name: azure-resource-lookup
description: "List, find, and show Azure resources across subscriptions or resource groups. Handles prompts like "list websites", "list virtual machines", "list my VMs", "show storage accounts", "find container apps", and "what resources do I have". USE FOR: resource inventory, find resources by tag, tag analysis, orphaned resource discovery (not for cost analysis), unattached disks, count resources by type, cross-subscription lookup, and Azure Resource Graph queries. DO NOT USE FOR: deploying/changing resources (use azure-deploy), cost optimization (use azure-cost), or non-Azure clouds."
license: MIT
metadata:
author: Microsoft
version: "1.0.1"
Azure Resource Lookup
List, find, and discover Azure resources of any type across subscriptions and resource groups. Use Azure Resource Graph (ARG) for fast, cross-cutting queries when dedicated MCP tools don't cover the resource type.
When to Use This Skill
Use this skill when the user wants to:
- List resources of any type (VMs, web apps, storage accounts, container apps, databases, etc.)
- Show resources in a specific subscription or resource group
- Query resources across multiple subscriptions or resource types
- Find orphaned resources (unattached disks, unused NICs, idle IPs)
- Discover resources missing required tags or configurations
- Get a resource inventory spanning multiple types
- Find resources in a specific state (unhealthy, failed provisioning, stopped)
- Answer "what resources do I have?" or "show me my Azure resources"
💡 Tip: For single-resource-type queries, first check if a dedicated MCP tool can handle it (see routing table below). If none exists, use Azure Resource Graph.
Quick Reference
| Property |
Value |
| Query Language |
KQL (Kusto Query Language subset) |
| CLI Command |
az graph query -q "<KQL>" -o table |
| Extension |
az extension add --name resource-graph |
| MCP Tool |
extension_cli_generate with intent for az graph query |
| Best For |
Cross-subscription queries, orphaned resources, tag audits |
MCP Tools
| Tool |
Purpose |
When to Use |
extension_cli_generate |
Generate az graph query commands |
Primary tool — generate ARG queries from user intent |
mcp_azure_mcp_subscription_list |
List available subscriptions |
Discover subscription scope before querying |
mcp_azure_mcp_group_list |
List resource groups |
Narrow query scope |
Workflow
Step 1: Check for a Dedicated MCP Tool
For single-resource-type queries, check if a dedicated MCP tool can handle it:
| Resource Type |
MCP Tool |
Coverage |
| Virtual Machines |
compute |
✅ Full — list, details, sizes |
| Storage Accounts |
storage |
✅ Full — accounts, blobs, tables |
| Cosmos DB |
cosmos |
✅ Full — accounts, databases, queries |
| Key Vault |
keyvault |
⚠️ Partial — secrets/keys only, no vault listing |
| SQL Databases |
sql |
⚠️ Partial — requires resource group name |
| Container Registries |
acr |
✅ Full — list registries |
| Kubernetes (AKS) |
aks |
✅ Full — clusters, node pools |
| App Service / Web Apps |
appservice |
❌ No list command — use ARG |
| Container Apps |
— |
❌ No MCP tool — use ARG |
| Event Hubs |
eventhubs |
✅ Full — namespaces, hubs |
| Service Bus |
servicebus |
✅ Full — queues, topics |
If a dedicated tool is available with full coverage, use it. Otherwise proceed to Step 2.
Step 2: Generate the ARG Query
Use extension_cli_generate to build the az graph query command:
mcp_azure_mcp_extension_cli_generate
intent: "query Azure Resource Graph to <user's request>"
cli-type: "az"
See Azure Resource Graph Query Patterns for common KQL patterns.
Step 3: Execute and Format Results
Run the generated command. Use --query (JMESPath) to shape output:
az graph query -q "<KQL>" --query "data[].{name:name, type:type, rg:resourceGroup}" -o table
Use --first N to limit results. Use --subscriptions to scope.
Error Handling
| Error |
Cause |
Fix |
resource-graph extension not found |
Extension not installed |
az extension add --name resource-graph |
AuthorizationFailed |
No read access to subscription |
Check RBAC — need Reader role |
BadRequest on query |
Invalid KQL syntax |
Verify table/column names; use =~ for case-insensitive type matching |
| Empty results |
No matching resources or wrong scope |
Check --subscriptions flag; verify resource type spelling |
Constraints
- ✅ Always use
=~ for case-insensitive type matching (types are lowercase)
- ✅ Always scope queries with
--subscriptions or --first for large tenants
- ✅ Prefer dedicated MCP tools for single-resource-type queries
- ❌ Never use ARG for real-time monitoring (data has slight delay)
- ❌ Never attempt mutations through ARG (read-only)
Converted and distributed by TomeVault — claim your Tome and manage your conversions.
1---2name: microsoft-skills-azure-resource-lookup3description: ---4---5---6name: azure-resource-lookup7description: "List, find, and show Azure resources across subscriptions or resource groups. Handles prompts like \"list websites\", \"list virtual machines\", \"list my VMs\", \"show storage accounts\", \"find container apps\", and \"what resources do I have\". USE FOR: resource inventory, find resources by tag, tag analysis, orphaned resource discovery (not for cost analysis), unattached disks, count resources by type, cross-subscription lookup, and Azure Resource Graph queries. DO NOT USE FOR: deploying/changing resources (use azure-deploy), cost optimization (use azure-cost), or non-Azure clouds."8license: MIT9metadata:10 author: Microsoft11 version: "1.0.1"12---1314# Azure Resource Lookup1516List, find, and discover Azure resources of any type across subscriptions and resource groups. Use Azure Resource Graph (ARG) for fast, cross-cutting queries when dedicated MCP tools don't cover the resource type.1718## When to Use This Skill1920Use this skill when the user wants to:21- **List resources** of any type (VMs, web apps, storage accounts, container apps, databases, etc.)22- **Show resources** in a specific subscription or resource group23- Query resources **across multiple subscriptions** or resource types24- Find **orphaned resources** (unattached disks, unused NICs, idle IPs)25- Discover resources **missing required tags** or configurations26- Get a **resource inventory** spanning multiple types27- Find resources in a **specific state** (unhealthy, failed provisioning, stopped)28- Answer "**what resources do I have?**" or "**show me my Azure resources**"2930> 💡 **Tip:** For single-resource-type queries, first check if a dedicated MCP tool can handle it (see routing table below). If none exists, use Azure Resource Graph.3132## Quick Reference3334| Property | Value |35|----------|-------|36| **Query Language** | KQL (Kusto Query Language subset) |37| **CLI Command** | `az graph query -q "<KQL>" -o table` |38| **Extension** | `az extension add --name resource-graph` |39| **MCP Tool** | `extension_cli_generate` with intent for `az graph query` |40| **Best For** | Cross-subscription queries, orphaned resources, tag audits |4142## MCP Tools4344| Tool | Purpose | When to Use |45|------|---------|-------------|46| `extension_cli_generate` | Generate `az graph query` commands | Primary tool — generate ARG queries from user intent |47| `mcp_azure_mcp_subscription_list` | List available subscriptions | Discover subscription scope before querying |48| `mcp_azure_mcp_group_list` | List resource groups | Narrow query scope |4950## Workflow5152### Step 1: Check for a Dedicated MCP Tool5354For single-resource-type queries, check if a dedicated MCP tool can handle it:5556| Resource Type | MCP Tool | Coverage |57|---|---|---|58| Virtual Machines | `compute` | ✅ Full — list, details, sizes |59| Storage Accounts | `storage` | ✅ Full — accounts, blobs, tables |60| Cosmos DB | `cosmos` | ✅ Full — accounts, databases, queries |61| Key Vault | `keyvault` | ⚠️ Partial — secrets/keys only, no vault listing |62| SQL Databases | `sql` | ⚠️ Partial — requires resource group name |63| Container Registries | `acr` | ✅ Full — list registries |64| Kubernetes (AKS) | `aks` | ✅ Full — clusters, node pools |65| App Service / Web Apps | `appservice` | ❌ No list command — use ARG |66| Container Apps | — | ❌ No MCP tool — use ARG |67| Event Hubs | `eventhubs` | ✅ Full — namespaces, hubs |68| Service Bus | `servicebus` | ✅ Full — queues, topics |6970If a dedicated tool is available with full coverage, use it. Otherwise proceed to Step 2.7172### Step 2: Generate the ARG Query7374Use `extension_cli_generate` to build the `az graph query` command:7576```yaml77mcp_azure_mcp_extension_cli_generate78 intent: "query Azure Resource Graph to <user's request>"79 cli-type: "az"80```8182See [Azure Resource Graph Query Patterns](references/azure-resource-graph.md) for common KQL patterns.8384### Step 3: Execute and Format Results8586Run the generated command. Use `--query` (JMESPath) to shape output:8788```bash89az graph query -q "<KQL>" --query "data[].{name:name, type:type, rg:resourceGroup}" -o table90```9192Use `--first N` to limit results. Use `--subscriptions` to scope.9394## Error Handling9596| Error | Cause | Fix |97|-------|-------|-----|98| `resource-graph extension not found` | Extension not installed | `az extension add --name resource-graph` |99| `AuthorizationFailed` | No read access to subscription | Check RBAC — need Reader role |100| `BadRequest` on query | Invalid KQL syntax | Verify table/column names; use `=~` for case-insensitive type matching |101| Empty results | No matching resources or wrong scope | Check `--subscriptions` flag; verify resource type spelling |102103## Constraints104105- ✅ **Always** use `=~` for case-insensitive type matching (types are lowercase)106- ✅ **Always** scope queries with `--subscriptions` or `--first` for large tenants107- ✅ **Prefer** dedicated MCP tools for single-resource-type queries108- ❌ **Never** use ARG for real-time monitoring (data has slight delay)109- ❌ **Never** attempt mutations through ARG (read-only)110111---112> Converted and distributed by [TomeVault](https://tomevault.io/claim/microsoft) — claim your Tome and manage your conversions.113<!-- tomevault:4.0:skill_md:2026-04-11 -->