Skip to content

Triagic + Azure: ticket investigations over your cloud account, read-only

Ask about any Azure service the service principal can read: compute, storage, SQL, Cosmos, AKS, App Service, Monitor and more. Runs the Azure MCP server read-only; Key Vault values are never exposed. Triagic connects to Azure from the desktop app on each member's machine, with a credential you configure, and shows every call it makes while it investigates a ticket. Nothing is copied out of Azure.

What you can ask

  • In Azure, find the log lines for the Lambda that handles webhook retries between 10:00 and 10:20
  • Did the error rate in Azure for the API gateway change in the last six hours?
  • Which alarms in Azure fired this week, and which are still in alarm?
  • Show me the Azure deployment that was live when ticket 4819 was filed
  • What is the dead-letter queue depth in Azure right now?

What the agent can do

These are the 35 tools Triagic exposes from the Azure MCP server. Anything else the server lists is dropped at connect time.

  • subscription_list
  • group_list
  • group_resource_list
  • acr
  • advisor
  • aks
  • appconfig
  • applens
  • applicationinsights
  • appservice
  • compute
  • containerapps
  • cosmos
  • eventgrid
  • eventhubs
  • fileshares
  • functionapp
  • grafana
  • kusto
  • monitor
  • mysql
  • policy
  • postgres
  • quota
  • redis
  • resourcehealth
  • role
  • search
  • servicebus
  • servicefabric
  • signalr
  • sql
  • storage
  • storagesync
  • workbooks

Connect in three steps

  1. 1

    Mint a read-only credential in Azure

    Create a dedicated user or token that can only read. Started with --read-only, with an allowlist of routers that never names keyvault.

  2. 2

    Add it in the Triagic portal

    Integrations, then Add shared data source, then Azure.

    • Tenant ID: Entra ID → App registrations → your app → Directory (tenant) ID.
    • Client ID: The same app registration's Application (client) ID.
    • Client secret: Certificates & secrets → New client secret. These expire. Note the date.
    • Client certificate path: The certificate you uploaded under Certificates & secrets → Certificates. PEM or PFX; a PEM must contain the private key as well as the certificate. Only a PEM can be pasted. A PFX is binary, so give it as a path. Path on each machine running Triagic, or paste the file itself.
    • Subscription ID: The subscription to query. Grant the service principal Monitoring Reader on it, and Log Analytics Reader on the workspaces.
  3. 3

    Let a desktop pick it up

    Saving validates the shape of what you typed. The first desktop app to sync starts Azure locally and reports running or degraded with the error text.

Field-by-field setup, TLS options and the error table: Azure in the docs.

Read-only, by construction

Started with --read-only, with an allowlist of routers that never names keyvault.

FAQ

Can Triagic change anything in Azure?
No. Started with --read-only, with an allowlist of routers that never names keyvault. Give it a read-only credential as well, so the guarantee does not rest on one layer.
What do I need to connect Azure?
Tenant ID, Client ID, Client secret, Client certificate path, Subscription ID. The desktop app on a member's machine starts the connection; the portal never holds a live process.
Does Azure cost extra?
No. Every connector is included in the seat price. Start a 14-day trial without a card.

Related integrations

Try it on your own Azure

No card. Install the desktop app, connect Azure read-only, and triage a real ticket this afternoon.