generated: '2026-09-06' method: derived source: >- mcp/azure-cloud-mcp.yml (live tools/list from https://learn.microsoft.com/api/mcp, plus the Azure MCP Server command reference at https://github.com/microsoft/mcp/blob/main/servers/Azure.Mcp.Server/docs/azmcp-commands.md) bound against the operationIds in the eight first-party OpenAPI/Swagger contracts under openapi/. provider: Microsoft Azure Cloud providerId: azure-cloud surfaces: openapi: gated: false files: - file: openapi/azure-cloud-compute-api-openapi.json operations: 205 - file: openapi/azure-cloud-virtual-network-api-openapi.json operations: 245 - file: openapi/azure-cloud-service-bus-api-openapi.json operations: 70 - file: openapi/azure-cloud-key-vault-api-openapi.json operations: 48 - file: openapi/azure-cloud-resource-manager-api-openapi.json operations: 40 - file: openapi/azure-cloud-iot-hub-api-openapi.json operations: 38 - file: openapi/azure-cloud-sql-databases-api-openapi.json operations: 14 - file: openapi/azure-cloud-azure-openai-api-openapi.json operations: 6 graphql: endpoint: null note: Azure Resource Manager publishes no GraphQL surface. Azure Resource Graph is a REST + KQL query API, not GraphQL. mcp: - name: Microsoft Learn MCP Server url: https://learn.microsoft.com/api/mcp gated: false introspected: true - name: Azure MCP Server url: null transport: stdio gated: true introspected: false note: >- stdio-only; a live tools/list needs a local install under an Azure credential. Bindings below for azmcp tools are mapped by name and documented semantics, never from a fetched inputSchema, so their confidence is capped at medium. crosswalk: - tool: microsoft_docs_search category: documentation server: Microsoft Learn MCP Server rest: [] binding: none confidence: high note: >- Documentation retrieval. There is no public Azure REST operation behind it — the Learn search backend is not part of the ARM contract surface. - tool: microsoft_code_sample_search category: documentation server: Microsoft Learn MCP Server rest: [] binding: none confidence: high - tool: microsoft_docs_fetch category: documentation server: Microsoft Learn MCP Server rest: [] binding: none confidence: high - tool: azmcp compute vm get category: compute server: Azure MCP Server rest: - VirtualMachines_Get - VirtualMachines_List - VirtualMachines_ListAll binding: direct confidence: medium - tool: azmcp compute vm create category: compute server: Azure MCP Server rest: - VirtualMachines_CreateOrUpdate binding: direct confidence: medium - tool: azmcp compute vm update category: compute server: Azure MCP Server rest: - VirtualMachines_Update binding: direct confidence: medium - tool: azmcp compute vm delete category: compute server: Azure MCP Server rest: - VirtualMachines_Delete binding: direct confidence: medium - tool: azmcp compute vm power-state category: compute server: Azure MCP Server rest: - VirtualMachines_Start - VirtualMachines_PowerOff - VirtualMachines_Restart - VirtualMachines_Deallocate - VirtualMachines_InstanceView binding: composite confidence: medium note: >- One tool multiplexes five REST operations with very different consequences — Deallocate releases the compute lease and PowerOff does not. An agent reading only the tool name cannot see that. - tool: azmcp compute vmss get category: compute server: Azure MCP Server rest: - VirtualMachineScaleSets_Get - VirtualMachineScaleSets_List - VirtualMachineScaleSets_ListAll binding: direct confidence: medium - tool: azmcp compute vmss create category: compute server: Azure MCP Server rest: - VirtualMachineScaleSets_CreateOrUpdate binding: direct confidence: medium - tool: azmcp compute vmss update category: compute server: Azure MCP Server rest: - VirtualMachineScaleSets_Update binding: direct confidence: medium - tool: azmcp compute vmss delete category: compute server: Azure MCP Server rest: - VirtualMachineScaleSets_Delete binding: direct confidence: medium - tool: azmcp compute disk get category: compute server: Azure MCP Server rest: [] binding: unmapped confidence: low note: >- Managed disks live in the ComputeDisk resource provider, which is a separate Azure spec directory not harvested here. The tool is real; the backing operationIds are simply outside the eight contracts in this repo. - tool: azmcp keyvault secret get category: security server: Azure MCP Server rest: - Secrets_Get - Secrets_List binding: direct confidence: medium note: >- The management-plane Secrets_* operations in openapi/azure-cloud-key-vault-api-openapi.json manage secret RESOURCES via ARM. Reading a secret VALUE is a data-plane call against {vault}.vault.azure.net, which is a different contract not harvested here. - tool: azmcp keyvault secret create category: security server: Azure MCP Server rest: - Secrets_CreateOrUpdate binding: direct confidence: medium - tool: azmcp keyvault key get category: security server: Azure MCP Server rest: - Keys_Get - Keys_List - Keys_GetVersion - Keys_ListVersions binding: direct confidence: medium - tool: azmcp keyvault key create category: security server: Azure MCP Server rest: - Keys_CreateIfNotExist binding: direct confidence: medium - tool: azmcp keyvault admin settings get category: security server: Azure MCP Server rest: [] binding: unmapped confidence: low note: Managed HSM administration is a data-plane surface, not in the harvested ARM contract. - tool: azmcp servicebus queue details category: integration server: Azure MCP Server rest: - Queues_Get - Queues_ListByNamespace binding: direct confidence: medium - tool: azmcp servicebus topic details category: integration server: Azure MCP Server rest: - Topics_Get - Topics_ListByNamespace binding: direct confidence: medium - tool: azmcp servicebus topic subscription details category: integration server: Azure MCP Server rest: - Subscriptions_Get - Subscriptions_ListByTopic binding: direct confidence: medium - tool: azmcp sql db get category: databases server: Azure MCP Server rest: - Databases_Get - Databases_ListByServer binding: direct confidence: medium - tool: azmcp sql db create category: databases server: Azure MCP Server rest: - Databases_CreateOrUpdate binding: direct confidence: medium - tool: azmcp sql db update category: databases server: Azure MCP Server rest: - Databases_Update binding: direct confidence: medium - tool: azmcp sql db delete category: databases server: Azure MCP Server rest: - Databases_Delete binding: direct confidence: medium - tool: azmcp sql db rename category: databases server: Azure MCP Server rest: - Databases_Rename binding: direct confidence: medium - tool: azmcp iothub device list category: iot server: Azure MCP Server rest: [] binding: unmapped confidence: low note: >- Device registry listing is an IoT Hub DATA-plane call against {hub}.azure-devices.net. The harvested openapi/azure-cloud-iot-hub-api-openapi.json is the ARM management plane (hubs, routes, consumer groups, keys) and contains no per-device operation. - tool: azmcp group list category: management server: Azure MCP Server rest: - ResourceGroups_List binding: direct confidence: medium - tool: azmcp group resource list category: management server: Azure MCP Server rest: - Resources_ListByResourceGroup - Resources_List binding: direct confidence: medium mcp_only: - tool: microsoft_docs_search reason: Documentation retrieval; no public Azure REST operation exists for it. - tool: microsoft_code_sample_search reason: Documentation retrieval; no public Azure REST operation exists for it. - tool: microsoft_docs_fetch reason: Documentation retrieval; no public Azure REST operation exists for it. - tool: azmcp bicep best-practices reason: Static guidance returned by the server; no service call behind it. - tool: azmcp azureterraformbestpractices get reason: Static guidance returned by the server; no service call behind it. - tool: azmcp extension az reason: >- Shells out to the local Azure CLI. Its reach is the whole ARM surface, but it has no single backing operationId and is not describable as a REST binding. rest_only: note: >- The overwhelming majority of the 666 harvested operations have no MCP tool. Only the counts are given rather than an operation-by-operation list, because the gap is structural, not incidental. by_contract: - file: openapi/azure-cloud-virtual-network-api-openapi.json operations: 245 tools: 0 note: >- No networking namespace in the Azure MCP command reference at all. Virtual networks, load balancers, ExpressRoute, gateways and firewalls are entirely absent from the agent surface. - file: openapi/azure-cloud-compute-api-openapi.json operations: 205 tools_mapped: 9 note: >- Capture, RunCommand, InstallPatches, AttachDetachDataDisks, SimulateEviction, Redeploy, Reimage and the whole rolling-upgrade family have no tool. - file: openapi/azure-cloud-service-bus-api-openapi.json operations: 70 tools_mapped: 3 note: All three tools are reads. No create/delete/authorization-rule tool exists. - file: openapi/azure-cloud-key-vault-api-openapi.json operations: 48 tools_mapped: 4 - file: openapi/azure-cloud-resource-manager-api-openapi.json operations: 40 tools_mapped: 2 note: >- Resources_MoveResources, Resources_Delete and ResourceGroups_Delete — the highest-consequence operations in the contract — have no tool, which is defensible but undocumented. - file: openapi/azure-cloud-iot-hub-api-openapi.json operations: 38 tools_mapped: 0 - file: openapi/azure-cloud-sql-databases-api-openapi.json operations: 14 tools_mapped: 5 - file: openapi/azure-cloud-azure-openai-api-openapi.json operations: 6 tools_mapped: 0 note: >- Inference is reached through the OpenAI-compatible SDKs, not through Azure MCP. A separate Microsoft Foundry MCP server exists and is documented on Learn but was not probed in this pass. coverage: mcp_tools_recorded: 32 rest_operations_harvested: 666 tools_bound_to_rest: 23 tools_unmapped_or_mcp_only: 9 rest_operations_reachable_via_mcp: 40 rest_coverage_pct: 6.0 finding: >- Azure's REST estate and its agent surface are two different products. Six percent of the harvested operations are reachable through a documented MCP tool, the networking contract has no agent surface whatsoever, and the one MCP server Microsoft actually hosts is documentation-only.