Setting up the Azure MCP Server

Install the Azure MCP Server via the VS Code extension or a package manager, sign in, and scope permissions sensibly.

Published on 09.09.2026

The Azure MCP Server can be set up in several ways — via an IDE extension, a package manager, or as a container. Which path fits best mainly depends on the client you use.

Choosing an installation path

For VS Code, the Marketplace extension is the best fit since it bundles installation and sign-in into one step. For terminal/CLI agents such as Claude Code or Codex, starting via npx, dotnet tool, or uvx is more practical. Docker suits you if the server should run isolated or inside a CI/CD pipeline.

Setting up via VS Code

First install the "Azure MCP Server" extension from the VS Code Marketplace, then run "Azure: Sign In" via the Command Palette. The server is then usable for GitHub Copilot Chat and other MCP-capable tools in VS Code.

Setting up via a package manager

Depending on your existing toolchain, pick one of the following:

# Node.js
npx -y @azure/mcp@latest server start

# .NET
dotnet tool install Azure.Mcp

# Python (uv)
uvx --from msmcp-azure azmcp server start

# Docker
docker run -i --rm mcr.microsoft.com/azure-sdk/azure-mcp:latest

Sign in to Azure with az login before the first call.

Scoping permissions

The server's effective permissions exactly match the signed-in Azure account. For automated agents, a dedicated service principal with as narrow an RBAC role as possible is recommended, rather than a personal account with broad rights.

Verifying the setup

After starting, test with a harmless question such as "What resource groups do I have in my subscription?" to confirm the agent can use Azure tools, and check the Azure Activity Log to see which actions are actually performed.

Working with multiple Azure accounts

Anyone working across multiple Azure subscriptions or tenants should sign in separately for each account via az login --tenant <tenant-id> and confirm the active subscription before each session with az account show. An accidentally wrong active subscription can otherwise lead the agent to make changes in the wrong environment.

Troubleshooting connection issues

If the client reports it can't connect to the server, this is often an expired Azure CLI session — running az login again usually resolves it. With the VS Code extension, restarting the editor after signing in often helps the extension pick up the current session.

When Docker beats a local installation

For CI/CD pipelines or isolated test environments, the Docker route is often preferable, since it requires no local installation of Node.js, .NET, or Python and integrates easily into existing container workflows. Credentials must reach the container via environment variables or mounted configuration files, never baked into the image itself.

Source: learn.microsoft.com/en-us/azure/developer/azure-mcp-server, checked on 2026-09-05.

Published on 09.09.2026

Categories

Frequently asked questions

Does the Azure MCP Server run locally or in the cloud?

It runs locally, in your own machine or environment — started via npx, dotnet tool, uvx, Docker, or as an IDE extension. It is not a remote service hosted by Microsoft.

Which Azure services can the server access?

Per the documentation, more than 45 service areas, including virtual machines, storage, databases, and AI services. Which of these are actually usable depends on the permissions of the signed-in account.

Does it also work with Claude Code or Codex?

Yes, since it implements the open MCP protocol, it can be configured in any MCP-capable client, explicitly documented for Claude Code, Claude Desktop, and Cursor among others, and usable with Codex via standard MCP configuration.

What does the Azure MCP Server cost?

The server itself is free and open source (MIT license). Only the Azure resources the agent actually uses through the server are billed.

How do I stop an agent from making overly broad changes?

Use a dedicated service principal with a tightly scoped RBAC role instead of a personal account, and regularly review actions in the Azure Activity Log.