt on Linux) are DISCARDED, and because the machines leave their hosts dynamically-assigned public IPs are released and will differ on next start. Managed OS and data disks and their data survive and keep costing storage. This is the correct tool for "stop this fleet to save money"; azure_power_off_vm_scale_set keeps billing it. To free ONE node use azure_deallocate_vm_scale_set_instance. The operation is ASYNCHRONOUS and returns immediately.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set whose EVERY instance should be DEALLOCATED. Temporary disks are discarded and dynamic IPs released.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Deallocate ONE instance in a scale set — shut it down AND release its compute, which stops that instance's compute bill. Destructive for that machine: it stops serving, sessions drop, in-memory work is lost, the contents of its temporary/resource disk (D: on Windows, /mnt on Linux) are DISCARDED, and its dynamically-assigned public IP is released and will differ on next start. Its managed OS and data disks survive with their data and keep costing storage. The rest of the fleet is untouched. A deallocated instance still occupies a slot in the set's capacity, so Azure does not create a replacement for it — if the intent is to shrink the fleet, azure_scale_vm_scale_set or azure_delete_vm_scale_set_instances is the tool. The operation is ASYNCHRONOUS and returns immediately.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
instanceIdstringyesThe instance id to DEALLOCATE. Its temporary disk is discarded and its dynamic IP released.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] DELETE an entire scale set and EVERY instance in it. There is no recycle bin and no undo: the machines, their OS disks and any data disk whose deleteOption is "Delete" are destroyed, and a fleet without a backup cannot be brought back. Read azure_get_vm_scale_set and azure_list_vm_scale_set_instances first and tell the caller how many machines this is — a scale set name gives no hint of its size, and deleting a set of 40 looks identical to deleting a set of 1. To remove SOME instances rather than the whole fleet use azure_delete_vm_scale_set_instances; to stop the compute bill without destroying anything use azure_deallocate_vm_scale_set. forceDeletion skips Azure's graceful shutdown on every instance, so in-flight guest writes are lost — reserve it for a fleet that is already broken. The operation is ASYNCHRONOUS; a delete lock or a policy on the set blocks it outright.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
forceDeletionbooleannofalseSkip the graceful shutdown on every instance and force the delete. Only for an already-broken fleet.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set to DELETE, along with every instance inside it.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] DELETE the named instances from a scale set, permanently. Each listed machine and its OS disk are destroyed, along with any data disk whose deleteOption is "Delete"; there is no undo. This is how a specific bad node is removed rather than letting Azure choose on scale-in — the set's capacity drops by the number deleted, and unless an autoscale rule adds them back the fleet stays smaller. instanceIds must name at least one instance and does NOT accept "*": deleting everything is azure_delete_vm_scale_set, whose name says so. Read azure_list_vm_scale_set_instances first and confirm the ids — instance ids are integers in Uniform orchestration and machine NAMES in Flexible, so an id copied from the wrong place can address the wrong machine. forceDeletion skips the graceful shutdown on each named instance, losing in-flight guest writes. The operation is ASYNCHRONOUS and returns immediately.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
forceDeletionbooleannofalseSkip the graceful shutdown on each named instance. In-flight guest writes are lost.
instanceIdsstringyesThe instances to DELETE, comma-separated, e.g. "0" or "3,7,11". At least one is required and "*" is refused.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one scale set's full MODEL — the desired state the fleet is built from: sku (VM size, tier and capacity), orchestrationMode, upgradePolicy (Manual, Automatic or Rolling, plus the rolling-upgrade policy), scaleInPolicy (which instances Azure removes first when scaling in), automaticRepairsPolicy, the virtualMachineProfile with its image reference, OS profile, network profile, extension profile and health probe, singlePlacementGroup, overprovision, zones and tags. This is the model, NOT the running fleet: when upgradePolicy.mode is Manual, instances created before a model change keep their old configuration until they are explicitly brought up to date. Pass expand="userData" to include the base64 user-data blob. A 404 usually means the caller meant a CUSTOMER's subscription and omitted entraTenant.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullOptional expansion: "userData" to include the base64 user-data blob.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get ONE instance inside a scale set by its instance id — that machine's own model: its resolved hardware profile, storage profile with the managed-disk ids actually attached to it, network profile with its NIC and IP configuration, its zone, and properties.latestModelApplied telling you whether it is running the current scale set model or an older one. Pass expand="instanceView" to append its runtime state in the same call. Use this to identify a specific node before acting on it — the instance-level power tools are far less disruptive than their set-level counterparts, but only if the id is right. A 404 means no instance with that id is in the set: instances are removed on scale-in and the ids are not reused, so a stale id is a normal way to get one.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullSet to "instanceView" to append the instance's runtime state.
instanceIdstringyesThe instance id, from azure_list_vm_scale_set_instances — an integer in Uniform orchestration, the machine name in Flexible.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get ONE instance's RUNTIME state — this is the tool that answers "is this particular node up?". Returns the statuses array whose PowerState/* code is one of PowerState/running, PowerState/stopped (still allocated, still billed), PowerState/deallocated or PowerState/starting|stopping|deallocating, plus per-extension health with each extension's last message, per-disk status, the OS name and version and any boot-diagnostics blob URIs. ARM calls this endpoint the instance's instanceView; it is named "status" here so it cannot be confused with azure_get_vm_scale_set_instance_view, which rolls up the WHOLE SET. Do not read provisioningState from azure_get_vm_scale_set_instance for this — that field describes the last ARM write, not the power state.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
instanceIdstringyesThe instance id, from azure_list_vm_scale_set_instances.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get the WHOLE SET's runtime rollup — ARM's instanceView on the scale set itself. This is the tool that answers "is this fleet healthy?": virtualMachine.statusesSummary counts instances by status code (so a fleet with capacity 10 and only 7 at PowerState/running is visible in one read), extensions carries each extension's per-instance status summary, orchestrationServices reports whether automatic instance repairs are Running or Suspended, and statuses carries the set-level provisioning status. It does NOT tell you which particular node is unhealthy — for one machine use azure_get_vm_scale_set_instance_status, and for the per-instance list use azure_list_vm_scale_set_instances with expand="instanceView". Poll this after any set-level power action to confirm the outcome.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get the status of the most recent ROLLING UPGRADE on a scale set — the batch-by-batch roll-out Azure performs when upgradePolicy.mode is Rolling or when an automatic OS upgrade runs. Returns policy (the maxBatchInstancePercent, maxUnhealthyInstancePercent and pauseTimeBetweenBatches the roll-out is bound by), runningStatus (code, startTime, lastAction and its time) and progress (successfulInstanceCount, failedInstanceCount, inProgressInstanceCount, pendingInstanceCount). This is the tool to read when a customer reports instances restarting on their own: a rolling upgrade in progress is the usual explanation, and a runningStatus of Faulted with a non-zero failedInstanceCount is a stalled roll-out that stopped itself before breaching the unhealthy threshold. A 404 means no rolling upgrade has ever run on this set, which is a legitimate answer rather than a fault.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the individual virtual machines INSIDE one scale set. Each item carries instanceId (the value every instance-level tool in this family needs), name, the resolved virtualMachineProfile for that machine, properties.latestModelApplied — which is false on any instance still running an older model — and properties.provisioningState. Pass expand="instanceView" to get every instance's PowerState/* code and extension health in ONE call rather than one call per node; on a large fleet that is the difference between a single read and being throttled by ARM. filter="properties/latestModelApplied eq false" is the direct answer to "which nodes are behind the model?". Instance ids are integers in Uniform orchestration and machine NAMES in Flexible orchestration. Returns ARM's {value:[...]} envelope, paged.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expandstringnonullSet to "instanceView" to include each instance's power state and extension health inline.
filterstringnonullOData filter, e.g. "properties/latestModelApplied eq false". Omit for every instance.
maxItemsintegerno1000Maximum instances to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
selectstringnonullComma-separated properties to return, e.g. "instanceView". Narrows the response on a large fleet.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the history of AUTOMATIC OS IMAGE UPGRADES on a scale set — one entry per upgrade Azure has run, with properties.runningStatus (code, startTime, endTime), properties.progress (successful, failed, in-progress and pending instance counts), properties.startedBy (Platform when Azure initiated it, User when a person did), and properties.targetImageReference naming the image version the fleet was moved to. Where azure_get_vm_scale_set_rolling_upgrade answers "what is happening right now", this answers "what has been done to this fleet, and when" — which is the read that turns "the servers rebooted last Tuesday night" into a dated platform event with an image version attached. An empty {"value":[]} means automatic OS upgrades have never run here.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum history entries to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the SKUs available to THIS scale set, each with a capacity block giving minimum, maximum and defaultCapacity. Read it before azure_scale_vm_scale_set: it is the answer to "how far can this fleet actually scale out?", and it is narrower than the region-wide answer because it is constrained by the set's own SKU and placement. A requested capacity above the reported maximum fails the scale operation outright rather than scaling part-way. Returns ARM's {value:[...]} envelope.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum SKUs to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every virtual machine scale set in a subscription, across all resource groups. Each item carries id, name, location, zones, tags, sku (name = the VM size, tier, and capacity = HOW MANY INSTANCES ARE ASKED FOR), properties.orchestrationMode (Uniform or Flexible), properties.upgradePolicy, properties.scaleInPolicy and properties.provisioningState. Note that sku.capacity is the DESIRED count from the model, not the number of instances actually healthy right now — azure_get_vm_scale_set_instance_view answers that, and the two differ during a scale operation or when instances are failing to provision. Requires a subscription id from azure_list_subscriptions. Returns ARM's {value:[...]} envelope; up to 1000 items across 10 pages per call, with nextLink returned when more remain.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum scale sets to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the virtual machine scale sets inside one resource group. Same item shape as azure_list_vm_scale_sets but scoped to a single group, which is the cheaper call when the caller already knows where the fleet lives. A 404 here means the resource GROUP does not exist in that subscription; an empty {"value":[]} means the group exists and holds no scale sets — the two are different answers and worth distinguishing for the caller. In Flexible orchestration the member machines are also ordinary virtual machines, so a group can look like it holds both a scale set and a pile of loose VMs when it really holds one fleet.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum scale sets to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name, from azure_list_resource_groups.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Power off (stop) EVERY INSTANCE in a scale set, leaving them ALLOCATED. Destructive and fleet-wide: the whole set stops serving at once, every session drops and in-memory work is lost. Understand the billing difference before choosing this over azure_deallocate_vm_scale_set — powered-off instances keep their host reservation and their addresses and are STILL CHARGED for compute, so this is the wrong tool for "shut it down to save money" and the right one when the fleet must keep its IPs or be able to start again immediately. skipShutdown cuts power with no guest shutdown at all, risking filesystem corruption and unflushed application writes on every instance — reserve it for a fleet that is already hung. To stop ONE node use azure_power_off_vm_scale_set_instance. The operation is ASYNCHRONOUS and returns immediately.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set whose EVERY instance should be POWERED OFF. They stay allocated and stay billed.
skipShutdownbooleannofalseCut power without a guest shutdown on every instance. Risks filesystem corruption — only for an already-hung fleet.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Power off (stop) ONE instance in a scale set, leaving it ALLOCATED and leaving every other instance running. Destructive for that machine: it stops serving, its sessions drop and its in-memory work is lost. It is STILL BILLED for compute because it keeps its host reservation — choose azure_deallocate_vm_scale_set_instance to stop that charge, and choose this one when the node must keep its address or be able to start again immediately. Note that a stopped instance still counts towards the set's capacity, so Azure will not replace it. skipShutdown cuts power with no guest shutdown, risking filesystem corruption — only for a node that is already hung. The operation is ASYNCHRONOUS and returns immediately.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
instanceIdstringyesThe instance id to POWER OFF. It stays allocated and stays billed.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
skipShutdownbooleannofalseCut power without a guest shutdown. Risks filesystem corruption — only for a node that is already hung.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Reimage EVERY INSTANCE in a scale set — reset every machine's OS disk back to the original image. THIS IS FLEET-WIDE DATA LOSS BY DESIGN: on every instance, every change made to the operating system disk since it was created is destroyed — installed software, configuration, local user profiles, and anything an application wrote outside a data disk. Attached data disks are not touched. It is also a full outage: the whole fleet is unavailable while it runs. On a scale set built from a golden image this is the standard way to return a drifted fleet to a known state, and on ephemeral OS disks it is the only recovery; on anything else treat it as a last resort and confirm with a human first. To reset ONE drifted node use azure_reimage_vm_scale_set_instance. Set tempDisk=true to also reset the temporary/resource disk (ephemeral OS disks only). The operation is ASYNCHRONOUS and can run a long time on a large fleet.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set whose EVERY instance should be REIMAGED. Every OS disk in the fleet is wiped back to the image.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tempDiskbooleannofalseAlso reset each instance's temporary disk. Valid only where the OS disk is ephemeral.

[Microsoft Azure] Reimage ONE instance in a scale set — reset that machine's OS disk back to the original image. THIS IS DATA LOSS BY DESIGN, and the fact that it is only one node does not soften it: every change made to that instance's operating system disk since it was created is destroyed, including installed software, configuration, local user profiles and anything an application wrote outside a data disk. Attached data disks are not touched. On a stateless fleet built from a golden image this is the normal repair for one drifted or broken node and the rest of the set keeps serving throughout; on a node someone has been treating as a pet it is unrecoverable. Read azure_get_vm_scale_set_instance first and tell the caller what the node is. Set tempDisk=true to also reset the temporary disk (ephemeral OS disks only). The operation is ASYNCHRONOUS and the instance is unavailable for several minutes.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
instanceIdstringyesThe instance id to REIMAGE. Everything on this node's OS disk is destroyed.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tempDiskbooleannofalseAlso reset the temporary disk. Valid only where the OS disk is ephemeral.

[Microsoft Azure] Restart EVERY INSTANCE in a scale set at once. Destructive, and its blast radius is the whole fleet rather than one machine: if this set is a customer's web tier, this takes the entire tier down together — Azure does not stage it into batches, so there is no surviving capacity behind the load balancer while it runs. Every session on every instance drops and everything held in memory is lost. This is almost never the right tool for troubleshooting one bad node: use azure_restart_vm_scale_set_instance, which takes out a single machine while the rest keep serving. Confirm with a human before restarting a production fleet. Disks, IP configuration and the scale set model are unaffected. The operation is ASYNCHRONOUS — poll azure_get_vm_scale_set_instance_view for the statusesSummary to come back to full strength.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set whose EVERY instance should be RESTARTED. The whole fleet goes down together.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Restart ONE instance in a scale set. Destructive because it is still a real interruption on a live machine — every session on THAT node drops and its in-memory work is lost — but the blast radius is one instance, not the fleet: behind a load balancer with other healthy instances this is close to routine, and it is the correct remedy for a single misbehaving node. Compare azure_restart_vm_scale_set, which restarts EVERY instance at once and takes the whole tier down. Check azure_get_vm_scale_set_instance_view first: restarting the last healthy instance of a set is a full outage no matter which tool did it. The instance's disks and IP configuration are unaffected. The operation is ASYNCHRONOUS — poll azure_get_vm_scale_set_instance_status for PowerState/running.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
instanceIdstringyesThe instance id to RESTART. Sessions on this one node drop; the rest of the fleet keeps serving.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Set a scale set's instance count. DESTRUCTIVE IN BOTH DIRECTIONS, and for different reasons. Scaling IN terminates running instances along with whatever work they were doing — connections drop mid-request, and unless properties.scaleInPolicy says otherwise Azure chooses WHICH machines die, so it is not safe to assume the newest or the least busy goes first; a capacity of 0 terminates every instance in the fleet. Scaling OUT is an open-ended hourly cost: each new instance bills from the moment it allocates and nothing here caps the total. Read azure_list_vm_scale_set_skus first — a capacity above the reported maximum fails outright rather than scaling part-way — and check whether an autoscale rule governs this set (azure_list_autoscale_settings), because if one does it will simply revert this change at its next evaluation and the fleet will appear to ignore you. New instances are built from the CURRENT model, so on a set whose model has changed since the last upgrade a scale-out mixes old and new instances. This is a narrow PATCH of sku.capacity — no other property is touched. The operation is ASYNCHRONOUS and returns immediately.

ParamTypeRequiredDefaultDescription
capacityintegeryesThe new instance count. Below the current count Azure TERMINATES the difference; 0 terminates every instance.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Set the tags on a scale set, leaving every other property untouched. Not destructive: tags carry no workload or access-control semantics, no instance is disturbed and nothing stops running. Note the REPLACE semantics — Microsoft.Compute treats the tags map as a single value, so any tag you omit is REMOVED. Read the set with azure_get_vm_scale_set first and include everything worth keeping, or use the provider-agnostic azure_update_resource_tags with operation="Merge" to add one tag without knowing the rest. Tags set here apply to the scale set RESOURCE, not to the individual instances inside it, which carry their own tags.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringyesThe COMPLETE tag set as a JSON object, e.g. {"environment":"production","costCentre":"CC-1042"}. Omitted tags are removed.

[Microsoft Azure] Start (power on) EVERY instance in a scale set. Not destructive — starting is additive: nothing is lost and no in-flight work is interrupted. The consequence worth telling a caller about is cost, multiplied by the fleet: a deallocated instance is not billed for compute, and starting the set resumes that billing for all of them at once. Instances that were deallocated come back on fresh hosts, so dynamically-assigned public IPs normally change. To bring ONE node back use azure_start_vm_scale_set_instance. The operation is ASYNCHRONOUS — this returns immediately and a large fleet takes minutes to settle; confirm with azure_get_vm_scale_set_instance_view.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set whose EVERY instance should be started.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Start (power on) ONE instance in a scale set, leaving every other instance alone. Not destructive — starting is additive and interrupts nothing. It resumes compute billing for that one machine, and an instance that was deallocated returns on a fresh host, so a dynamically-assigned public IP normally changes. Requires an instance id from azure_list_vm_scale_set_instances. The operation is ASYNCHRONOUS — confirm with azure_get_vm_scale_set_instance_status. To bring a whole stopped fleet back use azure_start_vm_scale_set instead of calling this once per node.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
instanceIdstringyesThe instance id to start, from azure_list_vm_scale_set_instances. Only this instance is affected.
resourceGroupNamestringyesThe resource group the scale set lives in.
scaleSetNamestringyesThe scale set name.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

Containers

ToolPlanAccessSummary
azure_delete_container_groupProDestructiveDelete a container group.
azure_delete_container_registryProDestructiveDelete a container registry and EVERY image in it.
azure_get_container_groupProDestructiveGet one container group in full, including each container's instanceView with its currentState, previousState, restartCount and the group's recent events.
azure_get_container_logsFreeRead-onlyRead one container's stdout and stderr — the call an engineer actually wants when an ACI workload misbehaves, and the reason this family is worth having.
azure_get_container_registryFreeRead-onlyGet one container registry in full: sku, loginServer, adminUserEnabled, anonymousPullEnabled, identity, encryption, networkRuleSet with its ip rules and defaultAction, networkRuleBypassOptions,…
azure_list_acr_credentialsProDestructiveReturn a registry's ADMIN username and both passwords in plaintext.
azure_list_acr_webhooksFreeRead-onlyList a registry's webhooks with each one's actions, scope, status and provisioningState — the notifications the registry fires when an image is pushed, deleted or quarantined, and therefore the list…
azure_list_container_groupsProDestructiveList every Azure Container Instances container group in a subscription, each with its containers and their images, resource requests, ports and instanceView state, plus the group's osType,…
azure_list_container_groups_in_resource_groupProDestructiveList the container groups inside one resource group.
azure_list_container_registriesFreeRead-onlyList every Azure Container Registry in a subscription with each one's sku, loginServer, adminUserEnabled, anonymousPullEnabled, publicNetworkAccess, provisioningState and creation date.
azure_list_container_registries_in_resource_groupFreeRead-onlyList the container registries inside one resource group.
azure_regenerate_acr_credentialProDestructiveRegenerate one of a registry's two admin passwords and return the new value.
azure_restart_container_groupProDestructiveRestart every container in a group in place.
azure_start_container_groupProWriteStart a stopped container group.
azure_stop_container_groupProDestructiveStop a container group: every container halts and the compute is deallocated.

[Microsoft Azure] Delete a container group. NO UNDO, and the loss is larger than the running containers: THE LOGS GO WITH IT. ACI stores a container's output on the instance itself, so deleting the group destroys the only record of what it did unless the customer had wired diagnostics to a Log Analytics workspace when the group was created — which is uncommon, and cannot be added afterwards. Read azure_get_container_logs FIRST, every time; that ordering is the difference between a tidy-up and destroying the evidence for the incident that prompted it. The definition goes too: the container spec, environment variables, volume mounts and any registry credentials embedded in it are not recoverable, so a group that was created by hand rather than from a template cannot be rebuilt from anything Azure retains. Mounted Azure File shares and any external resources the containers used survive; the group's public IP and DNS label do not, and the label may not be reusable afterwards.

ParamTypeRequiredDefaultDescription
containerGroupNamestringyesThe container group name to DELETE, with its logs and its definition.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the container group lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a container registry and EVERY image in it. NO UNDO: repositories, tags, manifests and layers all go, there is no recycle bin, and unless the registry had a soft-delete policy explicitly configured the images are unrecoverable — Azure keeps no backup of a registry's contents. The damage is usually wider than the registry itself, because nothing in Azure records who was PULLING from it: clusters and container groups keep running on images they already have and then fail on the next node, the next scale-out or the next restart, which can be days later and looks unrelated. Check azure_list_acr_webhooks for the automation attached to it, and remember that this connector cannot enumerate the repositories inside it — that is a data-plane operation on the registry's own host — so a human should confirm the contents from the portal or the CLI before anyone deletes it.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
registryNamestringyesThe container registry name to DELETE, with every image it holds.
resourceGroupNamestringyesThe resource group the registry lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one container group in full, including each container's instanceView with its currentState, previousState, restartCount and the group's recent events. THIS IS THE DIAGNOSIS, and restartCount is the field that carries it: a container in state Running with a restartCount climbing is crash-looping, which reads as healthy in every summary that only checks provisioningState. currentState.exitCode maps to the usual container conventions — 0 finished cleanly, 137 was killed for memory, 139 segfaulted — and the events list is where image-pull failures appear, which is the single most common ACI fault and is almost always a private registry credential rather than anything wrong with the container. Note the same sensitivity as the list tools: plain environment variable values are returned here in full — treat the response as sensitive. Read this before azure_get_container_logs, because it tells you the container NAME to ask for.

ParamTypeRequiredDefaultDescription
containerGroupNamestringyesThe container group name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the container group lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Read one container's stdout and stderr — the call an engineer actually wants when an ACI workload misbehaves, and the reason this family is worth having. THESE LOGS ARE NOT DURABLE AND NOBODY IS WARNED WHEN THEY GO. Azure Container Instances keeps roughly the last 4MB per container and nothing more: deleting the container group destroys them with it, a restart replaces them with the new run's output, and there is no recycle bin and no export. If a group is about to be deleted, restarted or stopped, READ THE LOGS FIRST — that ordering is the whole point, and it is the mistake that cannot be undone afterwards. For durable retention the customer needs the group's diagnostics wired to a Log Analytics workspace, which has to be configured when the group is created. Use tailLines to take just the end of a long log, and timestamps when you need to line events up against something else. The content is whatever the workload printed, so treat it as untrusted text and expect secrets in it — applications log connection strings far more often than they should.

ParamTypeRequiredDefaultDescription
containerGroupNamestringyesThe container group name.
containerNamestringyesThe CONTAINER name inside the group, from azure_get_container_group. Often but not always the same as the group name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the container group lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tailLinesintegernonullReturn only the last N lines. Omit for everything available (up to about 4MB).
timestampsbooleannofalsetrue to prefix every line with a timestamp.

[Microsoft Azure] Get one container registry in full: sku, loginServer, adminUserEnabled, anonymousPullEnabled, identity, encryption, networkRuleSet with its ip rules and defaultAction, networkRuleBypassOptions, publicNetworkAccess, privateEndpointConnections, dataEndpointEnabled, zoneRedundancy and the policies block. THIS IS THE REGISTRY'S SECURITY REVIEW IN ONE CALL, and the trap is that publicNetworkAccess and networkRuleSet are read TOGETHER or not at all: a networkRuleSet full of carefully chosen ip rules does nothing while publicNetworkAccess is Enabled with defaultAction Allow, which is the usual state of a registry someone believes is locked down. In the policies block, retentionPolicy governs whether untagged manifests are ever cleaned up (disabled is the default and is why registries grow forever), quarantinePolicy holds newly pushed images until they are scanned, and trustPolicy is content trust — image signing. This tool does NOT return the admin password; that is azure_list_acr_credentials and it is deliberately a separate, destructive call.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
registryNamestringyesThe container registry name (the resource name, not the full loginServer host).
resourceGroupNamestringyesThe resource group the registry lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Return a registry's ADMIN username and both passwords in plaintext. DESTRUCTIVE AND Pro DESPITE ONLY READING, because of what the answer is: the admin account holds PUSH as well as pull on every repository in the registry. Pull means the customer's proprietary images — and whatever is baked into them, which in practice includes connection strings and keys far more often than anyone admits. Push is the serious half: an attacker with these credentials can overwrite an EXISTING tag with a modified image, and every cluster, pipeline, container group and developer that pulls that tag afterwards runs their code believing nothing changed. Nothing in the registry records that the tag moved. Never paste this into a ticket, a chat message or a document. Expect a failure rather than a secret when the registry has adminUserEnabled false, which is the default and the recommended state — check azure_get_container_registry first, and treat 'enable the admin account so I can read it' as a change that needs a human. The right long-term answer is a token with a scope map, or an Entra identity with AcrPull, neither of which is a shared password.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
registryNamestringyesThe container registry name whose admin username and passwords are returned.
resourceGroupNamestringyesThe resource group the registry lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List a registry's webhooks with each one's actions, scope, status and provisioningState — the notifications the registry fires when an image is pushed, deleted or quarantined, and therefore the list of automated systems that react to this registry. Read scope carefully: it is a repository filter, so 'foo:*' fires for every tag under foo while an empty scope fires for everything, and a webhook someone believes is narrow is usually the latter. A status of disabled means the downstream automation has silently stopped being triggered, which is a common and hard-to-spot cause of 'the deployment did not happen'. SAFE TO READ FREELY: the webhook's target URI and custom headers — the parts that carry a bearer token — are NOT returned by this listing. They come from a separate callback-config action that this connector deliberately does not expose.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum webhooks to return (1-1000, default 1000).
registryNamestringyesThe container registry name.
resourceGroupNamestringyesThe resource group the registry lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every Azure Container Instances container group in a subscription, each with its containers and their images, resource requests, ports and instanceView state, plus the group's osType, restartPolicy, ipAddress, sku, priority, provisioningState and subnetIds. THE ENVIRONMENT VARIABLES COME BACK WITH IT AND THAT IS THE FINDING: a container's environmentVariables carry a plain value and a secureValue, only the secure one is withheld from this response, and connection strings and API keys land in the plain field far more often than in the secure one — the App Service app-settings trap in a different provider. Read imageRegistryCredentials too: the password is withheld, but the server and username reveal which private registry this group pulls from, which is how you find the registry nobody documented. restartPolicy Always on a group that has finished its work is the usual explanation for an ACI bill nobody can account for, because the group restarts forever.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum container groups to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the container groups inside one resource group. Same item shape as azure_list_container_groups, scoped to a single group — including the same environment-variable exposure, so treat the response as sensitive. Useful when tracing an application's moving parts: ACI is where the pieces that are too small for a cluster end up, so a resource group's container groups are usually its scheduled jobs, build agents and one-off migrations rather than anything anyone drew on the architecture diagram.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum container groups to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name, from azure_list_resource_groups.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List every Azure Container Registry in a subscription with each one's sku, loginServer, adminUserEnabled, anonymousPullEnabled, publicNetworkAccess, provisioningState and creation date. TWO FIELDS ARE THE SECURITY ANSWER AND BOTH DEFAULT TO THE SAFE VALUE, so a true is somebody's decision rather than a default nobody touched. adminUserEnabled true means a single shared username and password exists that grants push and pull over the whole registry — Azure ships a built-in policy specifically to forbid it, and finding it enabled on an inherited estate is a routine audit finding. anonymousPullEnabled true means the internet can pull the customer's images without authenticating at all. The sku also decides capability rather than just price: private endpoints, geo-replication and content trust are Premium-only, so a Basic registry cannot be network-isolated no matter what anyone asks for.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum registries to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the container registries inside one resource group. Same item shape as azure_list_container_registries, scoped to a single group. Worth knowing before anyone tidies up: a registry's images do NOT live in this resource group in any visible way — the storage backing them is managed by the service and never appears as a resource, so a registry that looks like an empty shell in the portal can still hold hundreds of gigabytes of the customer's images and bill for every one of them.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum registries to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group name, from azure_list_resource_groups.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Regenerate one of a registry's two admin passwords and return the new value. DESTRUCTIVE AND IMMEDIATE: the old value stops working the moment this returns, and everything still holding it breaks at its next pull — CI pipelines, Kubernetes imagePullSecrets, container groups whose imageRegistryCredentials embed it, and any developer's stored docker login. None of those fail loudly here; they fail later, as an unauthorized pull in somebody else's log. THE REGISTRY HAS TWO PASSWORDS SPECIFICALLY SO THIS DOES NOT HAVE TO BE AN OUTAGE: rotate password, move every consumer onto the still-valid password2, then rotate password2. Regenerating BOTH in one sitting is how a rotation becomes an incident. Use this when a credential from azure_list_acr_credentials has leaked, and know beforehand who is holding it — this connector cannot tell you, because the registry does not record which consumers use which password.

ParamTypeRequiredDefaultDescription
credentialNamestringno"password"Which of the two admin passwords to regenerate: password or password2.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
registryNamestringyesThe container registry name whose password is INVALIDATED and replaced.
resourceGroupNamestringyesThe resource group the registry lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Restart every container in a group in place. DESTRUCTIVE FOR TWO REASONS THAT BOTH GET OVERLOOKED. It interrupts a live workload — there is no drain, no health gate and no per-container choice, so anything mid-request or mid-job is cut off — and it DISCARDS THE CURRENT LOGS, replacing them with the new run's output. Run azure_get_container_logs first if there is any chance you will want to know why it was misbehaving, because after this the evidence is gone. The other surprise is that a restart is not a no-op on the image: if the tag this group pulls has moved, the restart downloads the NEW image, so a container that had been running a known-good build can come back running something nobody chose. Check the tag before restarting anything that matters, and prefer this over stop-then-start only when you specifically want the fresh pull.

ParamTypeRequiredDefaultDescription
containerGroupNamestringyesThe container group name to RESTART. Its current logs are lost.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the container group lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Start a stopped container group. Not destructive — starting is additive and the group comes back running the same containers from the same images. Two consequences worth stating anyway. It RESTARTS BILLING immediately, and ACI bills per second for the vCPU and memory requested rather than used, so a group left started is a meter nobody is watching. And the containers begin from a clean state: anything written inside a container during its previous run is gone, because only mounted volumes survive a stop. ARM answers before the containers are actually up — poll azure_get_container_group until each container's instanceView shows Running rather than assuming this call finishing means the workload is serving.

ParamTypeRequiredDefaultDescription
containerGroupNamestringyesThe container group name to START.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the container group lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Stop a container group: every container halts and the compute is deallocated. DESTRUCTIVE BECAUSE THE WORKLOAD STOPS AT ONCE, with no drain and no confirmation per container — anything serving traffic stops answering, and anything mid-job loses its work unless the job wrote to a mounted volume. The group's resource definition survives and azure_start_container_group brings it back, so this is recoverable in the way a delete is not, which is exactly why it gets used casually on things that turn out to matter. Billing for vCPU and memory stops, which makes it the correct lever for a group nobody is using. Read azure_get_container_logs before stopping if the reason for stopping is that something is wrong, because the logs do not survive the restart afterwards.

ParamTypeRequiredDefaultDescription
containerGroupNamestringyesThe container group name to STOP. Every container in it halts.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the container group lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

DNS

ToolPlanAccessSummary
azure_create_dns_record_setProDestructiveCreate or REPLACE a record set in a public DNS zone.
azure_create_dns_zoneProWriteCreate a public DNS zone, or update an existing one's tags.
azure_create_private_dns_record_setProDestructiveCreate or REPLACE a record set in a private DNS zone.
azure_create_private_dns_virtual_network_linkProDestructiveLink a virtual network to a private DNS zone, or update an existing link.
azure_create_private_dns_zoneProWriteCreate a private DNS zone, or update an existing one's tags.
azure_delete_dns_record_setProDestructiveDelete a record set from a public DNS zone.
azure_delete_dns_zoneProDestructiveDelete a public DNS zone AND every record set inside it, in one call.
azure_delete_private_dns_record_setProDestructiveDelete a record set from a private DNS zone.
azure_delete_private_dns_virtual_network_linkProDestructiveRemove a virtual network link from a private DNS zone.
azure_delete_private_dns_zoneProDestructiveDelete a private DNS zone and every record set inside it.
azure_get_dns_record_setFreeRead-onlyGet one record set by type and name, with its records, TTL, fqdn, metadata and etag.
azure_get_dns_zoneFreeRead-onlyGet one public DNS zone: its nameServers, numberOfRecordSets, maxNumberOfRecordSets, tags and etag.
azure_get_private_dns_record_setFreeRead-onlyGet one record set from a private DNS zone by type and name, with its records, ttl, fqdn, isAutoRegistered flag and etag.
azure_get_private_dns_virtual_network_linkFreeRead-onlyGet one virtual network link: the virtual network it points at, its registrationEnabled flag, provisioningState, virtualNetworkLinkState, tags and etag.
azure_get_private_dns_zoneFreeRead-onlyGet one private DNS zone with its record-set and virtual-network-link counts, tags, provisioningState and etag.
azure_list_dns_record_setsFreeRead-onlyList the record sets in a public DNS zone — every type at once, or a single type when recordType is given.
azure_list_dns_zonesFreeRead-onlyList the PUBLIC DNS zones in a subscription, or in one resource group when resourceGroupName is given.
azure_list_private_dns_record_setsFreeRead-onlyList the record sets in a private DNS zone — every type at once, or one type when recordType is given.
azure_list_private_dns_virtual_network_linksFreeRead-onlyList the virtual network links on a private DNS zone.
azure_list_private_dns_zonesFreeRead-onlyList the PRIVATE DNS zones in a subscription, or in one resource group when resourceGroupName is given.

[Microsoft Azure] Create or REPLACE a record set in a public DNS zone. DESTRUCTIVE DESPITE BEING A CREATE, for the same reason an NSG rule write is: the write IS the change, and here the change is live traffic. Repointing an A or CNAME record moves a customer's website, portal or authentication endpoint to a different address, and nothing in Azure announces it. An MX write redirects the domain's MAIL. A TXT write is that same hazard aimed at mail authentication and domain ownership — overwriting the record carrying an SPF policy or a DKIM key breaks mail authentication for the entire domain — and because this PUT replaces the ENTIRE set, sending one value drops every other value that shared the name. The damage also arrives LATE: resolvers keep serving the previous answer for the old record's TTL, so the breakage starts minutes to hours after this call and the recovery is delayed by the same amount, which is why a DNS change is rarely blamed for the outage it caused. Read azure_get_dns_record_set first and send back everything you are not deliberately changing. Use @ for the zone apex.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
metadataJsonstringnonullOptional metadata as a JSON object — free-text key/value pairs stored on the record set, useful as the only audit trail on a change.
recordTypestringyesRecord type: A, AAAA, CAA, CNAME, MX, NS, PTR, SOA, SRV or TXT.
recordsJsonstringyesThe records, as JSON matching the type. A: [{"ipv4Address":"1.2.3.4"}]. AAAA: [{"ipv6Address":"2001:db8::1"}]. CNAME: {"cname":"target.example.com"}. MX: [{"preference":10,"exchange":"mail.example.com"}]. NS: [{"nsdname":"ns1.example.com"}]. PTR: [{"ptrdname":"host.example.com"}]. SRV: [{"priority":1,"weight":1,"port":443,"target":"host.example.com"}]. TXT: [{"value":["v=spf1 include:spf.protection.outlook.com -all"]}]. CAA: [{"flags":0,"tag":"issue","value":"letsencrypt.org"}]. SOA and CNAME take a single OBJECT; every other type takes an ARRAY, and the array is the complete set after this call.
relativeRecordSetNamestringyesThe record set name RELATIVE to the zone, e.g. www, or @ for the zone apex.
resourceGroupNamestringyesThe resource group the zone lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
ttlintegeryesTime to live in SECONDS. This is how long the whole internet keeps the answer after you change it — use 300 or less while a change is in flight, and raise it once it is settled.
zoneNamestringyesThe DNS zone name WITHOUT a trailing dot, e.g. contoso.com.

[Microsoft Azure] Create a public DNS zone, or update an existing one's tags. DELIBERATELY NOT DESTRUCTIVE, and the reason is worth stating because every other write in this family is: record sets are separate child resources and survive a zone-level write, so this call cannot empty a zone and is safe to run before you know whether the zone already exists. Two things to know anyway. It is a create-or-UPDATE and tags are REPLACED wholesale rather than merged, so send the full set — and omitting tagsJson entirely CLEARS the zone's existing tags rather than leaving them alone. And a new zone changes nothing on its own — Azure assigns it a fresh set of name servers, and the domain only resolves through Azure once the registrar's delegation points at them, which is a change made at the registrar and not here. Zones are global resources; there is no region to choose and none is accepted.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group to create the zone in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullOptional tags as a JSON object, e.g. {"owner":"networking"}. REPLACES the existing tags.
zoneNamestringyesThe DNS zone name WITHOUT a trailing dot, e.g. contoso.com.

[Microsoft Azure] Create or REPLACE a record set in a private DNS zone. DESTRUCTIVE FOR THE SAME REASON THE PUBLIC ONE IS: this is a create-or-replace and the write IS the traffic change. In a private zone the usual content is a privatelink A record pointing an application at a private endpoint's internal address, so changing it moves that application's traffic elsewhere inside the network within the TTL, with no firewall rule touched and nothing raising an alert. Where a private zone shadows a real domain name, an MX or TXT write carries the same mail-authentication hazard as on a public zone, and the PUT still replaces the ENTIRE set, so one value sent drops every other value sharing that name. Overwriting an auto-registered record is possible and pointless — the registration-enabled link rewrites it. Read azure_get_private_dns_record_set first and send back every value you are not changing. Use @ for the zone apex.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
metadataJsonstringnonullOptional metadata as a JSON object — free-text key/value pairs stored on the record set.
privateZoneNamestringyesThe private DNS zone name WITHOUT a trailing dot.
recordTypestringyesRecord type: A, AAAA, CNAME, MX, PTR, SOA, SRV or TXT. Private zones have no CAA and no NS.
recordsJsonstringyesThe records, as JSON matching the type. A: [{"ipv4Address":"10.0.1.4"}]. AAAA: [{"ipv6Address":"fd00::1"}]. CNAME: {"cname":"target.internal"}. MX: [{"preference":10,"exchange":"mail.internal"}]. PTR: [{"ptrdname":"host.internal"}]. SRV: [{"priority":1,"weight":1,"port":443,"target":"host.internal"}]. TXT: [{"value":["some text"]}]. SOA and CNAME take a single OBJECT; every other type takes an ARRAY, and the array is the complete set after this call.
relativeRecordSetNamestringyesThe record set name RELATIVE to the zone, e.g. myserver, or @ for the zone apex.
resourceGroupNamestringyesThe resource group the zone lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
ttlintegeryesTime to live in SECONDS — how long every resolver in the linked networks keeps this answer after you change it.

[Microsoft Azure] Create a private DNS zone, or update an existing one's tags. DELIBERATELY NOT DESTRUCTIVE, for the same reason as its public counterpart: record sets and virtual network links are separate child resources and survive a zone-level write, so this cannot empty a zone or unlink a network, and it is safe to run before you know whether the zone exists. It is still a create-or-UPDATE whose tags are REPLACED wholesale rather than merged, and omitting tagsJson CLEARS the zone's existing tags rather than leaving them alone. A new private zone resolves for nobody until azure_create_private_dns_virtual_network_link attaches at least one virtual network — which is the step people forget, and the reason a freshly created privatelink zone appears to do nothing. Private zones are global resources; there is no region to choose.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
privateZoneNamestringyesThe private DNS zone name WITHOUT a trailing dot, e.g. privatelink.blob.core.windows.net.
resourceGroupNamestringyesThe resource group to create the zone in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullOptional tags as a JSON object, e.g. {"owner":"platform"}. REPLACES the existing tags.

[Microsoft Azure] Delete a record set from a public DNS zone. DESTRUCTIVE, and the damage arrives LATE: name resolution for that name stops, but resolvers keep serving the cached answer until the record's TTL expires, so the outage begins minutes to hours after this call and recovery after a fix is delayed by exactly the same amount. That gap is why a DNS deletion is so rarely blamed for the incident it caused. There is no undo and no recycle bin — read azure_get_dns_record_set first and keep the records, because an MX set, an SPF policy or a DKIM key cannot be reconstructed from memory. Note that the zone's SOA record and the apex NS record set are created with the zone and cannot be removed; Azure refuses those.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
recordTypestringyesRecord type: A, AAAA, CAA, CNAME, MX, NS, PTR, SOA, SRV or TXT.
relativeRecordSetNamestringyesThe record set name RELATIVE to the zone to DELETE, e.g. www, or @ for the zone apex.
resourceGroupNamestringyesThe resource group the zone lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
zoneNamestringyesThe DNS zone name WITHOUT a trailing dot, e.g. contoso.com.

[Microsoft Azure] Delete a public DNS zone AND every record set inside it, in one call. DESTRUCTIVE AND UNRECOVERABLE, and worse than most deletes in two ways. Azure does NOT refuse when the zone still holds records — the documented behaviour is that all of them are deleted with it — so there is no safety catch here and nothing to force. And re-creating the zone does not undo it: a recreated zone is assigned DIFFERENT name servers, so the domain stays dark until the registrar's delegation is changed as well, which StackJack cannot do and a registrar may take hours to publish. Everything the domain does — its website, its mail, its authentication endpoints — stops resolving as caches expire, so the damage lands after the call rather than during it. Read azure_get_dns_zone and azure_list_dns_record_sets first and KEEP the output: that listing is the only copy of the zone anyone will have.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the zone lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
zoneNamestringyesThe DNS zone name to DELETE, with every record set it contains.

[Microsoft Azure] Delete a record set from a private DNS zone. DESTRUCTIVE with the same delayed arrival as the public side: resolvers inside every linked virtual network keep serving the cached answer until the ttl expires, so the failure appears minutes to hours after this call rather than during it. Deleting a privatelink record is the sharp case — the name usually falls back to the service's PUBLIC address, so instead of failing outright the application quietly starts leaving the virtual network, which is a data-path change nobody is alerted to. An auto-registered record (isAutoRegistered true) is different: its registration-enabled link recreates it, so deleting one does not achieve what it appears to. The zone's SOA record is created with the zone and cannot be deleted. Read azure_get_private_dns_record_set first and keep the records.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
privateZoneNamestringyesThe private DNS zone name WITHOUT a trailing dot.
recordTypestringyesRecord type: A, AAAA, CNAME, MX, PTR, SOA, SRV or TXT. Private zones have no CAA and no NS.
relativeRecordSetNamestringyesThe record set name RELATIVE to the zone to DELETE, or @ for the zone apex.
resourceGroupNamestringyesThe resource group the zone lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a private DNS zone and every record set inside it. DESTRUCTIVE AND UNRECOVERABLE. Azure applies ONE safety catch here that the public side does not have: the zone cannot be deleted while any virtual network link remains, so this call fails until every link is removed — and removing them is itself the outage, because each removal stops the linked network resolving these names. There is no force parameter and none is wanted; that refusal is the last thing standing between an agent and a resolution failure across every linked network. Private zones commonly hold the privatelink records that keep storage, SQL and Key Vault traffic inside the virtual network, so deleting one can push an application back out to the public endpoint — or leave it resolving nothing at all — and the failures start only once cached answers expire. Read azure_get_private_dns_zone and azure_list_private_dns_record_sets first and keep the output.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
privateZoneNamestringyesThe private DNS zone name to DELETE, with every record set it contains.
resourceGroupNamestringyesThe resource group the zone lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one record set by type and name, with its records, TTL, fqdn, metadata and etag. READ THIS BEFORE EVERY WRITE. azure_create_dns_record_set is a PUT that replaces the WHOLE set, so anything not sent back is gone — and the case that bites is a TXT name holding both an SPF policy and a domain-verification token, where sending only the value you meant to change deletes the other and breaks mail authentication or a service's ownership proof. Use @ as the record set name for the zone apex, meaning the domain itself: that is where the SOA, the apex A record and the domain's MX records normally live.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
recordTypestringyesRecord type: A, AAAA, CAA, CNAME, MX, NS, PTR, SOA, SRV or TXT.
relativeRecordSetNamestringyesThe record set name RELATIVE to the zone, e.g. www, or @ for the zone apex.
resourceGroupNamestringyesThe resource group the zone lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
zoneNamestringyesThe DNS zone name WITHOUT a trailing dot, e.g. contoso.com.

[Microsoft Azure] Get one public DNS zone: its nameServers, numberOfRecordSets, maxNumberOfRecordSets, tags and etag. Read this before deleting a zone or repointing a domain. nameServers is assigned when the zone is CREATED, so a zone that is deleted and recreated gets a DIFFERENT set — which is why deleting a zone is not something a later create can undo, and why the registrar has to be changed too. numberOfRecordSets is the blast radius of azure_delete_dns_zone: every one of those record sets goes with the zone in the same call.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the zone lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
zoneNamestringyesThe DNS zone name WITHOUT a trailing dot, e.g. contoso.com.

[Microsoft Azure] Get one record set from a private DNS zone by type and name, with its records, ttl, fqdn, isAutoRegistered flag and etag. The same replace-before-you-write warning applies as on the public side, because azure_create_private_dns_record_set is a PUT over the whole set. Inside a private zone the usual content is the A record for a private endpoint, and repointing it sends an application's traffic somewhere else INSIDE the network with no firewall rule changed and no alert raised — a redirection that leaves no trace outside this record. Use @ for the zone apex.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
privateZoneNamestringyesThe private DNS zone name WITHOUT a trailing dot.
recordTypestringyesRecord type: A, AAAA, CNAME, MX, PTR, SOA, SRV or TXT. Private zones have no CAA and no NS.
relativeRecordSetNamestringyesThe record set name RELATIVE to the zone, e.g. myserver, or @ for the zone apex.
resourceGroupNamestringyesThe resource group the zone lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one private DNS zone with its record-set and virtual-network-link counts, tags, provisioningState and etag. Read it before deleting: unlike a public zone, a private zone CANNOT be deleted while any virtual network link still exists, so numberOfVirtualNetworkLinks tells you how many calls to azure_delete_private_dns_virtual_network_link stand between here and the delete — and every one of those removals is itself a resolution outage for the network it unlinks, which makes the count a measure of blast radius rather than of effort.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
privateZoneNamestringyesThe private DNS zone name WITHOUT a trailing dot, e.g. privatelink.blob.core.windows.net.
resourceGroupNamestringyesThe resource group the zone lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the record sets in a public DNS zone — every type at once, or a single type when recordType is given. THIS IS THE CUSTOMER'S ACTUAL NAME RESOLUTION: where the website points (A and CNAME), where mail is delivered (MX), which senders are authorised and which domain-ownership proofs are published (both live inside TXT, as SPF policies and verification tokens), and which certificate authorities may issue for the domain (CAA). Read the TTL on each set before changing anything — it is how long resolvers keep serving the OLD answer after an edit, so a TTL of 3600 means a change made now is still invisible to part of the internet an hour later, in both directions. Use nameSuffix to narrow a large zone to one subtree instead of paging through it. Up to 1000 record sets per call.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum record sets to return (1-1000, default 1000).
nameSuffixstringnonullOptional name suffix filter — returns only record sets whose name ends with .<suffix>.
recordTypestringnonullOptional record type to list only that type: A, AAAA, CAA, CNAME, MX, NS, PTR, SOA, SRV or TXT. Omit for every type in the zone.
resourceGroupNamestringyesThe resource group the zone lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
zoneNamestringyesThe DNS zone name WITHOUT a trailing dot, e.g. contoso.com.

[Microsoft Azure] List the PUBLIC DNS zones in a subscription, or in one resource group when resourceGroupName is given. Each zone carries id, name, tags, numberOfRecordSets and — the field worth reading first — nameServers, the Azure name servers the domain's registrar must be delegated to. A zone can exist in Azure, look perfectly healthy, and serve nothing at all because the registrar still points somewhere else; comparing these nameServers against the domain's real delegation is the only way to tell a live zone from an abandoned one, and nothing in the Azure portal does it for you. Private DNS is a DIFFERENT resource type and does not appear here — use azure_list_private_dns_zones. Returns ARM's {"value":[...]} envelope; up to 1000 zones per call.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum zones to return (1-1000, default 1000).
resourceGroupNamestringnonullOptional resource group to scope to. Omit to list every public zone in the subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the record sets in a private DNS zone — every type at once, or one type when recordType is given. Private zones support A, AAAA, CNAME, MX, PTR, SOA, SRV and TXT ONLY: there is no CAA and no NS record set, because a private zone is never delegated and never authorises a certificate authority. Read isAutoRegistered on each set — true means the record was written automatically for a virtual machine by a registration-enabled network link, and it will simply be recreated after any manual deletion while that machine exists, which is worth knowing before treating one as a stale entry. Use nameSuffix to narrow a large zone. Up to 1000 record sets per call.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum record sets to return (1-1000, default 1000).
nameSuffixstringnonullOptional name suffix filter — returns only record sets whose name ends with .<suffix>.
privateZoneNamestringyesThe private DNS zone name WITHOUT a trailing dot.
recordTypestringnonullOptional record type to list only that type: A, AAAA, CNAME, MX, PTR, SOA, SRV or TXT. Omit for every type in the zone.
resourceGroupNamestringyesThe resource group the zone lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the PRIVATE DNS zones in a subscription, or in one resource group when resourceGroupName is given. A private zone is a different resource type from a public one and resolves only inside the virtual networks linked to it, which makes numberOfVirtualNetworkLinks the field to read first: a private zone with zero links resolves for nobody, and that is the usual explanation for a private endpoint an application cannot reach. numberOfRecordSets and numberOfVirtualNetworkLinksWithRegistration are the other two that matter — auto-registration writes VM records into the zone on its own, so a zone routinely holds records nobody created by hand. Private zones are also where the privatelink names live that keep storage, SQL and Key Vault traffic inside the network. Up to 1000 zones per call.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum zones to return (1-1000, default 1000).
resourceGroupNamestringnonullOptional resource group to scope to. Omit to list every private zone in the subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

Key Vault

ToolPlanAccessSummary
azure_check_key_vault_name_availabilityFreeRead-onlyCheck whether a key vault name is valid and still free.
azure_create_key_vaultProDestructiveCreate a key vault.
azure_delete_key_vaultProDestructiveDelete a key vault.
azure_get_deleted_key_vaultFreeRead-onlyGet one soft-deleted key vault: the resource id it had, its deletionDate, its scheduledPurgeDate, its tags and whether purgeProtectionEnabled was set.
azure_get_key_vaultFreeRead-onlyGet one key vault in full: SKU, the Entra tenant it authenticates against, enableRbacAuthorization, enableSoftDelete, softDeleteRetentionInDays, enablePurgeProtection, publicNetworkAccess, the…
azure_get_key_vault_key_metadataFreeRead-onlyGet one key's PROPERTIES: type, size or curve, permitted operations, whether it is enabled, its not-before and expiry dates, whether it is marked exportable, and its rotation policy with the lifetime…
azure_get_key_vault_secret_metadataFreeRead-onlyGet one secret's PROPERTIES: contentType, whether it is enabled, its not-before and expiry dates, its tags and its identifier URI.
azure_list_deleted_key_vaultsFreeRead-onlyList the soft-deleted key vaults in a subscription, each with the location it lived in, its deletionDate, its scheduledPurgeDate and whether purge protection was on.
azure_list_key_vault_keysFreeRead-onlyList the keys in a vault by NAME and PROPERTIES — key type (RSA, EC, and the -HSM variants), key size or curve, the permitted keyOps, attributes.enabled, attributes.exp and attributes.nbf, the…
azure_list_key_vault_secretsFreeRead-onlyList the secrets in a vault by NAME and PROPERTIES — contentType, attributes.enabled, attributes.exp, attributes.nbf, tags and the secret's identifier URI.
azure_list_key_vaultsFreeRead-onlyList the key vaults in a subscription, or in one resource group, each with its location, SKU, tags and full properties.
azure_purge_deleted_key_vaultProDestructivePermanently destroy a soft-deleted key vault.
azure_set_key_vault_secret_enabledProDestructiveEnable or disable one secret, by setting its enabled flag and nothing else.
azure_update_key_vault_access_policyProDestructiveAdd, replace or remove a legacy access-policy entry on a key vault.
azure_update_key_vault_network_rulesProDestructiveReplace a key vault's firewall rules — the default action, the trusted-services bypass, the allowed IP ranges and the allowed virtual network subnets — and optionally its public network access.
azure_update_key_vault_tagsProWriteSet the tags on a key vault.

[Microsoft Azure] Check whether a key vault name is valid and still free. Vault names live in a GLOBAL DNS namespace, not a per-subscription one, so a name can be taken by an organisation you have never heard of — and the reason field distinguishes 'AccountNameInvalid' (wrong shape: 3-24 characters, alphanumerics and hyphens, must start with a letter) from 'AlreadyExists'. The trap worth knowing: a SOFT-DELETED vault still holds its name for the whole retention period, so a name you deleted yesterday reads as taken. Run azure_list_deleted_key_vaults before concluding someone else has it — the fix there is to recover or purge your own vault, not to pick a new name.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name to check, e.g. contoso-prod-kv.

[Microsoft Azure] Create a key vault. NOT destructive on the path it is meant for — a new vault takes nothing away and starts empty — but this is ARM's create-or-UPDATE verb, so aiming it at a name that already exists in this resource group REWRITES that vault's properties and REPLACES its access policies with the empty set this tool sends. Check with azure_get_key_vault first whenever you are not certain the name is new. Two settings are effectively permanent and worth getting right now: enableRbacAuthorization decides forever-ish whether access is granted through Azure RBAC role assignments (recommended, and the default here) or through the legacy per-vault access-policy array, and enablePurgeProtection is IRREVERSIBLE once switched on — Azure does not accept turning it back off, which is the point, and means a deleted vault must then wait out its full retention. Soft delete is always on and cannot be disabled. The vault is created with NO access policies at all; grant access afterwards, with azure_create_role_assignment on an RBAC vault or azure_update_key_vault_access_policy on a legacy one.

ParamTypeRequiredDefaultDescription
enablePurgeProtectionbooleannofalsetrue to enable purge protection. IRREVERSIBLE — Azure does not accept turning it off again.
enableRbacAuthorizationbooleannotruetrue to authorize data access through Azure RBAC (recommended); false to use the legacy per-vault access-policy array.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesAzure region, e.g. eastus.
resourceGroupNamestringyesThe resource group to create the vault in.
skustringno"standard"SKU: standard, or premium for HSM-backed keys.
softDeleteRetentionInDaysintegerno90Soft-delete retention, 7-90 days. Cannot be shortened later.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullOptional tags as a JSON object, e.g. {"env":"prod","owner":"platform"}.
vaultNamestringyesThe vault name to create — 3-24 characters, letters, digits and hyphens, starting with a letter. Globally unique.
vaultTenantIdstringyesThe Entra directory (tenant) GUID the vault authenticates against — normally the customer's own directory id.

[Microsoft Azure] Delete a key vault. DESTRUCTIVE, AND RECOVERABLE ONLY FOR A WHILE. Soft delete is always on, so the vault and everything in it move to a deleted state and can be recovered for the retention period — but every application using it breaks the moment this returns, because a soft-deleted vault answers nothing. Then the two-part question that decides whether this is reversible: if purge protection is OFF, anyone with rights can follow this with a purge and the secrets are gone permanently; if it is ON, no purge is possible and the vault survives until its scheduled date whatever anyone wants. Read enablePurgeProtection and softDeleteRetentionInDays with azure_get_key_vault BEFORE deleting, and list the secrets and keys first — the names alone tell you which systems are about to fail, and you cannot read them back afterwards. The vault also keeps its globally unique NAME for the whole retention period, so this does not free the name.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name to DELETE, from azure_list_key_vaults.

[Microsoft Azure] Get one soft-deleted key vault: the resource id it had, its deletionDate, its scheduledPurgeDate, its tags and whether purgeProtectionEnabled was set. This is the confirmation step before azure_purge_deleted_key_vault — read it, check the resource id really is the vault you mean, and note that purgeProtectionEnabled true means the purge will be REFUSED and the vault will come back on its own schedule instead. A deleted vault is addressed by LOCATION rather than by resource group, because deletion removed it from one; take the location from azure_list_deleted_key_vaults rather than guessing, since the wrong location answers 404 in a way that reads exactly like 'already purged'.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region the vault lived in, e.g. eastus. From azure_list_deleted_key_vaults — a wrong location 404s and looks like 'already purged'.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe deleted vault's name, from azure_list_deleted_key_vaults.

[Microsoft Azure] Get one key vault in full: SKU, the Entra tenant it authenticates against, enableRbacAuthorization, enableSoftDelete, softDeleteRetentionInDays, enablePurgeProtection, publicNetworkAccess, the complete networkAcls rule set, every private endpoint connection, and — when the vault is in legacy mode — the entire accessPolicies array with each identity's key, secret and certificate permissions. READ THIS BEFORE ANY WRITE IN THIS FAMILY. It is the only call that tells you which authorization mode the vault is in, which decides whether an access-policy change does anything at all; it is where you find the tenantId that an access-policy entry must match; and its accessPolicies array is the record you will want back if a policy change goes wrong. It returns properties, never the contents: no secret value, no key material, no certificate private key exists on this API.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_key_vaults.

[Microsoft Azure] Get one key's PROPERTIES: type, size or curve, permitted operations, whether it is enabled, its not-before and expiry dates, whether it is marked exportable, and its rotation policy with the lifetime actions that drive automatic rotation. The name says metadata because that is the whole contract — the private key is generated inside the vault, is not extractable through any Azure API, and is not what this returns. Read attributes.exp against the rotation policy when investigating an outage: a key that expired without a rotate action configured breaks every signature and every envelope-encrypted service using it, all at once, with errors that name the consuming service rather than the key.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
keyNamestringyesThe key name, from azure_list_key_vault_keys.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_key_vaults.

[Microsoft Azure] Get one secret's PROPERTIES: contentType, whether it is enabled, its not-before and expiry dates, its tags and its identifier URI. THE VALUE IS NOT INCLUDED AND CANNOT BE — this is the management-plane view, whose own model states the value is never returned by the service, and StackJack deliberately exposes no tool against the vault data plane that would return one. That is a design decision, not a missing feature. What this is genuinely for: confirming a secret exists under the name an application expects, reading contentType to see what shape of credential it holds, and checking expiry before assuming a running service is about to keep working. To retrieve a value, use the vault's own portal, CLI or SDK with a data-plane credential.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the vault lives in.
secretNamestringyesThe secret name, from azure_list_key_vault_secrets.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_key_vaults.

[Microsoft Azure] List the soft-deleted key vaults in a subscription, each with the location it lived in, its deletionDate, its scheduledPurgeDate and whether purge protection was on. Soft delete is on by default and cannot be turned off, so every vault anyone has ever deleted sits here until its retention window expires — which makes this two answers at once: what was recently destroyed and might need recovering, and what is still holding a name you want back. Read scheduledPurgeDate as a deadline: after it the vault and everything in it are gone permanently and nobody can retrieve them. The location on each entry is not decoration — azure_get_deleted_key_vault and azure_purge_deleted_key_vault both address a deleted vault by location, and it is the only place to get it.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum deleted vaults to return (1-1000, default 1000).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the keys in a vault by NAME and PROPERTIES — key type (RSA, EC, and the -HSM variants), key size or curve, the permitted keyOps, attributes.enabled, attributes.exp and attributes.nbf, the rotation policy, and the key's identifier URI. This is the cryptographic inventory: which keys exist, which are disabled, which expire soon, and which have no rotation policy at all. NO KEY MATERIAL IS RETURNED OR RETURNABLE — the private half of a key never leaves the vault by any API, and even the public half lives on the data plane, which this connector does not reach. Keys backing a certificate appear here too, which is why a vault often has more keys than anyone created by hand.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum keys to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_key_vaults.

[Microsoft Azure] List the secrets in a vault by NAME and PROPERTIES — contentType, attributes.enabled, attributes.exp, attributes.nbf, tags and the secret's identifier URI. NO SECRET VALUES ARE RETURNED, and none can be: Microsoft's management-plane model documents the value as never returned by the service, and the API that would return one lives on the vault data plane, which this connector never calls. What this gives you is the audit answer nobody usually has — what this application actually depends on, which entries are disabled, and which are about to expire. An expiring secret is worth acting on days early: Key Vault does not warn anyone, the value keeps working until the moment it does not, and the outage surfaces as an authentication failure in the consuming app.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum secrets to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_key_vaults.

[Microsoft Azure] List the key vaults in a subscription, or in one resource group, each with its location, SKU, tags and full properties. THE INVENTORY QUESTION FOR EVERY SECRETS AUDIT, and three properties are what you actually came for: enableRbacAuthorization says whether the vault authorizes access through Azure RBAC or through the legacy accessPolicies array (they are mutually exclusive and the answer changes which tool grants access); enablePurgeProtection says whether a deleted vault can still be destroyed permanently; and networkAcls.defaultAction says whether the vault is reachable from the whole internet. Omit resourceGroupName for the whole subscription — that is the version worth running first, because the vault nobody remembers creating is the one holding a credential nobody has rotated.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum vaults to return (1-1000, default 1000).
resourceGroupNamestringnonullOptional resource group to scope to. Omit for the whole subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Permanently destroy a soft-deleted key vault. THIS IS THE POINT OF NO RETURN IN THIS FAMILY — there is no recovery, no support case and no backup: every secret, key and certificate inside is gone, and anything that used them has to be re-issued from the upstream system that minted it, which for a third-party API key means a human logging in somewhere and generating a new one. Nothing else in this connector is as final. Azure refuses the purge outright when purge protection was enabled, which is exactly what that setting is for. Legitimate uses are narrow: freeing a globally unique vault name for reuse, and satisfying a data-deletion obligation. Read azure_get_deleted_key_vault first and confirm the resource id is the vault you mean — a deleted vault is addressed by location, and a mistyped name simply 404s while a name that resolves is destroyed with no further prompt.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region the vault lived in, from azure_list_deleted_key_vaults.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe deleted vault's name to DESTROY PERMANENTLY.

[Microsoft Azure] Enable or disable one secret, by setting its enabled flag and nothing else. DESTRUCTIVE WHEN DISABLING, and quietly so: the change takes effect immediately, every consumer that reads the secret starts failing, and nothing about the vault looks wrong — the secret is still listed, still named, still there. It is the fastest containment action for a credential you believe is compromised and the fastest way to take down a healthy application by mistake, and the two look identical from here. Re-enabling is the exact inverse and is safe. THIS TOOL WRITES ONLY THE ENABLED FLAG: it cannot set, read or alter a secret's value, because it takes no argument that could carry one — the value never appears in this connector in either direction. One vendor caveat: Microsoft describes the management-plane secret surface as intended for ARM deployments and directs value-level work to the data plane, so a vault may answer this call with an error that is the vendor's stance rather than a fault in the tool.

ParamTypeRequiredDefaultDescription
enabledbooleanyestrue to enable the secret, false to DISABLE it — every consumer starts failing immediately.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the vault lives in.
secretNamestringyesThe secret name, from azure_list_key_vault_secrets.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_key_vaults.

[Microsoft Azure] Add, replace or remove a legacy access-policy entry on a key vault. DESTRUCTIVE IN BOTH DIRECTIONS, AND THIS IS THE SHARPEST CALL IN THE FAMILY: an access policy decides who can read EVERY secret in the vault, so granting one hands an identity standing access to all of it until somebody notices, and removing one breaks every running application that authenticated through it — with a 403 that names the application rather than this change, at whatever hour that application next runs. It is azure_create_role_assignment's argument applied to a container of credentials. FIRST CHECK WHICH MODE THE VAULT IS IN: run azure_get_key_vault and read enableRbacAuthorization. When it is true the vault authorizes data access through Azure RBAC and IGNORES this array entirely — this call will succeed, change the stored policies, and grant nobody anything, which is the most common confusion in the product. Use azure_create_role_assignment with a Key Vault data role instead. operationKind add merges permissions for one identity, remove takes that identity's entry out, and replace REWRITES the whole array to contain only the entry given here — replace is how a vault loses every other grant in one call. Every entry must carry the vault's OWN tenant id, which is properties.tenantId from azure_get_key_vault.

ParamTypeRequiredDefaultDescription
certificatePermissionsstringnonullComma-separated certificate permissions, e.g. get,list. Ignored for remove.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
keyPermissionsstringnonullComma-separated key permissions, e.g. get,list,unwrapKey. Ignored for remove.
objectIdstringyesThe Entra principal OBJECT ID (a GUID) — user, group, service principal or managed identity.
operationKindstringyesadd to merge this identity's permissions, remove to delete its entry, or replace to REWRITE the whole array to this one entry.
resourceGroupNamestringyesThe resource group the vault lives in.
secretPermissionsstringnonullComma-separated secret permissions, e.g. get,list. Ignored for remove.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_key_vaults.
vaultTenantIdstringyesThe VAULT's own Entra tenant id (properties.tenantId from azure_get_key_vault). Entries must match it.

[Microsoft Azure] Replace a key vault's firewall rules — the default action, the trusted-services bypass, the allowed IP ranges and the allowed virtual network subnets — and optionally its public network access. DESTRUCTIVE IN BOTH DIRECTIONS, for the same reason a network security group rule is: it changes who can reach the vault at all. Tightening it cuts off every caller you forget to list, and the caller that breaks is usually an automation nobody has thought about in a year — with an error that says the vault is unreachable rather than that this rule did it. Loosening it exposes a container of credentials to a wider network, which is the change that never shows up in a diff anyone reads. THE RULE SET IS REPLACED, NOT MERGED: read azure_get_key_vault first and send the existing ipRules and subnets back alongside the new ones, or they are gone. Two things that catch people out — an Azure service outside the trusted list is blocked even with bypass AzureServices, and publicNetworkAccess Disabled OVERRIDES every allow rule you just wrote, leaving only private endpoints.

ParamTypeRequiredDefaultDescription
bypassstringno"AzureServices"Trusted-services bypass: AzureServices or None.
defaultActionstringyesDefault action when no rule matches: Deny (firewall on) or Allow (open to any network).
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
ipRulesstringnonullComma-separated IPv4 addresses or CIDR ranges to allow, e.g. 203.0.113.4,198.51.100.0/24. REPLACES the existing list.
publicNetworkAccessstringnonullOptional public network access: Enabled, or Disabled to allow only private endpoints — which overrides every rule above.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_key_vaults.
virtualNetworkSubnetIdsstringnonullComma-separated full ARM subnet resource ids to allow. REPLACES the existing list.

[Microsoft Azure] Set the tags on a key vault. Not destructive: tags carry no access, no network reachability and no configuration, so the worst case is a wrong label. One real caveat — this sends the object you give it as the vault's WHOLE tags property, so send the COMPLETE set rather than only the additions: read azure_get_key_vault first and include the tags you want to keep. Tags are how most organisations attribute cost and ownership, so losing an existing cost-centre tag is the one way this call causes trouble downstream, and it would not show up anywhere until a bill did.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringyesThe COMPLETE tag set as a JSON object, e.g. {"env":"prod","owner":"platform"}. Replaces the existing tags.
vaultNamestringyesThe vault name, from azure_list_key_vaults.

Backup

ToolPlanAccessSummary
azure_create_backup_policyProDestructiveCreate a backup policy, or REPLACE an existing one's schedule and retention.
azure_create_recovery_services_vaultProWriteCreate a Recovery Services vault, or update an existing one's tags and properties.
azure_delete_backup_policyProDestructiveDelete a backup policy.
azure_delete_recovery_services_vaultProDestructiveDelete a Recovery Services vault.
azure_enable_backup_protectionProDestructiveProtect an item with a backup policy — and, because ARM models both with the same call, RE-POINT an already-protected item at a DIFFERENT policy.
azure_get_backup_jobFreeRead-onlyGet one backup or restore job with its full extended info: the per-task breakdown, transferred bytes, progress percentage, the localized error string and — the field that actually resolves tickets —…
azure_get_backup_policyFreeRead-onlyGet one backup policy with its complete schedule and retention definition — daily, weekly, monthly and yearly retention durations, the instant-restore snapshot window, the timezone the schedule runs…
azure_get_backup_protected_itemFreeRead-onlyGet one protected item in full: its policy binding, protectionState, health status, last backup result and error, the source resource it backs up, the oldest and newest recovery point times, and for…
azure_get_backup_recovery_pointFreeRead-onlyGet one recovery point with everything the list response leaves out: the full disk configuration including which LUNs were included and excluded, the immutability and soft-delete state of the point…
azure_get_recovery_services_vaultFreeRead-onlyGet one Recovery Services vault in full: sku, provisioningState, redundancy configuration, cross-region restore state, encryption settings, public network access and any managed identity.
azure_list_backup_jobsFreeRead-onlyList a vault's backup, restore, configure-backup and delete-backup-data jobs, each with its operation, status, entityFriendlyName, startTime, endTime, duration and error details.
azure_list_backup_policiesFreeRead-onlyList a vault's backup policies — the schedules and retention rules every protected item is bound to — each with its backupManagementType, schedulePolicy, retentionPolicy and protectedItemsCount.
azure_list_backup_protected_itemsFreeRead-onlyList everything a vault is protecting — VMs, file shares, SQL and SAP HANA databases, on-premises servers — each with its friendlyName, protectionStatus, protectionState, lastBackupStatus,…
azure_list_backup_protection_containersFreeRead-onlyList the protection containers registered with a vault — the VMs, storage accounts, SQL-in-VM hosts, MABS/DPM servers and on-premises machines that hold the things being backed up.
azure_list_backup_recovery_pointsFreeRead-onlyList the recovery points (backup copies) held for one protected item, each with its recoveryPointTime, recoveryPointType, tier details and — for VMs — the disk configuration captured at that moment.
azure_list_backup_usage_summariesFreeRead-onlyGet a vault's usage summary — how many protected items or registered containers it holds, broken down by backup management type.
azure_list_recovery_services_vaultsFreeRead-onlyList the Recovery Services vaults in a subscription, or in one resource group, with each vault's location, sku, provisioningState, redundancy settings and any managed identity.
azure_stop_backup_protection_delete_dataProDestructiveStop backing up an item AND PERMANENTLY DESTROY EVERY RECOVERY POINT IT HAS.
azure_stop_backup_protection_retain_dataProDestructiveStop backing up an item but KEEP every recovery point it already has.
azure_trigger_backupProWriteRun an on-demand backup of a protected item right now.
azure_trigger_backup_restoreProDestructiveRestore from a recovery point.
azure_unregister_backup_containerProDestructiveUnregister a protection container from a vault — a storage account, a SQL-in-VM or SAP HANA host, or an on-premises MABS/DPM server.

[Microsoft Azure] Create a backup policy, or REPLACE an existing one's schedule and retention. DESTRUCTIVE ON UPDATE, and this is the retention lever: the policy body carries the retention durations directly, and SHORTENING any of them applies to the recovery points that already exist — points that fall outside the new retention are pruned on the next cleanup pass and cannot be recovered. Updating a policy also re-applies protection to EVERY item bound to it at once; azure_get_backup_policy reports protectedItemsCount, and that number is the blast radius. Creating a NEW policy is additive and is the safe way to change one item's schedule: create the new policy, then re-point just that item with azure_enable_backup_protection. The policyJson shape is workload-specific and must match the item type — AzureIaaSVMProtectionPolicy for VMs, AzureFileShareProtectionPolicy for file shares, AzureVmWorkloadProtectionPolicy for SQL and SAP HANA — so copy an existing policy's properties block and edit it rather than writing one from memory. Schedule and retention times must be full date-times, not times alone.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
policyJsonstringyesThe policy properties as a JSON object — backupManagementType, schedulePolicy, retentionPolicy and so on. Copy the properties block of an existing policy and edit it.
policyNamestringyesThe policy name to create or replace, e.g. contoso-daily-35day.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] Create a Recovery Services vault, or update an existing one's tags and properties. NOT destructive: this adds a container for backups and cannot delete backup data — an update PUT against an existing vault leaves every protected item and recovery point exactly where it was. Two choices made here are effectively permanent, so make them deliberately. The vault's LOCATION cannot be changed and should match the resources it will protect, because a vault can only back up resources in its own region. And the storage redundancy (locally, zone or geo redundant) can only be set while the vault has NO protected items — once the first backup lands it is fixed for the life of the vault, which is how customers end up with locally-redundant backups they believed were geo-redundant. Pass redundancy and cross-region-restore settings through propertiesJson, e.g. {"redundancySettings":{"standardTierStorageRedundancy":"GeoRedundant"}}.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesAzure region, e.g. eastus. Must match the region of the resources this vault will protect.
propertiesJsonstringnonullOptional vault properties as a JSON object, e.g. {"publicNetworkAccess":"Enabled"}. Omit for defaults.
resourceGroupNamestringyesThe resource group to create the vault in.
skuNamestringno"Standard"Vault sku: Standard, or RS0 (which sends tier Standard).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullOptional resource tags as a JSON object, e.g. {"customer":"contoso"}.
vaultNamestringyesThe vault name to create, e.g. contoso-prod-rsv.

[Microsoft Azure] Delete a backup policy. DESTRUCTIVE AND SILENT IN THE WORST WAY: a policy is the schedule, so every item still bound to it loses its schedule and simply stops being backed up — no job fails, no alert fires, and the only symptom is a lastBackupTime that gradually ages. Existing recovery points are not deleted, but nothing new is created, so the customer's recoverable window silently shrinks to nothing as old points expire. Azure will refuse to delete a policy that still has protected items in most cases, and that refusal is a feature; the answer is to move those items to another policy with azure_enable_backup_protection first, not to force the deletion through. Check protectedItemsCount with azure_get_backup_policy before calling this, and keep the policy's retention definition — recreating a policy is easy, reconstructing which retention a customer had is not.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
policyNamestringyesThe policy name to DELETE.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] Delete a Recovery Services vault. DESTRUCTIVE, AND AZURE'S OWN REFUSAL IS THE LAST SAFETY NET HERE: the delete FAILS while the vault still contains protected items, registered containers, or backup data that is only soft-deleted — so a vault that deletes successfully is one whose backups are already gone, and this call is the final step of a teardown rather than a way to perform one. Treat a failure as correct and informative, not as an obstacle to work around: the way to make this succeed is to stop protection and delete the data item by item, which is exactly the decision that deserves a human. Read azure_list_backup_protected_items and azure_list_backup_protection_containers first — if either returns anything, do not proceed without explicit instruction. Deleting the vault also removes every backup POLICY defined in it, so any documentation of the customer's retention rules disappears with it.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name to DELETE.

[Microsoft Azure] Protect an item with a backup policy — and, because ARM models both with the same call, RE-POINT an already-protected item at a DIFFERENT policy. DESTRUCTIVE FOR THAT SECOND CASE: this is the only tool in the connector that changes an existing item's policy, and moving an item from a 365-day policy to a 30-day one applies the shorter retention to the recovery points that already exist, so eleven months of backup history is pruned and cannot be recovered. On an unprotected item the call is purely additive: it schedules backups and starts costing money, nothing is lost. Check azure_get_backup_protected_item first — if it returns an item, you are changing a policy, not enabling one. The policy must match the workload: an AzureIaasVM policy cannot protect a file share. protectedItemType is the discriminator ARM keys the request on and must be exact: Microsoft.Compute/virtualMachines for Azure VMs, AzureFileShareProtectedItem for file shares, AzureVmWorkloadSQLDatabase for SQL in a VM, AzureVmWorkloadSAPHanaDatabase for SAP HANA.

ParamTypeRequiredDefaultDescription
containerNamestringyesThe protection container name, VERBATIM from azure_list_backup_protected_items or the protectable-item id.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
fabricNamestringno"Azure"The backup fabric. Always Azure for Azure workloads.
policyNamestringyesThe backup policy name to bind this item to, from azure_list_backup_policies.
protectedItemNamestringyesThe protected item name, VERBATIM — e.g. VM;iaasvmcontainerv2;my-rg;my-vm.
protectedItemTypestringyesThe ARM discriminator for the workload, e.g. Microsoft.Compute/virtualMachines or AzureFileShareProtectedItem.
resourceGroupNamestringyesThe resource group the vault lives in.
sourceResourceIdstringyesFull ARM resource id of the thing being backed up, e.g. /subscriptions/.../providers/Microsoft.Compute/virtualMachines/my-vm.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] Get one backup or restore job with its full extended info: the per-task breakdown, transferred bytes, progress percentage, the localized error string and — the field that actually resolves tickets — the recommendations list Azure attaches to each error code. That recommendation is usually the fix, and it appears nowhere in the job LIST response. Use this on any job azure_list_backup_jobs shows as Failed, and on a Restore job to see how far it has got before telling anyone it is stuck. The job name is a GUID; it is also what the trigger-backup and trigger-restore tools hand back so an operation can be followed to completion.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
jobNamestringyesThe job name (a GUID), from azure_list_backup_jobs.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] Get one backup policy with its complete schedule and retention definition — daily, weekly, monthly and yearly retention durations, the instant-restore snapshot window, the timezone the schedule runs in, and how many items are bound to it. READ THIS BEFORE CHANGING OR DELETING IT: the retention durations here are the only record of how far back this customer can recover, and the timezone is the usual explanation for a backup that appears to run at the wrong hour. instantRpRetentionRangeInDays governs the fast local snapshots (typically 1-5 days) and is separate from vault retention — an item can have a five-day instant window and a five-year vault retention, and confusing the two is how people conclude their long-term backups are missing.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
policyNamestringyesThe policy name, from azure_list_backup_policies.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] Get one protected item in full: its policy binding, protectionState, health status, last backup result and error, the source resource it backs up, the oldest and newest recovery point times, and for VMs the list of disks included in or excluded from the backup. oldestRecoveryPoint is the honest answer to 'how far back can we restore?' — it is frequently much more recent than the policy's retention promises, because retention only applies from the day the item was protected. The excluded-disk list is the other thing worth reading before an incident: a VM can be backing up successfully every night with its data disk excluded, and nothing in the job history says so. Take protectedItemName and containerName verbatim from azure_list_backup_protected_items; both contain semicolons.

ParamTypeRequiredDefaultDescription
containerNamestringyesThe protection container name, VERBATIM from the containerName field of azure_list_backup_protected_items.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
fabricNamestringno"Azure"The backup fabric. Always Azure for Azure workloads; leave as-is unless a listing says otherwise.
protectedItemNamestringyesThe protected item name, VERBATIM from the name field of azure_list_backup_protected_items.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] Get one recovery point with everything the list response leaves out: the full disk configuration including which LUNs were included and excluded, the immutability and soft-delete state of the point itself, its expiry time, and for SQL and SAP HANA the data-directory paths a restore has to map. Read this before triggering a restore from a point you did not create — the included-disk list decides what the restore can actually produce, and an immutable or already-soft-deleted point behaves differently from a normal one. SAME SENSITIVITY NOTE AS THE LIST TOOL: for an encrypted VM the response carries a keyAndSecret block with BitLocker and key-encryption-key material; it is there because an encrypted VM cannot be restored without it, and it should not be repeated back to anyone.

ParamTypeRequiredDefaultDescription
containerNamestringyesThe protection container name, VERBATIM from azure_list_backup_protected_items.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
fabricNamestringno"Azure"The backup fabric. Always Azure for Azure workloads.
protectedItemNamestringyesThe protected item name, VERBATIM from azure_list_backup_protected_items.
recoveryPointIdstringyesThe recovery point id — the name field of an entry from azure_list_backup_recovery_points.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] Get one Recovery Services vault in full: sku, provisioningState, redundancy configuration, cross-region restore state, encryption settings, public network access and any managed identity. Read this before deleting a vault or changing anything under it. Two fields are worth naming: cross-region restore, once enabled, cannot be disabled while items are protected, and it is the only thing that makes a restore possible when the primary region is down; and publicNetworkAccess set to Disabled means every backup agent reaches the vault over a private endpoint, so a vault that looks healthy here can still be failing every backup if that endpoint was removed. The vault's own properties say nothing about whether backups are SUCCEEDING — for that read azure_list_backup_jobs.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] List a vault's backup, restore, configure-backup and delete-backup-data jobs, each with its operation, status, entityFriendlyName, startTime, endTime, duration and error details. THIS IS THE DAILY BACKUP REPORT, and it is the only place a failure is visible as an event rather than as a stale timestamp. Filter is the whole tool: status eq 'Failed' finds what broke, operation eq 'Restore' shows every restore anyone has run, and startTime/endTime narrow the window — note the service expects a filter such as startTime eq '2026-08-01 00:00:00 AM' and endTime eq '2026-08-13 00:00:00 AM', and that queries wider than about 30 days are rejected rather than truncated. An operation of DeleteBackupData in this list is the audit trail of someone destroying recovery points, and it is worth checking whenever backup data is unexpectedly missing.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOptional OData filter, e.g. status eq 'Failed' and operation eq 'Backup'.
maxItemsintegerno1000Maximum jobs to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] List a vault's backup policies — the schedules and retention rules every protected item is bound to — each with its backupManagementType, schedulePolicy, retentionPolicy and protectedItemsCount. THE RETENTION RULES ARE THE CUSTOMER'S ACTUAL RECOVERY GUARANTEE, and they are almost never what the contract says: a vault full of items on the built-in DefaultPolicy is keeping 30 days of daily backups and nothing more, which fails most compliance claims and every ransomware-recovery expectation. protectedItemsCount is the blast radius of any change to that policy. Filter with backupManagementType eq 'AzureIaasVM' (or AzureStorage, AzureWorkload, MAB) to separate VM policies from file-share and SQL ones, which are different shapes entirely.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOptional OData filter, e.g. backupManagementType eq 'AzureIaasVM'.
maxItemsintegerno1000Maximum policies to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] List everything a vault is protecting — VMs, file shares, SQL and SAP HANA databases, on-premises servers — each with its friendlyName, protectionStatus, protectionState, lastBackupStatus, lastBackupTime, the policy it is bound to and its containerName. THIS IS THE BACKUP ANSWER FOR A CUSTOMER, and two fields carry it. protectionState of ProtectionStopped means someone stopped backups and the item is holding old recovery points that are quietly ageing out; lastBackupStatus of Failed with a lastBackupTime weeks old is an item that everyone believes is protected and is not. Both look identical to a healthy item in any summary that only counts protected items. Filter with backupManagementType eq 'AzureIaasVM' and itemType eq 'VM' to narrow. Copy the name and containerName fields VERBATIM — they contain semicolons and are the ids every per-item tool needs.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOptional OData filter, e.g. backupManagementType eq 'AzureIaasVM' and itemType eq 'VM'.
maxItemsintegerno1000Maximum items to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] List the protection containers registered with a vault — the VMs, storage accounts, SQL-in-VM hosts, MABS/DPM servers and on-premises machines that hold the things being backed up. A container is the registration, not the backup: it can be present and healthy while nothing inside it is protected, and it survives the deletion of every protected item under it. registrationStatus of NotRegistered or a healthStatus of Unhealthy on a workload container is the usual cause of 'SQL backups stopped working' when the vault, policy and item all look fine. This is also where you get the containerName that azure_unregister_backup_container needs. Filter with backupManagementType eq 'AzureWorkload' to see just the workload hosts.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOptional OData filter, e.g. backupManagementType eq 'AzureWorkload'.
maxItemsintegerno1000Maximum containers to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] List the recovery points (backup copies) held for one protected item, each with its recoveryPointTime, recoveryPointType, tier details and — for VMs — the disk configuration captured at that moment. THIS IS THE PROOF A RESTORE IS POSSIBLE, and nothing else in this family substitutes for it: an item can report a successful last backup and still have no usable point at the date someone needs. Read recoveryPointTierDetails before promising a fast restore — a point whose only Valid tier is ArchivedRP must be rehydrated first, which takes hours, while InstantRP points restore in minutes. The name field of each entry is the recoveryPointId the restore tool takes. NOTE FOR ENCRYPTED VMs: when isSourceVMEncrypted is true these entries carry a keyAndSecret block containing BitLocker key and key-encryption-key material for the VM as it was at backup time — treat that part of the response as sensitive and do not echo it.

ParamTypeRequiredDefaultDescription
containerNamestringyesThe protection container name, VERBATIM from azure_list_backup_protected_items.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
fabricNamestringno"Azure"The backup fabric. Always Azure for Azure workloads.
filterstringnonullOptional OData filter, e.g. startDate eq '2026-08-01 00:00:00 AM' and endDate eq '2026-08-13 00:00:00 AM'.
maxItemsintegerno1000Maximum recovery points to return (1-1000, default 1000).
protectedItemNamestringyesThe protected item name, VERBATIM from azure_list_backup_protected_items.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] Get a vault's usage summary — how many protected items or registered containers it holds, broken down by backup management type. Filter with type eq 'BackupProtectedItemCountSummary' for items or type eq 'BackupProtectionContainerCountSummary' for containers. This is the cheap roll-up for a multi-tenant review: one call per vault tells you whether a vault is genuinely in use, holds a handful of stragglers, or is empty and paying for nothing, without paging every protected item. It does NOT report protected storage volume or cost — use the Cost Management tools for spend, and note a vault with zero protected items can still be billing for soft-deleted data that has not finished purging.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
filterstringnonullOptional OData filter, e.g. type eq 'BackupProtectedItemCountSummary'.
maxItemsintegerno1000Maximum summary rows to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] List the Recovery Services vaults in a subscription, or in one resource group, with each vault's location, sku, provisioningState, redundancy settings and any managed identity. START EVERY BACKUP INVESTIGATION HERE: a vault name plus its resource group is the key every other tool in this family needs, and on an inherited environment the vault list is also the fastest read on whether backup exists at all — an MSP taking over a tenant frequently finds one vault in a region nobody uses and nothing protected in it. storageModelType / storageType tell you whether backups are geo-redundant or locally redundant, which is the difference between surviving a regional outage and not, and it cannot be changed once items are protected. Omit resourceGroupName for the whole subscription.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum vaults to return (1-1000, default 1000).
resourceGroupNamestringnonullOptional resource group to scope to. Omit for every vault in the subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Stop backing up an item AND PERMANENTLY DESTROY EVERY RECOVERY POINT IT HAS. THE SINGLE MOST DESTRUCTIVE CALL IN THIS CONNECTOR: this deletes the customer's entire backup history for that item — every daily, weekly, monthly and yearly point, however many years deep — and once purged there is no undo, no other tool that can recover it, and no trace except a DeleteBackupData entry in the job list. The loss is INVISIBLE UNTIL SOMEONE NEEDS A RESTORE, which is the worst possible moment to find out. If the vault has soft delete enabled the data sits recoverable for 14 days first; if soft delete was disabled — which teardown automation routinely does — the purge is immediate, and NO tool in this family can read that setting, so never assume the 14 days exist. THIS IS NOT THE TOOL FOR STOPPING BACKUPS: for that use azure_stop_backup_protection_retain_data, which keeps every recovery point restorable and is reversible. Use this one only on an explicit, unambiguous instruction to destroy backup data, after reading azure_list_backup_recovery_points to see exactly what is about to be lost.

ParamTypeRequiredDefaultDescription
containerNamestringyesThe protection container name, VERBATIM from azure_list_backup_protected_items.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
fabricNamestringno"Azure"The backup fabric. Always Azure for Azure workloads.
protectedItemNamestringyesThe protected item name whose backup data is to be DESTROYED, VERBATIM from azure_list_backup_protected_items.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] Stop backing up an item but KEEP every recovery point it already has. This is the RECOVERABLE half of the stop-protection pair: no new backups run, no new recovery points are created, and every existing one stays restorable — you keep paying to store them, and you can resume protection later with azure_enable_backup_protection. Destructive because it silently ends the customer's protection: the item disappears from nothing, still appears in listings, and its recoverable window shrinks day by day as existing points reach their expiry, so an item stopped and forgotten ends up with no usable backup and no failure ever recorded. This is the correct tool for decommissioning something in stages, for pausing backups during a migration, and for cutting cost on a machine that is going away. IT IS NOT azure_stop_backup_protection_delete_data — that one destroys the recovery points and cannot be undone.

ParamTypeRequiredDefaultDescription
containerNamestringyesThe protection container name, VERBATIM from azure_list_backup_protected_items.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
fabricNamestringno"Azure"The backup fabric. Always Azure for Azure workloads.
protectedItemNamestringyesThe protected item name, VERBATIM from azure_list_backup_protected_items.
protectedItemTypestringyesThe ARM discriminator for the workload, e.g. Microsoft.Compute/virtualMachines — must match the item's own protectedItemType.
resourceGroupNamestringyesThe resource group the vault lives in.
sourceResourceIdstringyesFull ARM resource id of the thing being backed up, from the item's sourceResourceId.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] Run an on-demand backup of a protected item right now. NOT DESTRUCTIVE, and that ruling is deliberate: an ad-hoc backup only ADDS a recovery point. It changes nothing about the live resource, deletes no existing point, and does not alter the schedule — the scheduled backups continue exactly as before. What it does cost is storage, and on a busy VM it briefly adds I/O load, so it is a change worth announcing but not one worth blocking. This is the right call before any risky maintenance: patch a server, migrate a database, or run an upgrade AFTER taking a point you know is good. The on-demand point's retention is independent of the policy — set recoveryPointExpiryTimeUtc to keep it for a specific window, or omit it to inherit the policy's default. objectType must match the workload, and backupType (Full, Differential, Log, CopyOnlyFull) applies ONLY to AzureWorkloadBackupRequest.

ParamTypeRequiredDefaultDescription
backupTypestringnonullFull, Differential, Log or CopyOnlyFull. Valid ONLY with AzureWorkloadBackupRequest.
containerNamestringyesThe protection container name, VERBATIM from azure_list_backup_protected_items.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
fabricNamestringno"Azure"The backup fabric. Always Azure for Azure workloads.
objectTypestringno"IaasVMBackupRequest"Request type: IaasVMBackupRequest for Azure VMs, AzureFileShareBackupRequest for file shares, AzureWorkloadBackupRequest for SQL or SAP HANA in a VM.
protectedItemNamestringyesThe protected item name, VERBATIM from azure_list_backup_protected_items.
recoveryPointExpiryTimeUtcstringnonullOptional UTC expiry for this on-demand recovery point, e.g. 2026-09-30T00:00:00Z. Omit to use the policy's retention.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] Restore from a recovery point. DESTRUCTIVE BECAUSE A RESTORE OVERWRITES THE PRESENT WITH THE PAST, and which present depends entirely on the recoveryType inside the request: OriginalLocation REPLACES the running VM's disks with the backed-up ones, discarding everything written since that point was taken — that is a data-loss operation aimed at live production, and it is the option people reach for under pressure. RestoreDisks writes disks into a staging storage account and touches nothing live; AlternateLocation builds a new VM alongside the original. Prefer those two unless replacing production is explicitly what was asked for. Read azure_get_backup_recovery_point first: its included-disk list decides what the restore can produce, and an archived point must be rehydrated (hours) before it will restore at all. The restore body is workload-specific and large, so it is passed through verbatim — for a VM it needs objectType IaasVMRestoreRequest plus recoveryPointId, recoveryType, sourceResourceId and the target (storageAccountId, targetResourceGroupId, region). The response is a job reference, not a finished restore: follow it with azure_get_backup_job.

ParamTypeRequiredDefaultDescription
containerNamestringyesThe protection container name, VERBATIM from azure_list_backup_protected_items.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
fabricNamestringno"Azure"The backup fabric. Always Azure for Azure workloads.
protectedItemNamestringyesThe protected item name, VERBATIM from azure_list_backup_protected_items.
recoveryPointIdstringyesThe recovery point id to restore from — the name field of an entry from azure_list_backup_recovery_points.
resourceGroupNamestringyesThe resource group the vault lives in.
restoreRequestJsonstringyesThe restore request as a JSON object: objectType, recoveryPointId, recoveryType and the target. Read the recoveryType warning in this tool's description before choosing one.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

[Microsoft Azure] Unregister a protection container from a vault — a storage account, a SQL-in-VM or SAP HANA host, or an on-premises MABS/DPM server. DESTRUCTIVE: unregistering severs the vault's relationship with that host, and everything it was protecting stops being backed up. For a workload host this also drops the backup extension's registration, so re-protecting those databases later means re-registering the container and re-discovering every database rather than flipping a switch back. Azure requires every protected item under the container to be removed first, which means someone has already decided what happened to their backup data — check azure_list_backup_protected_items for anything still under this container before calling. This is a teardown step for a decommissioned host, not a way to clear a registration error; a container showing an unhealthy registration usually needs the agent re-registered, not removed.

ParamTypeRequiredDefaultDescription
containerNamestringyesThe container name to unregister, VERBATIM from azure_list_backup_protection_containers.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
fabricNamestringno"Azure"The backup fabric. Always Azure for Azure workloads.
resourceGroupNamestringyesThe resource group the vault lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
vaultNamestringyesThe vault name, from azure_list_recovery_services_vaults.

Automation

ToolPlanAccessSummary
azure_create_automation_accountProWriteCreate an Automation account.
azure_create_automation_scheduleProWriteCreate a schedule.
azure_delete_automation_accountProDestructiveDelete an Automation account.
azure_delete_automation_scheduleProDestructiveDelete a schedule.
azure_delete_runbookProDestructiveDelete a runbook.
azure_get_automation_accountFreeRead-onlyGet one Automation account in full: its sku, state, creation and last-modified times, encryption settings, publicNetworkAccess, disableLocalAuth and — the field that matters most before you start…
azure_get_automation_jobFreeRead-onlyGet one Automation job: its status, statusDetails, exception, the runbook it ran, the exact parameters it was given, its jobId, runOn, startedBy and the full timeline of creation, start, end and…
azure_get_automation_job_streamFreeRead-onlyGet ONE job stream record in full, including streamText — the untruncated line the runbook wrote, which azure_list_automation_job_streams only summarises.
azure_get_automation_scheduleFreeRead-onlyGet one schedule in full, including the advancedSchedule block that the list view flattens away: weekDays for a weekly recurrence, monthDays for specific dates, and monthlyOccurrences for patterns…
azure_get_runbookFreeRead-onlyGet one runbook's full definition-of-record: runbookType, state, parameters (each with its type, whether it is mandatory and its default), outputTypes, the publishContentLink the published body came…
azure_list_automation_accountsFreeRead-onlyList the Azure Automation accounts in a subscription, or in one resource group, with each account's location, sku, state and MANAGED IDENTITY.
azure_list_automation_certificatesFreeRead-onlyList the certificate assets in an Automation account, each with its thumbprint, expiryTime, isExportable, description and timestamps.
azure_list_automation_credentialsFreeRead-onlyList the credential assets in an Automation account — the username/password pairs runbooks fetch with Get-AutomationPSCredential.
azure_list_automation_job_streamsFreeRead-onlyList everything a job printed, as a timestamped stream of records each carrying a jobStreamId, a streamType and a summary.
azure_list_automation_jobsFreeRead-onlyList the jobs an Automation account has run, each with its runbook name, status, statusDetails, exception, startTime, endTime, the parameters it was given and startedBy.
azure_list_automation_schedulesFreeRead-onlyList an Automation account's schedules, each with its frequency, interval, startTime, expiryTime, timeZone, nextRun and — the field to read first — isEnabled.
azure_list_automation_variablesProDestructiveList the variable assets in an Automation account — the shared values runbooks read at run time — each with its isEncrypted flag, description, timestamps and, for an unencrypted variable, ITS VALUE IN…
azure_list_runbooksFreeRead-onlyList the runbooks in an Automation account, each with its runbookType, state, jobCount, lastModifiedTime and logging flags.
azure_publish_runbookProDestructivePublish a runbook's draft, making it the live version.
azure_set_automation_schedule_enabledProDestructiveEnable or disable a schedule.
azure_start_runbookProDestructiveStart a runbook, creating a job that executes it.
azure_stop_automation_jobProDestructiveStop a running Automation job.

[Microsoft Azure] Create an Automation account. NOT marked destructive: a new account is empty — no runbooks, no schedules, no assets — so it executes nothing and costs nothing until something is put in it. Two real consequences anyway. This is a PUT, so reusing the name of an EXISTING account replaces its sku, identity and publicNetworkAccess wholesale rather than merging them; check azure_list_automation_accounts first and pick a name that is not already there. And enabling the system-assigned identity creates a service principal that holds NO permissions until someone gives it an Azure role — which is a separate, deliberate act, and the moment it happens every runbook in this account inherits it. Free sku allows 500 job minutes per month; Basic bills per minute beyond that.

ParamTypeRequiredDefaultDescription
automationAccountNamestringyesThe account name to create. Reusing an existing name REPLACES that account's configuration.
enableSystemAssignedIdentitybooleannofalsetrue to enable a system-assigned managed identity. It holds no permissions until an Azure role is assigned to it.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
locationstringyesThe Azure region, e.g. eastus — from azure_list_locations.
resourceGroupNamestringyesThe resource group to create the account in. It must already exist.
skustringno"Free"Sku: Free (500 job minutes a month) or Basic (billed per minute).
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
tagsJsonstringnonullOptional tags as a JSON object, e.g. {"owner":"servicedesk"}.

[Microsoft Azure] Create a schedule. NOT marked destructive: a newly created schedule is linked to NO runbook, so it fires nothing — linking it is a separate act this connector does not perform. Three things ARM will reject, and each reads as a broken tool rather than a bad argument. startTime must be at least five minutes in the future, in ISO-8601 with an offset (2026-08-20T02:00:00+00:00). frequency must be one of OneTime, Minute, Hour, Day, Week or Month — "Daily" and "Weekly" are the words people reach for and both are 400s. interval is meaningless for OneTime and is omitted automatically in that case; for the others it is how many units between runs, so frequency Day with interval 7 is weekly. Set timeZone to a named zone if the customer cares about local time, because the schedule then follows their daylight-saving changes. This is a PUT: reusing an existing schedule's name REWRITES when that schedule fires, for every runbook already linked to it — check azure_list_automation_schedules first.

ParamTypeRequiredDefaultDescription
automationAccountNamestringyesThe Automation account name.
descriptionstringnonullOptional description — say what this schedule is for and who asked for it.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
expiryTimestringnonullOptional last run, ISO-8601 with offset. After this the schedule retires silently.
frequencystringyesRecurrence: OneTime, Minute, Hour, Day, Week or Month.
intervalintegerno1Units between runs — frequency Day with interval 7 is weekly. Ignored for OneTime.
resourceGroupNamestringyesThe resource group the account lives in.
scheduleNamestringyesThe schedule name to create. Reusing an existing name REWRITES that schedule's timing.
startTimestringyesFirst run, ISO-8601 with offset, at least five minutes in the future, e.g. 2026-08-20T02:00:00+00:00.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.
timeZonestringnonullOptional IANA or Windows time zone name, e.g. America/New_York. Omit for UTC.

[Microsoft Azure] Delete an Automation account. DESTRUCTIVE AND TOTAL: this removes every runbook in it — including the customer's own scripts, whose only copy is frequently here — along with every schedule, every asset, every module and the entire job history. There is no soft delete and no recycle bin for an Automation account; nothing in this connector can restore one. The second-order damage is the part people miss: any process that was being kept alive by a schedule in this account stops silently, and the first sign is usually a backup or cleanup that quietly did not run. Enumerate azure_list_runbooks and azure_list_automation_schedules first and show the caller what is inside before asking for approval.

ParamTypeRequiredDefaultDescription
automationAccountNamestringyesThe Automation account to DELETE, with every runbook, schedule, asset and job history in it.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the account lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a schedule. DESTRUCTIVE: every runbook linked to it stops being launched, immediately and without an error, and the links themselves go with the schedule — recreating one with the same name does NOT reconnect the runbooks that used to be attached, so restoring this is a two-step job and the second step is not available in this connector. Read azure_get_automation_schedule first and keep its frequency, interval, startTime, timeZone and advancedSchedule block: reconstructing "the last Friday of the month at 23:00 Eastern" from memory is exactly the detail that gets lost. If the intent is a temporary pause, azure_set_automation_schedule_enabled is reversible and keeps the links.

ParamTypeRequiredDefaultDescription
automationAccountNamestringyesThe Automation account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the account lives in.
scheduleNamestringyesThe schedule to DELETE, along with its links to every runbook it launches.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Delete a runbook. DESTRUCTIVE AND UNRECOVERABLE: the script text goes with it, and for a customer-written runbook the Automation account is very often the only place that code exists — no repository, no backup, no export. There is no soft delete. The quieter damage is what stops happening: any schedule linked to this runbook stops producing jobs, and any webhook pointing at it starts failing, both without an error anyone sees. Read azure_list_automation_schedules and the runbook's jobCount from azure_list_runbooks first — a runbook with recent jobs is in active use whatever anyone remembers about it. If the goal is to stop it running rather than to remove it, disabling its schedule is reversible and this is not.

ParamTypeRequiredDefaultDescription
automationAccountNamestringyesThe Automation account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the account lives in.
runbookNamestringyesThe runbook to DELETE. Its script text is destroyed with it and cannot be recovered here.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one Automation account in full: its sku, state, creation and last-modified times, encryption settings, publicNetworkAccess, disableLocalAuth and — the field that matters most before you start anything — its identity. THE IDENTITY IS WHO THE RUNBOOKS RUN AS. A systemAssigned identity has a principalId you can look up with the RBAC tools to see exactly what this account can do to the subscription; a userAssigned one points at a separate resource with its own role assignments. Also carries automationHybridServiceUrl, which is present when Hybrid Runbook Workers are registered — meaning some runbooks execute on the customer's OWN servers rather than in Azure, and the blast radius extends inside their network.

ParamTypeRequiredDefaultDescription
automationAccountNamestringyesThe Automation account name, from azure_list_automation_accounts.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the account lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one Automation job: its status, statusDetails, exception, the runbook it ran, the exact parameters it was given, its jobId, runOn, startedBy and the full timeline of creation, start, end and lastStatusModifiedTime. Poll this after azure_start_runbook — a start returns while the job is still New or Activating, and only this call says how it ended. The status vocabulary is larger than it looks and the differences matter: Suspended means a PowerShell Workflow runbook threw and Azure will retry it up to three times, Blocked means it is waiting on a resource, Disconnected means the Hybrid Worker running it lost contact and the work may have half happened. exception carries the terminating error; the non-terminating ones only appear in the Error stream, which is azure_list_automation_job_streams.

ParamTypeRequiredDefaultDescription
automationAccountNamestringyesThe Automation account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
jobNamestringyesThe job name, from azure_list_automation_jobs or the one you supplied to azure_start_runbook.
resourceGroupNamestringyesThe resource group the account lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get ONE job stream record in full, including streamText — the untruncated line the runbook wrote, which azure_list_automation_job_streams only summarises. This is the last step of a failure investigation: list the streams, find the Error record, then read it here for the complete message and stack. Note what this means for anything the runbook printed: a script that echoed a connection string or a token into its Output stream stored it here in plain text, and Azure keeps job streams for 30 days, so a job's output can be a credential even when nothing in this family looks like a credential tool.

ParamTypeRequiredDefaultDescription
automationAccountNamestringyesThe Automation account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
jobNamestringyesThe job name, from azure_list_automation_jobs.
jobStreamIdstringyesThe jobStreamId of the record to read, from azure_list_automation_job_streams.
resourceGroupNamestringyesThe resource group the account lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one schedule in full, including the advancedSchedule block that the list view flattens away: weekDays for a weekly recurrence, monthDays for specific dates, and monthlyOccurrences for patterns like "the last Friday". Read timeZone with startTime rather than separately — an Automation schedule stores its start in the named zone, so a schedule that looks like 02:00 runs at 02:00 LOCAL and shifts by an hour across daylight-saving changes, which is the usual explanation for a maintenance job that drifted out of its window. A monthDays entry of 31 simply does not fire in months that have no 31st; Azure treats that as normal rather than an error.

ParamTypeRequiredDefaultDescription
automationAccountNamestringyesThe Automation account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the account lives in.
scheduleNamestringyesThe schedule name, from azure_list_automation_schedules.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] Get one runbook's full definition-of-record: runbookType, state, parameters (each with its type, whether it is mandatory and its default), outputTypes, the publishContentLink the published body came from, the logVerbose/logProgress/logActivityTrace flags, and the draft block. READ THIS BEFORE azure_start_runbook — the parameters map is the only place that says what the runbook expects, and starting one without a mandatory parameter fails the job rather than the request. The draft block is the other half worth reading: draft.inEdit true means an unpublished version exists, and draft.lastModifiedTime against the runbook's own lastModifiedTime tells you how far the live body has drifted from what someone is working on. NOTE the deliberate limit — this returns the runbook's METADATA, never its script text; the content endpoint answers plain text rather than JSON and is not reachable through this connector.

ParamTypeRequiredDefaultDescription
automationAccountNamestringyesThe Automation account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
resourceGroupNamestringyesThe resource group the account lives in.
runbookNamestringyesThe runbook name, from azure_list_runbooks.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the Azure Automation accounts in a subscription, or in one resource group, with each account's location, sku, state and MANAGED IDENTITY. Start every Automation investigation here, and read the identity block rather than skipping it: an Automation account's identity is what its runbooks execute as, so an account carrying a systemAssigned or userAssigned identity can act on Azure resources with whatever roles that identity holds — frequently far more than the account's own name suggests. Omit resourceGroupName to sweep the whole subscription, which is what you want on an inherited tenancy where nobody knows how many automation accounts exist or who created them.

ParamTypeRequiredDefaultDescription
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum accounts to return (1-1000, default 1000).
resourceGroupNamestringnonullOptional resource group to scope to. Omit to list across the WHOLE subscription.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the certificate assets in an Automation account, each with its thumbprint, expiryTime, isExportable, description and timestamps. NO KEY MATERIAL IS RETURNED — ARM's certificate object has no field for the encoded certificate or its private key, only the thumbprint — which is why this is an ordinary read. READ expiryTime FIRST, because this is one of the highest-yield checks in the whole family: an expired Automation certificate does not announce itself, it just makes every runbook that authenticates with it start failing, and those failures surface as unrelated errors deep in a job's Error stream weeks after anyone changed anything. Sort by expiryTime and treat anything inside 60 days as work. isExportable true means the private key can be pulled out by anything with access to this account, which is worth flagging on a certificate that authenticates to something important.

ParamTypeRequiredDefaultDescription
automationAccountNamestringyesThe Automation account name, from azure_list_automation_accounts.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum certificate assets to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the account lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List the credential assets in an Automation account — the username/password pairs runbooks fetch with Get-AutomationPSCredential. THE PASSWORD IS NOT RETURNED AND CANNOT BE: ARM's credential object carries userName, description, creationTime and lastModifiedTime and has no password field in its schema at all, which is why this is an ordinary read rather than a credential-disclosing one. What you get is the part an MSP actually needs — WHICH accounts a customer's automation runs as, and how long ago each was last rotated. lastModifiedTime is the finding: a service account credential untouched for three years is a live password that has outlived several staff changes, and this listing is often the only inventory of them that exists. Runbooks reference these by name, so a name that appears here and nowhere in any runbook is likely abandoned.

ParamTypeRequiredDefaultDescription
automationAccountNamestringyesThe Automation account name, from azure_list_automation_accounts.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
maxItemsintegerno1000Maximum credential assets to return (1-1000, default 1000).
resourceGroupNamestringyesThe resource group the account lives in.
subscriptionIdstringyesThe subscription id, from azure_list_subscriptions.

[Microsoft Azure] List everything a job printed, as a timestamped stream of records each carrying a jobStreamId, a streamType and a summary. THIS IS HOW YOU READ A RUNBOOK'S OUTPUT through this connector, and it is better than the single blob of console text it replaces: streamType separates Output from Error, Warning, Verbose, Debug and Progress, so "the job succeeded but wrote three warnings" is visible rather than buried — filter the returned records on streamType yourself, ARM's own filter for this collection is not exposed for the same documentation reason as on azure_list_automation_jobs. summary is TRUNCATED for long records; take that record's jobStreamId to azure_get_automation_job_stream for the full text. Verbose records only exist if the runbook had logVerbose enabled BEFORE the job ran, so a quiet job is often just an unlogged one rather than one that did nothing. Azure keeps job streams for 30 days.

ParamTypeRequiredDefaultDescription
automationAccountNamestringyesThe Automation account name.
entraTenantstringnonullCustomer Entra directory to act in. Omit to use your own directory.
jobNamestringyesThe job name, from azure_list_automation_jobs.
maxItemsintegerno1000Maximum stream records to return (1-1000, default 1000).
resourceGroupNamestring