Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For Claude users who want to work with Azure resources, Microsoft’s Azure MCP Server is the main starting point. Claude Desktop has an installation path using Microsoft’s downloadable .mcpb extension bundle; Claude Code has a documented Azure plugin command. Choose Foundry MCP Server instead when the tools you need are specifically for Microsoft Foundry services. In either case, Claude’s available actions depend on the client, server version, enabled tools, and the signed-in user’s Azure permissions.

Which Microsoft MCP server should you use with Claude?

Start with the service you want Claude to work with, not with the fact that both products use MCP:

Server Choose it when What it provides
Azure MCP Server You want Claude to interact with Azure resources or services. A Microsoft MCP implementation for Azure operations, with tools and accessible resources governed by authentication, permissions, and server configuration.
Foundry MCP Server Your work is specifically with Microsoft Foundry services. A cloud-hosted MCP implementation that gives agents secure tool access to Foundry services.

These servers are not interchangeable just because they speak the same protocol. Azure MCP Server is the broad Azure choice; Foundry MCP Server is focused on Foundry. Microsoft’s Foundry getting-started material includes Visual Studio Code setup guidance, while the Azure server’s client guidance covers a wider range of hosts. For Claude, use the Claude-specific installation route rather than assuming that a setup documented for another host applies unchanged.

How Claude connects to Azure MCP Server

There are two documented Claude paths: install the extension bundle in Claude Desktop, or install the Azure plugin in Claude Code. These are different host workflows, not two names for the same installation.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Claude Desktop: install the .mcpb bundle

  1. Open Microsoft’s Azure MCP Server installation guide and download the .mcpb bundle for your operating system and architecture. Microsoft lists bundles for Windows, macOS, and Linux architectures.
  2. In Claude Desktop, drag the downloaded bundle into the application, or use Claude Desktop’s extension installation settings to install it.
  3. Complete the extension’s setup and authentication prompts. Sign in with the Microsoft Entra ID account intended for this work, and confirm that the account has access to the Azure subscription and resources you expect to use.
  4. Start a small, read-only task first. Confirm that Claude can discover and use the server’s available tools before asking it to make a change.

The bundle is a software extension for Claude Desktop, not a physical device. Bundle availability and installation behavior can change with server releases and Claude Desktop updates, so use Microsoft’s current installation guide for the package and host version you have.

Claude Code: install the Azure plugin

Microsoft’s MCP Registry entry documents this command for installing the Azure plugin from Anthropic’s official Claude plugin marketplace:

/plugin install azure@claude-plugins-official

Run it in Claude Code, then follow the host’s prompts to finish installation and authentication. Marketplace listings and server releases can change; check the current listing if the command is not recognized or the plugin cannot be found. Microsoft describes Azure MCP Server 2.0 as generally available in its registry entry, but that status does not guarantee that every client, plugin listing, or tool has the same version or availability at all times.

Other clients and transport configurations

Microsoft also documents package-manager and HTTP configurations for compatible clients, alongside setup material for environments such as Visual Studio Code, Visual Studio, Cline, Cursor, Eclipse, IntelliJ, and Windsurf. A client appearing in that general list is not, by itself, a Claude setup instruction. If you are connecting Claude to an HTTP endpoint rather than installing locally, follow the current client and server documentation for the transport and authentication supported by your deployment. Do not copy a configuration from another MCP host and assume its field names, credential handling, or transport support will work in Claude.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Claude can do depends on Azure identity and permissions

Azure MCP Server uses Microsoft Entra ID through the Azure Identity library. Authentication establishes which identity is making the request; Azure role-based access control (RBAC) determines what that identity may do and at which scope. A successful server connection is not proof that Claude has access to every subscription, resource group, or operation.

Think of the setup as four layers: Claude is the MCP client; Azure MCP Server exposes tools; Entra ID authenticates the user or configured identity; Azure permissions constrain access to resources and actions. The tools Claude can use also depend on what the server enables and what the host supports. Consequently, two people using the same server may see different usable capabilities because their Azure roles differ.

Apply least privilege before enabling write operations

  • Use an account or identity scoped to only the subscription, resource group, or resources needed for the task.
  • Grant the narrowest Azure roles that allow the intended work; avoid using a broadly privileged administrator identity for routine exploration.
  • Begin with read-only requests and inspect what resources and actions are available before asking Claude to create, modify, or delete anything.
  • For change-capable workflows, review the proposed operation, target resource, and scope before execution. Natural-language requests do not replace authorization review.
  • Recheck role assignments and authentication context when expected tools or resources are missing. The server cannot grant permissions the identity does not have.

Microsoft’s documentation describes tool availability as reflecting Azure subscription permissions. Treat the server as an interface to the permissions already assigned, not as a mechanism that safely narrows an overprivileged identity by itself.

Local Claude setup or a remote enterprise endpoint?

A local extension or package-based setup is often the more direct route for an individual developer. A remote MCP endpoint can make sense when an organization needs centralized policy enforcement, shared operations, monitoring, or governance. The trade-off is operational: the local path keeps more of the setup close to the user’s Claude host, while the remote path introduces a service endpoint and the controls required to operate it securely.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Consideration Local installation Remote deployment
Where the MCP server runs On or through the user’s local Claude Desktop or Claude Code setup, depending on the chosen installation. At an organization-managed or hosted endpoint reached by a compatible client.
Identity and permissions Use the documented Entra ID authentication and Azure RBAC model; the user’s permissions shape accessible tools and resources. May add a gateway that validates identity and enforces additional access policies before requests reach the backend.
Governance and operations Primarily managed through the local host, server setup, and Azure access controls. Can centralize policy, observability, monitoring, and scaling, but requires ownership of gateway and backend configuration.
Best fit Individual use, development, or a direct client setup. Managed enterprise access to MCP backends where centralized controls are required.

Secure remote Claude access with Azure API Management

For an enterprise deployment, Microsoft describes Azure API Management (APIM) as a way to expose and govern MCP servers and their backends for AI clients including Claude. APIM can sit between Claude’s MCP client and the MCP backend, providing a control point for identity validation, authorization policies, observability, monitoring, and scaling.

Microsoft’s Claude-focused guidance presents APIM as an OAuth 2.0 gateway powered by Microsoft Entra ID. In this architecture, Claude connects to the exposed endpoint; the gateway validates the identity token and applies the organization’s policies; and only then does the request reach the backend. This is distinct from simply installing Azure MCP Server locally: a gateway adds a managed boundary and operating responsibilities, and it does not eliminate the need to secure the backend or assign appropriate Azure permissions.

Deployment checks for administrators

  • Define which users or applications may connect and which MCP operations they may invoke.
  • Configure OAuth 2.0 and Entra ID identity validation for the remote access pattern, including the expected token audience and authorization rules.
  • Apply policy at the gateway and ensure backend access is not unintentionally available around that gateway.
  • Set up monitoring and observability so administrators can review access and service behavior.
  • Test denied access as well as successful requests. A secure deployment should reject identities and operations outside the intended policy.
  • Keep the client, MCP server, gateway configuration, and identity policies aligned as versions and marketplace availability change.

Microsoft’s API Management guidance establishes the gateway pattern and its capabilities; exact endpoint configuration depends on the deployment and the MCP backend. Use the current Microsoft API Management and Claude integration documentation for implementation-specific settings rather than treating the architecture description as a ready-made configuration file.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common problems and how to diagnose them

Claude Desktop does not accept the bundle

Check that you downloaded the bundle for the correct operating system and architecture, and follow Claude Desktop’s current extension installation flow. If drag-and-drop does not work, use the extension installation settings. A bundle intended for a different platform or an outdated package can prevent installation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Claude Code plugin command cannot find the plugin

Verify that you are running Claude Code and that the current official marketplace listing still uses azure@claude-plugins-official. Plugin names and marketplace contents can change. If the listing is unavailable, consult the current Microsoft MCP Registry entry and Anthropic marketplace rather than substituting an unverified plugin identifier.

Authentication succeeds but resources or tools are missing

Confirm the Entra ID account and tenant context, the selected Azure subscription, and the identity’s RBAC assignments at the relevant scope. Also check the server version, enabled tools, and client support. A connection can be healthy while the signed-in identity lacks permission for a particular resource or operation.

A remote endpoint rejects a request

For a gateway-based deployment, have the administrator check token validity, OAuth configuration, identity-provider settings, authorization policy, and whether the requested operation is allowed. A rejection may be an intentional policy result rather than an MCP server failure. Review gateway monitoring and backend logs to distinguish identity, policy, transport, and service errors.

Claude sees the server but an operation fails

Check whether the operation is supported by the installed server version and enabled for the client, then verify that the identity has the necessary Azure permissions. For a write request, confirm the target resource and scope explicitly. Do not solve a permission error by granting broad access without first identifying the missing permission and whether the operation should be allowed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where ScreenshotNeo fits in a Claude workflow

ScreenshotNeo is not an Azure resource-management server and does not replace Azure MCP Server or Foundry MCP Server. It is a separate website screenshot API and MCP server that can be useful when a Claude workflow also needs to capture webpages. Its MCP tools include take_screenshot, get_page_info, and capture_pdf, and it works with Claude, Cursor, and other MCP clients. For that adjacent screenshot task, try ScreenshotNeo first: it removes cookie banners, newsletter popups, and chat widgets before capture, and only clean shots are billed.

For a direct API call, the endpoint returns an image or PDF for a supplied URL. See the ScreenshotNeo API documentation for options and response details.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing; response headers identify the page verdict and whether the request was billed. The MCP server lets AI agents take screenshots, and the free plan includes 1,000 screenshots per month with no card required; paid plans start at $5 for 3,000. Sign up for 1,000 free screenshots a month with no card.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.