generated: '2026-09-06' method: searched source: >- https://azure.microsoft.com/en-us/free/ (HTTP 200), https://shell.azure.com (HTTP 200), https://learn.microsoft.com/en-us/azure/cloud-shell/overview (HTTP 200), https://portal.azure.com (HTTP 200) and https://learn.microsoft.com/en-us/training/support/faq?pivots=sandbox (HTTP 200) — all read 2026-09-06. provider: Microsoft Azure Cloud providerId: azure-cloud headline_finding: >- Azure has NO test mode. There is no sandbox key prefix, no test-vs-live credential pair, no fixture or trigger tooling, and no way to exercise a write operation without creating a real resource that a real subscription is billed for. Everything below is a free or interactive surface, not a simulated one. This matters more for an agent than for a human: an agent cannot rehearse an Azure write anywhere. test_mode: available: false key_prefixes: null test_data: null note: >- Azure authenticates with Microsoft Entra ID tokens, which carry no mode flag. The same token that reads a resource can delete it; there is no test-mode equivalent of a Stripe sk_test_ key. consoles: - name: Azure portal url: https://portal.azure.com status: 200 kind: web-console description: >- Full interactive management console over the same ARM API. Every action taken here is a real, billed operation against real resources. - name: Azure Cloud Shell url: https://shell.azure.com status: 200 docs: https://learn.microsoft.com/en-us/azure/cloud-shell/overview kind: browser-shell description: >- Browser-hosted, pre-authenticated Bash or PowerShell with the Azure CLI, azd and the Az PowerShell module already installed. The closest thing Azure has to a try-it-now console for the REST surface — `az rest --method get --url https://management.azure.com/subscriptions?api-version=2022-12-01` works with no local setup — but it runs against the signed-in user's real subscription. requires: An Azure subscription and a mounted storage account for persistence. - name: Try It / interactive REST reference url: https://learn.microsoft.com/en-us/rest/api/azure/ status: 200 kind: docs-console description: >- The Learn REST reference pages carry a Try It affordance that acquires a token for the signed-in account and issues the real call. Again: real subscription, real resources. free_tier: name: Azure free account url: https://azure.microsoft.com/en-us/free/ status: 200 components: - '30-day trial credit for exploring paid services' - 'Selected services free for 12 months for new accounts' - 'A set of always-free service tiers that do not expire' note: >- This is the substitute for a sandbox: real infrastructure, spend-capped rather than simulated. Detail in plans/azure-cloud-plans-pricing.yml. retired: - name: Microsoft Learn sandbox status: retired evidence: >- "Sandboxes are no longer available. To complete exercises in training modules, you'll need access to an Azure subscription." — https://learn.microsoft.com/en-us/training/support/faq?pivots=sandbox , read 2026-09-06. note: >- Recorded because the Learn sandbox is still widely cited as Azure's free hands-on environment. It was the one Azure surface that let a learner run real az commands against a temporary subscription at no cost, and it is gone. adjacent_rehearsal_surfaces: note: >- Azure has no dry-run flag on resource operations, but a few adjacent affordances let a caller check before committing. None of them is a sandbox. surfaces: - name: Deployment what-if docs: https://learn.microsoft.com/en-us/azure/azure-resource-manager/bicep/deploy-what-if description: Previews what a template deployment would create, modify or delete, without applying it. - name: Deployment validate description: Validates a template and its parameters against ARM without deploying. - name: Resources_ValidateMoveResources contract: openapi/azure-cloud-resource-manager-api-openapi.json description: Pre-checks whether a set of resources can be moved, without moving them. - name: azmcp --read-only docs: https://github.com/microsoft/mcp/blob/main/servers/Azure.Mcp.Server/docs/azmcp-commands.md description: >- Starts the Azure MCP Server with every write tool suppressed. The best available guardrail for an agent operating on a real Azure subscription, and the closest Azure gets to a safe mode. local_emulators: note: >- Not sandboxes for the ARM API, but genuine first-party local test surfaces for individual Azure data planes, recorded because they are what developers actually use in CI. surfaces: - name: Azurite scope: Azure Storage (Blob, Queue, Table) repo: https://github.com/Azure/Azurite - name: Azure Cosmos DB emulator scope: Cosmos DB docs: https://learn.microsoft.com/en-us/azure/cosmos-db/emulator - name: Azure Functions Core Tools scope: Functions runtime docs: https://learn.microsoft.com/en-us/azure/azure-functions/functions-run-local - name: Foundry Local scope: Model inference on local hardware docs: https://learn.microsoft.com/en-us/azure/ai-foundry/foundry-local/what-is-foundry-local