ADR-024: Microsoft Ecosystem MCP — Live Azure Server, Reconciled 'Live' Rule, Link-Out Docs
Status: Proposed
Date: 2026-09-13
Last Updated: 2026-09-13
Deciders: cloud-architect, product-owner
Context
Azure MCP Server (@azure/mcp 2.0.5) and Azure Resource Manager MCP (preview) both expose Azure capabilities. Azure subscription listing and role assignment retrieval have been measured and reconciled against independent az cross-checks. Advisor recommendations cap at 50 per subscription. Resource health returns first page only. Policy compliance state is absent. ARM MCP preview includes write tools and has no client registration path today.
Evidence: tmp/adlc-framework/evidence/azure-stories-ac-2026-09-13.json
Options
A. Azure MCP Server (azmcp) is the only live Azure server; ARM MCP is shown as preview, not connected (CHOSEN)
Enforced --read-only start flag. 60 measured namespace tools. Tenant isolation proven. Reconciled answers exist for subscription_list and role assignments.
B. Both azmcp and ARM MCP live
ARM MCP preview includes write tools (create_deployment, create_or_update_resource) with no client-side fence. Remote endpoint has no dynamic client registration. Rejects this option.
C. ARM MCP only
Preview, GitHub Copilot/VS Code only, no DCR, not connectable from Claude Code today. Leaves zero live Azure capability. Rejects.
Decision: D5 — Eight Microsoft Product Groups
The /mcps/azure capability showcase spans eight distinct Microsoft product groups: Azure, Entra ID, Sentinel, Microsoft 365 and Teams, GitHub, Azure DevOps, Playwright, and Microsoft Fabric. This grouping supersedes the earlier five business-lens model and reflects the breadth of Microsoft's ecosystem.
Decision: D6 — Storytelling Order
The eight groups are presented in this order for risk-first narrative:
- Azure (cost)
- Entra ID (risk)
- Sentinel (risk)
- Microsoft 365 and Teams (speed)
- GitHub (speed)
- Azure DevOps (speed)
- Playwright (risk)
- Microsoft Fabric (cost)
This order matches the /showcase:video slide progression.
Decision: D7 — No Tenant Facts on Public Site
The public site (adlc.oceansoft.io) must never show tenant names, figures, subscription counts, or per-month usage numbers. Every item's scenario, story, and roadmap reason is authored for a generic audience. Evidence files stay in tmp/; only vendor-level facts appear publicly.
Decision: D8 — Services Tiles, Short Names, Official Icons
The /mcps/azure capability showcase adopts the same services tile format as /mcps/aws: icon + short name left, 'N tools' right, one-line footer 'C tools connected · A available'. Short names (1–3 words, vendor-prefix-free) replace namespace labels across all 15 items. Official Microsoft icons—Azure Architecture Icons, Microsoft Entra architecture icons, Microsoft Fabric icons (v6.1.0), and Microsoft 365 content icons—are vendored in-repo under .claude/mcps/vendor/ with no online links; GitHub and Playwright keep existing repo logos. This supersedes the 3-line summary tile (D8.1).
Decision: D9 — Hero from the Orbit Hub and Microsoft-Group Detail Cards
The hero section derives its counts (1 MCP-Server | 60 tools) from the same orbit hub data, replacing four metric cards with a two-line lede naming Azure, Entra ID, Sentinel, Microsoft 365, GitHub, Azure DevOps, Playwright and Fabric — tenant-free, no AWS-parity claim. Below the orbit, eight Microsoft-group detail sections (matching D6 order) replace nine legacy namespace-chip sections. Each detail card shows a question it answers, a copyable read-only prompt (when applicable), the read-only enforced marker, resource caveats, and setup steps. The read-only guarantee is stated once per page plus one data-derived marker per prompt card. See ADR-023 § "6. Azure mirrors AWS through namespaces" for the shared page structure; D9 replaces only Azure's namespace rendering, not the AWS output.
Consequences
Positive
- One read-only-enforced Azure server with clear boundaries serves the capability showcase.
- 'Live' means answered AND reconciled. Executives see only verified claims.
- Upstream behaviour linked to Microsoft Learn, not copied.
- Public site carries no customer reconnaissance data.
- Services tile aligns Azure visual identity with AWS; icon terms and short names clarify product scope.
- Official Microsoft icons (Azure, Entra, Fabric, Microsoft 365 content icons) stored in-repo under
.claude/mcps/vendor/; never linked externally (D8.4b locality rule). - Playwright and the Microsoft 365 connector cards show no prompt until read-only enforcement is evidenced; Resource Health shows a caveat that large subscriptions may return partial results.
- AWS
/mcps/awsoutput unchanged; Azure namespace rendering lives behind flag-gated data field, preserving AWS byte-identity.
Negative
- Advisor cost returns at most 50 per subscription with no paging. No billing tool.
- Resource health first-page only.
- Policy compliance state absent.
- Access review proven for one subscription scope, not tenant-wide.
Risks
- Future @azure/mcp repin silently changes tool surface or caps. Mitigation: reconciled_answers records carry evidence_sha256 and story ID.
- Fabric (write-capable) wired into product tenants. Escalated as HITL_REQUIRED.
Review Triggers
- ARM MCP reaches GA with read-only mode AND client path from Claude Code → re-evaluate option B.
- @azure/mcp adds paging to advisor_recommendation_list, nextLink to resourcehealth, or policy compliance-state → re-run stories; restore withheld playbooks if PASS.
- Microsoft Enterprise MCP provisioned with Claude Code client path → onboard with service principal + admin consent.
- Azure DevOps organisation configured AND Entra app registered → onboard ADO remote with X-MCP-Readonly header.
- Fabric ships read-only mode or permissions.deny fence authored → Fabric may leave not_connected.
- AWS reconciled_answers exist for every currently-live AWS server → flip live_rule to 'reconciled'.
- Any MCP server's read-only classification changes (from enforced to connector, or vice versa) → re-check D9 prompts and markers.
References
- Azure MCP Server Overview
- Microsoft Enterprise MCP
- Azure DevOps MCP
- ADR-023: AWS and Azure MCP Capability Pages (see "6. Azure mirrors AWS through namespaces" for the shared page structure)