Skip to content
Developer ToolsAuto-generatedScore: 34

PolicyClient MCP Server

The PolicyClient API is a foundational component of the Microsoft Azure Resource Manager, designed to provide granular, programmatic control over cloud governance and compliance.

Quick Start Summary

The PolicyClient MCP server is a Model Context Protocol bridge that connects AI assistants — including Claude Desktop, Cursor, Windsurf, and VS Code Copilot — to the PolicyClient API through natural language. It exposes 10 API endpoints as callable tools, such as PolicyDefinitions_ListBuiltIn, PolicyDefinitions_GetBuiltIn, PolicyDefinitions_ListByManagementGroup, and more. No authentication is required — setup takes approximately 30 seconds. The server uses STDIO transport and can be installed by running npx -y @mcp/azure-com-resources-policydefinitions. This integration is sourced from the auto PolicyClient OpenAPI specification (v2016-12-01) and has a quality score of 34/99 (fair documentation coverage).

10Endpointstools mapped
NoneAuthopen access
34/99Qualityfair
~30 secSetupno auth

Server Details

Category
Developer Tools
Authentication
None
Endpoints
10 operations
Transport
STDIO
Spec Version
v2016-12-01
Install Command
npx -y @mcp/azure-com-resources-policydefinitions

Environment Variables

POLICYCLIENT_API_KEY

Example: your_policyclient_api_key

Top Endpoints

GET
/providers/Microsoft.Authorization/policyDefinitions

PolicyDefinitions_ListBuiltIn

GET
/providers/Microsoft.Authorization/policyDefinitions/{policyDefinitionName}

PolicyDefinitions_GetBuiltIn

GET
/providers/Microsoft.Management/managementgroups/{managementGroupId}/providers/Microsoft.Authorization/policyDefinitions

PolicyDefinitions_ListByManagementGroup

GET
/providers/Microsoft.Management/managementgroups/{managementGroupId}/providers/Microsoft.Authorization/policyDefinitions/{policyDefinitionName}

PolicyDefinitions_GetAtManagementGroup

PUT
/providers/Microsoft.Management/managementgroups/{managementGroupId}/providers/Microsoft.Authorization/policyDefinitions/{policyDefinitionName}

PolicyDefinitions_CreateOrUpdateAtManagementGroup

Own this API?

Verify ownership of this listing to control the description, configuration details, and documentation links. Choose between free manual verification or instant premium placement.

Option 1: Free Verification

Slow manual review. Requires creating a GitHub issue with verified documentation or domain verification.

  • • Verified badge on page
  • • Standard search sorting
  • • 2-3 business days review
Start Free Claim →
Instant & Boosted

Option 2: Featured Upgrade($9/mo)

Instant verification plus premium styling, featured badges, and directory placement boost.

  • • ★ Featured star & amber highlight border
  • • Top of directory search placement
  • • Instant activation via claim token

📖 Detailed MCP Integration Guide

A technical breakdown of capabilities, agent workflows, and security/configuration best practices.

Capabilities & Use Cases
The PolicyClient API is a foundational component of the Microsoft Azure Resource Manager, designed to provide granular, programmatic control over cloud governance and compliance. It serves as the primary interface for managing Azure Policy definitions—the rules and conditions that evaluate the state of your cloud resources. At its core, this API enables organizations to define standards, enforce configurations, and maintain security and compliance across their Azure estates. It operates within Azure's hierarchical resource model, allowing policies to be defined and managed at both the subscription and management group levels. This hierarchical capability is crucial for enterprises, enabling them to establish centralized governance frameworks that cascade down to thousands of subscriptions, ensuring uniformity while allowing for necessary local customization. Typical use cases include automating the enforcement of security baselines (like requiring encryption for storage accounts), managing cost controls by restricting VM sizes, and ensuring that all deployed resources adhere to corporate tagging standards for allocation and tracking.
🤖AI Agent Value
When this API is exposed as a set of tools via the Model Context Protocol (MCP) to an AI coding assistant, it transforms from a mere REST interface into a dynamic engine for intelligent governance automation. The value proposition is significant: developers and cloud architects can move from manual, error-prone portal operations or complex scripting to natural language-driven interactions. The AI assistant gains the ability to understand the current state of policy configurations and perform precise, context-aware actions. This integration allows the AI to become a collaborative partner in infrastructure-as-code and compliance workflows, dramatically accelerating development cycles, reducing the risk of misconfigurations, and freeing expert resources to focus on higher-level strategy rather than routine management tasks.
💬Example Workflows
A developer interacting with an AI-powered coding assistant leveraging this MCP server can issue a variety of sophisticated, dynamic instructions. For instance, one could prompt the AI to "list all built-in policy definitions related to storage account security and summarize their effects," enabling rapid discovery and understanding of available governance controls. The assistant could be instructed to "create and apply a new policy definition at the 'Corp' management group that denies the creation of public IP addresses in production subscriptions, and tag it with 'Network-Security'," translating a complex security requirement into an immediate, correctly scoped deployment. For auditing and remediation, a command like "audit all policy assignments in subscription 'sub-prod-01' and identify any that are marked as non-compliant, then suggest a remediation task for the 'SQL-Encryption' policy" showcases the AI's ability to synthesize information across multiple API calls, analyze compliance states, and recommend actionable next steps. This moves the AI assistant beyond simple code generation into the realm of operational intelligence and automated cloud stewardship.
🛡️Security & Auth
Critical authentication and security considerations must be rigorously applied when implementing this API, even if the initial description notes "None." In practice, all management-plane operations require authentication via an Azure Active Directory (Entra ID) bearer token. The recommended approach is to register an application in Azure AD and use a service principal with tightly scoped Role-Based Access Control (RBAC) permissions, adhering strictly to the principle of least privilege. The necessary role is typically "Resource Policy Contributor" or "User Access Administrator" at the target scope. Credentials must never be hardcoded; they should be managed via secure mechanisms like environment variables or managed identities. Furthermore, API access should be monitored and logged using Azure Monitor and Activity Logs to maintain a clear audit trail of all policy modifications, which is essential for both security and governance compliance. Developers should always interact with the API over HTTPS and consider the use of Azure Policy's built-in initiatives to manage groups of related policies, simplifying both human and AI-driven management at scale.

Similar APIs

Other APIs in the Developer Tools category.

GitHub API

Access GitHub repositories, issues, pull requests, and more. Integrate GitHub workflows directly into your AI agent.

OAuth2

GitLab API

Manage repositories, CI/CD pipelines, and merge requests through your AI agent.

OAuth2

Box Platform API

The Box Platform API, provided by Box (box.com), is a robust and comprehensive RESTful service that enables deep integration with the Box cloud content management ecosystem. It serves as the programmatic backbone for enterprises and developers seeking to build custom applications and workflows that interact with content stored securely in Box. Its core capabilities extend far beyond basic file operations, encompassing a full spectrum of content lifecycle management. Developers can programmatically create, upload, download, search, and manage files and folders, but the API's true power lies in its enterprise-grade features. These include advanced collaboration management through invitations and permissions, granular user and group administration within an enterprise directory, and sophisticated security and compliance controls. Specific endpoint groups for managing collaboration whitelists and exempt targets allow for precise governance over external sharing policies, ensuring that content is only shared with approved domains. Furthermore, the API facilitates complex legal and compliance use cases, such as placing items on legal hold or applying retention policies, making it an indispensable tool for regulated industries and large organizations.

Asana

This API serves as the programmatic backbone for the Asana work management platform, provided by Asana, Inc. It enables developers to interact programmatically with one of the world's leading enterprise collaboration and productivity suites. The core capabilities of this interface center around the CRUD (Create, Read, Update, Delete) operations for fundamental Asana objects. Specifically, the provided endpoints grant control over project attachments—allowing for the uploading, retrieval, and management of files associated with tasks and projects—and custom fields, which are pivotal for creating structured, data-rich workflows. These custom fields allow organizations to define unique data types (like dropdown menus, text fields, or dates) to standardize information capture across projects, moving beyond basic task lists to true operational tracking. Typical use cases span from enterprise project management offices (PMOs) needing to programmatically generate status reports and audit attachments, to development teams automating the creation of bug-tracking projects with predefined custom fields for severity and status, to operational leaders building dashboards that aggregate and analyze custom field data for resource allocation insights.

Related MCP Server Integrations

GitHub API MCP Setup

Access GitHub repositories, issues, pull requests, and more. Integrate GitHub workflows directly into your AI agent.

Developer ToolsConfigure →

GitLab API MCP Setup

Manage repositories, CI/CD pipelines, and merge requests through your AI agent.

Developer ToolsConfigure →

Box Platform API MCP Setup

The Box Platform API, provided by Box (box.com), is a robust and comprehensive RESTful service that enables deep integration with the Box cloud content management ecosystem. It serves as the programmatic backbone for enterprises and developers seeking to build custom applications and workflows that interact with content stored securely in Box. Its core capabilities extend far beyond basic file operations, encompassing a full spectrum of content lifecycle management. Developers can programmatically create, upload, download, search, and manage files and folders, but the API's true power lies in its enterprise-grade features. These include advanced collaboration management through invitations and permissions, granular user and group administration within an enterprise directory, and sophisticated security and compliance controls. Specific endpoint groups for managing collaboration whitelists and exempt targets allow for precise governance over external sharing policies, ensuring that content is only shared with approved domains. Furthermore, the API facilitates complex legal and compliance use cases, such as placing items on legal hold or applying retention policies, making it an indispensable tool for regulated industries and large organizations.

Developer ToolsConfigure →

Asana MCP Setup

This API serves as the programmatic backbone for the Asana work management platform, provided by Asana, Inc. It enables developers to interact programmatically with one of the world's leading enterprise collaboration and productivity suites. The core capabilities of this interface center around the CRUD (Create, Read, Update, Delete) operations for fundamental Asana objects. Specifically, the provided endpoints grant control over project attachments—allowing for the uploading, retrieval, and management of files associated with tasks and projects—and custom fields, which are pivotal for creating structured, data-rich workflows. These custom fields allow organizations to define unique data types (like dropdown menus, text fields, or dates) to standardize information capture across projects, moving beyond basic task lists to true operational tracking. Typical use cases span from enterprise project management offices (PMOs) needing to programmatically generate status reports and audit attachments, to development teams automating the creation of bug-tracking projects with predefined custom fields for severity and status, to operational leaders building dashboards that aggregate and analyze custom field data for resource allocation insights.

Developer ToolsConfigure →

clickup20 MCP Setup

The clickup20 Polls API is a lightweight, focused web service designed to facilitate the creation and management of simple polling mechanisms. Provided by ClickUp, a platform known for its project management and productivity tools, this API serves as a specialized component for gathering quick, quantitative feedback. Its core capabilities are straightforward: it allows consumers to programmatically retrieve a list of existing poll questions and to submit new poll questions for consideration. Typical use cases span both enterprise and consumer domains. In an enterprise setting, a development team might integrate this API to run quick polls during sprint retrospectives, gauge internal sentiment on a new tool, or gather binary feedback on proposed technical designs within a project management workflow. For consumer applications, it could power simple feedback widgets within a mobile app or website, enabling users to vote on feature priorities or content topics. The API’s simplicity, requiring no authentication, makes it highly accessible for rapid prototyping and integration into internal tools where complex credential management is unnecessary.

Developer ToolsConfigure →