AzureSupportAgent

作者 zmustafa已验证

AI-driven Azure operations workbench. Chat with your tenant, investigate incidents with a team of specialist AI agents, and assess, monitor & remediate your cloud — runs in your own subscription. One-click deploy.

52
Stars
0
Forks
Python
语言
2026/8/24
添加时间

⚠️ 第三方软件声明

本 Skill 为第三方开源软件,独立托管于 GitHub。SkillTip 仅为信息目录,不控制或维护底层仓库。所显示的安全检查为自动化且范围有限,安装前请自行审查源码。

阅读服务条款

安装

添加到你的 Claude Code skills 目录:

# Add to your Claude Code skills
git clone https://github.com/zmustafa/AzureSupportAgent

快速入门

使用 AzureSupportAgent 等 Skills 的指南。

安全报告

已验证

上次扫描:—

{
  "status": "PASSED",
  "issues": []
}

README.md

🛠️ Azure Support Agent

An AI-driven Azure operations workbench that runs in your subscription. Point it at your tenant and AI discovers your workloads, reverse-engineers live architecture diagrams, and runs Well-Architected assessments — then a War Room of specialist agents helps you investigate, monitor, and remediate.

Deploy to Azure

License: MIT Docker Hub Python 3.12 React 18 FastAPI PRs welcome

Deploy · Install guide · User guide · How-to guides · Administration · Connectors · Docs

🆕 Latest: a ten-tab Entra ID identity workbench (Conditional Access simulator, PIM, app credentials, and Investigate for any principal), IAM access review (effective permissions, escalation paths, least-privilege, review campaigns), Backup Manager and Alerts Manager — both with approval-gated, reversible changes — and AI Insight Packs that watch your estate on a schedule and notify you only when something material happens.

Architecture designer reverse-engineering live Azure resources with AI rationale


Why Azure Support Agent?

Operating Azure at scale means hopping between the Portal, CLI, Resource Graph, Monitor, Advisor, and a dozen blades just to answer one question. Azure Support Agent puts an LLM in the driver's seat — it talks to your subscription through the official Azure MCP server and a Microsoft Graph (Entra ID) MCP server, reasons over live evidence, and turns "why is the website throwing 5xx?" into a ranked, validated answer — with the diagrams, assessments, and dashboards to back it up. And it doesn't just wait to be asked: a whole Proactive Support suite continuously scans your estate for coverage gaps and looming retirements, while scheduled autonomous agents push findings to Teams, Jira, ServiceNow, PagerDuty, your SIEM, or Azure Logic Apps before they bite.

  • 🧠 Agentic, not just a chatbot — a War Room of specialist agents investigates in parallel against your real Azure data.
  • 🛡️ Proactive, not just reactive — a Proactive Support hub (Assessments · Identity · Monitoring, Telemetry & Backup/DR coverage · Retirement Radar · Telemetry Intelligence · Performance Profiler · Ownership · Tag Intelligence · Change Explorer · Estate Graph) surfaces risks before you ask, and scheduled autonomous agents notify you via connectors.
  • 🏠 Runs in your tenant — one-click deploy to Azure Container Apps; your data never leaves your subscription.
  • 🔒 Safe by default — Azure access is read-only, writes are approval-gated + audited, and AI providers stay disabled until you configure them.
  • 🧰 A whole workbench — chat, investigations, architectures, a workloads cockpit, inventory, assessments, policy, monitoring, ownership, tagging, change forensics, an estate knowledge graph, and automations.

Built for cloud architects, SREs, platform teams, and Azure support engineers.

Table of Contents

✨ Features

💬 Conversational operations

Multi-session chat with isolated context, live SSE streaming, a per-message reasoning + tool-call timeline that persists across reloads, image support, and smart starter suggestions. Cancel a running turn anytime — work continues server-side and is saved.

🕵️ Deep investigations ("War Room")

Toggle deep mode to dispatch specialist agents (Networking, Identity, Compute, Storage, Security, Reliability, Cost, Monitoring) that research in parallel, form hypotheses, and validate them against your live Azure data — then converge on a conclusion.

📦 Workloads cockpit

Discover and group resources into workloads, then work a fleet cockpit with composite health scores, a resource taxonomy, table/board views, and rich visualizations (donut, radar, sparkline, treemap). Drill into a per-workload command center, or let Autopilot AI-discover and propose workloads for you.

🚀 Mission Control

Run every analysis against a workload from one cockpit — architecture, assessment, coverage, identity and more — and read a single go/no-go posture with the highest-risk items surfaced first.

🗺️ Architectures + Architecture Memory

AI reverse-engineers live resources into interactive diagrams with best-practice review, network boundaries, and cost hints. Save revisions, build collections, and keep persistent Architecture Memory that powers dashboards and investigations.

🕸️ Estate Graph

A live, workload-aware knowledge graph of your tenant with cost, retirement and RBAC overlays — pan, zoom, search, and deep-link straight into the workload, architecture or assessment behind any node.

🆔 Entra ID

A ten-tab identity workbench: posture scoring, Conditional Access (coverage, exposure, conflicts, break-glass, and a policy simulator), privileged access and PIM, app registrations and credential expiry, sign-in signals, guest and access governance, an identity graph, and a findings ledger. Investigate any user, guest, group, service principal or managed identity — including deleted ones — with provenance on every section, so "unreadable" never looks like "empty".

🔑 IAM

Azure RBAC you can actually reason about: effective permissions for any principal, an access map, privilege-escalation and bypass path detection, least-privilege recommendations, a what-if simulator, snapshot compare, scope and role explorers, and access review campaigns with reviewer routing, delegation, and evidence.

🪪 Ownership

A federated owner directory scoped by tenant, subscription or workload. Export owners, import any CSV/Excel with AI column-inference and a preview, then apply as Azure tags with snapshots and safe revert.

🏷️ Tag Intelligence

A tag census with coverage, casing-drift detection and a natural-language → Azure Resource Graph console. Propose, apply and revert tag changes with full revision history.

🛰️ Change Explorer

See what changed, when, and who did it across your estate — each change AI-categorized and risk-scored, with plain-English insights that float the highest-risk changes to the top for review.

✅ Assessments & governance

Run Well-Architected-style assessments across Security, Reliability, Cost, Operations, and Performance pillars — with custom controls, framework mappings (NIST, ISO, CIS), waivers, finding lifecycle, and ticketing. Plus Policy compliance, baselines, and AI advisors.

🗄️ Backup Manager

Beyond coverage reporting: a live backup inventory, job health, policy and vault management, and DR drills. Changes are approval-gated, encrypted before/after state is retained, and every apply has a rollback path.

🚨 Alerts Manager

A fired-alert inbox with action-group management, overlap and routing analysis, and baseline gap detection. Rule and action-group edits follow the same approval-gated, audited, reversible path as Backup Manager.

🗂️ Inventory

One unified, filterable resource grid across every connected tenant, with overview, location, cost and optimization views, plus a change feed — the flat estate view the Portal never quite gives you.

🧾 Evidence & Case Files

An Evidence Locker of investigation snapshots with diffs, sharing and export, and durable Case Files that keep an incident's timeline, findings and the identity it concerns in one place — including cases opened straight from an identity investigation.

📈 Monitoring & resilience

Monitor 2.0 customizable dashboards with AI authoring and ping history; AMBA baseline-alert coverage with one-click Bicep/Terraform gap remediation; Performance Profiler, Backup/DR coverage, Retirement Radar, and telemetry intelligence.

🤖 Automations & workflows

Build custom sub-agents with scoped tools, schedule recurring tasks (advanced cron recurrence builder), chain Workbooks into Playbooks, and route results through in-app Notifications and external connectors — Teams, Slack, Jira, ServiceNow, PagerDuty, Splunk, Sumo Logic, CrowdStrike NG-SIEM, AWS Security Hub, Grafana, Azure Logic Apps, and more.

🛡️ Proactive Support hub

One categorized landing page that unifies every posture and forensic dashboard, in the same clusters the product and the docs use:

  • Daily intelligence — AI Insight Packs
  • Design & ownership — Architectures · Know-Me · Ownership · Estate Graph
  • Assessment & performance — Assessments · Performance Profiler · FMEA
  • Coverage — Monitoring (AMBA) · Alerts Manager · Telemetry · Backup & DR · Backup Manager · Connection Capability
  • Estate intelligence — Inventory · Tag Intelligence · Change Explorer
  • Governance & identity — Azure Policy · Entra ID · IAM
  • Lifecycle & investigation — Retirement Radar · Reservations · Quota · Telemetry Intelligence · Evidence Locker · Case Files

🔌 Bring your own AI

A dozen+ providers — OpenAI, Azure OpenAI, Anthropic Claude, Google Gemini, GitHub Copilot/Models, Grok, Mistral, OpenRouter, ChatGPT (OAuth), Claude OAuth (Pro/Max), Ollama, LM Studio — switchable at runtime with live model catalogs. Disabled until you set them up.

Enterprise-ready

🔐 Read-only Azure by default · ✅ approval-gated writes · 🧾 full audit log · 👥 RBAC (users / roles / groups) · 🔑 OIDC + SAML SSO · 🗝️ encrypted connection credentials · 🌐 IP allowlisting · 🖥️ Sandbox VMs for private-endpoint diagnostics · 🧩 multi-tenant Azure connections.

📸 Screenshots

Workloads fleet cockpit
Workloads cockpit — composite health scores, resource mix & trend sparklines across your fleet.
Workload command center
Workload command center — health, coverage, risk & next-best-actions for a single workload.
Estate Graph knowledge graph
Estate Graph — a live, workload-aware knowledge graph with cost, retirement & RBAC overlays.
Proactive Support hub
Proactive Support — every posture & forensic dashboard, grouped into one hub.
Mission Control
Mission Control — run every analysis against a workload from one go/no-go cockpit.
Tag Intelligence
Tag Intelligence — tag census, coverage & casing drift with a natural-language console.
Change Explorer
Change Explorer — what changed, when, who did it, how risky, and what it impacts — in plain English.
Architectures designer
Architectures designer — design diagrams with AI rationale & best-practice review.
Deep investigation War Room
War Room — assemble a team of specialist agents to investigate in parallel.
Well-Architected assessment
Assessments — pillar scores, controls, and framework mappings (NIST/ISO/CIS).
Performance Profiler heatmap
Performance Profiler — resource × AMBA-metric heatmap to find bottlenecks.
Monitoring coverage
Monitoring coverage — AMBA baseline-alert gaps with Bicep/Terraform fixes.
Telemetry coverage
Telemetry coverage — diagnostic-settings & log coverage with Bicep/Policy gap fixes.
Monitor 2.0 dashboard
Monitor 2.0 — usage, token cost, provider mix, and activity at a glance.
AI provider settings
AI providers — bring your own model; each one stays disabled until configured.
Backup and DR coverage
Backup & DR coverage — RTO/RPO protection posture with Bicep/runbook gap fixes.
Retirement and breaking-change radar
Retirement radar — service retirements & breaking changes mapped to workloads, owners, and deadlines.
Entra ID findings inbox
Entra ID — identity findings ranked by severity: standing global admins, expiring credentials, ownerless apps, MFA & conditional-access gaps.

🚀 Deploy to Azure (one-click)

Status: tested. Provisions a managed PostgreSQL database, Azure Files state storage, and the Container App running the public image — in your subscription, in one deployment. No CLI, no manual wiring.

Deploy to Azure

What it creates:

  1. Azure Container App running the public Docker Hub image
  2. Azure Database for PostgreSQL — Flexible Server (managed), auto-linked via DATABASE_URL (?ssl=require)
  3. Azure Files share mounted at /app/.data (registries, caches, encryption key)
  4. Container Apps environment + external HTTPS ingress on port 8000

💰 Estimated cost: ~$25–35 / month for the default infra at typical low/idle usage (West US 3, pay-as-you-go) — mostly the Container App (1 vCPU / 2 GiB) and a Burstable B1ms PostgreSQL server.

You supply only an admin password (you're forced to change it on first login). Then connect your Azure tenant and an LLM from Settings — the AI does the rest (workload discovery, architectures, coverage scans, assessments, retirement radar, performance profiling). Defaults to West US 3 (validated for Container Apps + PostgreSQL B1ms).

📖 New here? Follow the step-by-step installation guide — from clicking the button to onboarding your first workload.

Prefer the CLI or want full control? See the manual deployment guide.

⚡ Quick start (local)

Prerequisites: Docker Desktop · Azure CLI (az) · an LLM key (or a local Ollama / LM Studio).

# 1) Sign in to the subscription you want to work with
az login
az account set --subscription "<your-subscription-id>"

# 2) Configure environment
Copy-Item .env.example .env     # set LLM_API_KEY (optional — you can also do it in the UI)

# 3) Run the whole stack
docker compose up --build

Open http://localhost:5173. The backend runs DB migrations on startup; the first Azure MCP call fetches @azure/mcp via npx (a few seconds), then caches it.

Health check: /healthz · MCP tools (admin): /api/admin/mcp/tools

Full local/dev instructions (native backend, tests, type-check) live in CONTRIBUTING.md.

🧩 How it works

The whole app — FastAPI API + the built React SPA + the in-process MCP servers — ships as one container image and runs as a single Container App. No separate frontend, database, or Redis containers required.

flowchart LR
    U([Browser]) --> SPA[React SPA]
    SPA -->|/api| BE[FastAPI backend<br/>orchestrator · SSE streaming]
    BE --> LLM{{LLM providers<br/>OpenAI · Claude · Gemini<br/>Copilot · Ollama · …}}
    BE --> AZ[Azure MCP server · stdio]
    BE --> EID[Entra / Graph MCP server · stdio]
    BE --> TOOLS[Built-in tools<br/>DNS · HTTP · ping · traceroute]
    BE --> DB[(PostgreSQL / SQLite)]
    BE --> FILES[[Azure Files<br/>/app/.data]]
    AZ --> SUB[(Your Azure subscription)]
    EID --> GRAPH[(Microsoft Graph)]

For local dev nothing is deployed to Azure — the MCP server reaches your real subscription outbound using your signed-in identity and existing RBAC, read-only by default.

🔧 Tech stack

LayerTech
BackendPython 3.12 · FastAPI · async SQLAlchemy 2 · Pydantic v2 · Alembic · SSE
FrontendReact 18 · TypeScript · Vite · Tailwind · TanStack Query · Recharts · XYFlow · Cytoscape · Mermaid
AIProvider abstraction with streaming + normalized tool-calls (a dozen+ providers)
AzureOfficial Azure MCP server (@azure/mcp) · Azure CLI / Resource Graph runner
Entra IDVendored Microsoft Graph (EntraID) MCP server over stdio
DataPostgreSQL (prod) / SQLite (local) · Azure Files for state
HostingAzure Container Apps (single image)

🔐 Security & access model

  • Read-only by default. The Azure MCP server starts with --read-only; write-capable tools are classified, approval-gated, and audited.
  • AI providers off until configured. A fresh install ships every provider disabled; a provider only becomes selectable once you add a key (or sign in / set a local base URL).
  • Identity & SSO. Local users with RBAC (users / roles / groups), plus OIDC and SAML SSO. Forced password change on first admin login.
  • Network access. Restrict which source addresses can reach the application at all — an in-app IP allowlist with a monitor mode that shows what would be blocked before you enforce it, Container Apps ingress restrictions, or no public endpoint at all.
  • Secrets. Connection credentials are encrypted at rest and never returned to the UI. .env, backend/.data/, and keys are git-ignored.
  • Found a vulnerability? Please follow SECURITY.md — don't open a public issue.

📚 Documentation

The complete documentation is published at zmustafa.github.io/AzureSupportAgent. Every major application screen includes a contextual Help link to its owning guide.

Public documentationWhat's inside
Getting startedInstallation, first-run configuration, Azure tenant setup, and deployment
User guideFeature-by-feature product reference
How-to guidesTask-oriented operational procedures and verification steps
AdministrationProviders, tenants, access, security, reference sets, usage, audit, and backup
ConnectorsSetup guides for messaging, ticketing, SIEM, webhooks, queues, and storage
SecuritySecurity model, credentials, approval controls, and deployment posture
Permissions referenceProduct and Azure/Graph permissions by workflow
TroubleshootingCommon failures, diagnostics, and recovery
Concepts and glossaryProduct vocabulary and operating concepts
Technical documentationArchitecture, implementation, APIs, and deployment internals
Repository guidePurpose
CONTRIBUTING.mdLocal dev, tests, type-check, PR guidelines
SECURITY.mdVulnerability disclosure policy
CODE_OF_CONDUCT.mdCommunity guidelines

🤝 Contributing

Contributions are welcome! Please read CONTRIBUTING.md and our Code of Conduct. Good first steps: open an issue to discuss a change, keep PRs focused, and make sure backend tests and the frontend type-check pass.

📄 License

MIT © 2026 Zeeshan Mustafa (@zmustafa)

🙏 Acknowledgements

  • Azure MCP server — the official Azure tool surface
  • EntraID MCP server (Microsoft Graph, FastMCP) — vendored under third_party/
  • The Model Context Protocol community
If this project helps you, consider giving it a ⭐ — it helps others find it.

常见问题

What is AzureSupportAgent?

AzureSupportAgent is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by zmustafa. AI-driven Azure operations workbench. Chat with your tenant, investigate incidents with a team of specialist AI agents, and assess, monitor & remediate your cloud — runs in your own subscription. One-click deploy. It has 52 GitHub stars.

Is AzureSupportAgent safe to use?

Yes. AzureSupportAgent passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.

How do I install AzureSupportAgent?

Clone the repository with "git clone https://github.com/zmustafa/AzureSupportAgent" and add it to your Claude Code skills directory (see the Installation section above).

What programming language is AzureSupportAgent written in?

AzureSupportAgent is primarily written in Python. It is open-source under zmustafa on GitHub, so you can review or fork the full source.

Are there alternatives to AzureSupportAgent?

Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh AzureSupportAgent against similar tools.

评论 (0)

暂无评论,成为第一个分享想法的人!

ECC

by affaan-m

10

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

242,21936,702JavaScript
AI 智能体ai-agentsanthropicclaude-code
查看详情
15

An agentic skills framework & software development methodology that works.

234,96620,863Shell
AI 智能体ai-agentsbrainstorming
查看详情

hermes-agent

by NousResearch

10

The agent that grows with you

234,43747,175Python
AI 智能体ai-agentsagent-orchestration
查看详情

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

185,94028,768JavaScript
AI 智能体ai-agentsanthropicclaude-code
查看详情

cc-switch

by farion1231

3

A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Grok Build & Hermes Agent. Only official website: ccswitch.io

128,8688,826Rust
AI 智能体claude-codeai-tools
查看详情

claude-code

by anthropics

Claude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex code, and handling git workflows - all through natural language commands.

120,03119,897Shell
AI 智能体
查看详情

开发者还喜欢

基于喜欢此 Skill 的开发者投票和收藏

ECC

by affaan-m

10

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

242,21936,702JavaScript
AI 智能体ai-agentsanthropicclaude-code
查看详情
15

An agentic skills framework & software development methodology that works.

234,96620,863Shell
AI 智能体ai-agentsbrainstorming
查看详情

hermes-agent

by NousResearch

10

The agent that grows with you

234,43747,175Python
AI 智能体ai-agentsagent-orchestration
查看详情

n8n

by n8n-io

12

Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.

201,88160,308TypeScript
MCP 服务器apisai-tools
查看详情

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

185,94028,768JavaScript
AI 智能体ai-agentsanthropicclaude-code
查看详情

cc-switch

by farion1231

3

A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Grok Build & Hermes Agent. Only official website: ccswitch.io

128,8688,826Rust
AI 智能体claude-codeai-tools
查看详情