Skip to content
Developer ToolsAuto-generatedScore: 28

PolicyStatesClient MCP Server

The PolicyStatesClient API is a core component of Microsoft Azure's Policy Insights service, designed to query and retrieve detailed compliance and evaluation state data for Azure Policy across an organization's cloud footprint.

Quick Start Summary

The PolicyStatesClient MCP server is a Model Context Protocol bridge that connects AI assistants — including Claude Desktop, Cursor, Windsurf, and VS Code Copilot — to the PolicyStatesClient API through natural language. It exposes 5 API endpoints as callable tools, such as Operations_List, PolicyStates_ListQueryResultsForManagementGroup, PolicyStates_ListQueryResultsForSubscription, and more. No authentication is required — setup takes approximately 30 seconds. The server uses STDIO transport and can be installed by running npx -y @mcp/azure-com-policyinsights-policystates. This integration is sourced from the auto PolicyStatesClient OpenAPI specification (v2017-08-09-preview) and has a quality score of 28/99 (fair documentation coverage).

5Endpointstools mapped
NoneAuthopen access
28/99Qualityfair
~30 secSetupno auth

Server Details

Category
Developer Tools
Authentication
None
Endpoints
5 operations
Transport
STDIO
Spec Version
v2017-08-09-preview
Install Command
npx -y @mcp/azure-com-policyinsights-policystates

Environment Variables

POLICYSTATESCLIENT_API_KEY

Example: your_policystatesclient_api_key

Top Endpoints

GET
/providers/Microsoft.PolicyInsights/operations

Operations_List

POST
/providers/{managementGroupsNamespace}/managementGroups/{managementGroupName}/providers/Microsoft.PolicyInsights/policyStates/{policyStatesResource}/queryResults

PolicyStates_ListQueryResultsForManagementGroup

POST
/subscriptions/{subscriptionId}/providers/Microsoft.PolicyInsights/policyStates/{policyStatesResource}/queryResults

PolicyStates_ListQueryResultsForSubscription

POST
/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.PolicyInsights/policyStates/{policyStatesResource}/queryResults

PolicyStates_ListQueryResultsForResourceGroup

POST
/{resourceId}/providers/Microsoft.PolicyInsights/policyStates/{policyStatesResource}/queryResults

PolicyStates_ListQueryResultsForResource

Own this API?

Verify ownership of this listing to control the description, configuration details, and documentation links. Choose between free manual verification or instant premium placement.

Option 1: Free Verification

Slow manual review. Requires creating a GitHub issue with verified documentation or domain verification.

  • • Verified badge on page
  • • Standard search sorting
  • • 2-3 business days review
Start Free Claim →
Instant & Boosted

Option 2: Featured Upgrade($9/mo)

Instant verification plus premium styling, featured badges, and directory placement boost.

  • • ★ Featured star & amber highlight border
  • • Top of directory search placement
  • • Instant activation via claim token

📖 Detailed MCP Integration Guide

A technical breakdown of capabilities, agent workflows, and security/configuration best practices.

Capabilities & Use Cases
The PolicyStatesClient API is a core component of Microsoft Azure's Policy Insights service, designed to query and retrieve detailed compliance and evaluation state data for Azure Policy across an organization's cloud footprint. It serves as the programmatic interface for accessing the results of policy evaluations, enabling administrators and automated systems to understand the current compliance posture of resources, subscriptions, and management groups against defined governance rules. This API is essential for enterprises operating in Azure who need to move beyond static dashboards to perform dynamic analysis, automation, and reporting on their governance state. Typical use cases include generating compliance reports for auditors, identifying non-compliant resources for remediation, tracking the impact of new policy assignments, and building custom dashboards that provide real-time insight into resource compliance. The provider, Microsoft, structures the endpoints to support hierarchical queries from the broadest scope (management groups) down to individual resource and subscription levels, making it a powerful tool for organizations with complex, multi-tenant Azure landscapes.
🤖AI Agent Value
When exposed as tools to an AI coding assistant via the Model Context Protocol (MCP), this API becomes exceptionally powerful for developers working on infrastructure-as-code (IaC), DevOps pipelines, or cloud governance automation. An AI agent, such as one integrated into Cursor or Cline, can leverage these endpoints to perform sophisticated, context-aware tasks that bridge the gap between policy definition and operational reality. Instead of manually querying the Azure portal or writing separate scripts, a developer can instruct the AI to dynamically retrieve and analyze live policy state data directly within their coding workflow. This transforms the AI from a code-completion tool into an intelligent operations assistant capable of informing decisions with real-time cloud governance data, thereby accelerating development cycles while enhancing compliance adherence from the earliest stages of infrastructure provisioning.
💬Example Workflows
Practical workflow examples demonstrate significant automation potential. A developer could instruct the AI with a command like, "Query the policy states for the production management group and list all resources that have a failed compliance evaluation for the 'Allowed VM SKUs' policy," enabling the AI to fetch the results and even suggest code modifications to the related ARM or Bicep template to use an allowed SKU. For remediation workflows, a command such as, "Using the subscription-level policy states, identify all storage accounts that are not encrypted and generate a Python script using the Azure SDK to apply the required encryption," allows the AI to build a targeted remediation tool based on live data. Furthermore, an AI agent could be tasked with continuous compliance checks, for example: "Monitor the policy states for the '{subscriptionId}' subscription for any new non-compliant resources created in the last hour and prepare a summary for our DevOps Slack channel," illustrating its utility in proactive, automated governance.
🛡️Security & Auth
Critical implementation considerations must emphasize that while the current description notes "None" for authentication, in practice, all endpoints require valid OAuth 2.0 access tokens from Microsoft Entra ID (Azure AD) for authorization. Developers must configure the MCP server environment with appropriate Azure credentials. Adherence to the principle of least privilege is paramount; the identity or service principal used should be granted only the specific Azure RBAC roles needed, such as 'Policy Reader' for querying states or 'Contributor' only if remediation actions are also automated. It is vital to store credentials securely using mechanisms like environment variables or secret management services, and to ensure all communication occurs over encrypted channels. Configuration should also include proper error handling for scope-specific queries (e.g., handling invalid management group names) and awareness of API rate limits and pagination for large result sets to build robust, enterprise-grade integrations.

Similar APIs

Other APIs in the Developer Tools category.

GitHub API

Access GitHub repositories, issues, pull requests, and more. Integrate GitHub workflows directly into your AI agent.

OAuth2

GitLab API

Manage repositories, CI/CD pipelines, and merge requests through your AI agent.

OAuth2

Box Platform API

The Box Platform API, provided by Box (box.com), is a robust and comprehensive RESTful service that enables deep integration with the Box cloud content management ecosystem. It serves as the programmatic backbone for enterprises and developers seeking to build custom applications and workflows that interact with content stored securely in Box. Its core capabilities extend far beyond basic file operations, encompassing a full spectrum of content lifecycle management. Developers can programmatically create, upload, download, search, and manage files and folders, but the API's true power lies in its enterprise-grade features. These include advanced collaboration management through invitations and permissions, granular user and group administration within an enterprise directory, and sophisticated security and compliance controls. Specific endpoint groups for managing collaboration whitelists and exempt targets allow for precise governance over external sharing policies, ensuring that content is only shared with approved domains. Furthermore, the API facilitates complex legal and compliance use cases, such as placing items on legal hold or applying retention policies, making it an indispensable tool for regulated industries and large organizations.

Asana

This API serves as the programmatic backbone for the Asana work management platform, provided by Asana, Inc. It enables developers to interact programmatically with one of the world's leading enterprise collaboration and productivity suites. The core capabilities of this interface center around the CRUD (Create, Read, Update, Delete) operations for fundamental Asana objects. Specifically, the provided endpoints grant control over project attachments—allowing for the uploading, retrieval, and management of files associated with tasks and projects—and custom fields, which are pivotal for creating structured, data-rich workflows. These custom fields allow organizations to define unique data types (like dropdown menus, text fields, or dates) to standardize information capture across projects, moving beyond basic task lists to true operational tracking. Typical use cases span from enterprise project management offices (PMOs) needing to programmatically generate status reports and audit attachments, to development teams automating the creation of bug-tracking projects with predefined custom fields for severity and status, to operational leaders building dashboards that aggregate and analyze custom field data for resource allocation insights.

Related MCP Server Integrations

GitHub API MCP Setup

Access GitHub repositories, issues, pull requests, and more. Integrate GitHub workflows directly into your AI agent.

Developer ToolsConfigure →

GitLab API MCP Setup

Manage repositories, CI/CD pipelines, and merge requests through your AI agent.

Developer ToolsConfigure →

Box Platform API MCP Setup

The Box Platform API, provided by Box (box.com), is a robust and comprehensive RESTful service that enables deep integration with the Box cloud content management ecosystem. It serves as the programmatic backbone for enterprises and developers seeking to build custom applications and workflows that interact with content stored securely in Box. Its core capabilities extend far beyond basic file operations, encompassing a full spectrum of content lifecycle management. Developers can programmatically create, upload, download, search, and manage files and folders, but the API's true power lies in its enterprise-grade features. These include advanced collaboration management through invitations and permissions, granular user and group administration within an enterprise directory, and sophisticated security and compliance controls. Specific endpoint groups for managing collaboration whitelists and exempt targets allow for precise governance over external sharing policies, ensuring that content is only shared with approved domains. Furthermore, the API facilitates complex legal and compliance use cases, such as placing items on legal hold or applying retention policies, making it an indispensable tool for regulated industries and large organizations.

Developer ToolsConfigure →

Asana MCP Setup

This API serves as the programmatic backbone for the Asana work management platform, provided by Asana, Inc. It enables developers to interact programmatically with one of the world's leading enterprise collaboration and productivity suites. The core capabilities of this interface center around the CRUD (Create, Read, Update, Delete) operations for fundamental Asana objects. Specifically, the provided endpoints grant control over project attachments—allowing for the uploading, retrieval, and management of files associated with tasks and projects—and custom fields, which are pivotal for creating structured, data-rich workflows. These custom fields allow organizations to define unique data types (like dropdown menus, text fields, or dates) to standardize information capture across projects, moving beyond basic task lists to true operational tracking. Typical use cases span from enterprise project management offices (PMOs) needing to programmatically generate status reports and audit attachments, to development teams automating the creation of bug-tracking projects with predefined custom fields for severity and status, to operational leaders building dashboards that aggregate and analyze custom field data for resource allocation insights.

Developer ToolsConfigure →

clickup20 MCP Setup

The clickup20 Polls API is a lightweight, focused web service designed to facilitate the creation and management of simple polling mechanisms. Provided by ClickUp, a platform known for its project management and productivity tools, this API serves as a specialized component for gathering quick, quantitative feedback. Its core capabilities are straightforward: it allows consumers to programmatically retrieve a list of existing poll questions and to submit new poll questions for consideration. Typical use cases span both enterprise and consumer domains. In an enterprise setting, a development team might integrate this API to run quick polls during sprint retrospectives, gauge internal sentiment on a new tool, or gather binary feedback on proposed technical designs within a project management workflow. For consumer applications, it could power simple feedback widgets within a mobile app or website, enabling users to vote on feature priorities or content topics. The API’s simplicity, requiring no authentication, makes it highly accessible for rapid prototyping and integration into internal tools where complex credential management is unnecessary.

Developer ToolsConfigure →