List of Microsoft MCP Servers
A current guide to Microsoft-listed MCP servers, what each does, where it runs, and which option fits Azure, Microsoft 365, Fabric, or development.
Microsoft does not offer one single MCP server. Its catalog contains many task-specific integrations for Azure, Microsoft 365, Fabric, developer workflows, security, documentation, and data services. Some are remote endpoints hosted by Microsoft; others are local programs that you run in an environment you manage.
This guide uses Microsoft’s official MCP catalog and the Microsoft Fabric MCP directory. Both directories change, so open the linked project documentation before enabling a server.
1. What MCP is and how Microsoft servers fit
Microsoft’s MCP project README defines the Model Context Protocol as “an open protocol that standardizes how applications provide context to large language models (LLMs).” An MCP setup has three roles:
- Host: the AI application, such as Claude, Cursor, or another MCP client.
- Client: the protocol connection created by the host for a particular server.
- Server: a program or remote endpoint that exposes tools, resources, or prompts for a service.
A server’s local label describes where that server process runs. A remote label describes a network endpoint operated by a provider. Neither label alone tells you where the MCP client or model processes data. Authentication, permissions, prerequisites, supported clients, availability, and limitations vary by entry.
2. Microsoft-listed MCP server groups
The following is a practical map of the Microsoft-listed landscape. “Microsoft-listed” is deliberate: the catalog includes Microsoft repositories plus entries maintained by other teams or partners. Check each repository or product page for current ownership and support.
Azure and cloud infrastructure
| Server | Hosting in the catalog | Typical use |
|---|---|---|
| Azure MCP | Local | Connect an agent with Azure services and Azure operations. |
| Microsoft Foundry MCP | Remote: https://mcp.ai.azure.com |
Work with Microsoft Foundry capabilities through an MCP endpoint. |
| Azure Resource Manager | Remote | Manage or inspect Azure resources through Resource Manager operations. |
| Azure DevOps | Local | Use an agent with Azure DevOps project and development workflows. |
| AKS | Local | Work with Azure Kubernetes Service workflows. |
Code, documentation, and development tools
| Server | Hosting | What it is for |
|---|---|---|
| GitHub MCP | Remote: https://api.githubcopilot.com/mcp |
Repository and GitHub workflow tools exposed through GitHub’s MCP endpoint. |
| Microsoft Learn | Remote: https://learn.microsoft.com/api/mcp |
Look up Microsoft documentation from an MCP client. |
| MarkItDown | Local | Convert supported documents and content to Markdown for agent workflows. |
| Microsoft 365 Agents Toolkit | Local | Build and work with Microsoft 365 agent projects. |
| Playwright | Local | Browser automation and web interaction from an agent. |
| NuGet and binlog entries | Varies by entry | Developer package and build-log workflows listed in the catalog. |
Microsoft 365 productivity
The catalog lists remote Agent 365 endpoints for Microsoft 365 Calendar, Copilot Chat, Mail, User, Admin Center, Teams, Word, and OneDrive/SharePoint. These entries target focused collaboration, communication, administration, and document tasks. Use the individual entry’s authentication and permission instructions because access scopes are product-specific.
Data, analytics, and business applications
| Entry | Hosting | Scope |
|---|---|---|
| Clarity | Local | Microsoft Clarity workflows. |
| Dataverse | Local | Dataverse data and business application operations. |
| Dev Box | Local | Developer workstation and Dev Box workflows. |
| Fabric | Local | Fabric workflows, including OneLake tools. |
| SQL | Local | SQL database workflows. |
| Power BI and related entries | Varies | Querying, semantic-model authoring, and modeling tasks. |
| SharePoint Lists | Varies | List and SharePoint productivity workflows. |
| Fabric RTI | Varies | Real-time intelligence workflows. |
Security and identity
The catalog includes remote Microsoft Sentinel data exploration and Microsoft Entra enterprise data entries. Treat these as privileged integrations: review identity, consent, scopes, and tenant policy in the entry’s own documentation before connecting an agent.
3. Fabric MCP servers by workload
Fabric has several choices rather than one universal server. Microsoft Learn’s Fabric directory, last updated 2026-09-23, separates them by workload:
| Fabric server or entry | Hosting | Use it for |
|---|---|---|
| Fabric Core | Remote | Workspaces, items, folders, and roles. |
| Data Warehouse | Remote | T-SQL work against Fabric warehouses. |
| Eventhouse | Remote | Kusto Query Language (KQL) and event data. |
| Activator | Remote | Monitoring rules and activation workflows. |
| Operations agent | Remote | Instructions, playbooks, and monitoring operations. |
| Power BI query | Remote | Query Power BI data. |
| Power BI semantic-model authoring | Remote | Create or edit semantic-model definitions. |
| Fabric data agents | Remote | Data-agent workflows. |
| Ontology | Remote | Ontology-related Fabric work. |
| Fabric MCP Server | Local | Local Fabric operations, including OneLake tools. |
| DataFactory | Local | Data Factory workflows. |
| Local RTI | Local | Real-time intelligence workflows running locally. |
| Power BI Modeling | Local | Power BI modeling operations in a managed environment. |
The same directory mentions a customer-hosted SQL MCP integration and a locally built GraphQL sample. Those are related examples, not Microsoft-hosted Fabric endpoints.
4. Which Microsoft MCP server should you use?
| Your task | Start with | Check before connecting |
|---|---|---|
| Azure resource operations | Azure MCP or Azure Resource Manager | Whether the entry is local or remote, required Azure identity, and permitted operations. |
| Microsoft Foundry | Microsoft Foundry MCP | Remote endpoint instructions and current availability. |
| Azure DevOps or AKS | The corresponding local server | Local runtime prerequisites and repository instructions. |
| GitHub repositories | GitHub MCP | GitHub authentication, organization policy, and repository scopes. |
| Microsoft 365 mail, calendar, Teams, Word, or files | The matching Agent 365 endpoint | Tenant consent, user permissions, and supported client. |
| Microsoft documentation | Microsoft Learn remote MCP | Endpoint instructions and request limits documented by Microsoft. |
| Fabric workspaces and items | Fabric Core | Workspace roles and remote authentication. |
| Fabric warehouse SQL | Data Warehouse | T-SQL permissions and warehouse access. |
| Fabric event data and KQL | Eventhouse | Eventhouse access and KQL permissions. |
| Power BI queries | Power BI query | Dataset permissions and supported client. |
| Local Fabric or OneLake automation | Local Fabric MCP Server | Local installation and credentials. |
| Security exploration | Sentinel or Entra entry | Least-privilege scopes, tenant policy, and audit requirements. |
5. Connecting a remote server
Remote server configuration is client-specific. Use the exact JSON shape required by your MCP host and the current server documentation. A generic illustrative configuration for a remote URL looks like this:
{
"mcpServers": {
"microsoft-learn": {
"url": "https://learn.microsoft.com/api/mcp"
}
}
}
For GitHub MCP, the catalog lists https://api.githubcopilot.com/mcp; for Microsoft Foundry MCP, it lists https://mcp.ai.azure.com. Do not assume that all remote entries use identical authentication or transport settings. Follow the linked instructions for the selected entry.
6. Running a local server
- Open the repository or product documentation linked from the Microsoft catalog.
- Install its stated runtime and dependencies in an environment you control.
- Configure credentials through the method documented by that server.
- Add the local command to your MCP client configuration.
- Start with read-only permissions and a test workspace or tenant.
- Confirm which tools are exposed before allowing write or administrative actions.
“Local” means the server process runs in your environment. It does not guarantee that every connected service, MCP client, or model keeps data on that machine.
7. Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| The client cannot connect | Wrong endpoint, blocked network, or incorrect transport configuration. | Copy the current endpoint from the official entry and verify the client’s remote-server format. |
| A local server exits immediately | Missing runtime, dependency, environment variable, or permission. | Run the repository’s prerequisite checks and inspect the server’s startup output. |
| Authentication succeeds but tools are missing | The account lacks required scopes, roles, or tenant consent. | Review the server-specific permission list and request only the needed scopes. |
| Fabric operation is unavailable | The chosen server targets a different Fabric workload. | Switch to Fabric Core, Data Warehouse, Eventhouse, Activator, Power BI, or another workload-specific entry. |
| Data appears outside the expected environment | Local/remote hosting was mistaken for model or client data residency. | Trace every hop and read the provider’s data-processing documentation. |
| A catalog instruction no longer matches | The live repository or service changed. | Recheck the Microsoft catalog and the linked first-party documentation before deployment. |
8. Security, reliability, and operating checklist
- Choose the narrowest server that matches the task.
- Use least-privilege identities and separate read and write credentials where possible.
- Review tool descriptions before approving an agent action.
- Keep local servers patched and isolate credentials from prompt text.
- Log administrative actions and review tenant or workspace audit controls.
- Expect availability and authentication to differ between entries.
- Recheck the live catalog at publication and whenever a server stops working.
9. Or skip the browser setup
If your agent or application needs screenshots of Microsoft portals, dashboards, documentation, or any other URL, ScreenshotNeo provides a website screenshot API and MCP server. It removes cookie and consent banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, failed loads, timeouts, and cache hits are not billed; and each response reports its page verdict and billing status. Its MCP tools—take_screenshot, get_page_info, and capture_pdf—work with Claude, Cursor, and other MCP clients.
One request returns PNG, JPEG, WebP, or PDF. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. See the ScreenshotNeo API documentation for all options.
cURL
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://learn.microsoft.com -o shot.webp
Python
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://learn.microsoft.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://learn.microsoft.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Create a free ScreenshotNeo account and get 1,000 screenshots a month with no card.
10. FAQ
Is there one official Microsoft MCP server?
No. Microsoft’s catalog is a directory of many task-specific servers and integrations.
Are Microsoft MCP servers free?
The supplied directories do not establish a single pricing model. Check each project or service’s current documentation.
Does local always mean private?
No. Local describes the server process location, not necessarily where the MCP client, model, or connected service processes data.
Which Fabric server should I install first?
Start from the workload: Fabric Core for workspaces and items, Data Warehouse for T-SQL, Eventhouse for KQL, Power BI query for queries, or the local Fabric server for local Fabric and OneLake tooling.
Can any MCP client use every Microsoft server?
No. Supported clients, transports, authentication, prerequisites, and limitations vary by entry.


