Lead Image © jgroup, 123RF.com

Lead Image © jgroup, 123RF.com

AI Agents on Azure and SQL Server

Chain of Command

Article from ADMIN 95/2026
By
The Azure and SQL Model Context Protocol servers hand artificial intelligence agents typed access to subscriptions and relational data. Tool whitelisting, Entra ID, audience-bound tokens, and telemetry turn that access into something your operations team can run and your auditor can follow.

Two earlier ADMIN articles looked at front ends that put a conversational layer on top of administration: Microsoft AI Shell [1] and the LibreChat platform [2]. A front end on its own reads prompts and writes text, turning useful and risky at the same moment it reaches a live resource (e.g., a subscription, storage account, or production database). The Model Context Protocol (MCP) supplies that link as a standardized tool interface, and two servers from Microsoft cover the ground you care about as an admin. The Azure MCP Server opens your Azure services, and SQL MCP Server opens your relational data.

At the time of writing, Azure MCP Server ships version 2.0 as its release build, and version 3.0 is available as a beta that you can install today. The final 3.0 release is close enough that it might well be out by the time you read this. Microsoft moves this project along at a rapid pace, so treat every version number in this article as a snapshot. The mechanics described here – namely, namespaces, annotations, the Entra ID model, and the remote deployment pattern – carry over to later builds as long as Microsoft keeps the underlying structure in place.

The questions that matter in production are narrow. Which tools may an agent call, under which identity, and against which tenant, and what traces does the call leave behind? To answer these questions, I rebuilt the whole stack on a fresh Windows Server 2025 host against a live subscription, which revealed a fair number of details that no product page mentions.

MCP splits the field into three roles. You operate the host, the host embeds the client, and the capabilities arrive from the server [3]. Both sides exchange JSON-RPC (remote procedure call) messages, and a call carrying the tools/call method names the tool and its


...

Use one of the options below to read the full article

Buy this article as PDF

Download Article PDF now with Express Checkout
Price $2.95
(incl. VAT)

Buy ADMIN Magazine

Related content

  • Migrating to Azure Monitor Agent
    The replacement for the Log Analytics Agent has improved security and cost efficiency, better manageability, and greater reliability – and you must migrate to this new solution by the end of 2024.
  • Monitor Active Directory with Azure AD Connect Health
    Microsoft cloud service Azure Active Directory Connect Health supports monitoring of Active Directory, especially in large and distributed environments, but the tool is also useful for monitoring hybrid landscapes using Azure Active Directory.
  • Server update with Azure Update Management
    Microsoft Azure Update Management automatically patches servers in on-premises data centers, virtual servers on Azure and other cloud services, and even Linux servers.
  • The Azure Arc multicloud and on-premises management platform
    The Azure Arc cloud service supports centralized management of Windows and Linux servers, Kubernetes clusters, and SQL servers that are not themselves running in Azure, extending Azure management capabilities to servers in traditional data centers or any other cloud environment. We show you how to get Azure Arc up and running and look at its key features.
  • Private cloud with Microsoft Azure Stack
    Azure Stack is an Azure extension that implements an on-premises data center for consistent hybrid cloud deployments.
comments powered by Disqus