Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure Azure MCP Server for remote access as an authenticated HTTP service: deploy it to a host such as Azure Container Apps, require a Microsoft Entra bearer token on every request, and separately choose whether the server accesses Azure as the calling user (On-Behalf-Of) or as its hosting identity (usually managed identity). Microsoft’s Foundry reference deployment uses the azmcp-foundry-aca-mi Azure Developer CLI template and a managed identity.

What changes when Azure MCP Server is remote?

A local MCP integration commonly starts a stdio process on the same machine as the client. A remote deployment exposes an HTTP endpoint, so authentication and network protection become mandatory. There are two independent identity directions:

  • Client to MCP server: the client sends an Entra access token in the Authorization: Bearer ... header.
  • MCP server to Azure: the server obtains credentials for Azure resource operations, either by exchanging the user token with On-Behalf-Of (OBO) or by using its hosting identity.

Do not assume that authenticating the caller automatically determines the identity used against Storage, Foundry or other Azure services.

Choose a hosting and client pattern

Microsoft Foundry with Container Apps

The documented reference path uses the azmcp-foundry-aca-mi template. It deploys Azure MCP Server to Azure Container Apps and is designed for a Foundry agent using project managed identity authentication.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A standalone remote client

Any MCP client that supports HTTP and Entra authentication can call the deployed URL. For browser clients, including VS Code for the Web, configure explicit CORS origins and required headers. Desktop VS Code does not need browser CORS configuration. Connect only to an endpoint your team provisioned and approved.

Prerequisites

  • An Azure subscription and permission to create resources; Microsoft’s template prerequisites call for Owner or User Access Administrator access.
  • Azure Developer CLI (azd) installed and signed in.
  • The Azure MCP namespaces you intend to use enabled in the subscription.
  • An Azure Storage account.
  • A Microsoft Foundry project and its resource ID.
  • An Entra application registration for the remote server, including an application role.

Use separate development and production subscriptions or resource groups where possible. Inventory the exact Azure tools the client needs before assigning roles.

Deploy Azure MCP Server with the Microsoft template

  1. Initialize the template. In an empty working directory, run:
    azd init -t azmcp-foundry-aca-mi
  2. Deploy the environment.
    azd up
    The prompts request your subscription, Foundry project resource ID, Storage account resource ID and resource group. Complete sign-in when requested and review the proposed location and names before confirming.
  3. Record the outputs.
    azd env get-values
    Keep the resulting values in a protected secret store or deployment system rather than committing them to source control. The important client values include CONTAINER_APP_URL and ENTRA_APP_IDENTIFIER_URI.

The template creates a Container App running Azure MCP Server, assigns the Container Apps managed identity the Reader and Storage Blob Data Reader roles for the selected storage account, configures an Entra app registration and application role, and can deploy Application Insights telemetry. Verify each generated role assignment and remove anything your workload does not need.

Connect a Foundry agent

  1. Open the Foundry agent’s MCP tool configuration.
  2. Set the remote server endpoint to CONTAINER_APP_URL.
  3. Choose Microsoft Entra or Project Managed Identity authentication, according to the client option exposed in your Foundry project.
  4. Set Audience to ENTRA_APP_IDENTIFIER_URI.

The template assigns the Foundry project managed identity the Mcp.Tools.ReadWrite.All role. Confirm that the identity selected by the agent is the one receiving that role; a similarly named user or application will not work.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure inbound Entra authorization

Every remote request must include a valid Entra bearer token. The permission differs by OAuth flow:

Inbound flow Required permission When to use
Delegated authorization code Mcp.Tools.ReadWrite A signed-in user is represented in the request.
Client credentials Application role Mcp.Tools.ReadWrite.All A workload or service calls without a user.

Configure the client to request a token for the server’s audience (the app identifier URI), then send it as an HTTP authorization header. A token for another API, even if issued by the same tenant, is not sufficient.

Choose the server-to-Azure identity

Decision On-Behalf-Of Hosting environment identity
Downstream identity The user represented by the inbound token A shared server identity, commonly managed identity
Per-user RBAC Yes No
Audit attribution Individual user Server identity
Compatible inbound flow Delegated only Delegated or application
Typical fit Multi-tenant, enterprise or compliance-sensitive workflows A single team or client application, including the Foundry template

On-Behalf-Of

Enable UseOnBehalfOf when Azure authorization must follow the signed-in user. The server exchanges the inbound user token for a downstream token, so Azure RBAC and audit records can differ by caller. This requires delegated inbound authentication; a client-credentials token has no user identity to exchange.

Hosting identity

Enable UseHostingEnvironmentIdentity when all calls should use the Container App or other host identity. Managed identity avoids long-lived secrets and works with either delegated or application inbound authentication, but every caller receives the permissions granted to that shared identity. If neither flag is supplied, the authentication reference defines On-Behalf-Of as the default, so set the choice explicitly in production configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protect the remote endpoint

  • Grant only the Azure RBAC roles and MCP tools required for the workload. Broad permissions enlarge the actions an agent can perform.
  • Use managed or workload identities instead of stored client secrets whenever possible.
  • Pin the expected hostname and validate TLS certificates. Never disable certificate validation to work around an error.
  • For a self-hosted remote service, place Azure API Management in front when you need centralized token validation, rate limiting and audit policies.
  • If API Management forwards requests, decide whether it validates caller credentials, injects backend OAuth credentials, or performs both functions. Do not accidentally pass an end-user token to a backend that expects an application token.
  • Review MCP tool descriptions and outputs as untrusted agent context. A tool update can change what an agent is encouraged to do.

Microsoft’s security guidance explicitly warns: “Don’t use a local Azure MCP Server to handle production data or production credentials.” A remote production design should therefore include controlled hosting, identity governance, logging and an incident response path.

Browser clients and CORS

For direct browser access to a standalone Container App, allow only the exact trusted origins used by your application and include the headers required for the MCP and authorization requests. Avoid a wildcard origin when bearer tokens are involved. CORS is a browser policy; it does not replace Entra authorization or network controls. Desktop clients that do not run in a browser do not require this setup.

Do not confuse Container Apps with dynamic sessions

Azure Container Apps documentation also describes platform-managed MCP in dynamic sessions. That preview feature uses an API key and has API-version and setting changes. It is not the same as the documented Azure MCP Server remote template, which uses an Entra bearer token on the inbound HTTP request. Select documentation and configuration for the product you actually deployed.

Troubleshooting

401 Unauthorized

Check that the request has an unexpired bearer token, that the token audience exactly matches ENTRA_APP_IDENTIFIER_URI, and that the issuer and tenant are accepted by the app registration. A token issued for Microsoft Graph or another API will fail.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

403 Forbidden

For delegated callers, verify Mcp.Tools.ReadWrite. For client credentials, verify the Mcp.Tools.ReadWrite.All application role and consent. Then inspect Azure RBAC for the downstream identity: OBO uses the user, while hosting identity uses the Container App’s managed identity.

Foundry cannot reach the endpoint

Confirm that CONTAINER_APP_URL is the current HTTPS URL, the app is running, ingress permits the intended traffic, and any firewall or gateway allows it. Check the Container App revision and Application Insights logs if telemetry was deployed.

Storage operations fail after deployment

Verify that the managed identity receiving the request has both the intended data role and access to the selected Storage account. Role assignments can take time to propagate. If you chose OBO, grant the required data role to each user or group instead of only to the host.

Browser reports a CORS error

Add the precise browser origin and required authorization headers to the Container App CORS policy. Test from the same scheme, host and port used by the production application; a small difference creates a different origin.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Certificate or proxy errors

Inspect the complete certificate chain and hostname presented by the endpoint or gateway. Fix the certificate or trust configuration; do not bypass validation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your immediate goal is reliable website imagery rather than operating an MCP endpoint, ScreenshotNeo provides a website screenshot API and MCP server. One request returns PNG, JPEG, WebP or PDF, while consent banners, newsletter popups and chat widgets are removed before capture. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the page verdict and billing status.

For a direct call, see the ScreenshotNeo API documentation:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The service also includes an MCP server with take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients. It offers 1,000 screenshots per month free with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

Operational checklist

  • Endpoint is HTTPS and its hostname and certificate are verified.
  • Inbound audience and OAuth permissions match the registered MCP app.
  • OBO or hosting identity is explicit and documented.
  • RBAC is least privilege for both MCP tools and Azure resources.
  • Browser origins are allow-listed when direct browser access is required.
  • Logs and alerts cover authentication failures, authorization failures and unusual tool activity.
  • Secrets, deployment outputs and tokens are excluded from source control and routine logs.

Frequently Asked Questions

Can an application-only client use On-Behalf-Of?

No. On-Behalf-Of requires a user identity in the inbound delegated token. Application authentication must use the hosting environment identity.

Where do I find the remote URL after deployment?

Run azd env get-values and use the emitted CONTAINER_APP_URL value.

Does CORS authenticate an MCP caller?

No. CORS only controls which browser origins may make requests; Entra bearer-token validation remains the authentication mechanism.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.