Skip to main content

Overview

The Azure Resource Manager (MCP) connector lets Rootly AI inventory Azure resources and inspect Azure Resource Manager deployment status. Rootly connects to Microsoft’s maintained endpoint at https://mcp.management.azure.com and uses delegated Microsoft Entra OAuth, so you don’t deploy or operate an MCP server.
Azure has two Rootly AI connectors. Use this MCP connector for resource inventory and ARM deployment status. Use Azure Monitor for logs, metrics, alert instances, activity and resource changes, Resource Health, and diagnostic settings. You can connect both.
This connector is also separate from the existing Azure alert source, which sends Azure alerts into Rootly for routing and paging. See Alert Sources.

Before You Start

You’ll need:
  • A Microsoft Entra account that can authorize Rootly and read the Azure subscriptions and resources responders need to investigate.
  • Azure RBAC assignments for that account at the smallest appropriate subscription, resource-group, or resource scope.
  • Permission to manage AI connectors in Rootly.
Rootly AI inherits the authorizing user’s Azure access. Connecting the MCP endpoint does not grant additional Azure permissions. If that user is deprovisioned or loses Azure RBAC, Rootly AI immediately loses the same visibility; reconnect with an appropriate account when ownership or access changes.

Connect Azure Resource Manager (MCP)

1

Open the Azure Resource Manager (MCP) card

In Rootly, go to AI & Agents → Connectors and click Connect on the Azure Resource Manager (MCP) card.
2

Authorize with Microsoft Entra

Sign in with the Microsoft Entra account Rootly AI should use and approve the requested access. Rootly uses Microsoft’s fixed hosted MCP endpoint; there is no endpoint URL, tenant secret, or MCP server to configure.
3

Confirm the connection

After authorization and Rootly’s catalog probe succeed, the connector card shows Connected. Ask a resource question whose answer you can verify in Azure before relying on the connector during an incident.

What Rootly AI Can Read

Rootly exposes four reviewed MCP tools: The hosted MCP catalog also advertises write-capable Azure tools. Rootly filters those tools out; this connector exposes only the four operations above.
Treat generate_query as a draft, not proof that a query answers the intended question. Rootly AI validates and semantically reviews generated Resource Graph queries before execution. An empty result is inconclusive and can also mean the authorizing user lacks access to the relevant scope.

Choosing Between the Azure AI Connectors

Connect both when responders need resource discovery and deep operational evidence in the same investigation.

Security and Data Handling

  • Microsoft hosts and maintains the MCP endpoint; Rootly does not require a customer-hosted service.
  • Microsoft Entra OAuth identifies the authorizing user, and Azure RBAC remains authoritative.
  • Rootly fixes the endpoint to https://mcp.management.azure.com; users cannot substitute another host for this provider.
  • Rootly applies a read-only tool allowlist even if the upstream catalog exposes mutation tools.
  • Requests use a bounded 60-second timeout.
Query results can appear in Rootly AI traces used for quality monitoring. See Data Privacy for Rootly AI for retention and model-training controls.

Troubleshooting

Confirm that you’re signing in to the intended Microsoft Entra tenant and that your organization permits the Rootly enterprise application. An Entra administrator may need to approve the application or consent policy first.
Check the Azure RBAC assignments of the account that authorized Rootly. The connector can only query subscriptions and resources that account can read. Empty Resource Graph results are not proof that a resource doesn’t exist.
Query validation checks syntax and Azure acceptance, not whether the query captures the intended semantics. Make the resource types, subscriptions, tags, and desired fields explicit, then ask Rootly AI to review the query before execution.
Provide the exact ARM deployment identifiers and confirm the authorizing account can read that deployment scope. Use the native Azure Monitor connector when you need deployment operations correlated with logs, activity, or resource changes.

Azure Monitor

Query Azure operational evidence through Rootly’s native read-only connector.

Alert Sources

Send Azure alerts into Rootly for routing and paging.

Connectors Overview

Compare all Rootly AI connectors and setup flows.