{"id":3977,"date":"2026-08-31T11:37:17","date_gmt":"2026-08-31T18:37:17","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/azure-sdk\/?p=3977"},"modified":"2026-08-31T11:37:17","modified_gmt":"2026-08-31T18:37:17","slug":"power-azure-sre-agent-with-connector-namespace","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/azure-sdk\/power-azure-sre-agent-with-connector-namespace\/","title":{"rendered":"Power Azure SRE Agent with the tools it needs"},"content":{"rendered":"<p>This blog post shows how to expand the capabilities of Azure SRE Agent by giving it access to MCP servers hosted on Azure Connector Namespace. Connector Namespace is a managed MCP hosting platform that removes the operational and management overhead of self-hosting MCP servers. It entered public preview at Microsoft Build in June, with general availability estimated for the end of 2026.<\/p>\n<h2>What is Azure SRE Agent?<\/h2>\n<p><a href=\"https:\/\/learn.microsoft.com\/azure\/sre-agent\/overview\">Azure SRE Agent<\/a> is an AI-powered service designed to reduce operational toil. Teams can use it to:<\/p>\n<ul>\n<li>Investigate incidents and identify probable causes.<\/li>\n<li>Automate health checks, compliance reviews, and other scheduled work.<\/li>\n<li>Answer questions such as, &#8220;What changed before this service became degraded?&#8221;<\/li>\n<li>Propose remediations while allowing teams to require human approval.<\/li>\n<\/ul>\n<p>An effective investigation rarely depends on one source of information. An alert might originate in Azure Monitor, while deployment history lives in source control, telemetry is stored in another observability platform, and incident records are kept in a service-management tool. Without access to those systems, you must retrieve and transfer the information manually, which adds context switching and slows diagnosis.<\/p>\n<p>MCP servers can give Azure SRE Agent tools to query telemetry, inspect deployments, retrieve database records, and look up incidents. Azure SRE Agent provides native connections for some servers, including GitHub, Datadog, New Relic, and Splunk. <strong><a href=\"https:\/\/learn.microsoft.com\/azure\/connector-namespace\/connector-namespace-overview\">Azure Connector Namespace<\/a><\/strong> makes it easier to host additional remote MCP servers that you want the agent to use.<\/p>\n<h2>Removing remote MCP server hosting burden<\/h2>\n<p>Connecting Azure SRE Agent to an existing remote endpoint is straightforward. Hosting that endpoint yourself is not.<\/p>\n<p>You must deploy the server, provide secure HTTPS infrastructure, configure authentication, manage downstream credentials, scale the runtime, monitor its health, recover failed instances, and maintain it over time. These responsibilities are necessary, but the value is in the server&#8217;s tools, not in operating another service.<\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/azure\/connector-namespace\/connector-namespace-overview\">Azure Connector Namespace<\/a> is a fully managed service for hosting connectors and MCP servers. You select the server you need, and the namespace handles operational and maintenance tasks. The offering is currently in preview. Review the documentation for supported regions and other preview considerations.<\/p>\n<p>The Connector Namespace catalog includes servers for systems such as:<\/p>\n<ul>\n<li>Databases, including Azure SQL and Azure Cosmos DB.<\/li>\n<li>Source control and continuous integration and delivery (CI\/CD), including GitLab.<\/li>\n<li>Incident management, including Jira and PagerDuty.<\/li>\n<\/ul>\n<p>&#8220;Bring-your-own&#8221; server support is also in development. This capability will let you provide your own server image while Connector Namespace handles hosting and operations.<\/p>\n<h2>Deploy a server and connect it to Azure SRE Agent<\/h2>\n<p>The following example deploys the SQL MCP server in Connector Namespace and connects it to Azure SRE Agent.<\/p>\n<h3>1. Deploy the server<\/h3>\n<p>First, install the <a href=\"https:\/\/learn.microsoft.com\/azure\/developer\/azure-developer-cli\/install-azd\">Azure Developer CLI<\/a>. Then clone the SQL Server samples repository and open the Azure SQL MCP sample:<\/p>\n<pre><code class=\"language-bash\">git clone https:\/\/github.com\/microsoft\/sql-server-samples.git\r\ncd sql-server-samples\/samples\/applications\/azure-sql-mcp<\/code><\/pre>\n<p>Sign in to your Azure subscription, and then deploy the server and its related resources:<\/p>\n<pre><code class=\"language-bash\">azd auth login\r\nazd up<\/code><\/pre>\n<p>During deployment, use the following values when prompted:<\/p>\n<table>\n<thead>\n<tr>\n<th>Prompt<\/th>\n<th>Suggested value<\/th>\n<th>Explanation<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Enter a unique environment name<\/td>\n<td><code>mcp-dev<\/code><\/td>\n<td>This value is added as a prefix to the Azure resources.<\/td>\n<\/tr>\n<tr>\n<td>Select an Azure subscription<\/td>\n<td>Your subscription<\/td>\n<td>Resources are deployed to this subscription.<\/td>\n<\/tr>\n<tr>\n<td>Enter a value for <code>connectorNamespaceIdentityType<\/code><\/td>\n<td><code>UserAssigned<\/code><\/td>\n<td>User assigned identity is recommended as it\u2019s not tied to resource lifecycle<\/td>\n<\/tr>\n<tr>\n<td>Enter a value for <code>deployerLoginName<\/code><\/td>\n<td>Your Azure subscription sign-in email<\/td>\n<td>To give your identity access to the MCP server<\/td>\n<\/tr>\n<tr>\n<td>Enter a value for the location<\/td>\n<td>Pick a supported region<\/td>\n<td>Supported regions: West Central US, Central US, East Asia, North Europe<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>When deployment finishes, copy the MCP endpoint. It&#8217;s similar to the following:<\/p>\n<pre><code class=\"language-text\">https:\/\/&lt;app-name&gt;.&lt;region&gt;.logic.azure.com\/api\/connectorGateways\/&lt;gateway-id&gt;\/mcpServerConfigs\/sql-mcp\/mcp<\/code><\/pre>\n<p>You can <em>optionally<\/em> test the deployed server in Visual Studio Code with GitHub Copilot:<\/p>\n<ol>\n<li>Open the command palette and run <strong>MCP: Add Server<\/strong>.<\/li>\n<li>Select <strong>HTTP<\/strong>, enter the MCP endpoint and a server name, and select <strong>Local Workspace<\/strong>.<\/li>\n<li>In <code>.vscode\/mcp.json<\/code>, select <strong>Start<\/strong> above the server name.<\/li>\n<li>Allow Microsoft authentication in the browser and sign in with your Azure subscription account.<\/li>\n<\/ol>\n<h3>2. Configure MCP connector in SRE Agent<\/h3>\n<p>Connector Namespace hosts the server but doesn&#8217;t create its connection in Azure SRE Agent. Add the endpoint through the existing <a href=\"https:\/\/learn.microsoft.com\/azure\/sre-agent\/mcp-connector\">MCP connector experience<\/a>:<\/p>\n<ol>\n<li>Open the <a href=\"https:\/\/sre.azure.com\">Azure SRE Agent portal<\/a>.<\/li>\n<li>On the left menu, go to <strong>Builder<\/strong> &gt; <strong>Connectors<\/strong>, and select <strong>+ Add connector<\/strong>.<\/li>\n<li>On the <strong>MCP<\/strong> tab, choose <strong>MCP server<\/strong>, and then select <strong>Next<\/strong>.<\/li>\n<li>Configure the connector with the following values.<\/li>\n<\/ol>\n<table>\n<thead>\n<tr>\n<th>Field<\/th>\n<th>Value<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Name<\/td>\n<td>A descriptive name for the server<\/td>\n<\/tr>\n<tr>\n<td>Connection type<\/td>\n<td>Streamable HTTP<\/td>\n<\/tr>\n<tr>\n<td>URI<\/td>\n<td>The hosted server endpoint from Connector Namespace<\/td>\n<\/tr>\n<tr>\n<td>Authentication method<\/td>\n<td>Managed identity<\/td>\n<\/tr>\n<tr>\n<td>Microsoft Entra token scope<\/td>\n<td><code>https:\/\/apihub.azure.com\/.default<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Selecting managed identity automatically creates an identity for the connector. Select <strong>Next<\/strong>, but grant that identity access to the MCP server before you test the connection.<\/p>\n<h3>3. Authorize the managed identity<\/h3>\n<ol>\n<li>In the <a href=\"https:\/\/ms.portal.azure.com\/\">Azure portal<\/a>, search for the managed identity by name.<\/li>\n<li>On the identity&#8217;s <strong>Overview<\/strong> page, select <strong>JSON View<\/strong>, and copy the <code>tenantId<\/code> and <code>principalId<\/code>. The principal ID is also called the object ID.<\/li>\n<li>Open the <a href=\"https:\/\/connectors.azure.com\">Connector Namespace portal<\/a>, and select the deployed namespace.<\/li>\n<li>In the namespace, select <strong>MCP Connectors<\/strong> tab on the left, and then select the SQL MCP server.<\/li>\n<li>In the MCP server, select <strong>Access Policies<\/strong> &gt; <strong>Add Access Policy<\/strong>.<\/li>\n<li>Enter the <code>tenant ID<\/code> and `principal ID`, and then select <strong>Create<\/strong>.<\/li>\n<\/ol>\n<h3>4. Test and finish the connection<\/h3>\n<p>Return to the<a href=\"https:\/\/sre.azure.com\/\"> Azure SRE Agent portal<\/a> and select <strong>Test connection<\/strong>. After the test succeeds, select the server tools that the agent should use, and then select <strong>Add connector<\/strong>.<\/p>\n<p>Establishing the connection can take a minute. Select <strong>Refresh<\/strong> on the connectors page until the status changes to <strong>Connected<\/strong>.<\/p>\n<p>The agent can now use the selected server tools in chat threads. The azd deployment from previous created and seeded a SQL database with sample blog post data, so you can ask:<\/p>\n<blockquote><p>What are the top blog posts?<\/p><\/blockquote>\n<p><img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/azure-sdk\/wp-content\/uploads\/sites\/58\/2026\/08\/08-18-connector-namespace-sre-agent-demo.webp\" alt=\"Azure SRE Agent uses the SQL MCP server to read and display sample blog post records.\" \/><\/p>\n<h2>Focus on the server, not its infrastructure<\/h2>\n<p>MCP servers can give Azure SRE Agent access to the additional systems it needs to investigate incidents and perform operational work effectively. Operating every remote server yourself, however, introduces infrastructure, security, and maintenance responsibilities that distract from that goal.<\/p>\n<p>Connector Namespace removes much of that friction. Your primary question becomes, &#8220;Which MCP server do I want to host?&#8221; rather than, &#8220;How will I deploy, secure, scale, monitor, and maintain it?&#8221;<\/p>\n<p>Once deployed, the hosted endpoint can be added to Azure SRE Agent through its existing MCP connection experience. That gives teams a straightforward path to extending the agent with more operational tools, without turning MCP server hosting into another platform they must build and run.<\/p>\n<p>Try Connector Namespace with Azure SRE Agent and share your feedback.<\/p>\n<h2>Resources<\/h2>\n<ul>\n<li><a href=\"https:\/\/learn.microsoft.com\/azure\/sre-agent\/overview?tabs=task\">Azure SRE Agent overview<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/azure\/sre-agent\/mcp-connector\">Set up an MCP connector in Azure SRE Agent<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/azure\/connector-namespace\/connector-namespace-overview\">Connector Namespace overview<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/azure\/connector-namespace\/connector-namespace-hosted-mcp\">Hosted MCP servers in Connector Namespace<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Use Azure Connector Namespace to host MCP servers and give Azure SRE Agent access to the operational tools it needs without managing the server infrastructure yourself.<\/p>\n","protected":false},"author":42940,"featured_media":3979,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[967,991,989,990,940,959],"class_list":["post-3977","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azure-sdk","tag-ai-agents","tag-azure-sql","tag-azure-sre-agent","tag-connector-namespace","tag-mcp","tag-model-context-protocol"],"acf":[],"blog_post_summary":"<p>Use Azure Connector Namespace to host MCP servers and give Azure SRE Agent access to the operational tools it needs without managing the server infrastructure yourself.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/azure-sdk\/wp-json\/wp\/v2\/posts\/3977","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/azure-sdk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/azure-sdk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azure-sdk\/wp-json\/wp\/v2\/users\/42940"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azure-sdk\/wp-json\/wp\/v2\/comments?post=3977"}],"version-history":[{"count":1,"href":"https:\/\/devblogs.microsoft.com\/azure-sdk\/wp-json\/wp\/v2\/posts\/3977\/revisions"}],"predecessor-version":[{"id":3978,"href":"https:\/\/devblogs.microsoft.com\/azure-sdk\/wp-json\/wp\/v2\/posts\/3977\/revisions\/3978"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azure-sdk\/wp-json\/wp\/v2\/media\/3979"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/azure-sdk\/wp-json\/wp\/v2\/media?parent=3977"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azure-sdk\/wp-json\/wp\/v2\/categories?post=3977"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azure-sdk\/wp-json\/wp\/v2\/tags?post=3977"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}