azure-mcp-connection skillA
azure-mcp-connection is agent-read markdown (skill) from wyre-ai/msp-claude-plugins: Onboarding the azure-mcp connector in the WYRE MCP Gateway: Azure service-principal registration, the tenantId/clientId/clientSecret triple, least-privilege Reader-tier RBAC assignments, the gateway's read-only namespace allowlist, and connection verification and failure modes (expired secret, missing role assignment)..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Azure MCP Connection The `azure-mcp` vendor runs Microsoft's official Azure MCP Server (`mcr.microsoft.com/azure-sdk/azure-mcp`) as a WYRE-built sidecar inside the MCP gateway. Each connecting MSP supplies its own Azure **service principal**; the gateway isolates credentials per tenant and scopes every request to the principal you registered. ## Anti-triggers - **Microsoft 365 or Entra ID tenant work** — in MSP conversation "Azure tenant" almost always means the M365 tenant. This connector reaches Azure Resource Manager only. Tenant onboarding, GDAP, and CSP relationships are `cipp-tenants`; Graph app registrations are `microsoft-graph-connection`. - **What to actually query once connected** — use `azure-mcp-observability` or `azure-mcp-cost-and-capacity`. ## Read-only deployment — read this first The gateway runs the Azure MCP Server with the `--read-only` flag and a deliberately constrained namespace allowlist. Day-one the connector exposes exactly eight read-leaning namespaces: ``` monitor pricing quota advisor resourcehealth applens subscription group ``` …
Read the whole file at its exact version.
How to install
mdr add wyre-ai/msp-claude-plugins/azure-mcp-connection@git:20260804.055e86emdr add wyre-ai/msp-claude-plugins/azure-mcp-connection@sha256:fc8da1c3409da9bePin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_x3rvmsy5grwzfzel)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260804.055e86e latest | 2026-08-04 | 055e86e | 6,566 B | A | view · diff |
| git:20260728.b7e78fc | 2026-07-28 | b7e78fc | 6,128 B | A | view · diff |
| git:20260713.1fbd3f3 | 2026-07-13 | 1fbd3f3 | 6,100 B | A | view · diff |
| git:20260519.13c8941 | 2026-05-19 | 13c8941 | 6,112 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (6566 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
wyre-ai/msp-claude-plugins · 46 stars · license Apache-2.0 · pushed 2026-09-22 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_x3rvmsy5grwzfzel GET https://markdownregistry.com/api/v1/resolve?ref=wyre-ai/msp-claude-plugins/azure-mcp-connection GET https://markdownregistry.com/api/v1/blob/fc8da1c3409da9bec5f6643f767e23ed3fd06aa839c1b73b8013d572c8ba1815
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.