Install
$ agentstack add mcp-zmustafa-azuresupportagent ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
🛠️ Azure Support Agent
An AI-driven Azure operations workbench that runs in your subscription. Point it at your tenant and AI discovers your workloads, reverse-engineers live architecture diagrams, and runs Well-Architected assessments — then a War Room of specialist agents helps you investigate, monitor, and remediate.
[](https://portal.azure.com/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2Fzmustafa%2FAzureSupportAgent%2Fmain%2Fdeploy%2Fmain.json)
[](LICENSE) [](https://hub.docker.com/r/zmustafa/azure-support-agent) [](backend/pyproject.toml) [](frontend/package.json) [](https://fastapi.tiangolo.com/) [](CONTRIBUTING.md)
[Deploy](#-deploy-to-azure-one-click) · [Install guide](docs/INSTALLATION.md) · [Features](#-features) · [Screenshots](#-screenshots) · [Quick start](#-quick-start-local) · [Architecture](#-how-it-works) · [Docs](#-documentation)
> 🆕 Latest (v54): a Workloads cockpit (health scores, fleet board, per-workload command center, Autopilot discovery), an Estate Graph knowledge map, and Ownership, Tag Intelligence & Change Explorer — all under a new Proactive Support hub.
Why Azure Support Agent?
Operating Azure at scale means hopping between the Portal, CLI, Resource Graph, Monitor, Advisor, and a dozen blades just to answer one question. Azure Support Agent puts an LLM in the driver's seat — it talks to your subscription through the official Azure MCP server and a Microsoft Graph (Entra ID) MCP server, reasons over live evidence, and turns "why is the website throwing 5xx?" into a ranked, validated answer — with the diagrams, assessments, and dashboards to back it up. And it doesn't just wait to be asked: a whole Proactive Support suite continuously scans your estate for coverage gaps and looming retirements, while scheduled autonomous agents push findings to Teams, Jira, or ServiceNow before they bite.
- 🧠 Agentic, not just a chatbot — a War Room of specialist agents investigates in parallel against your real Azure data.
- 🛡️ Proactive, not just reactive — a Proactive Support hub (Assessments · Identity · Monitoring, Telemetry & Backup/DR coverage · Retirement Radar · Telemetry Intelligence · Performance Profiler · Ownership · Tag Intelligence · Change Explorer · Estate Graph) surfaces risks before you ask, and scheduled autonomous agents notify you via connectors.
- 🏠 Runs in your tenant — one-click deploy to Azure Container Apps; your data never leaves your subscription.
- 🔒 Safe by default — Azure access is read-only, writes are approval-gated + audited, and AI providers stay disabled until you configure them.
- 🧰 A whole workbench — chat, investigations, architectures, a workloads cockpit, inventory, assessments, policy, monitoring, ownership, tagging, change forensics, an estate knowledge graph, and automations.
> Built for cloud architects, SREs, platform teams, and Azure support engineers.
Table of Contents
- [Features](#-features)
- [Screenshots](#-screenshots)
- [Deploy to Azure (one-click)](#-deploy-to-azure-one-click)
- [Installation guide](docs/INSTALLATION.md)
- [Quick start (local)](#-quick-start-local)
- [How it works](#-how-it-works)
- [Tech stack](#-tech-stack)
- [Security & access model](#-security--access-model)
- [Documentation](#-documentation)
- [Contributing](#-contributing)
- [License](#-license)
✨ Features
💬 Conversational operations
Multi-session chat with isolated context, live SSE streaming, a per-message reasoning + tool-call timeline that persists across reloads, image support, and smart starter suggestions. Cancel a running turn anytime — work continues server-side and is saved.
🕵️ Deep investigations ("War Room")
Toggle deep mode to dispatch specialist agents (Networking, Identity, Compute, Storage, Security, Reliability, Cost, Monitoring) that research in parallel, form hypotheses, and validate them against your live Azure data — then converge on a conclusion.
📦 Workloads cockpit
Discover and group resources into workloads, then work a fleet cockpit with composite health scores, a resource taxonomy, table/board views, and rich visualizations (donut, radar, sparkline, treemap). Drill into a per-workload command center, or let Autopilot AI-discover and propose workloads for you.
🚀 Mission Control
Run every analysis against a workload from one cockpit — architecture, assessment, coverage, identity and more — and read a single go/no-go posture with the highest-risk items surfaced first.
🗺️ Architectures + Architecture Memory
AI reverse-engineers live resources into interactive diagrams with best-practice review, network boundaries, and cost hints. Save revisions, build collections, and keep persistent Architecture Memory that powers dashboards and investigations.
🕸️ Estate Graph
A live, workload-aware knowledge graph of your tenant with cost, retirement and RBAC overlays — pan, zoom, search, and deep-link straight into the workload, architecture or assessment behind any node.
🪪 Ownership
A federated owner directory scoped by tenant, subscription or workload. Export owners, import any CSV/Excel with AI column-inference and a preview, then apply as Azure tags with snapshots and safe revert.
🏷️ Tag Intelligence
A tag census with coverage, casing-drift detection and a natural-language → Azure Resource Graph console. Propose, apply and revert tag changes with full revision history.
🛰️ Change Explorer
See what changed, when, and who did it across your estate — each change AI-categorized and risk-scored, with plain-English insights that float the highest-risk changes to the top for review.
✅ Assessments & governance
Run Well-Architected-style assessments across Security, Reliability, Cost, Operations, and Performance pillars — with custom controls, framework mappings (NIST, ISO, CIS), waivers, finding lifecycle, and ticketing. Plus Policy compliance, baselines, and AI advisors.
📈 Monitoring & resilience
Monitor 2.0 customizable dashboards with AI authoring and ping history; AMBA baseline-alert coverage with one-click Bicep/Terraform gap remediation; Performance Profiler, Backup/DR coverage, Retirement Radar, and telemetry intelligence.
🤖 Automations & workflows
Build custom sub-agents with scoped tools, schedule recurring tasks, chain Workbooks into Playbooks, and route results through in-app Notifications and external connectors (Jira, ServiceNow).
🛡️ Proactive Support hub
One categorized landing page that unifies every posture & forensic dashboard — coverage, assessments, identity, ownership, tagging, change forensics and the estate graph — so nothing about your estate is more than a click away.
🔌 Bring your own AI
A dozen+ providers — OpenAI, Azure OpenAI, Anthropic Claude, Google Gemini, GitHub Copilot/Models, Grok, Mistral, OpenRouter, ChatGPT (OAuth), Claude OAuth (Pro/Max, incl. Opus 4.8), Ollama, LM Studio — switchable at runtime with live model catalogs. Disabled until you set them up.
Enterprise-ready
🔐 Read-only Azure by default · ✅ approval-gated writes · 🧾 full audit log · 👥 RBAC (users / roles / groups) · 🔑 OIDC + SAML SSO · 🗝️ encrypted connection credentials · 🖥️ Sandbox VMs for private-endpoint diagnostics · 🧩 multi-tenant Azure connections.
📸 Screenshots
Workloads cockpit — composite health scores, resource mix & trend sparklines across your fleet. Workload command center — health, coverage, risk & next-best-actions for a single workload.
Estate Graph — a live, workload-aware knowledge graph with cost, retirement & RBAC overlays. Proactive Support — every posture & forensic dashboard, grouped into one hub.
Mission Control — run every analysis against a workload from one go/no-go cockpit. Tag Intelligence — tag census, coverage & casing drift with a natural-language console.
Change Explorer — what changed, when, who did it, how risky, and what it impacts — in plain English. Architectures designer — design diagrams with AI rationale & best-practice review.
War Room — assemble a team of specialist agents to investigate in parallel. Assessments — pillar scores, controls, and framework mappings (NIST/ISO/CIS).
Performance Profiler — resource × AMBA-metric heatmap to find bottlenecks. Monitoring coverage — AMBA baseline-alert gaps with Bicep/Terraform fixes.
Telemetry coverage — diagnostic-settings & log coverage with Bicep/Policy gap fixes. Monitor 2.0 — usage, token cost, provider mix, and activity at a glance.
AI providers — bring your own model; each one stays disabled until configured. Backup & DR coverage — RTO/RPO protection posture with Bicep/runbook gap fixes.
Retirement radar — service retirements & breaking changes mapped to workloads, owners, and deadlines. Identity — expiring credentials, ownerless apps, MFA & conditional-access gaps, ranked by severity.
🚀 Deploy to Azure (one-click)
> Status: tested. Provisions a managed PostgreSQL database, Azure Files state storage, > and the Container App running the public image — in your subscription, in one > deployment. No CLI, no manual wiring.
[](https://portal.azure.com/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2Fzmustafa%2FAzureSupportAgent%2Fmain%2Fdeploy%2Fmain.json)
What it creates:
- Azure Container App running the public Docker Hub image
- Azure Database for PostgreSQL — Flexible Server (managed), auto-linked via
DATABASE_URL(?ssl=require) - Azure Files share mounted at
/app/.data(registries, caches, encryption key) - Container Apps environment + external HTTPS ingress on port 8000
> 💰 Estimated cost: ~$25–35 / month for the default infra at typical low/idle usage > (West US 3, pay-as-you-go) — mostly the Container App (1 vCPU / 2 GiB) and a Burstable > B1ms PostgreSQL server.
You supply only an admin password (you're forced to change it on first login). Then connect your Azure tenant and an LLM from Settings — the AI does the rest (workload discovery, architectures, coverage scans, assessments, retirement radar, performance profiling). Defaults to West US 3 (validated for Container Apps + PostgreSQL B1ms).
📖 New here? Follow the [step-by-step installation guide](docs/INSTALLATION.md) — from clicking the button to onboarding your first workload.
Prefer the CLI or want full control? See the [manual deployment guide](docs/DEPLOYMENT.md).
⚡ Quick start (local)
Prerequisites: Docker Desktop · Azure CLI (az) · an LLM key (or a local Ollama / LM Studio).
# 1) Sign in to the subscription you want to work with
az login
az account set --subscription ""
# 2) Configure environment
Copy-Item .env.example .env # set LLM_API_KEY (optional — you can also do it in the UI)
# 3) Run the whole stack
docker compose up --build
Open http://localhost:5173. The backend runs DB migrations on startup; the first Azure MCP call fetches @azure/mcp via npx (a few seconds), then caches it.
Health check: /healthz · MCP tools (admin): /api/admin/mcp/tools
Full local/dev instructions (native backend, tests, type-check) live in [CONTRIBUTING.md](CONTRIBUTING.md).
🧩 How it works
The whole app — FastAPI API + the built React SPA + the in-process MCP servers — ships as one container image and runs as a single Container App. No separate frontend, database, or Redis containers required.
flowchart LR
U([Browser]) --> SPA[React SPA]
SPA -->|/api| BE[FastAPI backendorchestrator · SSE streaming]
BE --> LLM{{LLM providersOpenAI · Claude · GeminiCopilot · Ollama · …}}
BE --> AZ[Azure MCP server · stdio]
BE --> EID[Entra / Graph MCP server · stdio]
BE --> TOOLS[Built-in toolsDNS · HTTP · ping · traceroute]
BE --> DB[(PostgreSQL / SQLite)]
BE --> FILES[[Azure Files/app/.data]]
AZ --> SUB[(Your Azure subscription)]
EID --> GRAPH[(Microsoft Graph)]
For local dev nothing is deployed to Azure — the MCP server reaches your real subscription outbound using your signed-in identity and existing RBAC, read-only by default.
🔧 Tech stack
| Layer | Tech | | --- | --- | | Backend | Python 3.12 · FastAPI · async SQLAlchemy 2 · Pydantic v2 · Alembic · SSE | | Frontend | React 18 · TypeScript · Vite · Tailwind · TanStack Query · Recharts · XYFlow · Cytoscape · Mermaid | | AI | Provider abstraction with streaming + normalized tool-calls (a dozen+ providers) | | Azure | Official Azure MCP server (@azure/mcp) · Azure CLI / Resource Graph runner | | Entra ID | Vendored Microsoft Graph (EntraID) MCP server over stdio | | Data | PostgreSQL (prod) / SQLite (local) · Azure Files for state | | Hosting | Azure Container Apps (single image) |
🔐 Security & access model
- Read-only by default. The Azure MCP server starts with
--read-only; write-capable tools are classified, approval-gated, and audited. - AI providers off until configured. A fresh install ships every provider disabled; a provider only becomes selectable once you add a key (or sign in / set a local base URL).
- Identity & SSO. Local users with RBAC (users / roles / groups), plus OIDC and SAML SSO. Forced password change on first admin login.
- Secrets. Connection credentials are encrypted at rest and never returned to the UI.
.env,backend/.data/, and keys are git-ignored. - Found a vulnerability? Please follow [SECURITY.md](SECURITY.md) — don't open a public issue.
📚 Documentation
| Doc | What's inside | | --- | --- | | [docs/INSTALLATION.md](docs/INSTALLATION.md) | Step-by-step one-click install: deploy, first login, connect an LLM & tenant, onboard a workload | | [docs/TECHNICALSPEC.md](docs/TECHNICALSPEC.md) | Full architecture & feature specification | | [docs/DEPLOYMENT.md](docs/DEPLOYMENT.md) | Manual Azure Container Apps deploy, env vars, cost/scaling, gotchas | | [docs/ENTRASETUP.md](docs/ENTRASETUP.md) | EntraID (Microsoft Graph) MCP setup + required permissions | | [CONTRIBUTING.md](CONTRIBUTING.md) | Local dev, tests, type-check, PR guidelines | | [SECURITY.md](SECURITY.md) | Vulnerability disclosure policy | | [CODEOFCONDUCT.md](CODEOFCONDUCT.md) | Community guidelines |
🤝 Contributing
Contributions are welcome! Please read [CONTRIBUTING.md](CONTRIBUTING.md) and our [Code of Conduct](CODEOFCONDUCT.md). Good first steps: open an issue to discuss a change, keep PRs focused, and make sure backend tests and the frontend type-check pass.
📄 License
[MIT](LICENSE) © 2026 Zeeshan Mustafa (@zmustafa)
🙏 Acknowledgements
- Azure MCP server — the official Azure tool surface
- EntraID MCP server (Microsoft Graph, FastMCP) — vendored under
third_party/ - The Model Context Protocol community
If this project helps you, consider giving it a ⭐ — it helps others find it.
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: zmustafa
- Source: zmustafa/AzureSupportAgent
- License: MIT
- Homepage: https://github.com/zmustafa/AzureSupportAgent
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.