Azure MCP Server: Setup in VS Code and Claude Code

Microsoft’s Azure MCP Server lets an AI assistant work with your Azure resources in plain language. What it covers, how it signs in with Entra ID, how to set it up in VS Code with GitHub Copilot and in Claude Code or Claude Desktop, and how to keep it read-only and on least-privilege roles.

7 min read

The Azure MCP Server is Microsoft’s open-source MCP server for Azure. It gives an AI assistant tools for dozens of Azure services, so you can ask “List my Azure resource groups” or “Show the containers in my storage account” and the assistant calls Azure for you. By default it runs locally as the npm package @azure/mcp and signs in with your own Microsoft Entra ID credentials, picked up from the Azure CLI, VS Code or another developer tool. In VS Code you install an extension and use GitHub Copilot in agent mode; in Claude Code you install Microsoft’s plugin or add one command. Start it with --read-only, and give the identity it runs as the smallest Azure role that does the job.

Not the Azure DevOps server

The Azure MCP Server works with Azure resources: storage, databases, Key Vault, Kubernetes, monitoring and so on. Work items, repos, pipelines and wikis in Azure DevOps are a different server, covered in the Azure DevOps MCP server guide.

What the Azure MCP Server is

Microsoft’s overview on Learn (opens in a new tab) describes a server that lets AI agents and clients work with Azure resources through natural language, implements the Model Context Protocol, and signs in with Entra ID through the Azure Identity library. Its source lives in the microsoft/mcp repository, which also holds Microsoft’s other MCP servers. It is published for npm, NuGet (run with dnx on .NET 10) and PyPI (uvx --from msmcp-azure), as a Docker image, and as .mcpb bundles for Claude Desktop.

It is under active development. Microsoft’s examples install @azure/mcp@latest, and on npm that tag currently resolves to a 3.0 beta build, so pin a version for a team that needs everyone on the same tools.

Its tool areas

Tools are grouped by service. The repository lists more than forty areas, including:

  • Data: Azure Storage, Cosmos DB, Azure SQL Database, Azure Database for PostgreSQL, Azure Data Explorer and Azure Managed Lustre.
  • Compute and apps: App Service, Container Apps, Azure Kubernetes Service, Azure Container Registry and Azure Compute.
  • Security and configuration: Key Vault, App Configuration and Confidential Ledger.
  • Messaging: Event Grid, Event Hubs, SignalR and Communication Services.
  • Operations: Azure Monitor, Resource Health, Advisor, Quota, Workbooks and Managed Grafana.
  • AI: Microsoft Foundry, Azure AI Search and Speech.
  • Tooling and guidance: Azure CLI command generation, Terraform best practices and the Well-Architected Framework.

Server modes: how many tools the assistant sees

Listed one by one there are more than 200 tools, which is too many for some clients. VS Code, for example, allows at most 128 tools across all servers. The server therefore has modes, set with --mode when it starts:

  • namespace, the default: one tool per service, such as a single storage tool that routes to storage operations inside.
  • consolidated: curated tools named after tasks, such as get_azure_databases_details, which Microsoft recommends for AI agents.
  • all: every operation as its own tool.
  • single: one azure tool that routes everything.

You can also narrow by service with one or more --namespace options, for example --namespace storage --namespace keyvault, or name individual tools with --tool. The command reference (opens in a new tab) documents every mode and option; --namespace and --tool cannot be combined.

Authentication: Entra ID and the credential chain

Running locally over stdio, the server signs in to Azure as you. There is no separate account for the assistant. It tries a chain of credentials and uses the first one that works: environment variables, Visual Studio, VS Code, the Azure CLI, Azure PowerShell, the Azure Developer CLI, and finally an interactive browser sign-in. That is essentially the Azure Identity library’s DefaultAzureCredential, which Microsoft’s troubleshooting guide names, and it needs a Microsoft Entra ID account; personal Microsoft accounts do not work.

  • The usual local setup: run az login, check the account and subscription with az account show, and start the server.
  • To skip the chain, set AZURE_TOKEN_CREDENTIALS to one credential, such as AzureCliCredential.
  • For CI, set a service principal’s AZURE_CLIENT_ID, AZURE_CLIENT_SECRET and AZURE_TENANT_ID, or use workload identity in Azure Pipelines. AZURE_TOKEN_CREDENTIALS=prod removes the interactive browser fallback.
  • For a server shared by several agents, the authentication guide (opens in a new tab) describes HTTP mode, where every request carries an Entra ID bearer token and Microsoft publishes azd templates to host it on Azure Container Apps.

Setup in VS Code with GitHub Copilot

  1. Install the GitHub Copilot Chat extension and the Azure MCP Server extension.
  2. Run Azure: Sign In from the Command Palette, or rely on an existing az login.
  3. Open Copilot Chat, choose Agent mode, and refresh the tools list; Azure MCP Server appears as a tool source.
  4. Ask “List my Azure resource groups”. Copilot asks before running each operation, and you can allow it for the session, the workspace or always.

The extension’s settings choose the mode (azureMcp.serverMode), the services (azureMcp.enabledServices) and read-only operation (azureMcp.readOnly). If you would rather keep the setup in the repository, the VS Code quickstart on Learn (opens in a new tab) shows a .vscode/mcp.json that runs the npm package instead. VS Code uses servers as the top-level key; before committing a file like this for a team, read how VS Code decides which servers to trust.

.vscode/mcp.json (read-only, two services)
{
  "servers": {
    "azure": {
      "command": "npx",
      "args": [
        "-y", "@azure/mcp@latest", "server", "start",
        "--namespace", "storage",
        "--namespace", "keyvault",
        "--read-only"
      ]
    }
  }
}

Setup in Claude Code and Claude Desktop

Microsoft’s recommended route for Claude Code is the Azure plugin from Anthropic’s official marketplace, which bundles the Azure MCP Server with Azure agents and skills. Run /plugin install azure@claude-plugins-official inside Claude Code. To add only the server, with your own flags, use claude mcp add; everything after -- is the command that starts the server.

In your terminal
az login

claude mcp add --transport stdio azure -- \
  npx -y @azure/mcp@latest server start --read-only

# then, inside Claude Code
/mcp

Add --scope project to write the entry to a shared .mcp.json instead of your local settings. Claude Code asks before each MCP tool call unless you approve it; allowing reads and keeping everything else on ask is covered in auto-approve in Claude Code.

Claude Desktop takes the same command in claude_desktop_config.json under mcpServers, with npx as the command and the rest as args. Microsoft also publishes .mcpb bundles that install into Claude Desktop without Node.js or .NET. Where the file lives on each platform is in the Claude Desktop MCP config guide.

Read-only mode and least-privilege roles

--read-only makes the server offer only tools that do not change anything, and it combines with every mode and filter. It is the sensible default for exploring, diagnosing and reporting. It is a convenience, not a security boundary: the real limit is what the signed-in identity may do in Azure.

Microsoft is direct about this in the repository: MCP clients can invoke operations based on the user’s Azure RBAC permissions, autonomous or misconfigured clients may perform destructive actions, and you should apply least-privilege roles and safeguards first. In practice:

  • Run the assistant under an identity with Reader, or a data-plane reader role such as Storage Blob Data Reader, on only the subscriptions or resource groups it needs, not your Owner account.
  • Grant a write role, such as Storage Blob Data Contributor, only for a specific task and scope, and remove it after.
  • Keep production in a subscription the assistant’s identity cannot reach. Azure’s RBAC best practices (opens in a new tab) recommend granting the least privilege needed to get the work done and avoiding broader roles at broader scopes.
  • Telemetry to Microsoft is on by default; set AZURE_MCP_COLLECT_TELEMETRY=false to turn it off.

Where the task list lives

The Azure MCP Server acts on infrastructure; it has nowhere to keep the list of what should be done next, or a record of which assistant did it. fenbs is that list: a board where each feature, enhancement or bug is a task with a note, a plan and a test status, in lanes To Do, Next Up, In Progress and Completed. Add it beside Azure with claude mcp add --transport http fenbs https://fenbs.ai/api/mcp and sign in through /mcp; the assistant gets an hour-long token with refresh, capped by the scopes you tick and your role on the board, and every task change is recorded in History under its name. Standing instructions, such as “never change production without a task”, go on the Decisions and rules page, which every connected assistant reads first. fenbs does not record Azure changes; Azure’s activity log does that.

Related

The other Azure server: Azure DevOps MCP server, and GitHub Copilot with Azure Boards. Habits for any connection: MCP security best practices and local vs remote MCP servers. Connecting fenbs: the MCP docs.

Questions people ask.

Is the Azure MCP Server the same as the Azure DevOps MCP server?

No. The Azure MCP Server works with Azure resources such as storage, databases, Key Vault and Kubernetes. The Azure DevOps MCP server works with work items, repos, pipelines and wikis in Azure DevOps. They are separate servers with separate setup.

How does the Azure MCP Server authenticate?

Locally it signs in as you with Microsoft Entra ID, trying environment variables, Visual Studio, VS Code, the Azure CLI, Azure PowerShell and the Azure Developer CLI before falling back to a browser sign-in. You can pin one credential with the AZURE_TOKEN_CREDENTIALS variable.

How do I make the Azure MCP Server read-only?

Start it with the --read-only option, or set azureMcp.readOnly to true in the VS Code extension. The server then offers only tools that do not change resources. Pair it with a Reader role so the identity cannot write either.

Does the Azure MCP Server work with Claude Code?

Yes. Install the Azure plugin with /plugin install azure@claude-plugins-official, or add the server yourself with claude mcp add --transport stdio azure -- npx -y @azure/mcp@latest server start.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.