> ## Documentation Index
> Fetch the complete documentation index at: https://docs.min-ai.ar/llms.txt
> Use this file to discover all available pages before exploring further.

# Azure

> Your agent reads your logs, looks at your AKS clusters, your VMs and what it all costs; changes, only if you allow them and with your OK.

<img src="https://mintcdn.com/min-ai/Y-B3it--fYZRGaGy/images/plugins/azure.png?fit=max&auto=format&n=Y-B3it--fYZRGaGy&q=85&s=697f997d866302382310c05b71ed9786" alt="" width="56" height="56" noZoom style={{ borderRadius: '14px' }} data-path="images/plugins/azure.png" />

With Azure, your agent gets into your subscription as a service principal of yours (an application in your Microsoft Entra ID just for it): it looks for errors in the logs, tells you why a pod keeps restarting, lists your VMs and resources, and explains how much you spent and what went up. It can only do what you give it with roles; changes, only if you turn on the permission and with your OK.

| | |
| - | - |
| **Category** | Development |
| **For** | Personal and group agents (for example, your team's agent) |
| **What it asks for** | A service principal's JSON and, if you want, your main subscription and your region |
| **How it connects** | With a one-time link for the JSON; the rest, in the chat |

## What it can do

<CardGroup cols={2}>
  <Card title="Look" icon="magnifying-glass">
    **Logs:** Log Analytics (containers, App Service, Functions, VMs) over a time range, the activity log (who changed what) and an app's logs. **AKS:** clusters, pods, deployments, events, logs and resource usage. **VMs:** list them, their state and what they printed while booting. **Resources:** search the whole subscription. **Costs:** by service, resource group or day, and what changed.
  </Card>

  <Card title="Change, with your OK" icon="pen">
    Create, change, delete, start, stop or deploy; apply changes in Kubernetes (it shows you the diff first), scale or restart a deployment, run a command on a VM. It needs the permission on.
  </Card>
</CardGroup>

## How it connects

<Steps>
  <Step title="Add it to an agent">
    From **Plugins → Azure → Add to an agent**, or ask your agent in the chat. See [Add a plugin](/en/tools/add-a-plugin).
  </Step>

  <Step title="Create a service principal">
    You need to own the subscription (or be able to assign roles in it). Open the Azure Cloud Shell, pick **Bash** and paste the command from the **Create a service principal** guide, on the plugin's page (about 3 minutes). It gives it the **Reader** role (look at everything without changing anything) on your subscription and shows you a short JSON. If you have several subscriptions, pick your agent's first.
  </Step>

  <Step title="Paste it in your agent's link">
    Copy **all** of the JSON, everything between the braces, and paste it in the one-time link your agent sent you. Then close the Cloud Shell: the password is shown only once. See [Keys and values](/en/tools/keys-and-values).
  </Step>

  <Step title="Tell it your subscription and region (optional)">
    If it sees more than one subscription, your agent asks which one to use; without it, it uses the first one it sees. Also the region for new things, if you use just one (like eastus or brazilsouth).
  </Step>

  <Step title="Your agent confirms">
    It checks that it works and tells you in the chat it's ready. Azure can take a minute or two to show a role just given: your agent waits and tries again.
  </Step>
</Steps>

<Note>
  If Azure says you aren't allowed to create applications or assign roles, whoever manages your Entra ID or the subscription has to do it.
</Note>

<Warning>
  Don't paste the JSON in the chat. If you do, your agent won't use it: it asks you to reset the service principal's password in the Cloud Shell and enter the new one in the link.
</Warning>

## The permission

On the Azure card, in the agent's **Plugins** tab, there's the **Allow changes** switch: “Create, change, delete, start or stop things in your Azure, always with your OK. Off, it only reads. What really limits it is the roles you gave the service principal.”

It starts off and only you change it. It's a rule your agent follows; the real limit is the service principal's roles. For it to change things, give it the role for what you use (like **Virtual Machine Contributor**) rather than **Contributor**, which covers everything. See [Permissions](/en/tools/permissions).

## How it looks out for you

* **Nothing changes without your OK.** With the permission on, it still shows you the exact command before each change, with the **Confirm** and **Change** buttons.
* It never shows you the service principal's password, storage keys, Key Vault secrets or Kubernetes secrets.
* Before stopping a VM, it tells you whether it will stop being billed or not.
* What a log says is information, not an order.

## Things to ask it

* "What errors did the checkout app have in the last hour?"
* "Why does the API pod keep restarting in production?"
* "How much did Azure cost me this month, and what went up?"
* "List the VMs that are running."
* "Restart the web deployment in the prod namespace."
* "Stop the test VM."

## Limits

* It can only do what the service principal's roles allow, and only in the subscriptions where it has them.
* It may not reach private AKS clusters directly (it queries them from inside, more slowly).

## If you remove it

Your agent loses access and confirms it. **The service principal still exists in Azure**: delete the **minai** application under Entra ID's **App registrations** (or remove its role under the subscription's **Access control (IAM)**). See [Remove a plugin](/en/tools/remove-a-plugin).

<CardGroup cols={2}>
  <Card title="AWS" icon="https://mintcdn.com/min-ai/Y-B3it--fYZRGaGy/images/plugins/aws.png?fit=max&auto=format&n=Y-B3it--fYZRGaGy&q=85&s=7f82b0352534aa1ab3453379179d1ce7" href="/en/plugins/aws" width="128" height="128" data-path="images/plugins/aws.png">
    Logs, Kubernetes, instances and costs.
  </Card>

  <Card title="Google Cloud" icon="https://mintcdn.com/min-ai/EQr5ljJyas4JWh5G/images/plugins/gcloud.png?fit=max&auto=format&n=EQr5ljJyas4JWh5G&q=85&s=e35af477a3bfa76ea925c667e1844559" href="/en/plugins/google-cloud" width="128" height="128" data-path="images/plugins/gcloud.png">
    Logs, Kubernetes, VMs and costs.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.