Azure MCP Server: Setup in VS Code and Claude Code
Microsoft’s Azure MCP Server lets an AI assistant work with your Azure resources in plain language. What it covers, how it signs in with Entra ID, how to set it up in VS Code with GitHub Copilot and in Claude Code or Claude Desktop, and how to keep it read-only and on least-privilege roles.
7 min read
The Azure MCP Server is Microsoft’s open-source MCP server for Azure. It gives an AI assistant tools for dozens of Azure services, so you can ask “List my Azure resource groups” or “Show the containers in my storage account” and the assistant calls Azure for you. By default it runs locally as the npm package @azure/mcp and signs in with your own Microsoft Entra ID credentials, picked up from the Azure CLI, VS Code or another developer tool. In VS Code you install an extension and use GitHub Copilot in agent mode; in Claude Code you install Microsoft’s plugin or add one command. Start it with --read-only, and give the identity it runs as the smallest Azure role that does the job.
Not the Azure DevOps server
The Azure MCP Server works with Azure resources: storage, databases, Key Vault, Kubernetes, monitoring and so on. Work items, repos, pipelines and wikis in Azure DevOps are a different server, covered in the Azure DevOps MCP server guide.
What the Azure MCP Server is
Microsoft’s overview on Learn (opens in a new tab) describes a server that lets AI agents and clients work with Azure resources through natural language, implements the Model Context Protocol, and signs in with Entra ID through the Azure Identity library. Its source lives in the microsoft/mcp repository, which also holds Microsoft’s other MCP servers. It is published for npm, NuGet (run with dnx on .NET 10) and PyPI (uvx --from msmcp-azure), as a Docker image, and as .mcpb bundles for Claude Desktop.
It is under active development. Microsoft’s examples install @azure/mcp@latest, and on npm that tag currently resolves to a 3.0 beta build, so pin a version for a team that needs everyone on the same tools.
Its tool areas
Tools are grouped by service. The repository lists more than forty areas, including:
- Data: Azure Storage, Cosmos DB, Azure SQL Database, Azure Database for PostgreSQL, Azure Data Explorer and Azure Managed Lustre.
- Compute and apps: App Service, Container Apps, Azure Kubernetes Service, Azure Container Registry and Azure Compute.
- Security and configuration: Key Vault, App Configuration and Confidential Ledger.
- Messaging: Event Grid, Event Hubs, SignalR and Communication Services.
- Operations: Azure Monitor, Resource Health, Advisor, Quota, Workbooks and Managed Grafana.
- AI: Microsoft Foundry, Azure AI Search and Speech.
- Tooling and guidance: Azure CLI command generation, Terraform best practices and the Well-Architected Framework.
Server modes: how many tools the assistant sees
Listed one by one there are more than 200 tools, which is too many for some clients. VS Code, for example, allows at most 128 tools across all servers. The server therefore has modes, set with --mode when it starts:
namespace, the default: one tool per service, such as a single storage tool that routes to storage operations inside.consolidated: curated tools named after tasks, such asget_azure_databases_details, which Microsoft recommends for AI agents.all: every operation as its own tool.single: oneazuretool that routes everything.
You can also narrow by service with one or more --namespace options, for example --namespace storage --namespace keyvault, or name individual tools with --tool. The command reference (opens in a new tab) documents every mode and option; --namespace and --tool cannot be combined.
Authentication: Entra ID and the credential chain
Running locally over stdio, the server signs in to Azure as you. There is no separate account for the assistant. It tries a chain of credentials and uses the first one that works: environment variables, Visual Studio, VS Code, the Azure CLI, Azure PowerShell, the Azure Developer CLI, and finally an interactive browser sign-in. That is essentially the Azure Identity library’s DefaultAzureCredential, which Microsoft’s troubleshooting guide names, and it needs a Microsoft Entra ID account; personal Microsoft accounts do not work.
- The usual local setup: run
az login, check the account and subscription withaz account show, and start the server. - To skip the chain, set
AZURE_TOKEN_CREDENTIALSto one credential, such asAzureCliCredential. - For CI, set a service principal’s
AZURE_CLIENT_ID,AZURE_CLIENT_SECRETandAZURE_TENANT_ID, or use workload identity in Azure Pipelines.AZURE_TOKEN_CREDENTIALS=prodremoves the interactive browser fallback. - For a server shared by several agents, the authentication guide (opens in a new tab) describes HTTP mode, where every request carries an Entra ID bearer token and Microsoft publishes
azdtemplates to host it on Azure Container Apps.
Setup in VS Code with GitHub Copilot
- Install the GitHub Copilot Chat extension and the Azure MCP Server extension.
- Run Azure: Sign In from the Command Palette, or rely on an existing
az login. - Open Copilot Chat, choose Agent mode, and refresh the tools list; Azure MCP Server appears as a tool source.
- Ask “List my Azure resource groups”. Copilot asks before running each operation, and you can allow it for the session, the workspace or always.
The extension’s settings choose the mode (azureMcp.serverMode), the services (azureMcp.enabledServices) and read-only operation (azureMcp.readOnly). If you would rather keep the setup in the repository, the VS Code quickstart on Learn (opens in a new tab) shows a .vscode/mcp.json that runs the npm package instead. VS Code uses servers as the top-level key; before committing a file like this for a team, read how VS Code decides which servers to trust.
{
"servers": {
"azure": {
"command": "npx",
"args": [
"-y", "@azure/mcp@latest", "server", "start",
"--namespace", "storage",
"--namespace", "keyvault",
"--read-only"
]
}
}
}Setup in Claude Code and Claude Desktop
Microsoft’s recommended route for Claude Code is the Azure plugin from Anthropic’s official marketplace, which bundles the Azure MCP Server with Azure agents and skills. Run /plugin install azure@claude-plugins-official inside Claude Code. To add only the server, with your own flags, use claude mcp add; everything after -- is the command that starts the server.
az login claude mcp add --transport stdio azure -- \ npx -y @azure/mcp@latest server start --read-only # then, inside Claude Code /mcp
Add --scope project to write the entry to a shared .mcp.json instead of your local settings. Claude Code asks before each MCP tool call unless you approve it; allowing reads and keeping everything else on ask is covered in auto-approve in Claude Code.
Claude Desktop takes the same command in claude_desktop_config.json under mcpServers, with npx as the command and the rest as args. Microsoft also publishes .mcpb bundles that install into Claude Desktop without Node.js or .NET. Where the file lives on each platform is in the Claude Desktop MCP config guide.
Read-only mode and least-privilege roles
--read-only makes the server offer only tools that do not change anything, and it combines with every mode and filter. It is the sensible default for exploring, diagnosing and reporting. It is a convenience, not a security boundary: the real limit is what the signed-in identity may do in Azure.
Microsoft is direct about this in the repository: MCP clients can invoke operations based on the user’s Azure RBAC permissions, autonomous or misconfigured clients may perform destructive actions, and you should apply least-privilege roles and safeguards first. In practice:
- Run the assistant under an identity with Reader, or a data-plane reader role such as Storage Blob Data Reader, on only the subscriptions or resource groups it needs, not your Owner account.
- Grant a write role, such as Storage Blob Data Contributor, only for a specific task and scope, and remove it after.
- Keep production in a subscription the assistant’s identity cannot reach. Azure’s RBAC best practices (opens in a new tab) recommend granting the least privilege needed to get the work done and avoiding broader roles at broader scopes.
- Telemetry to Microsoft is on by default; set
AZURE_MCP_COLLECT_TELEMETRY=falseto turn it off.
Where the task list lives
The Azure MCP Server acts on infrastructure; it has nowhere to keep the list of what should be done next, or a record of which assistant did it. fenbs is that list: a board where each feature, enhancement or bug is a task with a note, a plan and a test status, in lanes To Do, Next Up, In Progress and Completed. Add it beside Azure with claude mcp add --transport http fenbs https://fenbs.ai/api/mcp and sign in through /mcp; the assistant gets an hour-long token with refresh, capped by the scopes you tick and your role on the board, and every task change is recorded in History under its name. Standing instructions, such as “never change production without a task”, go on the Decisions and rules page, which every connected assistant reads first. fenbs does not record Azure changes; Azure’s activity log does that.
Related
The other Azure server: Azure DevOps MCP server, and GitHub Copilot with Azure Boards. Habits for any connection: MCP security best practices and local vs remote MCP servers. Connecting fenbs: the MCP docs.