An AI-driven Azure operations workbench that runs in your subscription. Point it at your tenant and AI discovers your workloads, reverse-engineers live architecture diagrams, and runs Well-Architected assessments — then a War Room of specialist agents helps you investigate, monitor, and remediate.
Deploy · Install guide · User guide · How-to guides · Administration · Connectors · Docs
🆕 Latest: a ten-tab Entra ID identity workbench (Conditional Access simulator, PIM, app credentials, and Investigate for any principal), IAM access review (effective permissions, escalation paths, least-privilege, review campaigns), Backup Manager and Alerts Manager — both with approval-gated, reversible changes — and AI Insight Packs that watch your estate on a schedule and notify you only when something material happens.
Operating Azure at scale means hopping between the Portal, CLI, Resource Graph, Monitor, Advisor, and a dozen blades just to answer one question. Azure Support Agent puts an LLM in the driver's seat — it talks to your subscription through the official Azure MCP server and a Microsoft Graph (Entra ID) MCP server, reasons over live evidence, and turns "why is the website throwing 5xx?" into a ranked, validated answer — with the diagrams, assessments, and dashboards to back it up. And it doesn't just wait to be asked: a whole Proactive Support suite continuously scans your estate for coverage gaps and looming retirements, while scheduled autonomous agents push findings to Teams, Jira, ServiceNow, PagerDuty, your SIEM, or Azure Logic Apps before they bite.
- 🧠 Agentic, not just a chatbot — a War Room of specialist agents investigates in parallel against your real Azure data.
- 🛡️ Proactive, not just reactive — a Proactive Support hub (Assessments · Identity · Monitoring, Telemetry & Backup/DR coverage · Retirement Radar · Telemetry Intelligence · Performance Profiler · Ownership · Tag Intelligence · Change Explorer · Estate Graph) surfaces risks before you ask, and scheduled autonomous agents notify you via connectors.
- 🏠 Runs in your tenant — one-click deploy to Azure Container Apps; your data never leaves your subscription.
- 🔒 Safe by default — Azure access is read-only, writes are approval-gated + audited, and AI providers stay disabled until you configure them.
- 🧰 A whole workbench — chat, investigations, architectures, a workloads cockpit, inventory, assessments, policy, monitoring, ownership, tagging, change forensics, an estate knowledge graph, and automations.
Built for cloud architects, SREs, platform teams, and Azure support engineers.
- Features
- Screenshots
- Deploy to Azure (one-click)
- Documentation portal
- Installation guide
- User guide
- How-to guides
- Administration
- Connectors
- Quick start (local)
- How it works
- Tech stack
- Security & access model
- Documentation
- Contributing
- License
|
Multi-session chat with isolated context, live SSE streaming, a per-message reasoning + tool-call timeline that persists across reloads, image support, and smart starter suggestions. Cancel a running turn anytime — work continues server-side and is saved. |
Toggle deep mode to dispatch specialist agents (Networking, Identity, Compute, Storage, Security, Reliability, Cost, Monitoring) that research in parallel, form hypotheses, and validate them against your live Azure data — then converge on a conclusion. |
|
Discover and group resources into workloads, then work a fleet cockpit with composite health scores, a resource taxonomy, table/board views, and rich visualizations (donut, radar, sparkline, treemap). Drill into a per-workload command center, or let Autopilot AI-discover and propose workloads for you. |
Run every analysis against a workload from one cockpit — architecture, assessment, coverage, identity and more — and read a single go/no-go posture with the highest-risk items surfaced first. |
|
AI reverse-engineers live resources into interactive diagrams with best-practice review, network boundaries, and cost hints. Save revisions, build collections, and keep persistent Architecture Memory that powers dashboards and investigations. |
A live, workload-aware knowledge graph of your tenant with cost, retirement and RBAC overlays — pan, zoom, search, and deep-link straight into the workload, architecture or assessment behind any node. |
|
A ten-tab identity workbench: posture scoring, Conditional Access (coverage, exposure, conflicts, break-glass, and a policy simulator), privileged access and PIM, app registrations and credential expiry, sign-in signals, guest and access governance, an identity graph, and a findings ledger. Investigate any user, guest, group, service principal or managed identity — including deleted ones — with provenance on every section, so "unreadable" never looks like "empty". |
Azure RBAC you can actually reason about: effective permissions for any principal, an access map, privilege-escalation and bypass path detection, least-privilege recommendations, a what-if simulator, snapshot compare, scope and role explorers, and access review campaigns with reviewer routing, delegation, and evidence. |
|
A federated owner directory scoped by tenant, subscription or workload. Export owners, import any CSV/Excel with AI column-inference and a preview, then apply as Azure tags with snapshots and safe revert. |
A tag census with coverage, casing-drift detection and a natural-language → Azure Resource Graph console. Propose, apply and revert tag changes with full revision history. |
|
See what changed, when, and who did it across your estate — each change AI-categorized and risk-scored, with plain-English insights that float the highest-risk changes to the top for review. |
Run Well-Architected-style assessments across Security, Reliability, Cost, Operations, and Performance pillars — with custom controls, framework mappings (NIST, ISO, CIS), waivers, finding lifecycle, and ticketing. Plus Policy compliance, baselines, and AI advisors. |
|
Beyond coverage reporting: a live backup inventory, job health, policy and vault management, and DR drills. Changes are approval-gated, encrypted before/after state is retained, and every apply has a rollback path. |
A fired-alert inbox with action-group management, overlap and routing analysis, and baseline gap detection. Rule and action-group edits follow the same approval-gated, audited, reversible path as Backup Manager. |
|
One unified, filterable resource grid across every connected tenant, with overview, location, cost and optimization views, plus a change feed — the flat estate view the Portal never quite gives you. |
An Evidence Locker of investigation snapshots with diffs, sharing and export, and durable Case Files that keep an incident's timeline, findings and the identity it concerns in one place — including cases opened straight from an identity investigation. |
|
Monitor 2.0 customizable dashboards with AI authoring and ping history; AMBA baseline-alert coverage with one-click Bicep/Terraform gap remediation; Performance Profiler, Backup/DR coverage, Retirement Radar, and telemetry intelligence. |
Build custom sub-agents with scoped tools, schedule recurring tasks (advanced cron recurrence builder), chain Workbooks into Playbooks, and route results through in-app Notifications and external connectors — Teams, Slack, Jira, ServiceNow, PagerDuty, Splunk, Sumo Logic, CrowdStrike NG-SIEM, AWS Security Hub, Grafana, Azure Logic Apps, and more. |
|
One categorized landing page that unifies every posture and forensic dashboard, in the same clusters the product and the docs use:
|
A dozen+ providers — OpenAI, Azure OpenAI, Anthropic Claude, Google Gemini, GitHub Copilot/Models, Grok, Mistral, OpenRouter, ChatGPT (OAuth), Claude OAuth (Pro/Max, incl. Opus 4.8), Ollama, LM Studio — switchable at runtime with live model catalogs. Disabled until you set them up. |
🔐 Read-only Azure by default · ✅ approval-gated writes · 🧾 full audit log · 👥 RBAC (users / roles / groups) · 🔑 OIDC + SAML SSO · 🗝️ encrypted connection credentials · 🌐 IP allowlisting · 🖥️ Sandbox VMs for private-endpoint diagnostics · 🧩 multi-tenant Azure connections.
Status: tested. Provisions a managed PostgreSQL database, Azure Files state storage, and the Container App running the public image — in your subscription, in one deployment. No CLI, no manual wiring.
What it creates:
- Azure Container App running the public Docker Hub image
- Azure Database for PostgreSQL — Flexible Server (managed), auto-linked via
DATABASE_URL(?ssl=require) - Azure Files share mounted at
/app/.data(registries, caches, encryption key) - Container Apps environment + external HTTPS ingress on port 8000
💰 Estimated cost: ~$25–35 / month for the default infra at typical low/idle usage (West US 3, pay-as-you-go) — mostly the Container App (1 vCPU / 2 GiB) and a Burstable
B1msPostgreSQL server.
You supply only an admin password (you're forced to change it on first login). Then connect your Azure tenant and an LLM from Settings — the AI does the rest (workload discovery, architectures, coverage scans, assessments, retirement radar, performance profiling). Defaults to West US 3 (validated for Container Apps + PostgreSQL B1ms).
📖 New here? Follow the step-by-step installation guide — from clicking the button to onboarding your first workload.
Prefer the CLI or want full control? See the manual deployment guide.
Prerequisites: Docker Desktop · Azure CLI (az) · an LLM key (or a local Ollama / LM Studio).
# 1) Sign in to the subscription you want to work with
az login
az account set --subscription "<your-subscription-id>"
# 2) Configure environment
Copy-Item .env.example .env # set LLM_API_KEY (optional — you can also do it in the UI)
# 3) Run the whole stack
docker compose up --buildOpen http://localhost:5173. The backend runs DB migrations on startup; the first Azure
MCP call fetches @azure/mcp via npx (a few seconds), then caches it.
Health check: /healthz · MCP tools (admin):
/api/admin/mcp/tools
Full local/dev instructions (native backend, tests, type-check) live in CONTRIBUTING.md.
The whole app — FastAPI API + the built React SPA + the in-process MCP servers — ships as one container image and runs as a single Container App. No separate frontend, database, or Redis containers required.
flowchart LR
U([Browser]) --> SPA[React SPA]
SPA -->|/api| BE[FastAPI backend<br/>orchestrator · SSE streaming]
BE --> LLM{{LLM providers<br/>OpenAI · Claude · Gemini<br/>Copilot · Ollama · …}}
BE --> AZ[Azure MCP server · stdio]
BE --> EID[Entra / Graph MCP server · stdio]
BE --> TOOLS[Built-in tools<br/>DNS · HTTP · ping · traceroute]
BE --> DB[(PostgreSQL / SQLite)]
BE --> FILES[[Azure Files<br/>/app/.data]]
AZ --> SUB[(Your Azure subscription)]
EID --> GRAPH[(Microsoft Graph)]
For local dev nothing is deployed to Azure — the MCP server reaches your real subscription outbound using your signed-in identity and existing RBAC, read-only by default.
| Layer | Tech |
|---|---|
| Backend | Python 3.12 · FastAPI · async SQLAlchemy 2 · Pydantic v2 · Alembic · SSE |
| Frontend | React 18 · TypeScript · Vite · Tailwind · TanStack Query · Recharts · XYFlow · Cytoscape · Mermaid |
| AI | Provider abstraction with streaming + normalized tool-calls (a dozen+ providers) |
| Azure | Official Azure MCP server (@azure/mcp) · Azure CLI / Resource Graph runner |
| Entra ID | Vendored Microsoft Graph (EntraID) MCP server over stdio |
| Data | PostgreSQL (prod) / SQLite (local) · Azure Files for state |
| Hosting | Azure Container Apps (single image) |
- Read-only by default. The Azure MCP server starts with
--read-only; write-capable tools are classified, approval-gated, and audited. - AI providers off until configured. A fresh install ships every provider disabled; a provider only becomes selectable once you add a key (or sign in / set a local base URL).
- Identity & SSO. Local users with RBAC (users / roles / groups), plus OIDC and SAML SSO. Forced password change on first admin login.
- Network access. Restrict which source addresses can reach the application at all — an in-app IP allowlist with a monitor mode that shows what would be blocked before you enforce it, Container Apps ingress restrictions, or no public endpoint at all.
- Secrets. Connection credentials are encrypted at rest and never returned to the UI.
.env,backend/.data/, and keys are git-ignored. - Found a vulnerability? Please follow SECURITY.md — don't open a public issue.
The complete documentation is published at zmustafa.github.io/AzureSupportAgent. Every major application screen includes a contextual Help link to its owning guide.
| Public documentation | What's inside |
|---|---|
| Getting started | Installation, first-run configuration, Azure tenant setup, and deployment |
| User guide | Feature-by-feature product reference |
| How-to guides | Task-oriented operational procedures and verification steps |
| Administration | Providers, tenants, access, security, reference sets, usage, audit, and backup |
| Connectors | Setup guides for messaging, ticketing, SIEM, webhooks, queues, and storage |
| Security | Security model, credentials, approval controls, and deployment posture |
| Permissions reference | Product and Azure/Graph permissions by workflow |
| Troubleshooting | Common failures, diagnostics, and recovery |
| Concepts and glossary | Product vocabulary and operating concepts |
| Technical documentation | Architecture, implementation, APIs, and deployment internals |
| Repository guide | Purpose |
|---|---|
| CONTRIBUTING.md | Local dev, tests, type-check, PR guidelines |
| SECURITY.md | Vulnerability disclosure policy |
| CODE_OF_CONDUCT.md | Community guidelines |
Contributions are welcome! Please read CONTRIBUTING.md and our Code of Conduct. Good first steps: open an issue to discuss a change, keep PRs focused, and make sure backend tests and the frontend type-check pass.
MIT © 2026 Zeeshan Mustafa (@zmustafa)
- Azure MCP server — the official Azure tool surface
- EntraID MCP server (Microsoft Graph, FastMCP) — vendored under
third_party/ - The Model Context Protocol community

















