For most custom MCP servers, deploy a container to Azure Container Apps. It accepts any language with an MCP SDK, gives you managed HTTPS ingress, scaling, managed identity and private networking options. Choose Azure Functions for stateless, event-driven handlers, App Service when your application or OpenAPI API is already there, and AKS only when you need Kubernetes-level control. The sections below show how to make each choice, deploy it, secure the endpoint and troubleshoot the failures that commonly stop clients from connecting.
Choose the Azure hosting model first
Model Context Protocol (MCP) connects an AI application to external data sources and tools. On Azure, there is no single MCP service: you deploy the server on a compute product whose networking, scaling and identity model fit your workload.
| Azure option | Best fit | What you deploy | Important trade-off |
|---|---|---|---|
| Container Apps (standalone) | Custom tools, any MCP SDK language, containerized dependencies, managed ingress, autoscaling, Dapr, service-to-service calls or managed identity | Your container exposing an HTTP MCP endpoint | You own the application authentication and authorization policy |
| Container Apps dynamic sessions | Sandboxed Python or shell execution with platform-defined tools and Hyper-V isolation | No custom MCP server code; the platform supplies the session environment | Not a path for shipping your own SDK-based server |
| Azure Functions | Stateless, event-driven work and per-invocation serverless economics | An MCP Functions project, or an official-SDK server packaged as a custom handler | Function-host configuration and authorization settings are part of the deployment |
| App Service | Existing App Service applications or code-based deployment | MCP routes beside your application, or an OpenAPI 3.x API mapped by the built-in preview | Built-in MCP is a preview feature and only applies to supported OpenAPI APIs |
| AKS | Teams already operating Kubernetes that need operators, service meshes, network policies, GPU pools or direct Kubernetes APIs | One or more Kubernetes workloads and services | You take on the cluster’s operational complexity |
If you have no existing platform commitment, standalone Container Apps is the broadest custom-server route. Dynamic sessions are a different product: they provide isolated execution, not a place to deploy your own MCP implementation.
Prepare the server and Azure resources
Define the transport and endpoint
Expose an HTTPS endpoint that accepts the transport your client supports. A common arrangement is /mcp over HTTP. The web framework or MCP SDK receives JSON-RPC messages, invokes your tools and returns protocol responses. Decide whether the endpoint is public, protected by Entra authentication, or reachable only through a private network before creating the ingress.
#1 Best Overall
- Universal 19” Rack Mount Compatibility – Perfect for pro audio, video, IT, and network gear. Compatible with mixers, routers, patch panels, servers, power amps, and more.
- Heavy-Duty Load Capacity – Built to support up to 550 lbs. Ideal for studio gear, DJ setups, server equipment, and AV components that demand serious stability.
- Robust Steel Frame & Design – Made with 1.5mm thick steel and weighs 36 lbs for maximum durability, reduced vibration, and long-term reliability in any setting.
- Mobile & Secure – Preinstalled with 3” industrial-grade caster wheels (lockable), making it easy to move and position your rack exactly where you need it.
- All-In-One Setup Kit Included – Comes with 34 rack screws (5mm & 6mm), a 1U blank spacer, and an assembly tool—ready for fast installation out of the box.
Check prerequisites
- An Azure subscription and a resource group in the region where the server and its dependencies should run.
- An MCP implementation built with an official SDK, plus a health route that does not require a tool invocation.
- A container registry if you are not using a source-to-container build.
- A client that supports the transport you intend to expose; transport capabilities must match on both sides.
- Secrets, downstream API permissions and data-store access defined separately from the image. Prefer managed identity where the target service supports it.
Containerize the application
Your image must listen on the port configured for Container Apps (8080 is a common choice) and bind to 0.0.0.0, not only localhost. A minimal pattern is:
FROM python:3.12-slim
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY . .
ENV PORT=8080
CMD ["sh", "-c", "python server.py --host 0.0.0.0 --port ${PORT}"]
Replace the startup command with the command used by your SDK and framework. The important deployment contract is that the process remains available, serves the MCP route and reports failures through standard output and error.
Deploy a custom MCP server to Azure Container Apps
1. Create the application
The Azure CLI can build from a local source and create the required Container Apps environment. Run this from the directory containing your Dockerfile:
az login
az group create --name rg-mcp-prod --location eastus
az containerapp up
--name mcp-server
--resource-group rg-mcp-prod
--location eastus
--source .
--ingress external
--target-port 8080
If you already publish an image, use your registry image instead and configure registry credentials or a managed identity. Keep the image immutable by deploying a tag or digest that identifies a release.
2. Route and test the MCP endpoint
Container Apps terminates TLS at its ingress and forwards the request to your target port. The app’s fully qualified domain name (FQDN) becomes the base URL; append the route implemented by your server, such as /mcp. Confirm that a request reaches the process, that the response has the expected content type and that JSON-RPC errors are returned as protocol responses rather than HTML error pages.
az containerapp show
--name mcp-server
--resource-group rg-mcp-prod
--query properties.configuration.ingress.fqdn
--output tsv
3. Set scaling for interactive use
Scale-to-zero is available, but an interactive MCP endpoint generally benefits from at least one warm replica. Set minimum and maximum replicas to match your concurrency and downstream limits:
Rank #2
- Adjustable Depth: Depth adjustable from 23" to 40", this open frame server rack accommodates servers and network equipment while providing ample space for A/V gears and cable management. Enjoy easy access to ports and devices from multiple angles.
- High Weight Capacity: Supports up to 300 lbs on the floor (200 lbs when adjusted to maximum depth) and 200 lbs when wall-mounted (depth cannot be adjusted in wall-mounted mode). Made from carbon steel for superior welding performance and durability, this open frame rack is designed to save space while accommodating multiple devices.
- User-Friendly Design: Designed with your convenience in mind, this open frame server rack features an top shelf for extra storage and improved space utilization. The rolling casters let you move it effortlessly wherever you need it, making setup and movement a breeze.
- Widely Applicable: Maximize your space with this adaptable open frame server rack, designed to make the most of every inch. Ideal for retail spots, classrooms, offices, and any area where space is at a premium, it delivers practical solutions for your storage needs.
- Everything You Need: Our open-frame rack comes with fully equipped accessory kit for easy setup and secure installation: 2 x Trays, 4 x Casters, 1 x set of Screws, 16 x M6*12 Cage Nuts, 1 x Grounding Wire, 1 x Internal & External Hex Wrenches, and 1 x User Manual.
az containerapp update
--name mcp-server
--resource-group rg-mcp-prod
--min-replicas 1
--max-replicas 10
Use request-based or event-based scaling only after observing real traffic. A high maximum does not make a non-thread-safe server safe; protect shared state and rate-limit calls to downstream systems.
4. Configure browser clients and dependencies
For browser-based or VS Code clients, configure CORS for the exact origins that need access. Do not use a wildcard origin when credentials are sent. Add environment variables and secret references through Container Apps configuration rather than baking keys into the image. Managed identity and service-to-service networking can keep those calls on Azure’s network.
Free tools Windows power users keep installed
One-click scans. No signup required.
5. Add identity and authorization
Standalone Container Apps can use built-in Microsoft Entra authentication. That authenticates callers, but your application still decides which user or workload may invoke each tool. Validate issuer, audience, scopes and tenant, then enforce authorization in the MCP layer. For a private deployment, use internal ingress and connect callers through the required virtual network path.
Deploy with Azure Functions
Use the MCP Functions programming model
Functions is appropriate when each tool invocation is stateless and event-driven. Create the MCP project with the supported Functions extension, run it locally, invoke every tool you plan to expose, then create the Function app and deploy through the Azure CLI, portal or a supported IDE workflow.
az functionapp create
--resource-group rg-mcp-prod
--consumption-plan-location eastus
--runtime python
--runtime-version 3.12
--functions-version 4
--name mcp-functions-app
--storage-account mcpstorageunique
The exact runtime flags depend on the language and plan you select. Deploy the project after local tests and then give the client the Function host name and MCP route.
Run an existing SDK server as a custom handler
An official-SDK server can also run as a Functions custom handler. Add the Functions host artifacts, including host.json, the custom-handler configuration and the files that tell Functions how to start and invoke your process. Without those artifacts, the deployment may succeed as files but will not be recognized as a Function app. Deploy the complete project, not only the server script.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- ADJUSTABLE DEPTH: 4- Post 22U 19" server rack enclosure with 4 vertical rails and adjustable mounting depth 5.7" to 33.0" (14,4cm to 83,8cm); IT rack is compatible with various servers / switches / data / video / AV and other IT networking equipment
- EASY SHIPPING AND ASSEMBLY: Enclosed 22U data rack cabinet ships compact flat-packed to avoid damage and facilitate installation; Include wheels & levelling feet to offer more stability; Home server rack cabinet is only 46.6in (118,3cm) in height
- DESIGN AND VENTILATION: Half height server rack cabinet has lockable and removable door and side panels with vented top allowing airflow; 4 Post 19" rack with 1764lb (800kg) weight capacity (stationary); Computer cabinet rack is EIA/ECA-310-E Compliant
- HARDWARE INCLUDED: Rolling home network rack includes rack mounting and equipment mounting hardware, such as 20 M6 cage nuts / screws, PVC cup washers; Front/rear doors and side panels Keys, 2x allen keys; Rack assembly hardware; Casters and leveling feet
- THE IT PRO'S CHOICE: Designed and built for IT Professionals, this 22U IT Server Cabinet is backed for life, including free lifetime 24/5 multi-lingual technical assistance
func azure functionapp publish mcp-functions-app
Understand Functions authentication
Functions defaults to key-based access. Its built-in MCP authentication preview uses App Service authentication to implement OAuth requirements for MCP authorization. Enabling that preview can turn off the default key requirement, so test the resulting policy and update every client with the correct issuer, audience and scopes. Preview behavior and API versions can change; verify the current Azure documentation before production rollout.
Use App Service for an existing app or OpenAPI API
Mount MCP beside application routes
If your application already runs on App Service, add the MCP SDK and mount the MCP endpoint beside your existing routes. Deploy it using the same code-based process, startup command, settings and deployment slots you use for the rest of the application. Keep tool authorization separate from ordinary web-page authorization so an authenticated browser session cannot automatically gain sensitive tool permissions.
Turn an OpenAPI API into MCP tools (preview)
App Service built-in MCP (Preview) can turn an existing REST API hosted on App Service into an MCP server without writing or deploying MCP code. Point the feature at an OpenAPI 3.x specification; App Service maps operations to tools and serves streamable HTTP while handling protocol negotiation and tool discovery. Review generated tool descriptions and security requirements before exposing the endpoint. Because this is preview functionality, pin and recheck the supported API version during each release.
When AKS is justified
Choose AKS when Kubernetes is already a team capability or you require controls Container Apps does not provide: custom operators, service meshes, network policies, GPU pools, specialized scheduling or direct Kubernetes APIs. Package the server as a Deployment, expose it through an HTTPS ingress, use a Kubernetes Secret or workload identity for credentials and apply a NetworkPolicy that limits tool-to-service traffic. AKS is not automatically faster or cheaper; it is a control decision that carries cluster operations, upgrades and observability responsibilities.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteSecure a remote MCP endpoint
Protect the edge
- Use TLS-protected ingress and reject plaintext callbacks.
- Choose one authentication model per endpoint. Standalone Container Apps commonly uses Entra ID/OAuth-style protection; dynamic sessions use an
x-ms-apikeyissued through Azure management APIs; Functions uses keys by default or its OAuth preview. - Authorize individual tools and resources, not only the connection. A token that can read invoices should not automatically be able to delete them.
- Store API keys, cookies and authorization headers in secret settings. Rotate them and avoid logging their values.
- Set request limits and downstream timeouts. An MCP client can retry, so make write tools idempotent where possible.
Plan private Foundry connectivity
For a private Azure AI Foundry integration, deploy Container Apps with internal-only ingress on a dedicated subnet delegated to Microsoft.App/environments. Confirm that the Foundry client can resolve and route to the private endpoint. Foundry guidance also requires HTTP POST/GET support on Container Apps; Functions integrations use streamable HTTP with chunked transfer. A protocol mismatch looks like an authentication failure but is actually a transport failure.
Operate, observe and control cost
State and reliability
Design the server as stateless unless the hosting model explicitly supplies a session store. Keep conversation or job state in an external database or cache, use correlation IDs in logs and make startup repeatable. A minimum Container Apps replica reduces cold-start latency; scale-to-zero saves idle compute but adds wake-up delay. Functions scales per invocation but still depends on its plan limits and downstream capacity.
Rank #4
- Adjustable Depth: 23-40'' adjustable depth is used for servers and network equipment, ensuring enough space for AV equipment, components, and cabling, while allowing you to access ports and equipment from multiple sides.
- Strong Load Capacity: Ground-Mounted Load Capacity: 500 lbs, Wall-Mounted Load Capacity: 150 lbs. The av rack is made of carbon steel for better weldability performance and can help save space while meeting your need to place multiple devices.
- User-friendly Design: Ergonomic design makes the open frame av rack easier to use. The additional top panel is able to place other items with more available space. Roller design moves anywhere and anytime, is convenient, and is more energy-saving.
- Complete Accessories: We provide the accessories you need, including 2 x Pallets, 145 x M5*10 Cross Head Screws, 4 x Casters, 4 x M10*50 Expansion Screws,10 x M6*12 Cage Nuts, 1 x Grounding Wire, 1 x User Manual.
- Wide Application: The server rack wall mount maximizes the use of available space, suitable for retail venues, classrooms, offices, and other places where space is limited.
Telemetry and release safety
- Log tool name, request ID, duration, status and dependency outcome; redact prompts, tokens and personal data.
- Expose a health check that tests process readiness without performing destructive work.
- Deploy revisions or slots, test tool discovery and representative calls, then shift traffic gradually.
- Monitor rejected tokens, 4xx/5xx responses, timeouts, replica count and downstream throttling together; an MCP error often originates in a dependency.
Cost decisions
No authoritative cross-service performance or price benchmark establishes a universal winner. Compare your expected invocation pattern, minimum replicas, data transfer, logging and dependency charges. Container Apps gives you a continuously available option or scale-to-zero; Functions gives per-invocation economics for event-driven work; AKS adds cluster costs even when the MCP server is idle.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshooting checklist
The client receives 404 or an HTML page
Check the FQDN, route and ingress target port. A server listening on /mcp will return 404 if the client calls /. Confirm the container binds to 0.0.0.0 and that the revision is running.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteThe connection hangs during initialization
Verify that client and server support the same transport. For Foundry, check POST/GET support on Container Apps or streamable HTTP with chunked transfer for Functions. Inspect proxy and ingress timeouts and ensure the process flushes streaming responses.
Authentication succeeds but tools are forbidden
Authentication proves identity; authorization still has to grant the requested tool. Check Entra audience, scopes, tenant and your server’s per-tool policy. For Functions, determine whether the endpoint expects a key or the OAuth preview flow.
Cold starts or timeouts are frequent
Keep one Container Apps replica for interactive traffic, shorten image startup, defer nonessential initialization and set realistic downstream timeouts. In Functions, split slow work into an asynchronous workflow rather than holding the MCP request open.
Private Foundry cannot reach the server
Confirm internal-only ingress, the delegated Microsoft.App/environments subnet, private DNS resolution and route tables. A publicly reachable test URL does not prove the private path is configured.
Recommended Free Tools
Best Value
- ADJUSTABLE DEPTH: 4-Post 25U open frame server rack with 4 vertical rails and adjustable mounting depth 22" to 40" (56,0cm to 101,7cm); Compatible with various servers / switches / data / AV and other IT equipment; EIA/ECA-310-E Compliant
- EASY ASSEMBLY: Mobile network rack with easy-to-follow assembly instructions and online video; Compact flat-pack shipping to avoid damage and facilitate installation; Total product height of 50.8in (129cm) with casters, 48in (122cm) without casters
- COLD ROLLED STEEL: Durable 4 Post 19in open frame rack designed for ventilation with 25U mounting height and 1200lb (544kg) weight capacity (stationary); 3 install options included: casters, levelling feet, or base-plate to secure rack to the floor
- HARDWARE INCLUDED: Rolling computer/data rack includes cage nuts and screws to mount equipment, easy to read Units (U) and depth adjustment markings, cable management hooks for organization, and required assembly tools
- THE IT PRO'S CHOICE: Designed and built for IT Professionals, this 25U rack is backed for 2-years, including free lifetime 24/5 multi-lingual technical assistance
Deployment succeeds but Functions exposes no MCP route
For a custom handler, verify host.json, handler metadata, executable permissions and the complete Functions directory. A plain SDK project is not automatically a Functions app.
Or skip the browser setup
If your MCP tools need website screenshots, you can call ScreenshotNeo instead of maintaining browser automation in Azure. One GET request returns a PNG, JPEG, WebP or PDF. The service accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Only clean shots are billed: bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits cost nothing, and response headers identify the page verdict and billing result. Its MCP server provides take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients.
See the complete parameter list in the ScreenshotNeo documentation. The following calls are ready to adapt:
cURL
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Every plan includes the same features, including full-page and element capture, device presets, retina scale, PDF controls, custom CSS and JavaScript, clicks, waits, blocking, headers, cookies, user agents, geolocation, resizing, chosen-TTL caching, signed links, asynchronous webhooks, bulk capture of up to 100 URLs per call, a usage API and an OpenAPI specification. Pricing starts with 1,000 screenshots per month free with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account to get started.
Final deployment checklist
- The endpoint URL and transport match the client.
- Ingress is HTTPS and restricted to the intended audience.
- Authentication and per-tool authorization are tested with a non-admin identity.
- Secrets are externalized and managed identity is used where practical.
- At least one readiness check, structured logging and revision rollback path exist.
- Scaling limits protect downstream systems and the selected service matches your team’s operational skills.
Frequently Asked Questions
Can I expose an existing REST API as MCP without rewriting it?
Yes. App Service’s built-in MCP preview maps an OpenAPI 3.x REST API hosted on App Service to streamable-HTTP MCP tools. Review the generated descriptions and security policy before enabling it.
Is Container Apps dynamic sessions the same as hosting my own MCP server?
No. Dynamic sessions provide sandboxed Python or shell execution with platform-defined tools. Deploy a standalone Container App when you need your own SDK-based server and tool implementations.
Which authentication header does a dynamic session use?
Dynamic sessions use an x-ms-apikey issued through Azure management APIs. Standalone apps and Functions use different authentication models.
Should an MCP server keep state in memory?
Treat deployments as stateless unless you provide an external state store. This allows replicas, revisions and restarts without losing conversations or jobs.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →The Bottom Line
Deploy a custom, interactive MCP server to standalone Azure Container Apps unless an existing Functions, App Service or AKS investment gives you a stronger fit. Match the transport and identity model to the client, use private networking for private Foundry integrations, and test the complete tool authorization path before production.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




