Skip to content
Developer ToolsAuto-generatedScore: 34

PolicyClient MCP Server

The PolicyClient API, provided by Microsoft as part of the Azure Resource Manager (ARM) ecosystem, serves as the authoritative gateway for managing and governing Azure Policy resources within an organization's cloud environment.

Quick Start Summary

The PolicyClient MCP server is a Model Context Protocol bridge that connects AI assistants — including Claude Desktop, Cursor, Windsurf, and VS Code Copilot — to the PolicyClient API through natural language. It exposes 10 API endpoints as callable tools, such as PolicyAssignments_List, PolicyDefinitions_List, PolicyDefinitions_Get, and more. No authentication is required — setup takes approximately 30 seconds. The server uses STDIO transport and can be installed by running npx -y @mcp/azure-com-resources-policy. This integration is sourced from the auto PolicyClient OpenAPI specification (v2015-10-01-preview) and has a quality score of 34/99 (fair documentation coverage).

10Endpointstools mapped
NoneAuthopen access
34/99Qualityfair
~30 secSetupno auth

Server Details

Category
Developer Tools
Authentication
None
Endpoints
10 operations
Transport
STDIO
Spec Version
v2015-10-01-preview
Install Command
npx -y @mcp/azure-com-resources-policy

Environment Variables

POLICYCLIENT_API_KEY

Example: your_policyclient_api_key

Top Endpoints

GET
/subscriptions/{subscriptionId}/providers/Microsoft.Authorization/policyassignments

PolicyAssignments_List

GET
/subscriptions/{subscriptionId}/providers/Microsoft.Authorization/policydefinitions

PolicyDefinitions_List

GET
/subscriptions/{subscriptionId}/providers/Microsoft.Authorization/policydefinitions/{policyDefinitionName}

PolicyDefinitions_Get

PUT
/subscriptions/{subscriptionId}/providers/Microsoft.Authorization/policydefinitions/{policyDefinitionName}

PolicyDefinitions_CreateOrUpdate

DELETE
/subscriptions/{subscriptionId}/providers/Microsoft.Authorization/policydefinitions/{policyDefinitionName}

PolicyDefinitions_Delete

Own this API?

Verify ownership of this listing to control the description, configuration details, and documentation links. Choose between free manual verification or instant premium placement.

Option 1: Free Verification

Slow manual review. Requires creating a GitHub issue with verified documentation or domain verification.

  • • Verified badge on page
  • • Standard search sorting
  • • 2-3 business days review
Start Free Claim →
Instant & Boosted

Option 2: Featured Upgrade($9/mo)

Instant verification plus premium styling, featured badges, and directory placement boost.

  • • ★ Featured star & amber highlight border
  • • Top of directory search placement
  • • Instant activation via claim token

📖 Detailed MCP Integration Guide

A technical breakdown of capabilities, agent workflows, and security/configuration best practices.

Capabilities & Use Cases
The PolicyClient API, provided by Microsoft as part of the Azure Resource Manager (ARM) ecosystem, serves as the authoritative gateway for managing and governing Azure Policy resources within an organization's cloud environment. This API empowers cloud administrators, platform engineers, and DevOps teams to programmatically define, assign, evaluate, and audit policy rules that control access to and configuration of Azure resources at scale. At its core, the PolicyClient API offers a comprehensive set of capabilities: retrieving and managing policy definitions that describe the compliance rules an organization wishes to enforce, assigning those policies at various scopes such as subscriptions or individual resource groups, and listing all active policy assignments to maintain visibility into governance posture. For enterprise customers operating under strict regulatory frameworks like GDPR, HIPAA, or internal security mandates, this API is indispensable. It allows organizations to codify compliance requirements as machine-readable policies, enforce tagging standards, restrict the provisioning of certain resource types or SKUs, and ensure that all resources conform to organizational baselines. Consumer-facing use cases include SaaS platform builders who need to enforce tenant-level guardrails, managed service providers managing multiple customer subscriptions, and development teams seeking to prevent cost overruns by restricting expensive VM sizes. The API's subscription-level and resource-group-level scoping endpoints ensure that governance can be applied with precision, whether at a broad organizational level or at the granularity of individual workloads.
🤖AI Agent Value
When exposed as tools through the Model Context Protocol (MCP) server and made available to AI coding assistants such as Claude Desktop, Cursor, or Cline, the PolicyClient API unlocks a powerful new dimension of AI-augmented cloud governance. Rather than requiring developers to manually navigate the Azure Portal or compose lengthy ARM CLI commands, the AI assistant gains the ability to directly query, create, update, and delete policy definitions and assignments through natural language interactions. This integration translates into tangible productivity gains and reduced cognitive overhead. An AI agent can, for instance, query all current policy assignments within a subscription to audit which compliance rules are active, fetch the details of a specific policy definition to explain its logic to a developer, or programmatically update a policy assignment to adjust remediation parameters without the developer leaving their IDE. The MCP server effectively turns the AI assistant into a cloud governance co-pilot that understands the full lifecycle of Azure Policy management, enabling it to bridge the gap between developer intent and infrastructure execution. This is particularly valuable in large organizations where maintaining policy hygiene across hundreds of subscriptions and thousands of resource groups is a persistent operational challenge. The AI can serve as a real-time compliance advisor, cross-referencing existing policies against new requirements and suggesting or implementing changes proactively.
💬Example Workflows
In practical workflows, the MCP server enables a wide range of dynamic tasks that developers and administrators can instruct the AI to perform through conversational directives. A developer might say, "List all policy assignments currently applied to subscription X so I can verify our tagging policy is active," and the AI agent will execute the appropriate GET call to retrieve and present the data in a human-readable format. Another scenario involves automation of policy drift remediation: a team lead could instruct the AI to "Find all policy definitions related to network security, show me their current settings, and update the definition for allowed virtual networks to include the new subnet CIDR." The AI would sequentially fetch relevant definitions, present them, and upon confirmation, execute the PUT operation to update the definition. When onboarding a new resource group, the AI can be directed to "Assign the mandatory encryption policy and the approved SKU policy to the new production resource group," streamlining what would otherwise be a multi-step manual process. The deletion capabilities also support lifecycle management, such as instructing the AI to "Remove all policy assignments from the decommissioned test subscription before we shut it down," ensuring clean teardown operations. These examples illustrate how the MCP integration transforms static API endpoints into an interactive, intent-driven governance workflow that accelerates decision-making, reduces human error, and maintains consistent compliance posture across the entire Azure estate.
🛡️Security & Auth
Developers integrating the PolicyClient API through the MCP server should be acutely aware of authentication and security considerations, as the API currently lists no built-in authentication method, which places the responsibility squarely on the implementer. All access to Azure Policy management operations must be secured through Microsoft Entra ID (formerly Azure Active Directory) authentication, typically via OAuth 2.0 bearer tokens obtained through service principals or managed identities. Following the principle of least privilege, service accounts used for MCP server connectivity should be granted only the Minimum Required Azure RBAC roles such as Policy Reader for read-only scenarios or Contributor at the specific subscription scope for environments requiring write operations, rather than broad Owner or Contributor roles at the management group level. It is strongly recommended to implement scope-restricted access tokens, ensuring the AI agent can only interact with designated subscriptions and resource groups rather than having blanket access to the entire tenant. Additionally, all API calls should be logged and audited, MCP server endpoints should be secured behind network controls, and sensitive configuration such as tenant IDs and client secrets must be stored in secure vault solutions rather than in plaintext configuration files. Organizations should also implement approval workflows for destructive operations like DELETE to prevent unintended policy removal, and regularly rotate credentials used by the MCP server to minimize the blast radius of potential credential compromise.

Similar APIs

Other APIs in the Developer Tools category.

GitHub API

Access GitHub repositories, issues, pull requests, and more. Integrate GitHub workflows directly into your AI agent.

OAuth2

GitLab API

Manage repositories, CI/CD pipelines, and merge requests through your AI agent.

OAuth2

Box Platform API

The Box Platform API, provided by Box (box.com), is a robust and comprehensive RESTful service that enables deep integration with the Box cloud content management ecosystem. It serves as the programmatic backbone for enterprises and developers seeking to build custom applications and workflows that interact with content stored securely in Box. Its core capabilities extend far beyond basic file operations, encompassing a full spectrum of content lifecycle management. Developers can programmatically create, upload, download, search, and manage files and folders, but the API's true power lies in its enterprise-grade features. These include advanced collaboration management through invitations and permissions, granular user and group administration within an enterprise directory, and sophisticated security and compliance controls. Specific endpoint groups for managing collaboration whitelists and exempt targets allow for precise governance over external sharing policies, ensuring that content is only shared with approved domains. Furthermore, the API facilitates complex legal and compliance use cases, such as placing items on legal hold or applying retention policies, making it an indispensable tool for regulated industries and large organizations.

Asana

This API serves as the programmatic backbone for the Asana work management platform, provided by Asana, Inc. It enables developers to interact programmatically with one of the world's leading enterprise collaboration and productivity suites. The core capabilities of this interface center around the CRUD (Create, Read, Update, Delete) operations for fundamental Asana objects. Specifically, the provided endpoints grant control over project attachments—allowing for the uploading, retrieval, and management of files associated with tasks and projects—and custom fields, which are pivotal for creating structured, data-rich workflows. These custom fields allow organizations to define unique data types (like dropdown menus, text fields, or dates) to standardize information capture across projects, moving beyond basic task lists to true operational tracking. Typical use cases span from enterprise project management offices (PMOs) needing to programmatically generate status reports and audit attachments, to development teams automating the creation of bug-tracking projects with predefined custom fields for severity and status, to operational leaders building dashboards that aggregate and analyze custom field data for resource allocation insights.

Related MCP Server Integrations

GitHub API MCP Setup

Access GitHub repositories, issues, pull requests, and more. Integrate GitHub workflows directly into your AI agent.

Developer ToolsConfigure →

GitLab API MCP Setup

Manage repositories, CI/CD pipelines, and merge requests through your AI agent.

Developer ToolsConfigure →

Box Platform API MCP Setup

The Box Platform API, provided by Box (box.com), is a robust and comprehensive RESTful service that enables deep integration with the Box cloud content management ecosystem. It serves as the programmatic backbone for enterprises and developers seeking to build custom applications and workflows that interact with content stored securely in Box. Its core capabilities extend far beyond basic file operations, encompassing a full spectrum of content lifecycle management. Developers can programmatically create, upload, download, search, and manage files and folders, but the API's true power lies in its enterprise-grade features. These include advanced collaboration management through invitations and permissions, granular user and group administration within an enterprise directory, and sophisticated security and compliance controls. Specific endpoint groups for managing collaboration whitelists and exempt targets allow for precise governance over external sharing policies, ensuring that content is only shared with approved domains. Furthermore, the API facilitates complex legal and compliance use cases, such as placing items on legal hold or applying retention policies, making it an indispensable tool for regulated industries and large organizations.

Developer ToolsConfigure →

Asana MCP Setup

This API serves as the programmatic backbone for the Asana work management platform, provided by Asana, Inc. It enables developers to interact programmatically with one of the world's leading enterprise collaboration and productivity suites. The core capabilities of this interface center around the CRUD (Create, Read, Update, Delete) operations for fundamental Asana objects. Specifically, the provided endpoints grant control over project attachments—allowing for the uploading, retrieval, and management of files associated with tasks and projects—and custom fields, which are pivotal for creating structured, data-rich workflows. These custom fields allow organizations to define unique data types (like dropdown menus, text fields, or dates) to standardize information capture across projects, moving beyond basic task lists to true operational tracking. Typical use cases span from enterprise project management offices (PMOs) needing to programmatically generate status reports and audit attachments, to development teams automating the creation of bug-tracking projects with predefined custom fields for severity and status, to operational leaders building dashboards that aggregate and analyze custom field data for resource allocation insights.

Developer ToolsConfigure →

clickup20 MCP Setup

The clickup20 Polls API is a lightweight, focused web service designed to facilitate the creation and management of simple polling mechanisms. Provided by ClickUp, a platform known for its project management and productivity tools, this API serves as a specialized component for gathering quick, quantitative feedback. Its core capabilities are straightforward: it allows consumers to programmatically retrieve a list of existing poll questions and to submit new poll questions for consideration. Typical use cases span both enterprise and consumer domains. In an enterprise setting, a development team might integrate this API to run quick polls during sprint retrospectives, gauge internal sentiment on a new tool, or gather binary feedback on proposed technical designs within a project management workflow. For consumer applications, it could power simple feedback widgets within a mobile app or website, enabling users to vote on feature priorities or content topics. The API’s simplicity, requiring no authentication, makes it highly accessible for rapid prototyping and integration into internal tools where complex credential management is unnecessary.

Developer ToolsConfigure →