Skip to main content
Connector guides

Connect Microsoft Azure

Microsoft Azure is where a great many of your customers' servers, networks, databases and bills live. Connecting it gives your AI a large set of azure_ MCP tools — MCP (Model Context Protocol) tools…

Written By Christopher Scaminaci

Last updated 6 days ago

Microsoft Azure is where a great many of your customers' servers, networks, databases and bills live. Connecting it gives your AI a large set of azure_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack — covering subscriptions, virtual machines, storage, networking, DNS, app services, Kubernetes, SQL, monitoring, cost, policy, access control and security posture.

Two things make this connector different from every other one in StackJack, and both are worth reading before you connect.

Nothing to enter, unless you bring your own app

Every other connector asks you for a key, a secret or a URL. Azure asks for none of them by default. StackJack has its own Microsoft application, so you connect by signing in with Microsoft and approving the request — that is the entire setup. (Organizations that prefer to consent to an application they own can bring their own app registration instead — the option lives under Advanced — use your own app registration on the connector card, and the Microsoft Graph connector guide describes the whole flow. Each Microsoft connector card stores its own application choice, so set it here and on Microsoft Graph if you use both.)

  1. Check who can approve. Many organizations require an administrator to approve a new application once, on behalf of everyone. If you are a Global Administrator you can approve it yourself as you connect. If you are not, either ask an administrator to connect first, or ask them to approve the request when Microsoft prompts for it.
  2. Connect with Microsoft. On the Connectors page, open Microsoft Azure and choose Connect with Microsoft. Sign in with the account you use to manage Azure and approve the request.
  3. Check what you can reach. Ask your AI to list your Azure subscriptions. If one you expected is missing, that is almost always a role question rather than a connection problem — see below.

Your Azure role decides everything

Azure grants StackJack exactly one thing: permission to act as you. It does not grant "read virtual machines" or "manage storage" separately, because Azure does not work that way. Instead, Azure checks your own role on every single call.

The consequences are worth stating plainly, because they surprise people who have set up other connectors:

  • What this connector can do is exactly what you can do in the Azure portal. No more, and no less.
  • Two people on the same team will legitimately get different answers. Someone with Reader gets reads and a clean refusal on writes. Someone with Contributor can make changes. That is Azure working correctly.
  • A refusal is not a broken connection. When Azure says you are not authorized, it names the action it refused and the scope it refused it at. The fix is an Azure role assignment from an Owner or User Access Administrator — reconnecting will not help, because signing in again grants the same single permission it already had.
  • StackJack's plan tiers are a separate, narrower thing. Read tools are available on Free and write tools on Pro, but that only decides which tools your AI is offered. It cannot grant Azure access you do not have.

Managing your customers' Azure

If you manage customers' Azure subscriptions through Microsoft's delegated access, your USER access comes along automatically — there is no separate connection per customer. One thing does need setting up per customer, once: admin consent for the StackJack application in that customer's tenant.

Microsoft asks two separate questions on a customer-directory call: whether YOU may act there (your delegated access), and whether the customer's tenant has admitted the APPLICATION the call comes through. Delegated roles do not answer the second — an administrator in the customer's tenant (Global Administrator, Application Administrator, or Cloud Application Administrator) must approve it once. Generate the link with Authorize a customer tenant on the Azure connector card and send it to them; until they approve, calls into that customer fail with a consent error (AADSTS65001), and reconnecting your own sign-in will not fix it. If the customer runs Conditional Access policies that block external accounts, ask their admin to exclude the specific partner accounts that need access — or the partner-user categorization the policy keys on — from the blocking policy.

Every Azure tool takes an optional customer directory (their Microsoft tenant ID or a verified domain such as contoso.onmicrosoft.com). Leave it out and the tool works on your own Azure. Provide it and the tool works on that customer's, with whatever access you already have there.

In practice you just name the customer when you ask:

  • "List the subscriptions in Contoso's directory."
  • "Which VMs in Contoso's production resource group are running an unsupported OS?"
  • "Compare last month's Azure spend across all our customers."

That last one is worth calling out. StackJack uses Azure's own cross-subscription query service for questions that span many subscriptions, which answers in a single call instead of walking each subscription one at a time. It is both much faster and much less likely to be throttled — so prefer broad questions over asking about each customer in turn.

Every person signs in for themselves

There is no shared Azure identity for a team to fall back on. The stored connection is one person's own Microsoft sign-in, carrying their Azure roles and everything those roles reach across your customers' directories, so StackJack will not run anyone else's calls under it.

  • Owners keep the fallback. The organization's owner and co-owners can use the stored connection before they personally sign in.
  • Everyone else must connect their own account, including Administrators. Until they do, Azure tools refuse for them with personal_sign_in_required. This is not a preference or an optimization — it is the only way that member gets an Azure identity at all.
  • Nothing has to be prepared for them. StackJack's own Microsoft application serves every organization, so a member can connect whether or not an owner ever configured the connector.

Signing in individually is also what keeps the record honest. Azure logs every action against the identity that performed it, so one shared identity would put one person's name against the whole team's work — and each person can only do what their own Azure role allows.

Members connect from the Connectors page, in their personal sign-ins section. The rules in full: Who can use which identity.

What this connector deliberately does not do

Stated up front so it does not read as a gap:

  • It does not read the contents of your data. Blob contents, queue messages, database rows and Key Vault secret values are all outside this connector. It manages Azure resources — it does not open what is inside them. For Key Vault this is deliberate and worth being explicit about: StackJack can list vaults, see their access policies, and see secret names and expiry dates, but it cannot read a secret's value.
  • It does not cover Azure Government or Azure China. Those are separate clouds that need their own setup.
  • It has no purpose-built tools for application platform services such as Cosmos DB, Service Bus, Data Factory or Synapse. Those are your customers' application data tiers rather than the infrastructure an MSP manages. They are still reachable through the raw request tools below, with the same Azure role you already hold — there is simply no tool written for them.
  • Classic (pre-Resource-Manager) resources have no tools either. They have been retired by Microsoft.
  • It does not give automations access by default. An automation has no signed-in person of its own, so it cannot borrow your connection. An administrator can enrol a dedicated Microsoft sign-in for a specific automation, and it then acts with exactly that account's Azure role — enrol a purpose-made account rather than a person's, so an unattended process reaches only what it needs and the Azure activity log names the automation rather than a technician who was not at their desk.

Things that catch people out

A tool says the subscription does not exist. A subscription ID only means something inside its own directory. If it is a customer's subscription, name their directory in the request — without it, the tool looked in your own.

Large lists come back partial. StackJack caps a single call at 1,000 items across 10 pages, and tells your AI where the list left off so it can continue. This is a StackJack safety limit rather than an Azure one, and it exists to stop one question consuming an enormous response.

A long-running change returns immediately, and the answer can look empty. Deleting a resource group, resizing a cluster or restoring a database can take many minutes in Azure. The tool does not wait: Azure answers accepted, the tool hands that answer straight back, and the work continues afterwards. Read the three outcomes differently:

  • Accepted — Azure took the request and is still working. The reply is often empty, because Azure returns no body with an acceptance. An empty reply here is not a failure and is not a completion.
  • Completed — the reply carries the changed resource.
  • Failed — the reply carries Azure's error.

Because an acceptance can come back empty, do not treat "it returned" as "it finished". Confirm the outcome with a read that suits the resource: check whether a resource group still exists, read the resource back, or read the activity log or the operation record for that resource. Ask your AI to confirm the result rather than assuming it.

Azure starts throttling. Azure limits how fast requests can arrive, and StackJack waits as long as Azure asks before retrying, within a bounded retry budget. Pacing reduces throttling; it does not remove it, and a long enough wait can end as a timeout instead. If it keeps happening, ask one broad cross-subscription question rather than many narrow ones, and check whether a write landed before you repeat it — see Retrying a failed or timed-out write.

Destructive actions

Some Azure tools remove data, interrupt running workloads, run code on a machine, or change who has access. StackJack marks those as destructive and they are all Pro-tier. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and restrict the tools you grant, before you allow destructive Azure actions.

The sharpest ones are worth knowing by name:

  • Deleting a resource group deletes everything inside it — virtual machines, disks, databases, storage accounts and their contents — with no confirmation from Azure and no undo. Ask your AI to list the group's contents first.
  • Storage account keys grant full access to everything in that account, and regenerating one breaks every existing application using it.
  • Cluster credentials and registry credentials hand back working administrative access.
  • Running a command on a virtual machine executes whatever you send, as an administrator on that machine.
  • Role assignments change who can reach what, for everyone.

Marking these clearly is what lets the rest of the connector be used freely.

Advanced: raw API requests

Reach for a purpose-built tool first. They pin the Azure API version for you, escape the names you pass, cap the page size, and their descriptions say what the answer means. Use the raw tools only where no purpose-built tool exists.

Two tools send a request you compose straight to Azure Resource Manager:

  • azure_raw_get sends one GET. It is Free-tier and read-only.
  • azure_raw_request sends one POST, PUT, PATCH or DELETE. It is Pro-tier and marked destructive. It refuses GET, so a read cannot be run through the write tool.

What they change, and what they do not:

  • They widen coverage, not permission. Your connector subscription, your endpoint's tool selection, your plan and your monthly allowance all still apply, and Azure still checks your own role on every call. A raw request returns exactly what your Azure role could reach anyway.
  • They reach resource types no tool was written for — Cosmos DB, Service Bus, Data Factory, Synapse and anything else Azure Resource Manager publishes. That is the point of them.
  • You supply the API version, and Azure is unforgiving about it. Every Azure resource provider versions independently, and a wrong version comes back as an unhelpful 400. Ask for the provider's supported versions first.
  • Paging is yours to drive. A continuation link comes back in the body; pass its path back to get the next page. Nothing pages for you.
  • A replacing write drops what you leave out. PUT on Azure Resource Manager replaces the whole resource, so a body assembled from a few fields silently clears every property you did not send. Read the resource first and send it back complete.
  • Long-running writes are not followed for you. Azure answers accepted with a tracking address in its response headers, and StackJack returns the body rather than the headers — so the reply can be empty and nothing polls on your behalf. Confirm the outcome with a read, as described above.
  • The path is fenced. It has to be rooted at a subscription, a provider or a tenant, with no scheme and no directory traversal. Anything else is refused before the request is sent.

Microsoft adding or promoting an API does not, on its own, produce a purpose-built StackJack tool for it, and it does not change what your organization has consented to. Both remain separate decisions.

See the generated Microsoft Azure tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Microsoft Azure tools

azure_ · 545 tools · Free 304 · Pro 241

Subscriptions

ToolWhat it does
azure_get_resource_provider
Free · Read-only
Get one resource provider's registration state and the full resourceTypes list it exposes in a subscription, including each type's supported locations and apiVersions.
azure_get_subscription
Free · Read-only
Get one Azure subscription's details: subscriptionId, displayName, state, tenantId, authorizationSource (the mechanism granting access, e.g. RoleBased or Legacy), managedByTenants (the partner directories with delegated access — how you confirm a GDAP relationship exists) and subscriptionPolicies including its quota id and spending limit.
azure_list_locations
Free · Read-only
List the Azure regions available to a subscription.
azure_list_resource_providers
Free · Read-only
List the Azure resource providers in a subscription and their registration state.
azure_list_subscriptions
Free · Read-only
List the Azure subscriptions the signed-in user can see — the ENTRY POINT for this connector.
azure_list_tenants
Free · Read-only
List the Microsoft Entra directories (tenants) the signed-in user can access — their own plus every customer directory they hold a delegated relationship with.
azure_register_resource_provider
Pro · Write
Register a resource provider in a subscription, making its resource types deployable there.
azure_unregister_resource_provider
Pro · Destructive
Unregister a resource provider from a subscription.

Resource Graph

ToolWhat it does
azure_get_resource_change_details
Free · Read-only
Get the full BEFORE and AFTER snapshots for one resource change, plus the property-level diff.
azure_list_resource_graph_facets
Free · Read-only
Run a KQL query and return FACET summaries — value counts for the columns you name — alongside the rows.
azure_query_resource_changes
Free · Read-only
List configuration CHANGES to Azure resources in a time window — the "what changed and when" surface, and usually the fastest route from an incident to its cause.
azure_query_resources
Free · Read-only
Run a KQL query across many subscriptions at once — the most powerful read in this connector.
azure_query_resources_count
Free · Read-only
Run a KQL query that returns only a COUNT, across many subscriptions at once.

Resource Groups

ToolWhat it does
azure_check_resource_group_exists
Free · Read-only
Check whether a resource group exists WITHOUT retrieving it, returning {"exists": true|false}.
azure_create_resource_group
Pro · Write
Create a resource group, or update an existing one's tags.
azure_delete_resource_group
Pro · Destructive
Delete a resource group AND EVERY RESOURCE INSIDE IT.
azure_export_resource_group_template
Free · Read-only
Export a resource group as an ARM template — the JSON that would recreate its resources.
azure_get_resource_group
Free · Read-only
Get one resource group: id, name, location, tags, managedBy and properties.provisioningState.
azure_list_resource_group_resources
Free · Read-only
List every resource inside one resource group.
azure_list_resource_groups
Free · Read-only
List the resource groups in a subscription.
azure_update_resource_group_tags
Pro · Write
Update a resource group's tags via PATCH, leaving everything else alone.

Resources & Tags

ToolWhat it does
azure_delete_resource_by_id
Pro · Destructive
Delete any Azure resource by its full ARM resource id.
azure_get_resource_by_id
Free · Read-only
Get any Azure resource by its full ARM resource id — the /subscriptions/...
azure_get_resource_tags
Free · Read-only
Get the tags on any Azure resource, resource group or subscription by its ARM id.
azure_list_resources
Free · Read-only
List every resource in a subscription, of any type.
azure_move_resources
Pro · Destructive
Move resources to a different resource group or subscription.
azure_set_resource_tags
Pro · Write
REPLACE the entire tag set on any Azure resource, resource group or subscription.
azure_update_resource_tags
Pro · Write
Merge, replace or delete tags on any Azure resource, resource group or subscription.
azure_validate_move_resources
Pro · Write
Validate a resource move WITHOUT performing it — the safe preview for azure_move_resources.

Virtual Machines

ToolWhat it does
azure_assess_vm_patches
Pro · Write
Assess which operating-system patches are available for a virtual machine.
azure_attach_vm_data_disks
Pro · Write
Attach one or more EXISTING managed disks to a virtual machine as data disks.
azure_convert_vm_to_managed_disks
Pro · Destructive
Convert a legacy virtual machine's unmanaged (page-blob) disks to managed disks.
azure_create_or_update_vm
Pro · Write
Create a virtual machine, or replace an existing one's model wholesale.
azure_create_or_update_vm_extension
Pro · Write
Install an extension on a virtual machine, or update one already installed.
azure_deallocate_vm
Pro · Destructive
Deallocate a virtual machine — shut it down AND release its compute resources, which is what stops the compute bill.
azure_delete_vm
Pro · Destructive
DELETE a virtual machine.
azure_delete_vm_extension
Pro · Destructive
Uninstall an extension from a virtual machine.
azure_detach_vm_data_disks
Pro · Destructive
Detach one or more data disks from a virtual machine.
azure_get_vm
Free · Read-only
Get one virtual machine's full model: size, OS profile, image reference, OS and data disks with their LUNs and managed-disk ids, network interface ids, boot-diagnostics settings, identity, zones and tags.
azure_get_vm_boot_diagnostics_data
Pro · Destructive
Mint time-limited SAS URIs for a virtual machine's boot diagnostics — consoleScreenshotBlobUri (a bitmap of the console at the moment of capture) and serialConsoleLogBlobUri (the boot serial log).
azure_get_vm_extension
Free · Read-only
Get one extension on one virtual machine by its instance name — the name the extension was DEPLOYED under, which is often not the same as its publisher type (azure_list_vm_extensions returns both).
azure_get_vm_instance_view
Free · Read-only
Get a virtual machine's RUNTIME state — this is the tool that answers "is this machine on?".
azure_get_vm_run_command
Free · Read-only
Get one managed run command on a virtual machine, and with expand="instanceView" its RESULT — executionState (Running, Succeeded, Failed, TimedOut), exitCode, startTime, endTime, and the captured standard output and standard error.
azure_get_vm_run_command_document
Free · Read-only
Get one built-in run command document by its command id — the full definition, including the script Azure will execute and the parameters array naming every value the command expects and which of them are required.
azure_install_vm_patches
Pro · Destructive
Install operating-system patches on a virtual machine now.
azure_list_vm_extensions
Free · Read-only
List the extensions installed on one virtual machine — the in-guest agents Azure manages, such as the Monitor agent, the Dependency agent, Custom Script, the antimalware extension and the domain-join extension.
azure_list_vm_image_offers
Free · Read-only
List one publisher's image offers in a region — the second rung of the image coordinate.
azure_list_vm_image_publishers
Free · Read-only
List the image publishers available in one region — the first rung of the four-part image coordinate (publisher, offer, SKU, version) that azure_create_or_update_vm needs.
azure_list_vm_image_skus
Free · Read-only
List the SKUs under one publisher/offer in a region — the third rung of the image coordinate, and the one that names the actual edition: 2022-datacenter-azure-edition, 22_04-lts-gen2, and so on.
azure_list_vm_image_versions
Free · Read-only
List the published versions of one publisher/offer/SKU image in a region — the fourth and last rung of the image coordinate.
azure_list_vm_resize_options
Free · Read-only
List the sizes THIS virtual machine can actually be resized to.
azure_list_vm_run_command_documents
Free · Read-only
List the BUILT-IN run command documents Azure publishes for a region — the vetted scripts an agent can invoke by id instead of writing its own.
azure_list_vm_run_commands
Free · Read-only
List the MANAGED run commands deployed on one virtual machine.
azure_list_vm_sizes
Free · Read-only
List every virtual machine size Azure offers in one region, with each size's numberOfCores, memoryInMB, maxDataDiskCount, osDiskSizeInMB and resourceDiskSizeInMB.
azure_list_vms
Free · Read-only
List every virtual machine in a subscription, across all resource groups.
azure_list_vms_in_resource_group
Free · Read-only
List the virtual machines inside one resource group.
azure_perform_vm_maintenance
Pro · Destructive
Trigger Azure's pending host maintenance on a virtual machine NOW, instead of waiting for the platform's self-service window to close and the maintenance to be applied automatically.
azure_power_off_vm
Pro · Destructive
Power off (stop) a virtual machine, leaving it ALLOCATED.
azure_reapply_vm
Pro · Destructive
Reapply a virtual machine's ARM model to the platform — Azure re-pushes the stored configuration to the machine's host.
azure_redeploy_vm
Pro · Destructive
Redeploy a virtual machine — shut it down, MOVE it to a new Azure host, and power it back on.
azure_reimage_vm
Pro · Destructive
Reimage a virtual machine — reset its OS disk back to the original image.
azure_restart_vm
Pro · Destructive
Restart a virtual machine.
azure_run_vm_command
Pro · Destructive
Run a command INSIDE a customer's virtual machine, through the Azure guest agent.
azure_set_vm_tags
Pro · Write
Set the tags on a virtual machine, leaving every other property untouched.
azure_simulate_vm_eviction
Pro · Destructive
Simulate the eviction of a SPOT virtual machine, so an owner can test that their workload survives being evicted.
azure_start_vm
Pro · Write
Start (power on) a stopped or deallocated virtual machine.
azure_update_vm
Pro · Write
Update an existing virtual machine with a PATCH — the tool to use for a resize, a boot-diagnostics change, an identity change or a licence-type change.

Storage

ToolWhat it does
azure_check_storage_account_name_availability
Free · Read-only
Check whether a storage account name is free BEFORE trying to create it.
azure_create_blob_container
Pro · Write
Create a blob container in a storage account.
azure_create_file_share
Pro · Write
Create an Azure Files share in a storage account.
azure_create_storage_account
Pro · Write
Create a new storage account.
azure_create_storage_queue
Pro · Write
Create a Storage queue in an account.
azure_create_storage_table
Pro · Write
Create a Storage table in an account.
azure_delete_blob_container
Pro · Destructive
Delete a blob container AND EVERY BLOB INSIDE IT.
azure_delete_file_share
Pro · Destructive
Delete an Azure Files share AND EVERY FILE AND FOLDER INSIDE IT.
azure_delete_storage_account
Pro · Destructive
Delete a storage account AND EVERYTHING INSIDE IT.
azure_delete_storage_queue
Pro · Destructive
Delete a Storage queue AND EVERY MESSAGE STILL IN IT.
azure_delete_storage_table
Pro · Destructive
Delete a Storage table AND EVERY ROW IN IT.
azure_get_blob_container
Free · Read-only
Get one blob container's ARM properties: publicAccess (None, Blob or Container — anything other than None means anonymous internet reads are possible), metadata, leaseStatus/leaseState/leaseDuration, hasImmutabilityPolicy, hasLegalHold, immutableStorageWithVersioning, lastModifiedTime and etag.
azure_get_blob_service_properties
Free · Read-only
Get the account-wide Blob service settings: deleteRetentionPolicy (blob soft delete and its retention in days), containerDeleteRetentionPolicy (container soft delete — this is what decides whether azure_delete_blob_container is recoverable), isVersioningEnabled, changeFeed, restorePolicy (point-in-time restore), cors and defaultServiceVersion.
azure_get_file_service_properties
Free · Read-only
Get the account-wide Azure Files settings: shareDeleteRetentionPolicy (share soft delete and its retention in days — this decides whether azure_delete_file_share is recoverable), protocolSettings.smb (the SMB versions, authentication methods, kerberos ticket encryption and channel encryption the account will accept) and cors.
azure_get_file_share
Free · Read-only
Get one Azure Files share's ARM properties: shareQuota (provisioned GiB), accessTier, enabledProtocols, rootSquash, leaseStatus, metadata, lastModifiedTime and etag.
azure_get_storage_account
Free · Read-only
Get one storage account's full configuration: kind, sku, location, tags, accessTier, primaryEndpoints, encryption, minimumTlsVersion, allowBlobPublicAccess, allowSharedKeyAccess, publicNetworkAccess and the networkAcls firewall rules.
azure_get_storage_lifecycle_policy
Free · Read-only
Get the account's lifecycle management policy — the rule set that automatically tiers blobs to Cool or Archive and DELETES them after an age threshold.
azure_lease_blob_container
Pro · Destructive
Acquire, renew, change, release or break a LEASE on a blob container.
azure_list_blob_containers
Free · Read-only
List the blob containers in a storage account, as ARM resources.
azure_list_file_shares
Free · Read-only
List the Azure Files shares in a storage account, as ARM resources.
azure_list_storage_account_keys
Pro · Destructive
Return the storage account's ROOT ACCESS KEYS in plain text.
azure_list_storage_account_usage
Free · Read-only
Report how many storage accounts the subscription has used against its per-region quota, as {value:[{unit, currentValue, limit, name:{value, localizedValue}}]}.
azure_list_storage_accounts
Free · Read-only
List every storage account in a subscription.
azure_list_storage_accounts_in_resource_group
Free · Read-only
List the storage accounts inside ONE resource group, with the same fields as azure_list_storage_accounts.
azure_list_storage_queues
Free · Read-only
List the Storage queues in an account.
azure_list_storage_skus
Free · Read-only
List the storage SKUs the subscription may deploy: each item carries name (Standard_LRS, Standard_GRS, Standard_ZRS, Premium_LRS, ...), tier, kind, the locations it is offered in, and a restrictions array explaining any region or quota block.
azure_list_storage_tables
Free · Read-only
List the Storage tables in an account.
azure_regenerate_storage_account_key
Pro · Destructive
Regenerate one of the storage account's root access keys.
azure_revoke_storage_user_delegation_keys
Pro · Destructive
Revoke ALL of the account's user delegation keys, invalidating every Microsoft Entra-signed shared access signature issued against it.
azure_set_blob_service_properties
Pro · Write
Set the account-wide Blob service settings — soft delete, container soft delete, versioning, change feed, point-in-time restore and CORS.
azure_set_file_service_properties
Pro · Write
Set the account-wide Azure Files settings — share soft delete and its retention, the SMB protocol settings (accepted versions, authentication methods, kerberos ticket encryption, channel encryption) and CORS.
azure_set_storage_account_network_rules
Pro · Write
Replace the storage account's firewall (networkAcls) via PATCH.
azure_set_storage_lifecycle_policy
Pro · Write
Set the account's lifecycle management policy — the rules that automatically tier blobs to Cool or Archive and delete them past an age threshold.
azure_update_blob_container
Pro · Write
Update an existing blob container's anonymous-access level or metadata via PATCH.
azure_update_file_share
Pro · Write
Update an existing Azure Files share's quota, access tier or metadata via PATCH.
azure_update_storage_account
Pro · Write
Update an existing storage account's SKU, tags or settings via PATCH.

Networking

ToolWhat it does
azure_check_vnet_ip_availability
Free · Read-only
Check whether a specific private IP address is free in a virtual network, and get suggested alternatives when it is not.
azure_create_network_security_group
Pro · Write
Create an empty network security group, or update its tags.
azure_create_nsg_rule
Pro · Destructive
Create or replace a security rule in a network security group.
azure_create_public_ip_address
Pro · Write
Create a public IP address resource, or replace an existing one's definition.
azure_create_route
Pro · Destructive
Create or replace a route in a route table.
azure_create_route_table
Pro · Write
Create an empty route table, or update its tags and BGP setting.
azure_create_subnet
Pro · Write
Create a subnet in a virtual network, or replace an existing one.
azure_create_virtual_network
Pro · Write
Create a virtual network, or replace an existing one's definition.
azure_create_vnet_peering
Pro · Write
Create a peering from this virtual network to another.
azure_delete_network_interface
Pro · Destructive
Delete a network interface.
azure_delete_network_security_group
Pro · Destructive
Delete a network security group and every rule in it.
azure_delete_nsg_rule
Pro · Destructive
Delete a security rule from a network security group.
azure_delete_public_ip_address
Pro · Destructive
Delete a public IP address resource.
azure_delete_route
Pro · Destructive
Delete a route from a route table.
azure_delete_subnet
Pro · Destructive
Delete a subnet from a virtual network.
azure_delete_virtual_network
Pro · Destructive
Delete a virtual network and every subnet inside it.
azure_delete_vnet_peering
Pro · Destructive
Delete a peering.
azure_get_application_gateway
Free · Read-only
Get one application gateway in full, including every listener, rule, backend setting, probe, rewrite rule set and certificate's metadata.
azure_get_application_gateway_backend_health
Free · Read-only
Ask an application gateway how it currently sees each of its backend servers: per pool and per HTTP setting, every server's address with a health status of Healthy, Unhealthy, Partial, Draining or Unknown, and for an unhealthy one the reason — a failed probe, a certificate the gateway does not trust, or a connection refused.
azure_get_azure_firewall
Free · Read-only
Get one Azure Firewall in full, including every inline rule collection with its priority and action, the private IP the firewall answers on, and its provisioning state.
azure_get_load_balancer
Free · Read-only
Get one load balancer in full: frontends, backend pools, rules, health probes, NAT rules and outbound rules.
azure_get_network_interface
Free · Read-only
Get one network interface in full: every IP configuration with its private address and allocation method, the subnet and public IP resource ids, the NSG attached to the NIC itself, applied DNS servers, accelerated networking and IP forwarding flags, and the VM it belongs to.
azure_get_network_security_group
Free · Read-only
Get one network security group with every rule and every attachment.
azure_get_nsg_rule
Free · Read-only
Get one security rule by name.
azure_get_public_ip_address
Free · Read-only
Get one public IP address resource: its SKU and tier, allocation method, the assigned ipAddress, idleTimeoutInMinutes, DNS label and FQDN, availability zones, and the ipConfiguration it is attached to.
azure_get_route_table
Free · Read-only
Get one route table with its full routes array and the list of subnets it is attached to.
azure_get_subnet
Free · Read-only
Get one subnet: its address prefix, attached network security group and route table, service endpoints, delegations and private-endpoint policies.
azure_get_virtual_network
Free · Read-only
Get one virtual network in full: address space, every subnet with its prefix, attached network security group, route table, service endpoints and delegations, plus peerings, DNS servers and DDoS settings.
azure_get_virtual_network_gateway
Free · Read-only
Get one virtual network gateway in full: type, SKU and generation, active-active state, BGP settings including the ASN and the peering addresses, the gateway subnet's IP configurations, and any point-to-site VPN client configuration.
azure_get_vnet_peering
Free · Read-only
Get one peering by name, including its peeringState and the four traffic flags.
azure_list_application_gateways
Free · Read-only
List every application gateway in a subscription: its sku and capacity or autoscale range, operationalState, frontend IP and port configurations, HTTP listeners, backend pools and settings, request routing rules, SSL certificates (metadata only — never the private key), and the webApplicationFirewallConfiguration when WAF is enabled.
azure_list_azure_firewalls
Free · Read-only
List every Azure Firewall in a subscription: its sku tier (Standard, Premium or Basic), threatIntelMode, the firewallPolicy it draws rules from when policy-managed, its ipConfigurations and hubIPAddresses, and — on older firewalls that still hold rules inline — the applicationRuleCollections, networkRuleCollections and natRuleCollections.
azure_list_bastion_hosts
Free · Read-only
List every Azure Bastion host in a subscription, with its sku, scaleUnits, the AzureBastionSubnet and public IP it uses, and the feature flags — enableTunneling, enableIpConnect, enableShareableLink and disableCopyPaste.
azure_list_express_route_circuits
Free · Read-only
List every ExpressRoute circuit in a subscription, with its serviceProviderProperties (the carrier, peering location and bandwidth), the sku tier and family, and — the two fields to read first — circuitProvisioningState and serviceProviderProvisioningState.
azure_list_load_balancer_backend_pools
Free · Read-only
List a load balancer's backend address pools with their full membership — every NIC ip configuration or explicit IP address in each pool.
azure_list_load_balancers
Free · Read-only
List every load balancer in a subscription with its sku (Basic or Standard), frontendIPConfigurations (the addresses it answers on, public or private), backendAddressPools, loadBalancingRules, probes, inboundNatRules and outboundRules.
azure_list_network_interfaces
Free · Read-only
List every network interface (NIC) in a subscription.
azure_list_network_interfaces_in_resource_group
Free · Read-only
List the network interfaces inside one resource group.
azure_list_network_security_groups
Free · Read-only
List every network security group in a subscription.
azure_list_network_security_groups_in_resource_group
Free · Read-only
List the network security groups inside one resource group.
azure_list_network_watchers
Free · Read-only
List the Network Watcher resources in a subscription.
azure_list_nic_effective_nsg_rules
Free · Read-only
Show the security rules that are ACTUALLY in force on one network interface — Azure's own evaluation of the NIC's NSG combined with the subnet's NSG, in priority order, including the built-in default rules that are invisible in azure_list_nsg_rules.
azure_list_nic_effective_routes
Free · Read-only
Show the routing table that is ACTUALLY in force on one network interface: Azure's system routes, routes learned over BGP from a VPN or ExpressRoute gateway, and any user-defined routes from an attached route table, each with its source, address prefix, next hop type and next hop address.
azure_list_nsg_rules
Free · Read-only
List the ADMIN-DEFINED security rules in a network security group.
azure_list_public_ip_addresses
Free · Read-only
List every public IP address resource in a subscription, with its sku (Basic or Standard), publicIPAllocationMethod (Static or Dynamic), the ipAddress currently assigned, the dnsSettings FQDN if one is configured, and ipConfiguration.id naming what the address is attached to.
azure_list_route_tables
Free · Read-only
List every route table in a subscription, each with its routes array (address prefix, next hop type, next hop IP), the subnets it is attached to, and disableBgpRoutePropagation.
azure_list_routes
Free · Read-only
List the individual routes in one route table, each with addressPrefix, nextHopType and, for a virtual-appliance hop, nextHopIpAddress.
azure_list_subnets
Free · Read-only
List the subnets in a virtual network.
azure_list_virtual_network_gateways
Free · Read-only
List the virtual network gateways in one resource group — the VPN and ExpressRoute gateways that connect a virtual network to on-premises or to other networks.
azure_list_virtual_network_usage
Free · Read-only
Report how many private IP addresses each subnet in a virtual network has consumed, with currentValue and limit per subnet.
azure_list_virtual_networks
Free · Read-only
List every virtual network in a subscription, across all resource groups.
azure_list_virtual_networks_in_resource_group
Free · Read-only
List the virtual networks inside one resource group.
azure_list_vnet_peerings
Free · Read-only
List the peerings on a virtual network — the links that let two networks route to each other directly.
azure_list_vpn_connections
Free · Read-only
List the gateway connections in one resource group — the site-to-site VPN tunnels, VNet-to-VNet links and ExpressRoute circuit connections.
azure_run_connectivity_check
Free · Read-only
Actually TEST reachability from a virtual machine to another Azure resource or to any address and port, and get the full hop-by-hop path back with latency and, at each hop, what allowed or blocked the traffic.
azure_run_ip_flow_verify
Free · Read-only
Ask Azure whether a specific packet would be allowed or denied to a specific virtual machine, and WHICH security rule decides it.
azure_run_next_hop
Free · Read-only
Ask Azure where traffic from a virtual machine to a given destination address would actually go NEXT, and which route decides it.
azure_start_application_gateway
Pro · Write
Start a stopped application gateway.
azure_stop_application_gateway
Pro · Destructive
Stop an application gateway.
azure_update_network_security_group_tags
Pro · Write
Update a network security group's tags via PATCH, leaving every rule and attachment untouched.
azure_update_virtual_network_tags
Pro · Write
Update a virtual network's tags via PATCH, leaving its address space, subnets and peerings untouched.

Cost Management

ToolWhat it does
azure_create_budget
Pro · Write
Create a spend budget, or update an existing one.
azure_create_cost_export
Pro · Write
Create a scheduled cost export, or update an existing one.
azure_delete_budget
Pro · Destructive
Delete a budget.
azure_delete_cost_export
Pro · Destructive
Delete a scheduled cost export.
azure_dismiss_cost_alert
Pro · Write
Dismiss a cost alert, marking it as handled so it stops appearing as active.
azure_forecast_cost
Free · Read-only
Forecast what a subscription (or resource group) WILL spend, using Azure's own projection from recent usage.
azure_get_budget
Free · Read-only
Get one budget by name, including its current and forecast spend and its full notification set.
azure_get_cost_export
Free · Read-only
Get one scheduled cost export by name: its schedule and recurrence, the dataset definition, the destination storage account and container, and the eTag.
azure_get_price_sheet
Free · Read-only
Get the price sheet for a subscription — the rate Azure actually charges this customer per meter, which for a CSP or enterprise agreement is not the public retail price.
azure_list_budgets
Free · Read-only
List the spend budgets configured on a subscription or resource group.
azure_list_cost_alerts
Free · Read-only
List the cost alerts currently raised on a subscription — budget thresholds crossed, spend anomalies Azure detected, and invoice or credit warnings.
azure_list_cost_dimensions
Free · Read-only
List the dimensions available for grouping and filtering cost, and the VALUES each one currently holds for this subscription — the resource groups that actually exist, the services actually in use, the meter categories actually billed.
azure_list_cost_export_runs
Free · Read-only
List the recent execution history of one scheduled cost export.
azure_list_cost_exports
Free · Read-only
List the scheduled cost exports configured on a subscription — the recurring jobs that write cost detail files to a storage account.
azure_list_reservation_recommendations
Free · Read-only
List Azure's reserved-instance recommendations for a subscription — where committing to a one- or three-year reservation would cost less than pay-as-you-go, based on the customer's own recent usage.
azure_list_usage_details
Free · Read-only
List individual billing line items — one row per meter per resource per day, with the resource id, meter, quantity, unit price, effective price and cost.
azure_query_cost
Free · Read-only
THE cost question tool: what a subscription (or one resource group) spent, broken down however you ask.
azure_run_cost_export
Pro · Destructive
Trigger a scheduled cost export to run immediately, without waiting for its next scheduled time.

Monitor

ToolWhat it does
azure_create_action_group
Pro · Write
Create an action group, or replace an existing one.
azure_create_diagnostic_setting
Pro · Write
Create a diagnostic setting, or replace an existing one, so a resource ships its logs and metrics to a Log Analytics workspace, a storage account or an event hub.
azure_delete_action_group
Pro · Destructive
Delete an action group.
azure_delete_autoscale_setting
Pro · Destructive
Delete an autoscale setting permanently.
azure_delete_diagnostic_setting
Pro · Destructive
Delete a diagnostic setting, stopping the export of that resource's logs and metrics.
azure_delete_log_alert_rule
Pro · Destructive
Delete a log search alert rule permanently.
azure_delete_metric_alert_rule
Pro · Destructive
Delete a metric alert rule permanently.
azure_get_action_group
Free · Read-only
Get one action group with every receiver in full, including each one's enabled state and, for webhooks, the URI and whether the common alert schema is used.
azure_get_autoscale_setting
Free · Read-only
Get one autoscale setting in full: every profile with its capacity bounds and its recurrence or fixed-date schedule, and every scale rule with its metric trigger, threshold, direction, instance change and cooldown.
azure_get_diagnostic_setting
Free · Read-only
Get one diagnostic setting by name, with its full logs and metrics arrays and every destination it writes to.
azure_get_log_alert_rule
Free · Read-only
Get one log search alert rule in full, including the complete KQL query it runs.
azure_get_metric_alert_rule
Free · Read-only
Get one metric alert rule in full: every criterion with its metric name, dimensions, threshold and operator, the auto-mitigate setting, the evaluation window and the action groups attached.
azure_get_metric_alert_rule_status
Free · Read-only
Get the current firing STATE of a metric alert rule, per dimension combination: whether it is currently Fired or Resolved, when that state was entered, and the value that caused it.
azure_get_metrics
Free · Read-only
Read actual metric VALUES for one Azure resource over a time window — CPU, memory, disk, request counts, latency, whatever azure_list_metric_definitions says the resource emits.
azure_list_action_groups
Free · Read-only
List every action group in a subscription with its short name and every receiver it notifies — email, SMS, voice, push, webhook, Logic App, Azure Function, ITSM connector and automation runbook.
azure_list_activity_log
Free · Read-only
Read the subscription's activity log — the control-plane audit trail of WHO changed WHAT and WHEN, including the caller's identity, the operation name, the status, the correlation id and the resource affected.
azure_list_activity_log_alert_rules
Free · Read-only
List the activity log alert rules in a subscription — the rules that fire when a control-plane EVENT happens rather than when a metric crosses a threshold: a resource deleted, a service health advisory published, a policy assignment changed, an administrative operation failing.
azure_list_autoscale_settings
Free · Read-only
List the autoscale settings in a subscription — the rules that add and remove instances on scale sets, App Service plans and other scalable resources.
azure_list_diagnostic_setting_categories
Free · Read-only
List the log and metric categories a specific resource is CAPABLE of exporting, with each category's type and, for logs, the category groups ("allLogs", "audit") it belongs to.
azure_list_diagnostic_settings
Free · Read-only
List the diagnostic settings on a resource — where its platform logs and metrics are being SHIPPED, if anywhere: a Log Analytics workspace, a storage account, an event hub, or a marketplace partner.
azure_list_log_alert_rules
Free · Read-only
List the log search alert rules in a subscription — the rules that run a KQL query against a Log Analytics workspace on a schedule and fire on the result.
azure_list_metric_alert_rules
Free · Read-only
List every metric alert rule in a subscription, with its scopes (what it watches), criteria (the metric, aggregation, operator and threshold), evaluationFrequency and windowSize, severity 0-4, the action groups it notifies, and — the field to read first — whether it is ENABLED.
azure_list_metric_definitions
Free · Read-only
List the metrics that a specific Azure resource actually emits, with each metric's name, display name, unit, the aggregations it supports (Average, Minimum, Maximum, Total, Count), its supported time grains and its dimensions.
azure_list_metric_namespaces
Free · Read-only
List the metric namespaces available on a resource.
azure_set_autoscale_setting_enabled
Pro · Destructive
Switch an autoscale setting on or off.
azure_set_log_alert_rule_enabled
Pro · Destructive
Switch a log search alert rule on or off.
azure_set_metric_alert_rule_enabled
Pro · Destructive
Switch a metric alert rule on or off.

Log Analytics

ToolWhat it does
azure_create_log_analytics_saved_search
Pro · Write
Save a KQL query into a workspace so the customer's team can reuse it, or update an existing one.
azure_create_log_analytics_workspace
Pro · Write
Create a Log Analytics workspace, or update an existing one's retention, SKU and access settings.
azure_delete_log_analytics_saved_search
Pro · Destructive
Delete a saved search.
azure_delete_log_analytics_workspace
Pro · Destructive
Delete a Log Analytics workspace and everything ingested into it.
azure_get_log_analytics_saved_search
Free · Read-only
Get one saved search with its full query text, category, display name and — when it is defined as a function — its alias and parameter list.
azure_get_log_analytics_table
Free · Read-only
Get one table's configuration: its plan, its effective retention and total retention, its schema with every column and type, and for a custom table its search-results or restored-logs origin.
azure_get_log_analytics_workspace
Free · Read-only
Get one Log Analytics workspace in full.
azure_get_log_analytics_workspace_usage
Free · Read-only
Report a workspace's current data-ingestion usage against its quota, with the current value, the limit, the unit and the reset time.
azure_list_log_analytics_saved_searches
Free · Read-only
List a workspace's saved searches — the stored KQL queries a customer's team has built up, each with its category, display name and query text.
azure_list_log_analytics_tables
Free · Read-only
List the tables in a workspace with each one's plan (Analytics, Basic or Auxiliary), its own retentionInDays and totalRetentionInDays, and whether it is a built-in Microsoft table or a custom one.
azure_list_log_analytics_workspace_keys
Pro · Destructive
Return a workspace's primary and secondary SHARED KEYS.
azure_list_log_analytics_workspaces
Free · Read-only
List every Log Analytics workspace in a subscription, each with its customerId (the GUID azure_query_log_analytics needs), sku, retentionInDays, provisioningState, publicNetworkAccess settings and the daily ingestion cap if one is set.
azure_list_log_analytics_workspaces_in_resource_group
Free · Read-only
List the Log Analytics workspaces inside one resource group.
azure_query_log_analytics
Free · Read-only
Run a KQL query against a Log Analytics workspace and get the result tables back.
azure_set_log_analytics_table_retention
Pro · Destructive
Set how long one table keeps its data.

App Service

ToolWhat it does
azure_create_app_service_plan
Pro · Write
Create an App Service plan.
azure_delete_app_service_plan
Pro · Destructive
Delete an App Service plan.
azure_delete_web_app
Pro · Destructive
Delete a web app or Function App permanently.
azure_delete_web_app_slot
Pro · Destructive
Delete a deployment slot.
azure_get_app_service_plan
Free · Read-only
Get one App Service plan: its tier and size, current instance capacity, worker count, the number of sites on it, per-site scaling, zone redundancy and maximum elastic worker count.
azure_get_web_app
Free · Read-only
Get one web app or Function App in full: state, hostnames and their SSL bindings, the App Service plan, httpsOnly, clientCertMode, the managed identity if one is assigned, VNet integration, and a siteConfig summary.
azure_get_web_app_configuration
Free · Read-only
Get a web app's site configuration — the runtime stack and version, alwaysOn, minTlsVersion, ftpsState, http20Enabled, remoteDebuggingEnabled, the health check path, IP restrictions and CORS.
azure_get_web_app_publishing_credentials
Pro · Destructive
Return a web app's publishing username and password.
azure_get_web_app_slot
Free · Read-only
Get one deployment slot in full — the same shape as azure_get_web_app, for the slot rather than production.
azure_get_web_app_source_control
Free · Read-only
Get a web app's source control configuration — the repository URL, the branch, and whether continuous deployment is enabled.
azure_list_app_service_plan_web_apps
Free · Read-only
List the web apps running on one App Service plan.
azure_list_app_service_plans
Free · Read-only
List every App Service plan in a subscription with its sku (tier, size and CAPACITY — the instance count), numberOfSites, whether it is Linux (reserved), and its zone redundancy.
azure_list_web_app_connection_strings
Pro · Destructive
Return a web app's connection strings, with their type (SQLAzure, PostgreSQL, Custom and so on).
azure_list_web_app_deployments
Free · Read-only
List a web app's deployment history — each deployment's id, status, author, message, start and end time, and whether it is the currently active one.
azure_list_web_app_functions
Free · Read-only
List the individual functions inside a Function App, each with its trigger configuration, script href, language and whether it is disabled.
azure_list_web_app_hostname_bindings
Free · Read-only
List a web app's custom domain bindings, each with its SSL state, certificate thumbprint, hostname type and whether the domain is verified.
azure_list_web_app_instances
Free · Read-only
List the running instances of a web app — the individual workers serving it, with each one's name and state.
azure_list_web_app_settings
Pro · Destructive
Return a web app's application settings — the environment variables the app runs with.
azure_list_web_app_slots
Free · Read-only
List a web app's deployment slots — the parallel copies (staging, testing, blue) that a release is warmed up in before being swapped into production.
azure_list_web_apps
Free · Read-only
List every App Service web app and Function App in a subscription, each with its state (Running or Stopped), defaultHostName, the serverFarmId of the plan it runs on, its enabled hostnames, httpsOnly, kind (app, functionapp, app,linux) and the outbound IP addresses it uses.
azure_list_web_apps_in_resource_group
Free · Read-only
List the web apps and Function Apps inside one resource group.
azure_restart_web_app
Pro · Destructive
Restart a web app.
azure_scale_app_service_plan
Pro · Destructive
Change an App Service plan's tier, size or instance count.
azure_set_web_app_configuration
Pro · Destructive
Update a web app's site configuration.
azure_set_web_app_settings
Pro · Destructive
Replace a web app's ENTIRE application settings collection.
azure_start_web_app
Pro · Write
Start a stopped web app.
azure_stop_web_app
Pro · Destructive
Stop a web app.
azure_swap_web_app_slots
Pro · Destructive
Swap a deployment slot into production.

SQL

ToolWhat it does
azure_create_sql_database
Pro · Write
Create an empty database on a SQL logical server.
azure_create_sql_elastic_pool
Pro · Write
Create an elastic pool, or update an existing pool's capacity and per-database limits.
azure_create_sql_firewall_rule
Pro · Destructive
Create or replace an IP firewall rule on a SQL logical server.
azure_create_sql_server
Pro · Write
Create an Azure SQL logical server, or update an existing one's TLS floor and public network access.
azure_create_sql_virtual_network_rule
Pro · Destructive
Allow a subnet to reach a SQL logical server, or replace an existing rule of the same name.
azure_delete_sql_database
Pro · Destructive
Delete a database.
azure_delete_sql_elastic_pool
Pro · Destructive
Delete an elastic pool.
azure_delete_sql_firewall_rule
Pro · Destructive
Delete an IP firewall rule from a SQL logical server.
azure_delete_sql_server
Pro · Destructive
Delete an Azure SQL logical server AND EVERY DATABASE AND ELASTIC POOL UNDER IT.
azure_delete_sql_virtual_network_rule
Pro · Destructive
Remove a subnet's access to a SQL logical server.
azure_failover_sql_database
Pro · Destructive
Force a failover of a database to another replica.
azure_get_sql_database
Free · Read-only
Get one database in full: sku and tier, status, maxSizeBytes, currentBackupStorageRedundancy, zoneRedundant, readScale, autoPauseDelay and minCapacity for serverless, the elastic pool it belongs to, creationDate and earliestRestoreDate.
azure_get_sql_database_backup_retention
Free · Read-only
Read a database's SHORT-TERM backup retention — retentionDays, which is how far back a point-in-time restore can reach, and diffBackupIntervalInHours.
azure_get_sql_database_encryption
Free · Read-only
Report whether Transparent Data Encryption is enabled on a database — the state of encryption at rest, which is what a compliance questionnaire is asking about.
azure_get_sql_database_long_term_retention
Free · Read-only
Read a database's LONG-TERM retention policy: weeklyRetention, monthlyRetention, yearlyRetention and weekOfYear, as ISO-8601 durations such as P4W, P12M or P7Y.
azure_get_sql_elastic_pool
Free · Read-only
Get one elastic pool in full: sku and capacity, perDatabaseSettings, maxSizeBytes, licenseType, zoneRedundant and creationDate.
azure_get_sql_server
Free · Read-only
Get one Azure SQL logical server in full: fullyQualifiedDomainName (the host a connection string points at), administratorLogin, administrators (the Entra admin and whether Entra-only authentication is on), version, minimalTlsVersion, publicNetworkAccess, restrictOutboundNetworkAccess and any assigned managed identity.
azure_get_sql_server_auditing_settings
Free · Read-only
Read a SQL logical server's auditing policy: whether auditing is Enabled, which action groups are captured, how many days of audit records are retained, whether events go to Azure Monitor, and the storage endpoint they are written to.
azure_list_sql_database_restore_points
Free · Read-only
List a database's discrete restore points, each with its restorePointType, earliestRestoreDate and creation time.
azure_list_sql_databases
Free · Read-only
List every database on a SQL logical server, each with its sku (tier and capacity), status, maxSizeBytes, collation, zoneRedundant flag, elasticPoolId when it is pooled, and the earliestRestoreDate that bounds any point-in-time restore.
azure_list_sql_elastic_pools
Free · Read-only
List a SQL logical server's elastic pools with each one's sku and capacity, perDatabaseSettings (the minimum and maximum capacity any single database may take), maxSizeBytes and zoneRedundant flag.
azure_list_sql_firewall_rules
Free · Read-only
List a SQL logical server's IP firewall rules, each with its start and end address.
azure_list_sql_server_entra_admins
Free · Read-only
List the Microsoft Entra administrators configured on a SQL logical server — the login name, the object id of the user or group, and the directory the principal comes from.
azure_list_sql_servers
Free · Read-only
List every Azure SQL logical server in a subscription, with each one's fully qualified domain name, administrator login, version, minimalTlsVersion, publicNetworkAccess and state.
azure_list_sql_servers_in_resource_group
Free · Read-only
List the Azure SQL logical servers inside one resource group.
azure_list_sql_virtual_network_rules
Free · Read-only
List a SQL logical server's virtual network rules — each one naming a subnet that is allowed to reach the server without any IP firewall rule.
azure_pause_sql_database
Pro · Destructive
Pause a Data Warehouse / dedicated SQL pool database so it stops billing for compute.
azure_restore_sql_database
Pro · Destructive
Restore a database to a point in time, as a NEW database alongside the original.
azure_resume_sql_database
Pro · Write
Resume a paused Data Warehouse / dedicated SQL pool database.
azure_scale_sql_database
Pro · Destructive
Change a database's service tier, compute size or maximum size.
azure_set_sql_database_backup_retention
Pro · Destructive
Set a database's short-term backup retention in days.
azure_set_sql_server_admin_password
Pro · Destructive
Reset the SQL administrator password on a logical server.

AKS

ToolWhat it does
azure_delete_aks_cluster
Pro · Destructive
Delete an AKS cluster and everything AKS created for it — every node pool, and the entire auto-generated node resource group with its virtual machines, managed disks, load balancers and public IPs.
azure_delete_aks_node_pool
Pro · Destructive
Delete a node pool and every node in it.
azure_get_aks_cluster
Free · Read-only
Get one AKS cluster in full: both version fields, every agent pool profile inline, the network profile (plugin, policy, service and pod CIDRs, outbound type), identity and RBAC configuration, apiServerAccessProfile, addonProfiles, autoUpgradeProfile and the fqdn.
azure_get_aks_cluster_upgrade_profile
Free · Read-only
Report what a cluster's control plane can upgrade TO: its current version, whether that version is still supported, and every available upgrade with its isPreview flag.
azure_get_aks_command_result
Free · Read-only
Fetch the result of a command started by azure_run_aks_command: its provisioningState, exitCode, startedAt and finishedAt, and the command's combined output as text.
azure_get_aks_node_pool
Free · Read-only
Get one node pool in full: count and the autoscaler's min and max, vmSize, both orchestrator version fields, nodeImageVersion, os disk size and type, maxPods, node labels and taints, upgradeSettings.maxSurge and provisioningState.
azure_get_aks_node_pool_upgrade_profile
Free · Read-only
Report what one node pool can upgrade to: its current Kubernetes and node image versions, its OS type, and the available upgrade versions with their isPreview flags.
azure_list_aks_cluster_admin_credentials
Pro · Destructive
Return a cluster's ADMIN kubeconfig, base64-encoded.
azure_list_aks_cluster_monitoring_credentials
Pro · Destructive
Return the MONITORING user's kubeconfig for a cluster, base64-encoded.
azure_list_aks_cluster_user_credentials
Pro · Destructive
Return a cluster's USER kubeconfig, base64-encoded.
azure_list_aks_clusters
Free · Read-only
List every AKS cluster in a subscription with its kubernetesVersion, currentKubernetesVersion, provisioningState, powerState, node resource group, SKU tier and API-server access profile.
azure_list_aks_clusters_in_resource_group
Free · Read-only
List the AKS clusters inside one resource group.
azure_list_aks_kubernetes_versions
Free · Read-only
List the Kubernetes versions AKS offers in one Azure region, each with its patch versions, support plan, isPreview flag and whether it is the default.
azure_list_aks_node_pools
Free · Read-only
List a cluster's node pools with each one's count, vmSize, mode (System or User), orchestratorVersion, currentOrchestratorVersion, nodeImageVersion, osType, osSKU, autoscaling settings, spot priority and provisioningState.
azure_rotate_aks_cluster_certificates
Pro · Destructive
Rotate a cluster's certificates and, with them, every kubeconfig ever issued for it.
azure_run_aks_command
Pro · Destructive
Run a kubectl or helm command inside a cluster through the AKS run-command channel.
azure_start_aks_cluster
Pro · Write
Start a stopped AKS cluster.
azure_stop_aks_cluster
Pro · Destructive
Stop an AKS cluster: the control plane is preserved and every node is DEALLOCATED.
azure_update_aks_cluster_tags
Pro · Write
Replace an AKS cluster's tags.
azure_upgrade_aks_node_pool_image
Pro · Destructive
Upgrade a node pool to the latest node IMAGE — the OS and runtime patches — without changing its Kubernetes version.

RBAC

ToolWhat it does
azure_create_custom_role_definition
Pro · Destructive
Create a custom role, or REPLACE an existing one with the same GUID.
azure_create_role_assignment
Pro · Destructive
Grant a role to an Entra principal at a scope.
azure_delete_role_assignment
Pro · Destructive
Remove a role assignment.
azure_delete_role_definition
Pro · Destructive
Delete a custom role definition.
azure_find_role_definition_by_name
Free · Read-only
Find a role definition by its exact display name, e.g. Contributor, Reader, Storage Blob Data Reader.
azure_get_role_assignment
Free · Read-only
Get one role assignment by its name (a GUID) at a scope.
azure_get_role_definition
Free · Read-only
Get one role definition by its GUID, with the full permissions arrays and assignableScopes.
azure_list_deny_assignments
Free · Read-only
List the deny assignments at a scope, each with the actions it blocks, the principals it applies to and any it excludes.
azure_list_deny_assignments_for_principal
Free · Read-only
List the deny assignments that apply to one user or service principal.
azure_list_role_assignments
Free · Read-only
List the role assignments at a scope: who (principalId and principalType) holds which role (roleDefinitionId) over what (scope), plus createdOn and createdBy and any ABAC condition.
azure_list_role_assignments_for_principal
Free · Read-only
List every role assignment held by one Entra principal — a user, group, service principal or managed identity — at, above or below a scope.
azure_list_role_assignments_for_resource
Free · Read-only
List the role assignments that apply to ONE specific resource — a storage account, a key vault, a virtual machine — including everything inherited from its resource group and subscription.
azure_list_role_definitions
Free · Read-only
List the role definitions available at a scope — every built-in Azure role plus any custom roles defined at or above it — with each one's roleName, description, type, permissions (actions, notActions, dataActions, notDataActions) and assignableScopes.

Policy

ToolWhat it does
azure_create_policy_assignment
Pro · Destructive
Assign a policy definition or initiative to a scope.
azure_delete_policy_assignment
Pro · Destructive
Remove a policy assignment.
azure_get_policy_assignment
Free · Read-only
Get one policy assignment in full: the definition or initiative it assigns, every parameter value, its scope and notScopes, enforcementMode, nonComplianceMessages and any managed identity it runs remediation as.
azure_get_policy_definition
Free · Read-only
Get one policy definition with its full policyRule — the if/then that decides which resources match and what happens when they do.
azure_get_policy_initiative
Free · Read-only
Get one policy initiative with every policy definition it contains, each with its policyDefinitionReferenceId and the parameter values the initiative passes down.
azure_list_policy_assignments
Free · Read-only
List the policy assignments in effect at a scope, each with the definition or initiative it assigns, its parameters, enforcementMode, notScopes and any managed identity.
azure_list_policy_assignments_for_resource
Free · Read-only
List the policy assignments that apply to ONE specific resource, including everything inherited from its resource group, subscription and management groups.
azure_list_policy_definitions
Free · Read-only
List the policy definitions available to a subscription — every built-in Azure policy plus the customer's own custom ones — with each definition's displayName, policyType, mode, description, parameters and the policyRule itself.
azure_list_policy_initiatives
Free · Read-only
List the policy INITIATIVES (policy set definitions) available to a subscription — named bundles of policy definitions assigned as one unit.
azure_set_policy_assignment_enforcement
Pro · Destructive
Switch a policy assignment between Default (enforcing) and DoNotEnforce (report-only).

Resource Health

ToolWhat it does
azure_get_resource_health
Free · Read-only
Get the CURRENT health of one Azure resource as Azure's own platform probes see it, not as its configuration claims.
azure_get_service_health_event
Free · Read-only
Get one service health event in full by its tracking id, including the complete communication history Microsoft has posted against it.
azure_list_emerging_issues
Free · Read-only
List Azure's EMERGING issues — problems Microsoft has noticed and published on the Azure status page but has not yet turned into a per-subscription service health event.
azure_list_resource_group_resource_health
Free · Read-only
List the current health of every probed resource inside ONE resource group.
azure_list_resource_health_history
Free · Read-only
List the health TRANSITIONS for one resource over time, newest first — every move between Available, Unavailable, Degraded and Unknown, each with its reason and timestamp.
azure_list_service_health_events
Free · Read-only
List Microsoft's own declared service health events for a subscription — active incidents, planned maintenance, health advisories and security advisories, each with a tracking id, the affected regions and services, and Microsoft's current status update.
azure_list_service_health_impacted_resources
Free · Read-only
List the customer's own resources that Microsoft has identified as impacted by a specific service health event.
azure_list_subscription_resource_health
Free · Read-only
List the current health of EVERY resource in a subscription that Azure health-probes, in one call.

Defender for Cloud

ToolWhat it does
azure_create_jit_network_access_policy
Pro · Destructive
Create or replace a just-in-time VM access policy.
azure_delete_jit_network_access_policy
Pro · Destructive
Delete a just-in-time access policy.
azure_delete_security_contact
Pro · Destructive
Remove a security contact configuration from a subscription.
azure_get_defender_plan
Free · Read-only
Get one Defender plan in full, including the extensions array that the list view summarises.
azure_get_jit_network_access_policy
Free · Read-only
Get one just-in-time access policy in full: every protected virtual machine, every port rule on it, and every currently open request with its requestor, source address, mapped port and expiry.
azure_get_security_alert
Free · Read-only
Get one security alert with everything the list view truncates — the full entities array, extendedProperties, supportingEvidence and extendedLinks to any threat-intelligence report behind it.
azure_get_security_assessment
Free · Read-only
Get ONE Defender for Cloud assessment for ONE specific resource — the answer to "is this particular VM, storage account or SQL database passing this particular recommendation, and if not, what exactly should be done about it?".
azure_list_defender_plans
Free · Read-only
List every Microsoft Defender for Cloud plan on a subscription with its pricingTier (Free or Standard), subPlan, enabled extensions, enablementTime and freeTrialRemainingTime.
azure_list_jit_network_access_policies
Free · Read-only
List the just-in-time VM access policies in a subscription or resource group.
azure_list_regulatory_compliance_assessments
Free · Read-only
List the assessments that decide one regulatory control's outcome, each with the underlying Defender recommendation it maps to, its state, and counts of passed, failed and skipped RESOURCES.
azure_list_regulatory_compliance_controls
Free · Read-only
List the individual controls inside one regulatory standard — the numbered clauses an auditor works through, such as PCI DSS 1.2.1 or ISO 27001 A.9.2.3 — each with its description, state and counts of passed, failed and skipped assessments.
azure_list_regulatory_compliance_standards
Free · Read-only
List the regulatory compliance standards Defender for Cloud is tracking for a subscription — PCI DSS, ISO 27001, SOC 2, NIST SP 800-53, CIS and whatever else has been applied — each with a state of Passed, Failed, Skipped or Unsupported and counts of passed, failed and skipped controls.
azure_list_security_alerts
Free · Read-only
List the Defender for Cloud security alerts on a subscription or resource group — the actual detections, not the recommendations: brute-force attempts, suspicious process execution, crypto-mining, malware uploads, anomalous data access.
azure_list_security_assessment_metadata
Free · Read-only
List the DEFINITIONS of every recommendation available to a subscription — every built-in Microsoft one plus any the customer added — with displayName, description, severity, remediationDescription, categories, threats, implementationEffort, userImpact, assessmentType and the policyDefinitionId that switches each one on.
azure_list_security_assessments
Free · Read-only
List every Defender for Cloud assessment in a subscription — one row PER RESOURCE PER RECOMMENDATION, each with the assessed resource's id, the recommendation's displayName and a status of Healthy, Unhealthy or NotApplicable.
azure_list_security_contacts
Free · Read-only
List the security contact configurations on a subscription — who Defender for Cloud emails when it detects something, at what minimum severity, and whether the notification is on at all.
azure_list_security_locations
Free · Read-only
Get the ASC location for a subscription — the single home region where Defender for Cloud stores that subscription's alerts and just-in-time policies.
azure_list_security_secure_score_controls
Free · Read-only
List the security CONTROLS behind a secure score — each one a themed group of recommendations such as "Enable MFA", "Remediate vulnerabilities" or "Restrict unauthorized network access" — with its current and maximum score, its weight, and how many resources are healthy, unhealthy or not applicable.
azure_list_security_secure_scores
Free · Read-only
List the Defender for Cloud secure scores for a subscription — for each security initiative, the current score, the maximum available and the percentage between them.
azure_list_security_sub_assessments
Free · Read-only
List the INDIVIDUAL FINDINGS behind Defender's assessments — the actual CVEs on a machine, the specific container image vulnerabilities, the SQL vulnerability-assessment rule failures — each with its id, displayName, description, severity, impact, remediation text and additionalData carrying the CVE list, CVSS scores and patchable status.
azure_request_jit_access
Pro · Destructive
Request just-in-time access to a virtual machine's management ports.
azure_set_defender_plan
Pro · Destructive
Turn a Defender for Cloud plan on or off for a subscription.
azure_set_security_alert_state
Pro · Write
Move a security alert between the four states Defender for Cloud defines: activate (back to Active), inProgress (someone is working it), resolve (handled, a true positive that was dealt with) and dismiss (a false positive).
azure_set_security_contact
Pro · Destructive
Set who Defender for Cloud emails about security alerts on a subscription.

Deployments

ToolWhat it does
azure_cancel_deployment
Pro · Destructive
Cancel a deployment that is still running.
azure_create_deployment
Pro · Destructive
Deploy an ARM or Bicep-compiled template to a resource group, or to the subscription itself when resourceGroupName is omitted.
azure_delete_deployment
Pro · Destructive
Delete a deployment from the history.
azure_export_deployment_template
Free · Read-only
Export the template EXACTLY AS IT WAS DEPLOYED, from the deployment history.
azure_get_deployment
Free · Read-only
Get one deployment in full: its mode, provisioningState, timestamp and duration, the templateLink or templateHash it ran from, every parameter value it was given, its outputs, the providers and resource ids it touched, and its error object when it failed.
azure_get_deployment_operation
Free · Read-only
Get ONE operation from a deployment by its operation id, when azure_list_deployment_operations returned too much to read or the interesting entry was truncated.
azure_list_deployment_operations
Free · Read-only
List the individual resource operations that made up one deployment.
azure_list_deployments
Free · Read-only
List the deployment history at a scope — every ARM or Bicep template deployment recorded against a resource group, or against the subscription itself when resourceGroupName is omitted.
azure_validate_deployment
Free · Read-only
Validate a template without deploying it: ARM parses the template, resolves its parameters, variables and functions, hands each resource declaration to its resource provider for semantic checks, and confirms the caller has permission to create what the template declares.
azure_whatif_deployment
Free · Read-only
Predict what a template WOULD do, without deploying it.

Management Groups

ToolWhat it does
azure_add_subscription_to_management_group
Pro · Destructive
Attach an existing subscription to a management group.
azure_check_management_group_name_availability
Free · Read-only
Check whether a management group id is valid and still free BEFORE creating one.
azure_create_management_group
Pro · Write
Create a management group, optionally under a named parent.
azure_delete_management_group
Pro · Destructive
Delete a management group.
azure_get_management_group
Free · Read-only
Get one management group: name, displayName, tenantId and details — the parent group, a version number and who last changed it.
azure_get_management_group_descendants
Free · Read-only
List EVERY entity descending from a management group — child management groups and subscriptions, at any depth — as one flat, PAGED list.
azure_list_management_group_entities
Free · Read-only
List every entity — management groups AND subscriptions — the signed-in user can see across a directory, with the fields the plain listings do not carry: parentNameChain and parentDisplayNameChain (the full path from the tenant root to each node), numberOfChildren, numberOfChildGroups, numberOfDescendants, and this user's own permissions and inheritedPermissions on each node (noaccess, view, edit or delete).
azure_list_management_group_subscriptions
Free · Read-only
List the subscriptions attached DIRECTLY to one management group — the ones this group's own policy and role assignments reach first-hand, as opposed to the whole subtree that azure_get_management_group_descendants returns.
azure_list_management_groups
Free · Read-only
List the management groups in a directory — the containers ABOVE subscriptions, and the scope at which Azure Policy assignments and RBAC role assignments are INHERITED by everything beneath them.
azure_move_management_group
Pro · Destructive
Move a management group to a different parent.
azure_remove_subscription_from_management_group
Pro · Destructive
Detach a subscription from a management group.

Disks & Snapshots

ToolWhat it does
azure_create_or_update_disk
Pro · Write
Create a managed disk, or replace an existing one's model wholesale.
azure_create_or_update_image
Pro · Write
Create a custom managed image from a generalized virtual machine, from managed disks or from snapshots, or replace an existing image's model.
azure_create_or_update_snapshot
Pro · Write
Take a point-in-time snapshot of a managed disk, or replace an existing snapshot's model.
azure_delete_disk
Pro · Destructive
DELETE a managed disk.
azure_delete_image
Pro · Destructive
DELETE a custom managed image.
azure_delete_snapshot
Pro · Destructive
DELETE a disk snapshot.
azure_get_disk
Free · Read-only
Get one managed disk in full: sku, diskSizeGB, diskIOPSReadWrite and diskMBpsReadWrite, osType, hyperVGeneration, encryption and encryptionSettingsCollection, networkAccessPolicy and publicNetworkAccess, maxShares, zones, tags and diskState.
azure_get_image
Free · Read-only
Get one custom managed image in full: hyperVGeneration, sourceVirtualMachine, provisioningState and the complete storageProfile — the OS disk with its osType, osState, diskSizeGB and storage account type, plus every data disk with its LUN.
azure_get_snapshot
Free · Read-only
Get one disk snapshot in full: sku, diskSizeGB, osType, hyperVGeneration, encryption, incremental, diskState, networkAccessPolicy and the creationData block naming the source disk and how the snapshot was made.
azure_grant_disk_access
Pro · Destructive
Mint a time-limited SAS URI that allows the raw contents of a managed disk to be downloaded or uploaded over the internet.
azure_grant_snapshot_access
Pro · Destructive
Mint a time-limited SAS URI that allows the raw contents of a disk snapshot to be downloaded over the internet.
azure_list_disks
Free · Read-only
List every managed disk in a subscription, across all resource groups.
azure_list_disks_in_resource_group
Free · Read-only
List the managed disks inside one resource group.
azure_list_images
Free · Read-only
List the customer's OWN managed images in a subscription — the gold builds captured from their machines, not Microsoft's marketplace catalogue.
azure_list_snapshots
Free · Read-only
List every disk snapshot in a subscription — the point-in-time copies that are a customer's cheapest and most immediate restore path when one exists.
azure_resize_disk
Pro · Destructive
Grow a managed disk to a new size in gibibytes.
azure_revoke_disk_access
Pro · Write
Revoke every SAS URI previously granted over a managed disk, immediately.
azure_revoke_snapshot_access
Pro · Write
Revoke every SAS URI previously granted over a disk snapshot, immediately.
azure_set_disk_sku
Pro · Destructive
Change a managed disk's performance SKU, and optionally its performance tier.

Virtual Machine Scale Sets

ToolWhat it does
azure_deallocate_vm_scale_set
Pro · Destructive
Deallocate EVERY INSTANCE in a scale set — shut them all down AND release their compute, which is what stops the compute bill for the whole fleet.
azure_deallocate_vm_scale_set_instance
Pro · Destructive
Deallocate ONE instance in a scale set — shut it down AND release its compute, which stops that instance's compute bill.
azure_delete_vm_scale_set
Pro · Destructive
DELETE an entire scale set and EVERY instance in it.
azure_delete_vm_scale_set_instances
Pro · Destructive
DELETE the named instances from a scale set, permanently.
azure_get_vm_scale_set
Free · Read-only
Get one scale set's full MODEL — the desired state the fleet is built from: sku (VM size, tier and capacity), orchestrationMode, upgradePolicy (Manual, Automatic or Rolling, plus the rolling-upgrade policy), scaleInPolicy (which instances Azure removes first when scaling in), automaticRepairsPolicy, the virtualMachineProfile with its image reference, OS profile, network profile, extension profile and health probe, singlePlacementGroup, overprovision, zones and tags.
azure_get_vm_scale_set_instance
Free · Read-only
Get ONE instance inside a scale set by its instance id — that machine's own model: its resolved hardware profile, storage profile with the managed-disk ids actually attached to it, network profile with its NIC and IP configuration, its zone, and properties.latestModelApplied telling you whether it is running the current scale set model or an older one.
azure_get_vm_scale_set_instance_status
Free · Read-only
Get ONE instance's RUNTIME state — this is the tool that answers "is this particular node up?".
azure_get_vm_scale_set_instance_view
Free · Read-only
Get the WHOLE SET's runtime rollup — ARM's instanceView on the scale set itself.
azure_get_vm_scale_set_rolling_upgrade
Free · Read-only
Get the status of the most recent ROLLING UPGRADE on a scale set — the batch-by-batch roll-out Azure performs when upgradePolicy.mode is Rolling or when an automatic OS upgrade runs.
azure_list_vm_scale_set_instances
Free · Read-only
List the individual virtual machines INSIDE one scale set.
azure_list_vm_scale_set_os_upgrade_history
Free · Read-only
List the history of AUTOMATIC OS IMAGE UPGRADES on a scale set — one entry per upgrade Azure has run, with properties.runningStatus (code, startTime, endTime), properties.progress (successful, failed, in-progress and pending instance counts), properties.startedBy (Platform when Azure initiated it, User when a person did), and properties.targetImageReference naming the image version the fleet was moved to.
azure_list_vm_scale_set_skus
Free · Read-only
List the SKUs available to THIS scale set, each with a capacity block giving minimum, maximum and defaultCapacity.
azure_list_vm_scale_sets
Free · Read-only
List every virtual machine scale set in a subscription, across all resource groups.
azure_list_vm_scale_sets_in_resource_group
Free · Read-only
List the virtual machine scale sets inside one resource group.
azure_power_off_vm_scale_set
Pro · Destructive
Power off (stop) EVERY INSTANCE in a scale set, leaving them ALLOCATED.
azure_power_off_vm_scale_set_instance
Pro · Destructive
Power off (stop) ONE instance in a scale set, leaving it ALLOCATED and leaving every other instance running.
azure_reimage_vm_scale_set
Pro · Destructive
Reimage EVERY INSTANCE in a scale set — reset every machine's OS disk back to the original image.
azure_reimage_vm_scale_set_instance
Pro · Destructive
Reimage ONE instance in a scale set — reset that machine's OS disk back to the original image.
azure_restart_vm_scale_set
Pro · Destructive
Restart EVERY INSTANCE in a scale set at once.
azure_restart_vm_scale_set_instance
Pro · Destructive
Restart ONE instance in a scale set.
azure_scale_vm_scale_set
Pro · Destructive
Set a scale set's instance count.
azure_set_vm_scale_set_tags
Pro · Write
Set the tags on a scale set, leaving every other property untouched.
azure_start_vm_scale_set
Pro · Write
Start (power on) EVERY instance in a scale set.
azure_start_vm_scale_set_instance
Pro · Write
Start (power on) ONE instance in a scale set, leaving every other instance alone.

Containers

ToolWhat it does
azure_delete_container_group
Pro · Destructive
Delete a container group.
azure_delete_container_registry
Pro · Destructive
Delete a container registry and EVERY image in it.
azure_get_container_group
Pro · Destructive
Get one container group in full, including each container's instanceView with its currentState, previousState, restartCount and the group's recent events.
azure_get_container_logs
Free · Read-only
Read one container's stdout and stderr — the call an engineer actually wants when an ACI workload misbehaves, and the reason this family is worth having.
azure_get_container_registry
Free · Read-only
Get one container registry in full: sku, loginServer, adminUserEnabled, anonymousPullEnabled, identity, encryption, networkRuleSet with its ip rules and defaultAction, networkRuleBypassOptions, publicNetworkAccess, privateEndpointConnections, dataEndpointEnabled, zoneRedundancy and the policies block.
azure_list_acr_credentials
Pro · Destructive
Return a registry's ADMIN username and both passwords in plaintext.
azure_list_acr_webhooks
Free · Read-only
List a registry's webhooks with each one's actions, scope, status and provisioningState — the notifications the registry fires when an image is pushed, deleted or quarantined, and therefore the list of automated systems that react to this registry.
azure_list_container_groups
Pro · Destructive
List every Azure Container Instances container group in a subscription, each with its containers and their images, resource requests, ports and instanceView state, plus the group's osType, restartPolicy, ipAddress, sku, priority, provisioningState and subnetIds.
azure_list_container_groups_in_resource_group
Pro · Destructive
List the container groups inside one resource group.
azure_list_container_registries
Free · Read-only
List every Azure Container Registry in a subscription with each one's sku, loginServer, adminUserEnabled, anonymousPullEnabled, publicNetworkAccess, provisioningState and creation date.
azure_list_container_registries_in_resource_group
Free · Read-only
List the container registries inside one resource group.
azure_regenerate_acr_credential
Pro · Destructive
Regenerate one of a registry's two admin passwords and return the new value.
azure_restart_container_group
Pro · Destructive
Restart every container in a group in place.
azure_start_container_group
Pro · Write
Start a stopped container group.
azure_stop_container_group
Pro · Destructive
Stop a container group: every container halts and the compute is deallocated.

DNS

ToolWhat it does
azure_create_dns_record_set
Pro · Destructive
Create or REPLACE a record set in a public DNS zone.
azure_create_dns_zone
Pro · Write
Create a public DNS zone, or update an existing one's tags.
azure_create_private_dns_record_set
Pro · Destructive
Create or REPLACE a record set in a private DNS zone.
azure_create_private_dns_virtual_network_link
Pro · Destructive
Link a virtual network to a private DNS zone, or update an existing link.
azure_create_private_dns_zone
Pro · Write
Create a private DNS zone, or update an existing one's tags.
azure_delete_dns_record_set
Pro · Destructive
Delete a record set from a public DNS zone.
azure_delete_dns_zone
Pro · Destructive
Delete a public DNS zone AND every record set inside it, in one call.
azure_delete_private_dns_record_set
Pro · Destructive
Delete a record set from a private DNS zone.
azure_delete_private_dns_virtual_network_link
Pro · Destructive
Remove a virtual network link from a private DNS zone.
azure_delete_private_dns_zone
Pro · Destructive
Delete a private DNS zone and every record set inside it.
azure_get_dns_record_set
Free · Read-only
Get one record set by type and name, with its records, TTL, fqdn, metadata and etag.
azure_get_dns_zone
Free · Read-only
Get one public DNS zone: its nameServers, numberOfRecordSets, maxNumberOfRecordSets, tags and etag.
azure_get_private_dns_record_set
Free · Read-only
Get one record set from a private DNS zone by type and name, with its records, ttl, fqdn, isAutoRegistered flag and etag.
azure_get_private_dns_virtual_network_link
Free · Read-only
Get one virtual network link: the virtual network it points at, its registrationEnabled flag, provisioningState, virtualNetworkLinkState, tags and etag.
azure_get_private_dns_zone
Free · Read-only
Get one private DNS zone with its record-set and virtual-network-link counts, tags, provisioningState and etag.
azure_list_dns_record_sets
Free · Read-only
List the record sets in a public DNS zone — every type at once, or a single type when recordType is given.
azure_list_dns_zones
Free · Read-only
List the PUBLIC DNS zones in a subscription, or in one resource group when resourceGroupName is given.
azure_list_private_dns_record_sets
Free · Read-only
List the record sets in a private DNS zone — every type at once, or one type when recordType is given.
azure_list_private_dns_virtual_network_links
Free · Read-only
List the virtual network links on a private DNS zone.
azure_list_private_dns_zones
Free · Read-only
List the PRIVATE DNS zones in a subscription, or in one resource group when resourceGroupName is given.

Key Vault

ToolWhat it does
azure_check_key_vault_name_availability
Free · Read-only
Check whether a key vault name is valid and still free.
azure_create_key_vault
Pro · Destructive
Create a key vault.
azure_delete_key_vault
Pro · Destructive
Delete a key vault.
azure_get_deleted_key_vault
Free · Read-only
Get one soft-deleted key vault: the resource id it had, its deletionDate, its scheduledPurgeDate, its tags and whether purgeProtectionEnabled was set.
azure_get_key_vault
Free · Read-only
Get one key vault in full: SKU, the Entra tenant it authenticates against, enableRbacAuthorization, enableSoftDelete, softDeleteRetentionInDays, enablePurgeProtection, publicNetworkAccess, the complete networkAcls rule set, every private endpoint connection, and — when the vault is in legacy mode — the entire accessPolicies array with each identity's key, secret and certificate permissions.
azure_get_key_vault_key_metadata
Free · Read-only
Get one key's PROPERTIES: type, size or curve, permitted operations, whether it is enabled, its not-before and expiry dates, whether it is marked exportable, and its rotation policy with the lifetime actions that drive automatic rotation.
azure_get_key_vault_secret_metadata
Free · Read-only
Get one secret's PROPERTIES: contentType, whether it is enabled, its not-before and expiry dates, its tags and its identifier URI.
azure_list_deleted_key_vaults
Free · Read-only
List the soft-deleted key vaults in a subscription, each with the location it lived in, its deletionDate, its scheduledPurgeDate and whether purge protection was on.
azure_list_key_vault_keys
Free · Read-only
List the keys in a vault by NAME and PROPERTIES — key type (RSA, EC, and the -HSM variants), key size or curve, the permitted keyOps, attributes.enabled, attributes.exp and attributes.nbf, the rotation policy, and the key's identifier URI.
azure_list_key_vault_secrets
Free · Read-only
List the secrets in a vault by NAME and PROPERTIES — contentType, attributes.enabled, attributes.exp, attributes.nbf, tags and the secret's identifier URI.
azure_list_key_vaults
Free · Read-only
List the key vaults in a subscription, or in one resource group, each with its location, SKU, tags and full properties.
azure_purge_deleted_key_vault
Pro · Destructive
Permanently destroy a soft-deleted key vault.
azure_set_key_vault_secret_enabled
Pro · Destructive
Enable or disable one secret, by setting its enabled flag and nothing else.
azure_update_key_vault_access_policy
Pro · Destructive
Add, replace or remove a legacy access-policy entry on a key vault.
azure_update_key_vault_network_rules
Pro · Destructive
Replace a key vault's firewall rules — the default action, the trusted-services bypass, the allowed IP ranges and the allowed virtual network subnets — and optionally its public network access.
azure_update_key_vault_tags
Pro · Write
Set the tags on a key vault.

Backup

ToolWhat it does
azure_create_backup_policy
Pro · Destructive
Create a backup policy, or REPLACE an existing one's schedule and retention.
azure_create_recovery_services_vault
Pro · Write
Create a Recovery Services vault, or update an existing one's tags and properties.
azure_delete_backup_policy
Pro · Destructive
Delete a backup policy.
azure_delete_recovery_services_vault
Pro · Destructive
Delete a Recovery Services vault.
azure_enable_backup_protection
Pro · Destructive
Protect an item with a backup policy — and, because ARM models both with the same call, RE-POINT an already-protected item at a DIFFERENT policy.
azure_get_backup_job
Free · Read-only
Get one backup or restore job with its full extended info: the per-task breakdown, transferred bytes, progress percentage, the localized error string and — the field that actually resolves tickets — the recommendations list Azure attaches to each error code.
azure_get_backup_policy
Free · Read-only
Get one backup policy with its complete schedule and retention definition — daily, weekly, monthly and yearly retention durations, the instant-restore snapshot window, the timezone the schedule runs in, and how many items are bound to it.
azure_get_backup_protected_item
Free · Read-only
Get one protected item in full: its policy binding, protectionState, health status, last backup result and error, the source resource it backs up, the oldest and newest recovery point times, and for VMs the list of disks included in or excluded from the backup.
azure_get_backup_recovery_point
Free · Read-only
Get one recovery point with everything the list response leaves out: the full disk configuration including which LUNs were included and excluded, the immutability and soft-delete state of the point itself, its expiry time, and for SQL and SAP HANA the data-directory paths a restore has to map.
azure_get_recovery_services_vault
Free · Read-only
Get one Recovery Services vault in full: sku, provisioningState, redundancy configuration, cross-region restore state, encryption settings, public network access and any managed identity.
azure_list_backup_jobs
Free · Read-only
List a vault's backup, restore, configure-backup and delete-backup-data jobs, each with its operation, status, entityFriendlyName, startTime, endTime, duration and error details.
azure_list_backup_policies
Free · Read-only
List a vault's backup policies — the schedules and retention rules every protected item is bound to — each with its backupManagementType, schedulePolicy, retentionPolicy and protectedItemsCount.
azure_list_backup_protected_items
Free · Read-only
List everything a vault is protecting — VMs, file shares, SQL and SAP HANA databases, on-premises servers — each with its friendlyName, protectionStatus, protectionState, lastBackupStatus, lastBackupTime, the policy it is bound to and its containerName.
azure_list_backup_protection_containers
Free · Read-only
List the protection containers registered with a vault — the VMs, storage accounts, SQL-in-VM hosts, MABS/DPM servers and on-premises machines that hold the things being backed up.
azure_list_backup_recovery_points
Free · Read-only
List the recovery points (backup copies) held for one protected item, each with its recoveryPointTime, recoveryPointType, tier details and — for VMs — the disk configuration captured at that moment.
azure_list_backup_usage_summaries
Free · Read-only
Get a vault's usage summary — how many protected items or registered containers it holds, broken down by backup management type.
azure_list_recovery_services_vaults
Free · Read-only
List the Recovery Services vaults in a subscription, or in one resource group, with each vault's location, sku, provisioningState, redundancy settings and any managed identity.
azure_stop_backup_protection_delete_data
Pro · Destructive
Stop backing up an item AND PERMANENTLY DESTROY EVERY RECOVERY POINT IT HAS.
azure_stop_backup_protection_retain_data
Pro · Destructive
Stop backing up an item but KEEP every recovery point it already has.
azure_trigger_backup
Pro · Write
Run an on-demand backup of a protected item right now.
azure_trigger_backup_restore
Pro · Destructive
Restore from a recovery point.
azure_unregister_backup_container
Pro · Destructive
Unregister a protection container from a vault — a storage account, a SQL-in-VM or SAP HANA host, or an on-premises MABS/DPM server.

Automation

ToolWhat it does
azure_create_automation_account
Pro · Write
Create an Automation account.
azure_create_automation_schedule
Pro · Write
Create a schedule.
azure_delete_automation_account
Pro · Destructive
Delete an Automation account.
azure_delete_automation_schedule
Pro · Destructive
Delete a schedule.
azure_delete_runbook
Pro · Destructive
Delete a runbook.
azure_get_automation_account
Free · Read-only
Get one Automation account in full: its sku, state, creation and last-modified times, encryption settings, publicNetworkAccess, disableLocalAuth and — the field that matters most before you start anything — its identity.
azure_get_automation_job
Free · Read-only
Get one Automation job: its status, statusDetails, exception, the runbook it ran, the exact parameters it was given, its jobId, runOn, startedBy and the full timeline of creation, start, end and lastStatusModifiedTime.
azure_get_automation_job_stream
Free · Read-only
Get ONE job stream record in full, including streamText — the untruncated line the runbook wrote, which azure_list_automation_job_streams only summarises.
azure_get_automation_schedule
Free · Read-only
Get one schedule in full, including the advancedSchedule block that the list view flattens away: weekDays for a weekly recurrence, monthDays for specific dates, and monthlyOccurrences for patterns like "the last Friday".
azure_get_runbook
Free · Read-only
Get one runbook's full definition-of-record: runbookType, state, parameters (each with its type, whether it is mandatory and its default), outputTypes, the publishContentLink the published body came from, the logVerbose/logProgress/logActivityTrace flags, and the draft block.
azure_list_automation_accounts
Free · Read-only
List the Azure Automation accounts in a subscription, or in one resource group, with each account's location, sku, state and MANAGED IDENTITY.
azure_list_automation_certificates
Free · Read-only
List the certificate assets in an Automation account, each with its thumbprint, expiryTime, isExportable, description and timestamps.
azure_list_automation_credentials
Free · Read-only
List the credential assets in an Automation account — the username/password pairs runbooks fetch with Get-AutomationPSCredential.
azure_list_automation_job_streams
Free · Read-only
List everything a job printed, as a timestamped stream of records each carrying a jobStreamId, a streamType and a summary.
azure_list_automation_jobs
Free · Read-only
List the jobs an Automation account has run, each with its runbook name, status, statusDetails, exception, startTime, endTime, the parameters it was given and startedBy.
azure_list_automation_schedules
Free · Read-only
List an Automation account's schedules, each with its frequency, interval, startTime, expiryTime, timeZone, nextRun and — the field to read first — isEnabled.
azure_list_automation_variables
Pro · Destructive
List the variable assets in an Automation account — the shared values runbooks read at run time — each with its isEncrypted flag, description, timestamps and, for an unencrypted variable, ITS VALUE IN PLAIN TEXT.
azure_list_runbooks
Free · Read-only
List the runbooks in an Automation account, each with its runbookType, state, jobCount, lastModifiedTime and logging flags.
azure_publish_runbook
Pro · Destructive
Publish a runbook's draft, making it the live version.
azure_set_automation_schedule_enabled
Pro · Destructive
Enable or disable a schedule.
azure_start_runbook
Pro · Destructive
Start a runbook, creating a job that executes it.
azure_stop_automation_job
Pro · Destructive
Stop a running Automation job.

Managed Identities

ToolWhat it does
azure_create_managed_identity
Pro · Write
Create a user-assigned managed identity in a resource group.
azure_delete_federated_identity_credential
Pro · Destructive
Remove a federated identity credential.
azure_delete_managed_identity
Pro · Destructive
Delete a user-assigned managed identity.
azure_get_federated_identity_credential
Free · Read-only
Get one federated identity credential in full: its issuer, subject and audiences.
azure_get_managed_identity
Free · Read-only
Get one user-assigned managed identity with its principalId, clientId, tenantId, location and tags.
azure_list_federated_identity_credentials
Free · Read-only
List the federated identity credentials configured on a user-assigned managed identity — the rules that let an EXTERNAL workload obtain this identity's Azure tokens without any secret.
azure_list_managed_identities
Free · Read-only
List the USER-ASSIGNED managed identities in a subscription, or in one resource group, each with its principalId, clientId, tenantId and location.
azure_list_managed_identity_associated_resources
Free · Read-only
List every Azure resource currently using a user-assigned managed identity — the virtual machines, function apps, AKS clusters, logic apps and automation accounts that authenticate as it.
azure_set_federated_identity_credential
Pro · Destructive
Create or replace a federated identity credential, letting an external workload obtain this identity's Azure tokens with no secret at all.

Advisor

ToolWhat it does
azure_create_advisor_suppression
Pro · Destructive
Snooze or dismiss an Advisor recommendation for one resource.
azure_delete_advisor_suppression
Pro · Write
Lift an Advisor suppression, so the recommendation it was hiding is reported again.
azure_generate_advisor_recommendations
Free · Read-only
Ask Advisor to recompute its recommendations for a subscription.
azure_get_advisor_recommendation
Free · Read-only
Get one Advisor recommendation in full, with the fields the listing truncates: the complete description, extendedProperties (where the actual numbers live — the annual saving for a cost finding, the recommended SKU, the target region), learnMoreLink, and any remediation block describing an automated fix.
azure_get_advisor_suppression
Free · Read-only
Get one Advisor suppression: its suppressionId, ttl and expirationTimeStamp.
azure_list_advisor_configurations
Free · Read-only
Read Advisor's configuration at subscription or resource-group scope: the low-CPU threshold and evaluation duration that decide when a virtual machine counts as underused, the digest (email report) settings, and the exclude flag.
azure_list_advisor_recommendations
Free · Read-only
List Azure Advisor's recommendations for a subscription — Microsoft's own standing findings across Cost, Security, HighAvailability, Performance and OperationalExcellence — each with its category, impact, risk, the resource it concerns, a problem/solution summary and the concrete actions to take.
azure_list_advisor_suppressions
Free · Read-only
List every Advisor suppression in a subscription — the snoozed and dismissed recommendations — each with the recommendation and resource it hides, its ttl and its expirationTimeStamp.
azure_set_advisor_configuration
Pro · Destructive
Configure Advisor at subscription or resource-group scope: the low-CPU threshold and evaluation duration behind virtual-machine cost findings, and the exclude flag.

Container Apps

ToolWhat it does
azure_get_container_app
Free · Read-only
Get one Azure Container App in full: its managed environment, ingress (fqdn, external, targetPort, transport, traffic weights and the customDomains bound to it), activeRevisionsMode, registries, the names of its secrets, and the complete template — every container with its image, resources, probes, command, args, volume mounts and environment variables.
azure_get_container_app_custom_domains
Free · Read-only
Run ARM's listCustomHostNameAnalysis on a container app and return the result verbatim: whether the hostname is already verified, the customDomainVerificationTest outcome, the alternate CNAME and TXT records ARM expects, whether the name conflicts with another container app, and the resource id of the app it conflicts with.
azure_list_container_app_revisions
Free · Read-only
List a container app's revisions with each one's active flag, createdTime, trafficWeight, replicas, provisioningState, healthState and the image it runs.
azure_list_container_apps
Free · Read-only
List the Azure Container Apps in a subscription, or in one resource group, with each app's provisioningState, runningStatus, latestRevisionName, managed environment, ingress configuration and full container template.
azure_list_managed_certificates
Free · Read-only
List the FREE managed certificates in one Container Apps environment, with each one's subjectName, domainControlValidation method, provisioningState and error.
azure_list_managed_environments
Free · Read-only
List the Container Apps managed environments in a subscription, or in one resource group, with each one's defaultDomain, staticIp, provisioningState, VNet configuration, Log Analytics destination, workload profiles and zoneRedundant flag.
azure_update_container_app_env_vars
Pro · Destructive
Add or change environment variables on ONE container inside a container app, leaving every other variable, every other field of that container, and every other container untouched.

Raw Requests

ToolWhat it does
azure_raw_get
Free · Read-only
Send one GET to any Azure Resource Manager path and return the response exactly as ARM sent it.
azure_raw_request
Pro · Destructive
Send one POST, PUT, PATCH or DELETE to any Azure Resource Manager path and return the response exactly as ARM sent it.