Connect Microsoft Azure
Microsoft Azure is where a great many of your customers' servers, networks, databases and bills live. Connecting it gives your AI a large set of azure_ MCP tools — MCP (Model Context Protocol) tools…
Written By Christopher Scaminaci
Last updated 6 days ago
Microsoft Azure is where a great many of your customers' servers, networks, databases and bills live. Connecting it gives your AI a large set of azure_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack — covering subscriptions, virtual machines, storage, networking, DNS, app services, Kubernetes, SQL, monitoring, cost, policy, access control and security posture.
Two things make this connector different from every other one in StackJack, and both are worth reading before you connect.
Nothing to enter, unless you bring your own app
Every other connector asks you for a key, a secret or a URL. Azure asks for none of them by default. StackJack has its own Microsoft application, so you connect by signing in with Microsoft and approving the request — that is the entire setup. (Organizations that prefer to consent to an application they own can bring their own app registration instead — the option lives under Advanced — use your own app registration on the connector card, and the Microsoft Graph connector guide describes the whole flow. Each Microsoft connector card stores its own application choice, so set it here and on Microsoft Graph if you use both.)
- Check who can approve. Many organizations require an administrator to approve a new application once, on behalf of everyone. If you are a Global Administrator you can approve it yourself as you connect. If you are not, either ask an administrator to connect first, or ask them to approve the request when Microsoft prompts for it.
- Connect with Microsoft. On the Connectors page, open Microsoft Azure and choose Connect with Microsoft. Sign in with the account you use to manage Azure and approve the request.
- Check what you can reach. Ask your AI to list your Azure subscriptions. If one you expected is missing, that is almost always a role question rather than a connection problem — see below.
Your Azure role decides everything
Azure grants StackJack exactly one thing: permission to act as you. It does not grant "read virtual machines" or "manage storage" separately, because Azure does not work that way. Instead, Azure checks your own role on every single call.
The consequences are worth stating plainly, because they surprise people who have set up other connectors:
- What this connector can do is exactly what you can do in the Azure portal. No more, and no less.
- Two people on the same team will legitimately get different answers. Someone with Reader gets reads and a clean refusal on writes. Someone with Contributor can make changes. That is Azure working correctly.
- A refusal is not a broken connection. When Azure says you are not authorized, it names the action it refused and the scope it refused it at. The fix is an Azure role assignment from an Owner or User Access Administrator — reconnecting will not help, because signing in again grants the same single permission it already had.
- StackJack's plan tiers are a separate, narrower thing. Read tools are available on Free and write tools on Pro, but that only decides which tools your AI is offered. It cannot grant Azure access you do not have.
Managing your customers' Azure
If you manage customers' Azure subscriptions through Microsoft's delegated access, your USER access comes along automatically — there is no separate connection per customer. One thing does need setting up per customer, once: admin consent for the StackJack application in that customer's tenant.
Microsoft asks two separate questions on a customer-directory call: whether YOU may act there (your delegated access), and whether the customer's tenant has admitted the APPLICATION the call comes through. Delegated roles do not answer the second — an administrator in the customer's tenant (Global Administrator, Application Administrator, or Cloud Application Administrator) must approve it once. Generate the link with Authorize a customer tenant on the Azure connector card and send it to them; until they approve, calls into that customer fail with a consent error (AADSTS65001), and reconnecting your own sign-in will not fix it. If the customer runs Conditional Access policies that block external accounts, ask their admin to exclude the specific partner accounts that need access — or the partner-user categorization the policy keys on — from the blocking policy.
Every Azure tool takes an optional customer directory (their Microsoft tenant ID or a verified domain such as contoso.onmicrosoft.com). Leave it out and the tool works on your own Azure. Provide it and the tool works on that customer's, with whatever access you already have there.
In practice you just name the customer when you ask:
- "List the subscriptions in Contoso's directory."
- "Which VMs in Contoso's production resource group are running an unsupported OS?"
- "Compare last month's Azure spend across all our customers."
That last one is worth calling out. StackJack uses Azure's own cross-subscription query service for questions that span many subscriptions, which answers in a single call instead of walking each subscription one at a time. It is both much faster and much less likely to be throttled — so prefer broad questions over asking about each customer in turn.
Every person signs in for themselves
There is no shared Azure identity for a team to fall back on. The stored connection is one person's own Microsoft sign-in, carrying their Azure roles and everything those roles reach across your customers' directories, so StackJack will not run anyone else's calls under it.
- Owners keep the fallback. The organization's owner and co-owners can use the stored connection before they personally sign in.
- Everyone else must connect their own account, including Administrators. Until they do, Azure tools refuse for them with
personal_sign_in_required. This is not a preference or an optimization — it is the only way that member gets an Azure identity at all. - Nothing has to be prepared for them. StackJack's own Microsoft application serves every organization, so a member can connect whether or not an owner ever configured the connector.
Signing in individually is also what keeps the record honest. Azure logs every action against the identity that performed it, so one shared identity would put one person's name against the whole team's work — and each person can only do what their own Azure role allows.
Members connect from the Connectors page, in their personal sign-ins section. The rules in full: Who can use which identity.
What this connector deliberately does not do
Stated up front so it does not read as a gap:
- It does not read the contents of your data. Blob contents, queue messages, database rows and Key Vault secret values are all outside this connector. It manages Azure resources — it does not open what is inside them. For Key Vault this is deliberate and worth being explicit about: StackJack can list vaults, see their access policies, and see secret names and expiry dates, but it cannot read a secret's value.
- It does not cover Azure Government or Azure China. Those are separate clouds that need their own setup.
- It has no purpose-built tools for application platform services such as Cosmos DB, Service Bus, Data Factory or Synapse. Those are your customers' application data tiers rather than the infrastructure an MSP manages. They are still reachable through the raw request tools below, with the same Azure role you already hold — there is simply no tool written for them.
- Classic (pre-Resource-Manager) resources have no tools either. They have been retired by Microsoft.
- It does not give automations access by default. An automation has no signed-in person of its own, so it cannot borrow your connection. An administrator can enrol a dedicated Microsoft sign-in for a specific automation, and it then acts with exactly that account's Azure role — enrol a purpose-made account rather than a person's, so an unattended process reaches only what it needs and the Azure activity log names the automation rather than a technician who was not at their desk.
Things that catch people out
A tool says the subscription does not exist. A subscription ID only means something inside its own directory. If it is a customer's subscription, name their directory in the request — without it, the tool looked in your own.
Large lists come back partial. StackJack caps a single call at 1,000 items across 10 pages, and tells your AI where the list left off so it can continue. This is a StackJack safety limit rather than an Azure one, and it exists to stop one question consuming an enormous response.
A long-running change returns immediately, and the answer can look empty. Deleting a resource group, resizing a cluster or restoring a database can take many minutes in Azure. The tool does not wait: Azure answers accepted, the tool hands that answer straight back, and the work continues afterwards. Read the three outcomes differently:
- Accepted — Azure took the request and is still working. The reply is often empty, because Azure returns no body with an acceptance. An empty reply here is not a failure and is not a completion.
- Completed — the reply carries the changed resource.
- Failed — the reply carries Azure's error.
Because an acceptance can come back empty, do not treat "it returned" as "it finished". Confirm the outcome with a read that suits the resource: check whether a resource group still exists, read the resource back, or read the activity log or the operation record for that resource. Ask your AI to confirm the result rather than assuming it.
Azure starts throttling. Azure limits how fast requests can arrive, and StackJack waits as long as Azure asks before retrying, within a bounded retry budget. Pacing reduces throttling; it does not remove it, and a long enough wait can end as a timeout instead. If it keeps happening, ask one broad cross-subscription question rather than many narrow ones, and check whether a write landed before you repeat it — see Retrying a failed or timed-out write.
Destructive actions
Some Azure tools remove data, interrupt running workloads, run code on a machine, or change who has access. StackJack marks those as destructive and they are all Pro-tier. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and restrict the tools you grant, before you allow destructive Azure actions.
The sharpest ones are worth knowing by name:
- Deleting a resource group deletes everything inside it — virtual machines, disks, databases, storage accounts and their contents — with no confirmation from Azure and no undo. Ask your AI to list the group's contents first.
- Storage account keys grant full access to everything in that account, and regenerating one breaks every existing application using it.
- Cluster credentials and registry credentials hand back working administrative access.
- Running a command on a virtual machine executes whatever you send, as an administrator on that machine.
- Role assignments change who can reach what, for everyone.
Marking these clearly is what lets the rest of the connector be used freely.
Advanced: raw API requests
Reach for a purpose-built tool first. They pin the Azure API version for you, escape the names you pass, cap the page size, and their descriptions say what the answer means. Use the raw tools only where no purpose-built tool exists.
Two tools send a request you compose straight to Azure Resource Manager:
azure_raw_getsends one GET. It is Free-tier and read-only.azure_raw_requestsends one POST, PUT, PATCH or DELETE. It is Pro-tier and marked destructive. It refuses GET, so a read cannot be run through the write tool.
What they change, and what they do not:
- They widen coverage, not permission. Your connector subscription, your endpoint's tool selection, your plan and your monthly allowance all still apply, and Azure still checks your own role on every call. A raw request returns exactly what your Azure role could reach anyway.
- They reach resource types no tool was written for — Cosmos DB, Service Bus, Data Factory, Synapse and anything else Azure Resource Manager publishes. That is the point of them.
- You supply the API version, and Azure is unforgiving about it. Every Azure resource provider versions independently, and a wrong version comes back as an unhelpful 400. Ask for the provider's supported versions first.
- Paging is yours to drive. A continuation link comes back in the body; pass its path back to get the next page. Nothing pages for you.
- A replacing write drops what you leave out. PUT on Azure Resource Manager replaces the whole resource, so a body assembled from a few fields silently clears every property you did not send. Read the resource first and send it back complete.
- Long-running writes are not followed for you. Azure answers accepted with a tracking address in its response headers, and StackJack returns the body rather than the headers — so the reply can be empty and nothing polls on your behalf. Confirm the outcome with a read, as described above.
- The path is fenced. It has to be rooted at a subscription, a provider or a tenant, with no scheme and no directory traversal. Anything else is refused before the request is sent.
Microsoft adding or promoting an API does not, on its own, produce a purpose-built StackJack tool for it, and it does not change what your organization has consented to. Both remain separate decisions.
See the generated Microsoft Azure tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Microsoft Azure tools
azure_ · 545 tools · Free 304 · Pro 241
Subscriptions
| Tool | What it does |
|---|---|
azure_Free · Read-only | Get one resource provider's registration state and the full resourceTypes list it exposes in a subscription, including each type's supported locations and apiVersions. |
azure_Free · Read-only | Get one Azure subscription's details: subscriptionId, displayName, state, tenantId, authorizationSource (the mechanism granting access, e.g. RoleBased or Legacy), managedByTenants (the partner directories with delegated access — how you confirm a GDAP relationship exists) and subscriptionPolicies including its quota id and spending limit. |
azure_Free · Read-only | List the Azure regions available to a subscription. |
azure_Free · Read-only | List the Azure resource providers in a subscription and their registration state. |
azure_Free · Read-only | List the Azure subscriptions the signed-in user can see — the ENTRY POINT for this connector. |
azure_Free · Read-only | List the Microsoft Entra directories (tenants) the signed-in user can access — their own plus every customer directory they hold a delegated relationship with. |
azure_Pro · Write | Register a resource provider in a subscription, making its resource types deployable there. |
azure_Pro · Destructive | Unregister a resource provider from a subscription. |
Resource Graph
| Tool | What it does |
|---|---|
azure_Free · Read-only | Get the full BEFORE and AFTER snapshots for one resource change, plus the property-level diff. |
azure_Free · Read-only | Run a KQL query and return FACET summaries — value counts for the columns you name — alongside the rows. |
azure_Free · Read-only | List configuration CHANGES to Azure resources in a time window — the "what changed and when" surface, and usually the fastest route from an incident to its cause. |
azure_Free · Read-only | Run a KQL query across many subscriptions at once — the most powerful read in this connector. |
azure_Free · Read-only | Run a KQL query that returns only a COUNT, across many subscriptions at once. |
Resource Groups
| Tool | What it does |
|---|---|
azure_Free · Read-only | Check whether a resource group exists WITHOUT retrieving it, returning {"exists": true|false}. |
azure_Pro · Write | Create a resource group, or update an existing one's tags. |
azure_Pro · Destructive | Delete a resource group AND EVERY RESOURCE INSIDE IT. |
azure_Free · Read-only | Export a resource group as an ARM template — the JSON that would recreate its resources. |
azure_Free · Read-only | Get one resource group: id, name, location, tags, managedBy and properties.provisioningState. |
azure_Free · Read-only | List every resource inside one resource group. |
azure_Free · Read-only | List the resource groups in a subscription. |
azure_Pro · Write | Update a resource group's tags via PATCH, leaving everything else alone. |
Resources & Tags
| Tool | What it does |
|---|---|
azure_Pro · Destructive | Delete any Azure resource by its full ARM resource id. |
azure_Free · Read-only | Get any Azure resource by its full ARM resource id — the /subscriptions/... |
azure_Free · Read-only | Get the tags on any Azure resource, resource group or subscription by its ARM id. |
azure_Free · Read-only | List every resource in a subscription, of any type. |
azure_Pro · Destructive | Move resources to a different resource group or subscription. |
azure_Pro · Write | REPLACE the entire tag set on any Azure resource, resource group or subscription. |
azure_Pro · Write | Merge, replace or delete tags on any Azure resource, resource group or subscription. |
azure_Pro · Write | Validate a resource move WITHOUT performing it — the safe preview for azure_move_resources. |
Virtual Machines
| Tool | What it does |
|---|---|
azure_Pro · Write | Assess which operating-system patches are available for a virtual machine. |
azure_Pro · Write | Attach one or more EXISTING managed disks to a virtual machine as data disks. |
azure_Pro · Destructive | Convert a legacy virtual machine's unmanaged (page-blob) disks to managed disks. |
azure_Pro · Write | Create a virtual machine, or replace an existing one's model wholesale. |
azure_Pro · Write | Install an extension on a virtual machine, or update one already installed. |
azure_Pro · Destructive | Deallocate a virtual machine — shut it down AND release its compute resources, which is what stops the compute bill. |
azure_Pro · Destructive | DELETE a virtual machine. |
azure_Pro · Destructive | Uninstall an extension from a virtual machine. |
azure_Pro · Destructive | Detach one or more data disks from a virtual machine. |
azure_Free · Read-only | Get one virtual machine's full model: size, OS profile, image reference, OS and data disks with their LUNs and managed-disk ids, network interface ids, boot-diagnostics settings, identity, zones and tags. |
azure_Pro · Destructive | Mint time-limited SAS URIs for a virtual machine's boot diagnostics — consoleScreenshotBlobUri (a bitmap of the console at the moment of capture) and serialConsoleLogBlobUri (the boot serial log). |
azure_Free · Read-only | Get one extension on one virtual machine by its instance name — the name the extension was DEPLOYED under, which is often not the same as its publisher type (azure_list_vm_extensions returns both). |
azure_Free · Read-only | Get a virtual machine's RUNTIME state — this is the tool that answers "is this machine on?". |
azure_Free · Read-only | Get one managed run command on a virtual machine, and with expand="instanceView" its RESULT — executionState (Running, Succeeded, Failed, TimedOut), exitCode, startTime, endTime, and the captured standard output and standard error. |
azure_Free · Read-only | Get one built-in run command document by its command id — the full definition, including the script Azure will execute and the parameters array naming every value the command expects and which of them are required. |
azure_Pro · Destructive | Install operating-system patches on a virtual machine now. |
azure_Free · Read-only | List the extensions installed on one virtual machine — the in-guest agents Azure manages, such as the Monitor agent, the Dependency agent, Custom Script, the antimalware extension and the domain-join extension. |
azure_Free · Read-only | List one publisher's image offers in a region — the second rung of the image coordinate. |
azure_Free · Read-only | List the image publishers available in one region — the first rung of the four-part image coordinate (publisher, offer, SKU, version) that azure_create_or_update_vm needs. |
azure_Free · Read-only | List the SKUs under one publisher/offer in a region — the third rung of the image coordinate, and the one that names the actual edition: 2022-datacenter-azure-edition, 22_04-lts-gen2, and so on. |
azure_Free · Read-only | List the published versions of one publisher/offer/SKU image in a region — the fourth and last rung of the image coordinate. |
azure_Free · Read-only | List the sizes THIS virtual machine can actually be resized to. |
azure_Free · Read-only | List the BUILT-IN run command documents Azure publishes for a region — the vetted scripts an agent can invoke by id instead of writing its own. |
azure_Free · Read-only | List the MANAGED run commands deployed on one virtual machine. |
azure_Free · Read-only | List every virtual machine size Azure offers in one region, with each size's numberOfCores, memoryInMB, maxDataDiskCount, osDiskSizeInMB and resourceDiskSizeInMB. |
azure_Free · Read-only | List every virtual machine in a subscription, across all resource groups. |
azure_Free · Read-only | List the virtual machines inside one resource group. |
azure_Pro · Destructive | Trigger Azure's pending host maintenance on a virtual machine NOW, instead of waiting for the platform's self-service window to close and the maintenance to be applied automatically. |
azure_Pro · Destructive | Power off (stop) a virtual machine, leaving it ALLOCATED. |
azure_Pro · Destructive | Reapply a virtual machine's ARM model to the platform — Azure re-pushes the stored configuration to the machine's host. |
azure_Pro · Destructive | Redeploy a virtual machine — shut it down, MOVE it to a new Azure host, and power it back on. |
azure_Pro · Destructive | Reimage a virtual machine — reset its OS disk back to the original image. |
azure_Pro · Destructive | Restart a virtual machine. |
azure_Pro · Destructive | Run a command INSIDE a customer's virtual machine, through the Azure guest agent. |
azure_Pro · Write | Set the tags on a virtual machine, leaving every other property untouched. |
azure_Pro · Destructive | Simulate the eviction of a SPOT virtual machine, so an owner can test that their workload survives being evicted. |
azure_Pro · Write | Start (power on) a stopped or deallocated virtual machine. |
azure_Pro · Write | Update an existing virtual machine with a PATCH — the tool to use for a resize, a boot-diagnostics change, an identity change or a licence-type change. |
Storage
| Tool | What it does |
|---|---|
azure_Free · Read-only | Check whether a storage account name is free BEFORE trying to create it. |
azure_Pro · Write | Create a blob container in a storage account. |
azure_Pro · Write | Create an Azure Files share in a storage account. |
azure_Pro · Write | Create a new storage account. |
azure_Pro · Write | Create a Storage queue in an account. |
azure_Pro · Write | Create a Storage table in an account. |
azure_Pro · Destructive | Delete a blob container AND EVERY BLOB INSIDE IT. |
azure_Pro · Destructive | Delete an Azure Files share AND EVERY FILE AND FOLDER INSIDE IT. |
azure_Pro · Destructive | Delete a storage account AND EVERYTHING INSIDE IT. |
azure_Pro · Destructive | Delete a Storage queue AND EVERY MESSAGE STILL IN IT. |
azure_Pro · Destructive | Delete a Storage table AND EVERY ROW IN IT. |
azure_Free · Read-only | Get one blob container's ARM properties: publicAccess (None, Blob or Container — anything other than None means anonymous internet reads are possible), metadata, leaseStatus/leaseState/leaseDuration, hasImmutabilityPolicy, hasLegalHold, immutableStorageWithVersioning, lastModifiedTime and etag. |
azure_Free · Read-only | Get the account-wide Blob service settings: deleteRetentionPolicy (blob soft delete and its retention in days), containerDeleteRetentionPolicy (container soft delete — this is what decides whether azure_delete_blob_container is recoverable), isVersioningEnabled, changeFeed, restorePolicy (point-in-time restore), cors and defaultServiceVersion. |
azure_Free · Read-only | Get the account-wide Azure Files settings: shareDeleteRetentionPolicy (share soft delete and its retention in days — this decides whether azure_delete_file_share is recoverable), protocolSettings.smb (the SMB versions, authentication methods, kerberos ticket encryption and channel encryption the account will accept) and cors. |
azure_Free · Read-only | Get one Azure Files share's ARM properties: shareQuota (provisioned GiB), accessTier, enabledProtocols, rootSquash, leaseStatus, metadata, lastModifiedTime and etag. |
azure_Free · Read-only | Get one storage account's full configuration: kind, sku, location, tags, accessTier, primaryEndpoints, encryption, minimumTlsVersion, allowBlobPublicAccess, allowSharedKeyAccess, publicNetworkAccess and the networkAcls firewall rules. |
azure_Free · Read-only | Get the account's lifecycle management policy — the rule set that automatically tiers blobs to Cool or Archive and DELETES them after an age threshold. |
azure_Pro · Destructive | Acquire, renew, change, release or break a LEASE on a blob container. |
azure_Free · Read-only | List the blob containers in a storage account, as ARM resources. |
azure_Free · Read-only | List the Azure Files shares in a storage account, as ARM resources. |
azure_Pro · Destructive | Return the storage account's ROOT ACCESS KEYS in plain text. |
azure_Free · Read-only | Report how many storage accounts the subscription has used against its per-region quota, as {value:[{unit, currentValue, limit, name:{value, localizedValue}}]}. |
azure_Free · Read-only | List every storage account in a subscription. |
azure_Free · Read-only | List the storage accounts inside ONE resource group, with the same fields as azure_list_storage_accounts. |
azure_Free · Read-only | List the Storage queues in an account. |
azure_Free · Read-only | List the storage SKUs the subscription may deploy: each item carries name (Standard_LRS, Standard_GRS, Standard_ZRS, Premium_LRS, ...), tier, kind, the locations it is offered in, and a restrictions array explaining any region or quota block. |
azure_Free · Read-only | List the Storage tables in an account. |
azure_Pro · Destructive | Regenerate one of the storage account's root access keys. |
azure_Pro · Destructive | Revoke ALL of the account's user delegation keys, invalidating every Microsoft Entra-signed shared access signature issued against it. |
azure_Pro · Write | Set the account-wide Blob service settings — soft delete, container soft delete, versioning, change feed, point-in-time restore and CORS. |
azure_Pro · Write | Set the account-wide Azure Files settings — share soft delete and its retention, the SMB protocol settings (accepted versions, authentication methods, kerberos ticket encryption, channel encryption) and CORS. |
azure_Pro · Write | Replace the storage account's firewall (networkAcls) via PATCH. |
azure_Pro · Write | Set the account's lifecycle management policy — the rules that automatically tier blobs to Cool or Archive and delete them past an age threshold. |
azure_Pro · Write | Update an existing blob container's anonymous-access level or metadata via PATCH. |
azure_Pro · Write | Update an existing Azure Files share's quota, access tier or metadata via PATCH. |
azure_Pro · Write | Update an existing storage account's SKU, tags or settings via PATCH. |
Networking
| Tool | What it does |
|---|---|
azure_Free · Read-only | Check whether a specific private IP address is free in a virtual network, and get suggested alternatives when it is not. |
azure_Pro · Write | Create an empty network security group, or update its tags. |
azure_Pro · Destructive | Create or replace a security rule in a network security group. |
azure_Pro · Write | Create a public IP address resource, or replace an existing one's definition. |
azure_Pro · Destructive | Create or replace a route in a route table. |
azure_Pro · Write | Create an empty route table, or update its tags and BGP setting. |
azure_Pro · Write | Create a subnet in a virtual network, or replace an existing one. |
azure_Pro · Write | Create a virtual network, or replace an existing one's definition. |
azure_Pro · Write | Create a peering from this virtual network to another. |
azure_Pro · Destructive | Delete a network interface. |
azure_Pro · Destructive | Delete a network security group and every rule in it. |
azure_Pro · Destructive | Delete a security rule from a network security group. |
azure_Pro · Destructive | Delete a public IP address resource. |
azure_Pro · Destructive | Delete a route from a route table. |
azure_Pro · Destructive | Delete a subnet from a virtual network. |
azure_Pro · Destructive | Delete a virtual network and every subnet inside it. |
azure_Pro · Destructive | Delete a peering. |
azure_Free · Read-only | Get one application gateway in full, including every listener, rule, backend setting, probe, rewrite rule set and certificate's metadata. |
azure_Free · Read-only | Ask an application gateway how it currently sees each of its backend servers: per pool and per HTTP setting, every server's address with a health status of Healthy, Unhealthy, Partial, Draining or Unknown, and for an unhealthy one the reason — a failed probe, a certificate the gateway does not trust, or a connection refused. |
azure_Free · Read-only | Get one Azure Firewall in full, including every inline rule collection with its priority and action, the private IP the firewall answers on, and its provisioning state. |
azure_Free · Read-only | Get one load balancer in full: frontends, backend pools, rules, health probes, NAT rules and outbound rules. |
azure_Free · Read-only | Get one network interface in full: every IP configuration with its private address and allocation method, the subnet and public IP resource ids, the NSG attached to the NIC itself, applied DNS servers, accelerated networking and IP forwarding flags, and the VM it belongs to. |
azure_Free · Read-only | Get one network security group with every rule and every attachment. |
azure_Free · Read-only | Get one security rule by name. |
azure_Free · Read-only | Get one public IP address resource: its SKU and tier, allocation method, the assigned ipAddress, idleTimeoutInMinutes, DNS label and FQDN, availability zones, and the ipConfiguration it is attached to. |
azure_Free · Read-only | Get one route table with its full routes array and the list of subnets it is attached to. |
azure_Free · Read-only | Get one subnet: its address prefix, attached network security group and route table, service endpoints, delegations and private-endpoint policies. |
azure_Free · Read-only | Get one virtual network in full: address space, every subnet with its prefix, attached network security group, route table, service endpoints and delegations, plus peerings, DNS servers and DDoS settings. |
azure_Free · Read-only | Get one virtual network gateway in full: type, SKU and generation, active-active state, BGP settings including the ASN and the peering addresses, the gateway subnet's IP configurations, and any point-to-site VPN client configuration. |
azure_Free · Read-only | Get one peering by name, including its peeringState and the four traffic flags. |
azure_Free · Read-only | List every application gateway in a subscription: its sku and capacity or autoscale range, operationalState, frontend IP and port configurations, HTTP listeners, backend pools and settings, request routing rules, SSL certificates (metadata only — never the private key), and the webApplicationFirewallConfiguration when WAF is enabled. |
azure_Free · Read-only | List every Azure Firewall in a subscription: its sku tier (Standard, Premium or Basic), threatIntelMode, the firewallPolicy it draws rules from when policy-managed, its ipConfigurations and hubIPAddresses, and — on older firewalls that still hold rules inline — the applicationRuleCollections, networkRuleCollections and natRuleCollections. |
azure_Free · Read-only | List every Azure Bastion host in a subscription, with its sku, scaleUnits, the AzureBastionSubnet and public IP it uses, and the feature flags — enableTunneling, enableIpConnect, enableShareableLink and disableCopyPaste. |
azure_Free · Read-only | List every ExpressRoute circuit in a subscription, with its serviceProviderProperties (the carrier, peering location and bandwidth), the sku tier and family, and — the two fields to read first — circuitProvisioningState and serviceProviderProvisioningState. |
azure_Free · Read-only | List a load balancer's backend address pools with their full membership — every NIC ip configuration or explicit IP address in each pool. |
azure_Free · Read-only | List every load balancer in a subscription with its sku (Basic or Standard), frontendIPConfigurations (the addresses it answers on, public or private), backendAddressPools, loadBalancingRules, probes, inboundNatRules and outboundRules. |
azure_Free · Read-only | List every network interface (NIC) in a subscription. |
azure_Free · Read-only | List the network interfaces inside one resource group. |
azure_Free · Read-only | List every network security group in a subscription. |
azure_Free · Read-only | List the network security groups inside one resource group. |
azure_Free · Read-only | List the Network Watcher resources in a subscription. |
azure_Free · Read-only | Show the security rules that are ACTUALLY in force on one network interface — Azure's own evaluation of the NIC's NSG combined with the subnet's NSG, in priority order, including the built-in default rules that are invisible in azure_list_nsg_rules. |
azure_Free · Read-only | Show the routing table that is ACTUALLY in force on one network interface: Azure's system routes, routes learned over BGP from a VPN or ExpressRoute gateway, and any user-defined routes from an attached route table, each with its source, address prefix, next hop type and next hop address. |
azure_Free · Read-only | List the ADMIN-DEFINED security rules in a network security group. |
azure_Free · Read-only | List every public IP address resource in a subscription, with its sku (Basic or Standard), publicIPAllocationMethod (Static or Dynamic), the ipAddress currently assigned, the dnsSettings FQDN if one is configured, and ipConfiguration.id naming what the address is attached to. |
azure_Free · Read-only | List every route table in a subscription, each with its routes array (address prefix, next hop type, next hop IP), the subnets it is attached to, and disableBgpRoutePropagation. |
azure_Free · Read-only | List the individual routes in one route table, each with addressPrefix, nextHopType and, for a virtual-appliance hop, nextHopIpAddress. |
azure_Free · Read-only | List the subnets in a virtual network. |
azure_Free · Read-only | List the virtual network gateways in one resource group — the VPN and ExpressRoute gateways that connect a virtual network to on-premises or to other networks. |
azure_Free · Read-only | Report how many private IP addresses each subnet in a virtual network has consumed, with currentValue and limit per subnet. |
azure_Free · Read-only | List every virtual network in a subscription, across all resource groups. |
azure_Free · Read-only | List the virtual networks inside one resource group. |
azure_Free · Read-only | List the peerings on a virtual network — the links that let two networks route to each other directly. |
azure_Free · Read-only | List the gateway connections in one resource group — the site-to-site VPN tunnels, VNet-to-VNet links and ExpressRoute circuit connections. |
azure_Free · Read-only | Actually TEST reachability from a virtual machine to another Azure resource or to any address and port, and get the full hop-by-hop path back with latency and, at each hop, what allowed or blocked the traffic. |
azure_Free · Read-only | Ask Azure whether a specific packet would be allowed or denied to a specific virtual machine, and WHICH security rule decides it. |
azure_Free · Read-only | Ask Azure where traffic from a virtual machine to a given destination address would actually go NEXT, and which route decides it. |
azure_Pro · Write | Start a stopped application gateway. |
azure_Pro · Destructive | Stop an application gateway. |
azure_Pro · Write | Update a network security group's tags via PATCH, leaving every rule and attachment untouched. |
azure_Pro · Write | Update a virtual network's tags via PATCH, leaving its address space, subnets and peerings untouched. |
Cost Management
| Tool | What it does |
|---|---|
azure_Pro · Write | Create a spend budget, or update an existing one. |
azure_Pro · Write | Create a scheduled cost export, or update an existing one. |
azure_Pro · Destructive | Delete a budget. |
azure_Pro · Destructive | Delete a scheduled cost export. |
azure_Pro · Write | Dismiss a cost alert, marking it as handled so it stops appearing as active. |
azure_Free · Read-only | Forecast what a subscription (or resource group) WILL spend, using Azure's own projection from recent usage. |
azure_Free · Read-only | Get one budget by name, including its current and forecast spend and its full notification set. |
azure_Free · Read-only | Get one scheduled cost export by name: its schedule and recurrence, the dataset definition, the destination storage account and container, and the eTag. |
azure_Free · Read-only | Get the price sheet for a subscription — the rate Azure actually charges this customer per meter, which for a CSP or enterprise agreement is not the public retail price. |
azure_Free · Read-only | List the spend budgets configured on a subscription or resource group. |
azure_Free · Read-only | List the cost alerts currently raised on a subscription — budget thresholds crossed, spend anomalies Azure detected, and invoice or credit warnings. |
azure_Free · Read-only | List the dimensions available for grouping and filtering cost, and the VALUES each one currently holds for this subscription — the resource groups that actually exist, the services actually in use, the meter categories actually billed. |
azure_Free · Read-only | List the recent execution history of one scheduled cost export. |
azure_Free · Read-only | List the scheduled cost exports configured on a subscription — the recurring jobs that write cost detail files to a storage account. |
azure_Free · Read-only | List Azure's reserved-instance recommendations for a subscription — where committing to a one- or three-year reservation would cost less than pay-as-you-go, based on the customer's own recent usage. |
azure_Free · Read-only | List individual billing line items — one row per meter per resource per day, with the resource id, meter, quantity, unit price, effective price and cost. |
azure_Free · Read-only | THE cost question tool: what a subscription (or one resource group) spent, broken down however you ask. |
azure_Pro · Destructive | Trigger a scheduled cost export to run immediately, without waiting for its next scheduled time. |
Monitor
| Tool | What it does |
|---|---|
azure_Pro · Write | Create an action group, or replace an existing one. |
azure_Pro · Write | Create a diagnostic setting, or replace an existing one, so a resource ships its logs and metrics to a Log Analytics workspace, a storage account or an event hub. |
azure_Pro · Destructive | Delete an action group. |
azure_Pro · Destructive | Delete an autoscale setting permanently. |
azure_Pro · Destructive | Delete a diagnostic setting, stopping the export of that resource's logs and metrics. |
azure_Pro · Destructive | Delete a log search alert rule permanently. |
azure_Pro · Destructive | Delete a metric alert rule permanently. |
azure_Free · Read-only | Get one action group with every receiver in full, including each one's enabled state and, for webhooks, the URI and whether the common alert schema is used. |
azure_Free · Read-only | Get one autoscale setting in full: every profile with its capacity bounds and its recurrence or fixed-date schedule, and every scale rule with its metric trigger, threshold, direction, instance change and cooldown. |
azure_Free · Read-only | Get one diagnostic setting by name, with its full logs and metrics arrays and every destination it writes to. |
azure_Free · Read-only | Get one log search alert rule in full, including the complete KQL query it runs. |
azure_Free · Read-only | Get one metric alert rule in full: every criterion with its metric name, dimensions, threshold and operator, the auto-mitigate setting, the evaluation window and the action groups attached. |
azure_Free · Read-only | Get the current firing STATE of a metric alert rule, per dimension combination: whether it is currently Fired or Resolved, when that state was entered, and the value that caused it. |
azure_Free · Read-only | Read actual metric VALUES for one Azure resource over a time window — CPU, memory, disk, request counts, latency, whatever azure_list_metric_definitions says the resource emits. |
azure_Free · Read-only | List every action group in a subscription with its short name and every receiver it notifies — email, SMS, voice, push, webhook, Logic App, Azure Function, ITSM connector and automation runbook. |
azure_Free · Read-only | Read the subscription's activity log — the control-plane audit trail of WHO changed WHAT and WHEN, including the caller's identity, the operation name, the status, the correlation id and the resource affected. |
azure_Free · Read-only | List the activity log alert rules in a subscription — the rules that fire when a control-plane EVENT happens rather than when a metric crosses a threshold: a resource deleted, a service health advisory published, a policy assignment changed, an administrative operation failing. |
azure_Free · Read-only | List the autoscale settings in a subscription — the rules that add and remove instances on scale sets, App Service plans and other scalable resources. |
azure_Free · Read-only | List the log and metric categories a specific resource is CAPABLE of exporting, with each category's type and, for logs, the category groups ("allLogs", "audit") it belongs to. |
azure_Free · Read-only | List the diagnostic settings on a resource — where its platform logs and metrics are being SHIPPED, if anywhere: a Log Analytics workspace, a storage account, an event hub, or a marketplace partner. |
azure_Free · Read-only | List the log search alert rules in a subscription — the rules that run a KQL query against a Log Analytics workspace on a schedule and fire on the result. |
azure_Free · Read-only | List every metric alert rule in a subscription, with its scopes (what it watches), criteria (the metric, aggregation, operator and threshold), evaluationFrequency and windowSize, severity 0-4, the action groups it notifies, and — the field to read first — whether it is ENABLED. |
azure_Free · Read-only | List the metrics that a specific Azure resource actually emits, with each metric's name, display name, unit, the aggregations it supports (Average, Minimum, Maximum, Total, Count), its supported time grains and its dimensions. |
azure_Free · Read-only | List the metric namespaces available on a resource. |
azure_Pro · Destructive | Switch an autoscale setting on or off. |
azure_Pro · Destructive | Switch a log search alert rule on or off. |
azure_Pro · Destructive | Switch a metric alert rule on or off. |
Log Analytics
| Tool | What it does |
|---|---|
azure_Pro · Write | Save a KQL query into a workspace so the customer's team can reuse it, or update an existing one. |
azure_Pro · Write | Create a Log Analytics workspace, or update an existing one's retention, SKU and access settings. |
azure_Pro · Destructive | Delete a saved search. |
azure_Pro · Destructive | Delete a Log Analytics workspace and everything ingested into it. |
azure_Free · Read-only | Get one saved search with its full query text, category, display name and — when it is defined as a function — its alias and parameter list. |
azure_Free · Read-only | Get one table's configuration: its plan, its effective retention and total retention, its schema with every column and type, and for a custom table its search-results or restored-logs origin. |
azure_Free · Read-only | Get one Log Analytics workspace in full. |
azure_Free · Read-only | Report a workspace's current data-ingestion usage against its quota, with the current value, the limit, the unit and the reset time. |
azure_Free · Read-only | List a workspace's saved searches — the stored KQL queries a customer's team has built up, each with its category, display name and query text. |
azure_Free · Read-only | List the tables in a workspace with each one's plan (Analytics, Basic or Auxiliary), its own retentionInDays and totalRetentionInDays, and whether it is a built-in Microsoft table or a custom one. |
azure_Pro · Destructive | Return a workspace's primary and secondary SHARED KEYS. |
azure_Free · Read-only | List every Log Analytics workspace in a subscription, each with its customerId (the GUID azure_query_log_analytics needs), sku, retentionInDays, provisioningState, publicNetworkAccess settings and the daily ingestion cap if one is set. |
azure_Free · Read-only | List the Log Analytics workspaces inside one resource group. |
azure_Free · Read-only | Run a KQL query against a Log Analytics workspace and get the result tables back. |
azure_Pro · Destructive | Set how long one table keeps its data. |
App Service
| Tool | What it does |
|---|---|
azure_Pro · Write | Create an App Service plan. |
azure_Pro · Destructive | Delete an App Service plan. |
azure_Pro · Destructive | Delete a web app or Function App permanently. |
azure_Pro · Destructive | Delete a deployment slot. |
azure_Free · Read-only | Get one App Service plan: its tier and size, current instance capacity, worker count, the number of sites on it, per-site scaling, zone redundancy and maximum elastic worker count. |
azure_Free · Read-only | Get one web app or Function App in full: state, hostnames and their SSL bindings, the App Service plan, httpsOnly, clientCertMode, the managed identity if one is assigned, VNet integration, and a siteConfig summary. |
azure_Free · Read-only | Get a web app's site configuration — the runtime stack and version, alwaysOn, minTlsVersion, ftpsState, http20Enabled, remoteDebuggingEnabled, the health check path, IP restrictions and CORS. |
azure_Pro · Destructive | Return a web app's publishing username and password. |
azure_Free · Read-only | Get one deployment slot in full — the same shape as azure_get_web_app, for the slot rather than production. |
azure_Free · Read-only | Get a web app's source control configuration — the repository URL, the branch, and whether continuous deployment is enabled. |
azure_Free · Read-only | List the web apps running on one App Service plan. |
azure_Free · Read-only | List every App Service plan in a subscription with its sku (tier, size and CAPACITY — the instance count), numberOfSites, whether it is Linux (reserved), and its zone redundancy. |
azure_Pro · Destructive | Return a web app's connection strings, with their type (SQLAzure, PostgreSQL, Custom and so on). |
azure_Free · Read-only | List a web app's deployment history — each deployment's id, status, author, message, start and end time, and whether it is the currently active one. |
azure_Free · Read-only | List the individual functions inside a Function App, each with its trigger configuration, script href, language and whether it is disabled. |
azure_Free · Read-only | List a web app's custom domain bindings, each with its SSL state, certificate thumbprint, hostname type and whether the domain is verified. |
azure_Free · Read-only | List the running instances of a web app — the individual workers serving it, with each one's name and state. |
azure_Pro · Destructive | Return a web app's application settings — the environment variables the app runs with. |
azure_Free · Read-only | List a web app's deployment slots — the parallel copies (staging, testing, blue) that a release is warmed up in before being swapped into production. |
azure_Free · Read-only | List every App Service web app and Function App in a subscription, each with its state (Running or Stopped), defaultHostName, the serverFarmId of the plan it runs on, its enabled hostnames, httpsOnly, kind (app, functionapp, app,linux) and the outbound IP addresses it uses. |
azure_Free · Read-only | List the web apps and Function Apps inside one resource group. |
azure_Pro · Destructive | Restart a web app. |
azure_Pro · Destructive | Change an App Service plan's tier, size or instance count. |
azure_Pro · Destructive | Update a web app's site configuration. |
azure_Pro · Destructive | Replace a web app's ENTIRE application settings collection. |
azure_Pro · Write | Start a stopped web app. |
azure_Pro · Destructive | Stop a web app. |
azure_Pro · Destructive | Swap a deployment slot into production. |
SQL
| Tool | What it does |
|---|---|
azure_Pro · Write | Create an empty database on a SQL logical server. |
azure_Pro · Write | Create an elastic pool, or update an existing pool's capacity and per-database limits. |
azure_Pro · Destructive | Create or replace an IP firewall rule on a SQL logical server. |
azure_Pro · Write | Create an Azure SQL logical server, or update an existing one's TLS floor and public network access. |
azure_Pro · Destructive | Allow a subnet to reach a SQL logical server, or replace an existing rule of the same name. |
azure_Pro · Destructive | Delete a database. |
azure_Pro · Destructive | Delete an elastic pool. |
azure_Pro · Destructive | Delete an IP firewall rule from a SQL logical server. |
azure_Pro · Destructive | Delete an Azure SQL logical server AND EVERY DATABASE AND ELASTIC POOL UNDER IT. |
azure_Pro · Destructive | Remove a subnet's access to a SQL logical server. |
azure_Pro · Destructive | Force a failover of a database to another replica. |
azure_Free · Read-only | Get one database in full: sku and tier, status, maxSizeBytes, currentBackupStorageRedundancy, zoneRedundant, readScale, autoPauseDelay and minCapacity for serverless, the elastic pool it belongs to, creationDate and earliestRestoreDate. |
azure_Free · Read-only | Read a database's SHORT-TERM backup retention — retentionDays, which is how far back a point-in-time restore can reach, and diffBackupIntervalInHours. |
azure_Free · Read-only | Report whether Transparent Data Encryption is enabled on a database — the state of encryption at rest, which is what a compliance questionnaire is asking about. |
azure_Free · Read-only | Read a database's LONG-TERM retention policy: weeklyRetention, monthlyRetention, yearlyRetention and weekOfYear, as ISO-8601 durations such as P4W, P12M or P7Y. |
azure_Free · Read-only | Get one elastic pool in full: sku and capacity, perDatabaseSettings, maxSizeBytes, licenseType, zoneRedundant and creationDate. |
azure_Free · Read-only | Get one Azure SQL logical server in full: fullyQualifiedDomainName (the host a connection string points at), administratorLogin, administrators (the Entra admin and whether Entra-only authentication is on), version, minimalTlsVersion, publicNetworkAccess, restrictOutboundNetworkAccess and any assigned managed identity. |
azure_Free · Read-only | Read a SQL logical server's auditing policy: whether auditing is Enabled, which action groups are captured, how many days of audit records are retained, whether events go to Azure Monitor, and the storage endpoint they are written to. |
azure_Free · Read-only | List a database's discrete restore points, each with its restorePointType, earliestRestoreDate and creation time. |
azure_Free · Read-only | List every database on a SQL logical server, each with its sku (tier and capacity), status, maxSizeBytes, collation, zoneRedundant flag, elasticPoolId when it is pooled, and the earliestRestoreDate that bounds any point-in-time restore. |
azure_Free · Read-only | List a SQL logical server's elastic pools with each one's sku and capacity, perDatabaseSettings (the minimum and maximum capacity any single database may take), maxSizeBytes and zoneRedundant flag. |
azure_Free · Read-only | List a SQL logical server's IP firewall rules, each with its start and end address. |
azure_Free · Read-only | List the Microsoft Entra administrators configured on a SQL logical server — the login name, the object id of the user or group, and the directory the principal comes from. |
azure_Free · Read-only | List every Azure SQL logical server in a subscription, with each one's fully qualified domain name, administrator login, version, minimalTlsVersion, publicNetworkAccess and state. |
azure_Free · Read-only | List the Azure SQL logical servers inside one resource group. |
azure_Free · Read-only | List a SQL logical server's virtual network rules — each one naming a subnet that is allowed to reach the server without any IP firewall rule. |
azure_Pro · Destructive | Pause a Data Warehouse / dedicated SQL pool database so it stops billing for compute. |
azure_Pro · Destructive | Restore a database to a point in time, as a NEW database alongside the original. |
azure_Pro · Write | Resume a paused Data Warehouse / dedicated SQL pool database. |
azure_Pro · Destructive | Change a database's service tier, compute size or maximum size. |
azure_Pro · Destructive | Set a database's short-term backup retention in days. |
azure_Pro · Destructive | Reset the SQL administrator password on a logical server. |
AKS
| Tool | What it does |
|---|---|
azure_Pro · Destructive | Delete an AKS cluster and everything AKS created for it — every node pool, and the entire auto-generated node resource group with its virtual machines, managed disks, load balancers and public IPs. |
azure_Pro · Destructive | Delete a node pool and every node in it. |
azure_Free · Read-only | Get one AKS cluster in full: both version fields, every agent pool profile inline, the network profile (plugin, policy, service and pod CIDRs, outbound type), identity and RBAC configuration, apiServerAccessProfile, addonProfiles, autoUpgradeProfile and the fqdn. |
azure_Free · Read-only | Report what a cluster's control plane can upgrade TO: its current version, whether that version is still supported, and every available upgrade with its isPreview flag. |
azure_Free · Read-only | Fetch the result of a command started by azure_run_aks_command: its provisioningState, exitCode, startedAt and finishedAt, and the command's combined output as text. |
azure_Free · Read-only | Get one node pool in full: count and the autoscaler's min and max, vmSize, both orchestrator version fields, nodeImageVersion, os disk size and type, maxPods, node labels and taints, upgradeSettings.maxSurge and provisioningState. |
azure_Free · Read-only | Report what one node pool can upgrade to: its current Kubernetes and node image versions, its OS type, and the available upgrade versions with their isPreview flags. |
azure_Pro · Destructive | Return a cluster's ADMIN kubeconfig, base64-encoded. |
azure_Pro · Destructive | Return the MONITORING user's kubeconfig for a cluster, base64-encoded. |
azure_Pro · Destructive | Return a cluster's USER kubeconfig, base64-encoded. |
azure_Free · Read-only | List every AKS cluster in a subscription with its kubernetesVersion, currentKubernetesVersion, provisioningState, powerState, node resource group, SKU tier and API-server access profile. |
azure_Free · Read-only | List the AKS clusters inside one resource group. |
azure_Free · Read-only | List the Kubernetes versions AKS offers in one Azure region, each with its patch versions, support plan, isPreview flag and whether it is the default. |
azure_Free · Read-only | List a cluster's node pools with each one's count, vmSize, mode (System or User), orchestratorVersion, currentOrchestratorVersion, nodeImageVersion, osType, osSKU, autoscaling settings, spot priority and provisioningState. |
azure_Pro · Destructive | Rotate a cluster's certificates and, with them, every kubeconfig ever issued for it. |
azure_Pro · Destructive | Run a kubectl or helm command inside a cluster through the AKS run-command channel. |
azure_Pro · Write | Start a stopped AKS cluster. |
azure_Pro · Destructive | Stop an AKS cluster: the control plane is preserved and every node is DEALLOCATED. |
azure_Pro · Write | Replace an AKS cluster's tags. |
azure_Pro · Destructive | Upgrade a node pool to the latest node IMAGE — the OS and runtime patches — without changing its Kubernetes version. |
RBAC
| Tool | What it does |
|---|---|
azure_Pro · Destructive | Create a custom role, or REPLACE an existing one with the same GUID. |
azure_Pro · Destructive | Grant a role to an Entra principal at a scope. |
azure_Pro · Destructive | Remove a role assignment. |
azure_Pro · Destructive | Delete a custom role definition. |
azure_Free · Read-only | Find a role definition by its exact display name, e.g. Contributor, Reader, Storage Blob Data Reader. |
azure_Free · Read-only | Get one role assignment by its name (a GUID) at a scope. |
azure_Free · Read-only | Get one role definition by its GUID, with the full permissions arrays and assignableScopes. |
azure_Free · Read-only | List the deny assignments at a scope, each with the actions it blocks, the principals it applies to and any it excludes. |
azure_Free · Read-only | List the deny assignments that apply to one user or service principal. |
azure_Free · Read-only | List the role assignments at a scope: who (principalId and principalType) holds which role (roleDefinitionId) over what (scope), plus createdOn and createdBy and any ABAC condition. |
azure_Free · Read-only | List every role assignment held by one Entra principal — a user, group, service principal or managed identity — at, above or below a scope. |
azure_Free · Read-only | List the role assignments that apply to ONE specific resource — a storage account, a key vault, a virtual machine — including everything inherited from its resource group and subscription. |
azure_Free · Read-only | List the role definitions available at a scope — every built-in Azure role plus any custom roles defined at or above it — with each one's roleName, description, type, permissions (actions, notActions, dataActions, notDataActions) and assignableScopes. |
Policy
| Tool | What it does |
|---|---|
azure_Pro · Destructive | Assign a policy definition or initiative to a scope. |
azure_Pro · Destructive | Remove a policy assignment. |
azure_Free · Read-only | Get one policy assignment in full: the definition or initiative it assigns, every parameter value, its scope and notScopes, enforcementMode, nonComplianceMessages and any managed identity it runs remediation as. |
azure_Free · Read-only | Get one policy definition with its full policyRule — the if/then that decides which resources match and what happens when they do. |
azure_Free · Read-only | Get one policy initiative with every policy definition it contains, each with its policyDefinitionReferenceId and the parameter values the initiative passes down. |
azure_Free · Read-only | List the policy assignments in effect at a scope, each with the definition or initiative it assigns, its parameters, enforcementMode, notScopes and any managed identity. |
azure_Free · Read-only | List the policy assignments that apply to ONE specific resource, including everything inherited from its resource group, subscription and management groups. |
azure_Free · Read-only | List the policy definitions available to a subscription — every built-in Azure policy plus the customer's own custom ones — with each definition's displayName, policyType, mode, description, parameters and the policyRule itself. |
azure_Free · Read-only | List the policy INITIATIVES (policy set definitions) available to a subscription — named bundles of policy definitions assigned as one unit. |
azure_Pro · Destructive | Switch a policy assignment between Default (enforcing) and DoNotEnforce (report-only). |
Resource Health
| Tool | What it does |
|---|---|
azure_Free · Read-only | Get the CURRENT health of one Azure resource as Azure's own platform probes see it, not as its configuration claims. |
azure_Free · Read-only | Get one service health event in full by its tracking id, including the complete communication history Microsoft has posted against it. |
azure_Free · Read-only | List Azure's EMERGING issues — problems Microsoft has noticed and published on the Azure status page but has not yet turned into a per-subscription service health event. |
azure_Free · Read-only | List the current health of every probed resource inside ONE resource group. |
azure_Free · Read-only | List the health TRANSITIONS for one resource over time, newest first — every move between Available, Unavailable, Degraded and Unknown, each with its reason and timestamp. |
azure_Free · Read-only | List Microsoft's own declared service health events for a subscription — active incidents, planned maintenance, health advisories and security advisories, each with a tracking id, the affected regions and services, and Microsoft's current status update. |
azure_Free · Read-only | List the customer's own resources that Microsoft has identified as impacted by a specific service health event. |
azure_Free · Read-only | List the current health of EVERY resource in a subscription that Azure health-probes, in one call. |
Defender for Cloud
| Tool | What it does |
|---|---|
azure_Pro · Destructive | Create or replace a just-in-time VM access policy. |
azure_Pro · Destructive | Delete a just-in-time access policy. |
azure_Pro · Destructive | Remove a security contact configuration from a subscription. |
azure_Free · Read-only | Get one Defender plan in full, including the extensions array that the list view summarises. |
azure_Free · Read-only | Get one just-in-time access policy in full: every protected virtual machine, every port rule on it, and every currently open request with its requestor, source address, mapped port and expiry. |
azure_Free · Read-only | Get one security alert with everything the list view truncates — the full entities array, extendedProperties, supportingEvidence and extendedLinks to any threat-intelligence report behind it. |
azure_Free · Read-only | Get ONE Defender for Cloud assessment for ONE specific resource — the answer to "is this particular VM, storage account or SQL database passing this particular recommendation, and if not, what exactly should be done about it?". |
azure_Free · Read-only | List every Microsoft Defender for Cloud plan on a subscription with its pricingTier (Free or Standard), subPlan, enabled extensions, enablementTime and freeTrialRemainingTime. |
azure_Free · Read-only | List the just-in-time VM access policies in a subscription or resource group. |
azure_Free · Read-only | List the assessments that decide one regulatory control's outcome, each with the underlying Defender recommendation it maps to, its state, and counts of passed, failed and skipped RESOURCES. |
azure_Free · Read-only | List the individual controls inside one regulatory standard — the numbered clauses an auditor works through, such as PCI DSS 1.2.1 or ISO 27001 A.9.2.3 — each with its description, state and counts of passed, failed and skipped assessments. |
azure_Free · Read-only | List the regulatory compliance standards Defender for Cloud is tracking for a subscription — PCI DSS, ISO 27001, SOC 2, NIST SP 800-53, CIS and whatever else has been applied — each with a state of Passed, Failed, Skipped or Unsupported and counts of passed, failed and skipped controls. |
azure_Free · Read-only | List the Defender for Cloud security alerts on a subscription or resource group — the actual detections, not the recommendations: brute-force attempts, suspicious process execution, crypto-mining, malware uploads, anomalous data access. |
azure_Free · Read-only | List the DEFINITIONS of every recommendation available to a subscription — every built-in Microsoft one plus any the customer added — with displayName, description, severity, remediationDescription, categories, threats, implementationEffort, userImpact, assessmentType and the policyDefinitionId that switches each one on. |
azure_Free · Read-only | List every Defender for Cloud assessment in a subscription — one row PER RESOURCE PER RECOMMENDATION, each with the assessed resource's id, the recommendation's displayName and a status of Healthy, Unhealthy or NotApplicable. |
azure_Free · Read-only | List the security contact configurations on a subscription — who Defender for Cloud emails when it detects something, at what minimum severity, and whether the notification is on at all. |
azure_Free · Read-only | Get the ASC location for a subscription — the single home region where Defender for Cloud stores that subscription's alerts and just-in-time policies. |
azure_Free · Read-only | List the security CONTROLS behind a secure score — each one a themed group of recommendations such as "Enable MFA", "Remediate vulnerabilities" or "Restrict unauthorized network access" — with its current and maximum score, its weight, and how many resources are healthy, unhealthy or not applicable. |
azure_Free · Read-only | List the Defender for Cloud secure scores for a subscription — for each security initiative, the current score, the maximum available and the percentage between them. |
azure_Free · Read-only | List the INDIVIDUAL FINDINGS behind Defender's assessments — the actual CVEs on a machine, the specific container image vulnerabilities, the SQL vulnerability-assessment rule failures — each with its id, displayName, description, severity, impact, remediation text and additionalData carrying the CVE list, CVSS scores and patchable status. |
azure_Pro · Destructive | Request just-in-time access to a virtual machine's management ports. |
azure_Pro · Destructive | Turn a Defender for Cloud plan on or off for a subscription. |
azure_Pro · Write | Move a security alert between the four states Defender for Cloud defines: activate (back to Active), inProgress (someone is working it), resolve (handled, a true positive that was dealt with) and dismiss (a false positive). |
azure_Pro · Destructive | Set who Defender for Cloud emails about security alerts on a subscription. |
Deployments
| Tool | What it does |
|---|---|
azure_Pro · Destructive | Cancel a deployment that is still running. |
azure_Pro · Destructive | Deploy an ARM or Bicep-compiled template to a resource group, or to the subscription itself when resourceGroupName is omitted. |
azure_Pro · Destructive | Delete a deployment from the history. |
azure_Free · Read-only | Export the template EXACTLY AS IT WAS DEPLOYED, from the deployment history. |
azure_Free · Read-only | Get one deployment in full: its mode, provisioningState, timestamp and duration, the templateLink or templateHash it ran from, every parameter value it was given, its outputs, the providers and resource ids it touched, and its error object when it failed. |
azure_Free · Read-only | Get ONE operation from a deployment by its operation id, when azure_list_deployment_operations returned too much to read or the interesting entry was truncated. |
azure_Free · Read-only | List the individual resource operations that made up one deployment. |
azure_Free · Read-only | List the deployment history at a scope — every ARM or Bicep template deployment recorded against a resource group, or against the subscription itself when resourceGroupName is omitted. |
azure_Free · Read-only | Validate a template without deploying it: ARM parses the template, resolves its parameters, variables and functions, hands each resource declaration to its resource provider for semantic checks, and confirms the caller has permission to create what the template declares. |
azure_Free · Read-only | Predict what a template WOULD do, without deploying it. |
Management Groups
| Tool | What it does |
|---|---|
azure_Pro · Destructive | Attach an existing subscription to a management group. |
azure_Free · Read-only | Check whether a management group id is valid and still free BEFORE creating one. |
azure_Pro · Write | Create a management group, optionally under a named parent. |
azure_Pro · Destructive | Delete a management group. |
azure_Free · Read-only | Get one management group: name, displayName, tenantId and details — the parent group, a version number and who last changed it. |
azure_Free · Read-only | List EVERY entity descending from a management group — child management groups and subscriptions, at any depth — as one flat, PAGED list. |
azure_Free · Read-only | List every entity — management groups AND subscriptions — the signed-in user can see across a directory, with the fields the plain listings do not carry: parentNameChain and parentDisplayNameChain (the full path from the tenant root to each node), numberOfChildren, numberOfChildGroups, numberOfDescendants, and this user's own permissions and inheritedPermissions on each node (noaccess, view, edit or delete). |
azure_Free · Read-only | List the subscriptions attached DIRECTLY to one management group — the ones this group's own policy and role assignments reach first-hand, as opposed to the whole subtree that azure_get_management_group_descendants returns. |
azure_Free · Read-only | List the management groups in a directory — the containers ABOVE subscriptions, and the scope at which Azure Policy assignments and RBAC role assignments are INHERITED by everything beneath them. |
azure_Pro · Destructive | Move a management group to a different parent. |
azure_Pro · Destructive | Detach a subscription from a management group. |
Disks & Snapshots
| Tool | What it does |
|---|---|
azure_Pro · Write | Create a managed disk, or replace an existing one's model wholesale. |
azure_Pro · Write | Create a custom managed image from a generalized virtual machine, from managed disks or from snapshots, or replace an existing image's model. |
azure_Pro · Write | Take a point-in-time snapshot of a managed disk, or replace an existing snapshot's model. |
azure_Pro · Destructive | DELETE a managed disk. |
azure_Pro · Destructive | DELETE a custom managed image. |
azure_Pro · Destructive | DELETE a disk snapshot. |
azure_Free · Read-only | Get one managed disk in full: sku, diskSizeGB, diskIOPSReadWrite and diskMBpsReadWrite, osType, hyperVGeneration, encryption and encryptionSettingsCollection, networkAccessPolicy and publicNetworkAccess, maxShares, zones, tags and diskState. |
azure_Free · Read-only | Get one custom managed image in full: hyperVGeneration, sourceVirtualMachine, provisioningState and the complete storageProfile — the OS disk with its osType, osState, diskSizeGB and storage account type, plus every data disk with its LUN. |
azure_Free · Read-only | Get one disk snapshot in full: sku, diskSizeGB, osType, hyperVGeneration, encryption, incremental, diskState, networkAccessPolicy and the creationData block naming the source disk and how the snapshot was made. |
azure_Pro · Destructive | Mint a time-limited SAS URI that allows the raw contents of a managed disk to be downloaded or uploaded over the internet. |
azure_Pro · Destructive | Mint a time-limited SAS URI that allows the raw contents of a disk snapshot to be downloaded over the internet. |
azure_Free · Read-only | List every managed disk in a subscription, across all resource groups. |
azure_Free · Read-only | List the managed disks inside one resource group. |
azure_Free · Read-only | List the customer's OWN managed images in a subscription — the gold builds captured from their machines, not Microsoft's marketplace catalogue. |
azure_Free · Read-only | List every disk snapshot in a subscription — the point-in-time copies that are a customer's cheapest and most immediate restore path when one exists. |
azure_Pro · Destructive | Grow a managed disk to a new size in gibibytes. |
azure_Pro · Write | Revoke every SAS URI previously granted over a managed disk, immediately. |
azure_Pro · Write | Revoke every SAS URI previously granted over a disk snapshot, immediately. |
azure_Pro · Destructive | Change a managed disk's performance SKU, and optionally its performance tier. |
Virtual Machine Scale Sets
| Tool | What it does |
|---|---|
azure_Pro · Destructive | Deallocate EVERY INSTANCE in a scale set — shut them all down AND release their compute, which is what stops the compute bill for the whole fleet. |
azure_Pro · Destructive | Deallocate ONE instance in a scale set — shut it down AND release its compute, which stops that instance's compute bill. |
azure_Pro · Destructive | DELETE an entire scale set and EVERY instance in it. |
azure_Pro · Destructive | DELETE the named instances from a scale set, permanently. |
azure_Free · Read-only | Get one scale set's full MODEL — the desired state the fleet is built from: sku (VM size, tier and capacity), orchestrationMode, upgradePolicy (Manual, Automatic or Rolling, plus the rolling-upgrade policy), scaleInPolicy (which instances Azure removes first when scaling in), automaticRepairsPolicy, the virtualMachineProfile with its image reference, OS profile, network profile, extension profile and health probe, singlePlacementGroup, overprovision, zones and tags. |
azure_Free · Read-only | Get ONE instance inside a scale set by its instance id — that machine's own model: its resolved hardware profile, storage profile with the managed-disk ids actually attached to it, network profile with its NIC and IP configuration, its zone, and properties.latestModelApplied telling you whether it is running the current scale set model or an older one. |
azure_Free · Read-only | Get ONE instance's RUNTIME state — this is the tool that answers "is this particular node up?". |
azure_Free · Read-only | Get the WHOLE SET's runtime rollup — ARM's instanceView on the scale set itself. |
azure_Free · Read-only | Get the status of the most recent ROLLING UPGRADE on a scale set — the batch-by-batch roll-out Azure performs when upgradePolicy.mode is Rolling or when an automatic OS upgrade runs. |
azure_Free · Read-only | List the individual virtual machines INSIDE one scale set. |
azure_Free · Read-only | List the history of AUTOMATIC OS IMAGE UPGRADES on a scale set — one entry per upgrade Azure has run, with properties.runningStatus (code, startTime, endTime), properties.progress (successful, failed, in-progress and pending instance counts), properties.startedBy (Platform when Azure initiated it, User when a person did), and properties.targetImageReference naming the image version the fleet was moved to. |
azure_Free · Read-only | List the SKUs available to THIS scale set, each with a capacity block giving minimum, maximum and defaultCapacity. |
azure_Free · Read-only | List every virtual machine scale set in a subscription, across all resource groups. |
azure_Free · Read-only | List the virtual machine scale sets inside one resource group. |
azure_Pro · Destructive | Power off (stop) EVERY INSTANCE in a scale set, leaving them ALLOCATED. |
azure_Pro · Destructive | Power off (stop) ONE instance in a scale set, leaving it ALLOCATED and leaving every other instance running. |
azure_Pro · Destructive | Reimage EVERY INSTANCE in a scale set — reset every machine's OS disk back to the original image. |
azure_Pro · Destructive | Reimage ONE instance in a scale set — reset that machine's OS disk back to the original image. |
azure_Pro · Destructive | Restart EVERY INSTANCE in a scale set at once. |
azure_Pro · Destructive | Restart ONE instance in a scale set. |
azure_Pro · Destructive | Set a scale set's instance count. |
azure_Pro · Write | Set the tags on a scale set, leaving every other property untouched. |
azure_Pro · Write | Start (power on) EVERY instance in a scale set. |
azure_Pro · Write | Start (power on) ONE instance in a scale set, leaving every other instance alone. |
Containers
| Tool | What it does |
|---|---|
azure_Pro · Destructive | Delete a container group. |
azure_Pro · Destructive | Delete a container registry and EVERY image in it. |
azure_Pro · Destructive | Get one container group in full, including each container's instanceView with its currentState, previousState, restartCount and the group's recent events. |
azure_Free · Read-only | Read one container's stdout and stderr — the call an engineer actually wants when an ACI workload misbehaves, and the reason this family is worth having. |
azure_Free · Read-only | Get one container registry in full: sku, loginServer, adminUserEnabled, anonymousPullEnabled, identity, encryption, networkRuleSet with its ip rules and defaultAction, networkRuleBypassOptions, publicNetworkAccess, privateEndpointConnections, dataEndpointEnabled, zoneRedundancy and the policies block. |
azure_Pro · Destructive | Return a registry's ADMIN username and both passwords in plaintext. |
azure_Free · Read-only | List a registry's webhooks with each one's actions, scope, status and provisioningState — the notifications the registry fires when an image is pushed, deleted or quarantined, and therefore the list of automated systems that react to this registry. |
azure_Pro · Destructive | List every Azure Container Instances container group in a subscription, each with its containers and their images, resource requests, ports and instanceView state, plus the group's osType, restartPolicy, ipAddress, sku, priority, provisioningState and subnetIds. |
azure_Pro · Destructive | List the container groups inside one resource group. |
azure_Free · Read-only | List every Azure Container Registry in a subscription with each one's sku, loginServer, adminUserEnabled, anonymousPullEnabled, publicNetworkAccess, provisioningState and creation date. |
azure_Free · Read-only | List the container registries inside one resource group. |
azure_Pro · Destructive | Regenerate one of a registry's two admin passwords and return the new value. |
azure_Pro · Destructive | Restart every container in a group in place. |
azure_Pro · Write | Start a stopped container group. |
azure_Pro · Destructive | Stop a container group: every container halts and the compute is deallocated. |
DNS
| Tool | What it does |
|---|---|
azure_Pro · Destructive | Create or REPLACE a record set in a public DNS zone. |
azure_Pro · Write | Create a public DNS zone, or update an existing one's tags. |
azure_Pro · Destructive | Create or REPLACE a record set in a private DNS zone. |
azure_Pro · Destructive | Link a virtual network to a private DNS zone, or update an existing link. |
azure_Pro · Write | Create a private DNS zone, or update an existing one's tags. |
azure_Pro · Destructive | Delete a record set from a public DNS zone. |
azure_Pro · Destructive | Delete a public DNS zone AND every record set inside it, in one call. |
azure_Pro · Destructive | Delete a record set from a private DNS zone. |
azure_Pro · Destructive | Remove a virtual network link from a private DNS zone. |
azure_Pro · Destructive | Delete a private DNS zone and every record set inside it. |
azure_Free · Read-only | Get one record set by type and name, with its records, TTL, fqdn, metadata and etag. |
azure_Free · Read-only | Get one public DNS zone: its nameServers, numberOfRecordSets, maxNumberOfRecordSets, tags and etag. |
azure_Free · Read-only | Get one record set from a private DNS zone by type and name, with its records, ttl, fqdn, isAutoRegistered flag and etag. |
azure_Free · Read-only | Get one virtual network link: the virtual network it points at, its registrationEnabled flag, provisioningState, virtualNetworkLinkState, tags and etag. |
azure_Free · Read-only | Get one private DNS zone with its record-set and virtual-network-link counts, tags, provisioningState and etag. |
azure_Free · Read-only | List the record sets in a public DNS zone — every type at once, or a single type when recordType is given. |
azure_Free · Read-only | List the PUBLIC DNS zones in a subscription, or in one resource group when resourceGroupName is given. |
azure_Free · Read-only | List the record sets in a private DNS zone — every type at once, or one type when recordType is given. |
azure_Free · Read-only | List the virtual network links on a private DNS zone. |
azure_Free · Read-only | List the PRIVATE DNS zones in a subscription, or in one resource group when resourceGroupName is given. |
Key Vault
| Tool | What it does |
|---|---|
azure_Free · Read-only | Check whether a key vault name is valid and still free. |
azure_Pro · Destructive | Create a key vault. |
azure_Pro · Destructive | Delete a key vault. |
azure_Free · Read-only | Get one soft-deleted key vault: the resource id it had, its deletionDate, its scheduledPurgeDate, its tags and whether purgeProtectionEnabled was set. |
azure_Free · Read-only | Get one key vault in full: SKU, the Entra tenant it authenticates against, enableRbacAuthorization, enableSoftDelete, softDeleteRetentionInDays, enablePurgeProtection, publicNetworkAccess, the complete networkAcls rule set, every private endpoint connection, and — when the vault is in legacy mode — the entire accessPolicies array with each identity's key, secret and certificate permissions. |
azure_Free · Read-only | Get one key's PROPERTIES: type, size or curve, permitted operations, whether it is enabled, its not-before and expiry dates, whether it is marked exportable, and its rotation policy with the lifetime actions that drive automatic rotation. |
azure_Free · Read-only | Get one secret's PROPERTIES: contentType, whether it is enabled, its not-before and expiry dates, its tags and its identifier URI. |
azure_Free · Read-only | List the soft-deleted key vaults in a subscription, each with the location it lived in, its deletionDate, its scheduledPurgeDate and whether purge protection was on. |
azure_Free · Read-only | List the keys in a vault by NAME and PROPERTIES — key type (RSA, EC, and the -HSM variants), key size or curve, the permitted keyOps, attributes.enabled, attributes.exp and attributes.nbf, the rotation policy, and the key's identifier URI. |
azure_Free · Read-only | List the secrets in a vault by NAME and PROPERTIES — contentType, attributes.enabled, attributes.exp, attributes.nbf, tags and the secret's identifier URI. |
azure_Free · Read-only | List the key vaults in a subscription, or in one resource group, each with its location, SKU, tags and full properties. |
azure_Pro · Destructive | Permanently destroy a soft-deleted key vault. |
azure_Pro · Destructive | Enable or disable one secret, by setting its enabled flag and nothing else. |
azure_Pro · Destructive | Add, replace or remove a legacy access-policy entry on a key vault. |
azure_Pro · Destructive | Replace a key vault's firewall rules — the default action, the trusted-services bypass, the allowed IP ranges and the allowed virtual network subnets — and optionally its public network access. |
azure_Pro · Write | Set the tags on a key vault. |
Backup
| Tool | What it does |
|---|---|
azure_Pro · Destructive | Create a backup policy, or REPLACE an existing one's schedule and retention. |
azure_Pro · Write | Create a Recovery Services vault, or update an existing one's tags and properties. |
azure_Pro · Destructive | Delete a backup policy. |
azure_Pro · Destructive | Delete a Recovery Services vault. |
azure_Pro · Destructive | Protect an item with a backup policy — and, because ARM models both with the same call, RE-POINT an already-protected item at a DIFFERENT policy. |
azure_Free · Read-only | Get one backup or restore job with its full extended info: the per-task breakdown, transferred bytes, progress percentage, the localized error string and — the field that actually resolves tickets — the recommendations list Azure attaches to each error code. |
azure_Free · Read-only | Get one backup policy with its complete schedule and retention definition — daily, weekly, monthly and yearly retention durations, the instant-restore snapshot window, the timezone the schedule runs in, and how many items are bound to it. |
azure_Free · Read-only | Get one protected item in full: its policy binding, protectionState, health status, last backup result and error, the source resource it backs up, the oldest and newest recovery point times, and for VMs the list of disks included in or excluded from the backup. |
azure_Free · Read-only | Get one recovery point with everything the list response leaves out: the full disk configuration including which LUNs were included and excluded, the immutability and soft-delete state of the point itself, its expiry time, and for SQL and SAP HANA the data-directory paths a restore has to map. |
azure_Free · Read-only | Get one Recovery Services vault in full: sku, provisioningState, redundancy configuration, cross-region restore state, encryption settings, public network access and any managed identity. |
azure_Free · Read-only | List a vault's backup, restore, configure-backup and delete-backup-data jobs, each with its operation, status, entityFriendlyName, startTime, endTime, duration and error details. |
azure_Free · Read-only | List a vault's backup policies — the schedules and retention rules every protected item is bound to — each with its backupManagementType, schedulePolicy, retentionPolicy and protectedItemsCount. |
azure_Free · Read-only | List everything a vault is protecting — VMs, file shares, SQL and SAP HANA databases, on-premises servers — each with its friendlyName, protectionStatus, protectionState, lastBackupStatus, lastBackupTime, the policy it is bound to and its containerName. |
azure_Free · Read-only | List the protection containers registered with a vault — the VMs, storage accounts, SQL-in-VM hosts, MABS/DPM servers and on-premises machines that hold the things being backed up. |
azure_Free · Read-only | List the recovery points (backup copies) held for one protected item, each with its recoveryPointTime, recoveryPointType, tier details and — for VMs — the disk configuration captured at that moment. |
azure_Free · Read-only | Get a vault's usage summary — how many protected items or registered containers it holds, broken down by backup management type. |
azure_Free · Read-only | List the Recovery Services vaults in a subscription, or in one resource group, with each vault's location, sku, provisioningState, redundancy settings and any managed identity. |
azure_Pro · Destructive | Stop backing up an item AND PERMANENTLY DESTROY EVERY RECOVERY POINT IT HAS. |
azure_Pro · Destructive | Stop backing up an item but KEEP every recovery point it already has. |
azure_Pro · Write | Run an on-demand backup of a protected item right now. |
azure_Pro · Destructive | Restore from a recovery point. |
azure_Pro · Destructive | Unregister a protection container from a vault — a storage account, a SQL-in-VM or SAP HANA host, or an on-premises MABS/DPM server. |
Automation
| Tool | What it does |
|---|---|
azure_Pro · Write | Create an Automation account. |
azure_Pro · Write | Create a schedule. |
azure_Pro · Destructive | Delete an Automation account. |
azure_Pro · Destructive | Delete a schedule. |
azure_Pro · Destructive | Delete a runbook. |
azure_Free · Read-only | Get one Automation account in full: its sku, state, creation and last-modified times, encryption settings, publicNetworkAccess, disableLocalAuth and — the field that matters most before you start anything — its identity. |
azure_Free · Read-only | Get one Automation job: its status, statusDetails, exception, the runbook it ran, the exact parameters it was given, its jobId, runOn, startedBy and the full timeline of creation, start, end and lastStatusModifiedTime. |
azure_Free · Read-only | Get ONE job stream record in full, including streamText — the untruncated line the runbook wrote, which azure_list_automation_job_streams only summarises. |
azure_Free · Read-only | Get one schedule in full, including the advancedSchedule block that the list view flattens away: weekDays for a weekly recurrence, monthDays for specific dates, and monthlyOccurrences for patterns like "the last Friday". |
azure_Free · Read-only | Get one runbook's full definition-of-record: runbookType, state, parameters (each with its type, whether it is mandatory and its default), outputTypes, the publishContentLink the published body came from, the logVerbose/logProgress/logActivityTrace flags, and the draft block. |
azure_Free · Read-only | List the Azure Automation accounts in a subscription, or in one resource group, with each account's location, sku, state and MANAGED IDENTITY. |
azure_Free · Read-only | List the certificate assets in an Automation account, each with its thumbprint, expiryTime, isExportable, description and timestamps. |
azure_Free · Read-only | List the credential assets in an Automation account — the username/password pairs runbooks fetch with Get-AutomationPSCredential. |
azure_Free · Read-only | List everything a job printed, as a timestamped stream of records each carrying a jobStreamId, a streamType and a summary. |
azure_Free · Read-only | List the jobs an Automation account has run, each with its runbook name, status, statusDetails, exception, startTime, endTime, the parameters it was given and startedBy. |
azure_Free · Read-only | List an Automation account's schedules, each with its frequency, interval, startTime, expiryTime, timeZone, nextRun and — the field to read first — isEnabled. |
azure_Pro · Destructive | List the variable assets in an Automation account — the shared values runbooks read at run time — each with its isEncrypted flag, description, timestamps and, for an unencrypted variable, ITS VALUE IN PLAIN TEXT. |
azure_Free · Read-only | List the runbooks in an Automation account, each with its runbookType, state, jobCount, lastModifiedTime and logging flags. |
azure_Pro · Destructive | Publish a runbook's draft, making it the live version. |
azure_Pro · Destructive | Enable or disable a schedule. |
azure_Pro · Destructive | Start a runbook, creating a job that executes it. |
azure_Pro · Destructive | Stop a running Automation job. |
Managed Identities
| Tool | What it does |
|---|---|
azure_Pro · Write | Create a user-assigned managed identity in a resource group. |
azure_Pro · Destructive | Remove a federated identity credential. |
azure_Pro · Destructive | Delete a user-assigned managed identity. |
azure_Free · Read-only | Get one federated identity credential in full: its issuer, subject and audiences. |
azure_Free · Read-only | Get one user-assigned managed identity with its principalId, clientId, tenantId, location and tags. |
azure_Free · Read-only | List the federated identity credentials configured on a user-assigned managed identity — the rules that let an EXTERNAL workload obtain this identity's Azure tokens without any secret. |
azure_Free · Read-only | List the USER-ASSIGNED managed identities in a subscription, or in one resource group, each with its principalId, clientId, tenantId and location. |
azure_Free · Read-only | List every Azure resource currently using a user-assigned managed identity — the virtual machines, function apps, AKS clusters, logic apps and automation accounts that authenticate as it. |
azure_Pro · Destructive | Create or replace a federated identity credential, letting an external workload obtain this identity's Azure tokens with no secret at all. |
Advisor
| Tool | What it does |
|---|---|
azure_Pro · Destructive | Snooze or dismiss an Advisor recommendation for one resource. |
azure_Pro · Write | Lift an Advisor suppression, so the recommendation it was hiding is reported again. |
azure_Free · Read-only | Ask Advisor to recompute its recommendations for a subscription. |
azure_Free · Read-only | Get one Advisor recommendation in full, with the fields the listing truncates: the complete description, extendedProperties (where the actual numbers live — the annual saving for a cost finding, the recommended SKU, the target region), learnMoreLink, and any remediation block describing an automated fix. |
azure_Free · Read-only | Get one Advisor suppression: its suppressionId, ttl and expirationTimeStamp. |
azure_Free · Read-only | Read Advisor's configuration at subscription or resource-group scope: the low-CPU threshold and evaluation duration that decide when a virtual machine counts as underused, the digest (email report) settings, and the exclude flag. |
azure_Free · Read-only | List Azure Advisor's recommendations for a subscription — Microsoft's own standing findings across Cost, Security, HighAvailability, Performance and OperationalExcellence — each with its category, impact, risk, the resource it concerns, a problem/solution summary and the concrete actions to take. |
azure_Free · Read-only | List every Advisor suppression in a subscription — the snoozed and dismissed recommendations — each with the recommendation and resource it hides, its ttl and its expirationTimeStamp. |
azure_Pro · Destructive | Configure Advisor at subscription or resource-group scope: the low-CPU threshold and evaluation duration behind virtual-machine cost findings, and the exclude flag. |
Container Apps
| Tool | What it does |
|---|---|
azure_Free · Read-only | Get one Azure Container App in full: its managed environment, ingress (fqdn, external, targetPort, transport, traffic weights and the customDomains bound to it), activeRevisionsMode, registries, the names of its secrets, and the complete template — every container with its image, resources, probes, command, args, volume mounts and environment variables. |
azure_Free · Read-only | Run ARM's listCustomHostNameAnalysis on a container app and return the result verbatim: whether the hostname is already verified, the customDomainVerificationTest outcome, the alternate CNAME and TXT records ARM expects, whether the name conflicts with another container app, and the resource id of the app it conflicts with. |
azure_Free · Read-only | List a container app's revisions with each one's active flag, createdTime, trafficWeight, replicas, provisioningState, healthState and the image it runs. |
azure_Free · Read-only | List the Azure Container Apps in a subscription, or in one resource group, with each app's provisioningState, runningStatus, latestRevisionName, managed environment, ingress configuration and full container template. |
azure_Free · Read-only | List the FREE managed certificates in one Container Apps environment, with each one's subjectName, domainControlValidation method, provisioningState and error. |
azure_Free · Read-only | List the Container Apps managed environments in a subscription, or in one resource group, with each one's defaultDomain, staticIp, provisioningState, VNet configuration, Log Analytics destination, workload profiles and zoneRedundant flag. |
azure_Pro · Destructive | Add or change environment variables on ONE container inside a container app, leaving every other variable, every other field of that container, and every other container untouched. |
Raw Requests
| Tool | What it does |
|---|---|
azure_Free · Read-only | Send one GET to any Azure Resource Manager path and return the response exactly as ARM sent it. |
azure_Pro · Destructive | Send one POST, PUT, PATCH or DELETE to any Azure Resource Manager path and return the response exactly as ARM sent it. |
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team