All skills
microsoft avatar

/azure-app-onboard

@cda1f27 official

End-to-end orchestrator: from a business idea, app idea, or existing app to running Azure deployment with cost estimates and pre-deploy approval. Analyzes your app, auto-detects the right Azure services, scaffolds infrastructure code, and deploys — tailored to your app, not a template. Handles moving existing apps to Azure without rewriting or with minimal changes. WHEN: bring your app to Azure, plan my app, cost to run, is my code ready to deploy, deploy my app to the cloud, deploy all my services, what Azure services do I need, plan my Azure deployment, deploy my new app to Azure, one-click deploy, I have an app and want it on Azure, migrate my app to Azure, help me get started, build an app, no code yet, starter project. DO NOT USE FOR: use azd for deployment(use azure-deploy), optimizing existing costs (use cost-optimization), code readiness checks only (use azure-app-onboard-prereq).

Use this Skill: https://skilld.dev/gh/microsoft/github-copilot-for-azure/azure-app-onboard

This session only. Nothing lands on disk.

referencesmcp-tool-reference.md

≈945 tokens on demand. Your agent reads this file only when SKILL.md points to it.

MCP Tool Reference — Shared Index

Shared tools used across multiple AppOnboard phases, plus the cross-cutting Phase→Tool Map. For phase-specific tools with full parameter tables, see the per-phase references linked below.

Troubleshooting: If a tool call fails with unknown parameter or missing command errors, consult the official docs for current parameter names and allowed values: https://learn.microsoft.com/en-us/azure/developer/azure-mcp-server/tools/

Per-Phase Tool References

Phase File Exclusive Tools
Prereq (shared tools only — see table below) (shared only)
Prepare mcp-tools.md pricing, quota, cloudarchitect, WAF, advisor, group_resource_list, policy
Scaffold mcp-tools.md bicepschema, all mcp_bicep_*, deploy (iac_rules/pipeline/plan), terraform best practices
Deploy mcp-tools.md resourcehealth, monitor, appservice, deploy (app_logs/arch_diagram), role

Global Parameters (all tools)

Every Azure MCP tool accepts these optional parameters in addition to its own:

Parameter Description
subscription Azure subscription ID or display name. Defaults to az account show default.
tenant Entra ID tenant GUID or name. Uses default tenant if omitted.
resource-group Resource group name. Required for most resource-specific operations.

Additional global params (not commonly needed by AppOnboard): authentication-method (credential|key|connectionString), max-retries (default 3), retry-delay (default 2s), retry-delay-maximum (default 10s), retry-mode (fixed|exponential), retry-network-timeout (default 100s). See official docs for details.


Shared Tools (used by 2+ phases)

mcp_azure_mcp_subscription_list

Required Optional Read-Only
(none) tenant ✅

Returns: subscriptionId, displayName, state, tenantId, isDefault. Use isDefault: true as default subscription.

Used by: prepare (Step 1), deploy (Step 1)

mcp_azure_mcp_group_list

Required Optional Read-Only
(none) subscription, tenant ✅

Returns: resource group names and IDs as JSON array.

Used by: prepare (Step 7), deploy (Step 3)

mcp_azure_mcp_extension_cli_install

Required Optional Read-Only
cli-type (az|azd|func) tenant ✅

Returns: installation instructions for the specified CLI tool.

Used by: prereq (Step 2), deploy (Step 3)

mcp_azure_mcp_get_azure_bestpractices (hierarchical)

Sub-command Required Params Optional Params Read-Only
get_azure_bestpractices_get resource (general|azurefunctions|static-web-app|coding-agent), action (all|code-generation|deployment) — ✅
get_azure_bestpractices_ai_app (none) — ✅

Usage: resource + action are both required for _get. For static-web-app and coding-agent, only action: "all" is supported.

Used by: prereq (Step 3), scaffold (Step 5)


Tool Pitfalls

  • mcp_azure_mcp_subscription_list is slow at scale: Returns ALL subscriptions across ALL tenants (238+ in large orgs), causing lengthy picker detours. Use az account show for the active subscription (<1 second). Reserve subscription_list for prepare Step 1 when the user explicitly wants a different subscription.

Source: SKILL.md on GitHub

No alerts22d3 checks · Risk SAFE
  • Gen Agent Trust Hub22d

    This skill includes some security considerations such as the processing of untrusted project files to generate deployment scripts and the dynamic generation of infrastructure code. While these warrant review, they are used within the skill's intended functionality to automate Azure onboarding. See detailed analysis for context.

  • Socket22d

    No alerts

  • Snyk22d

    Risk: LOW · No issues

Signed by skilld at cda1f27. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
metadata
{
  "author": "Microsoft",
  "version": "0.0.0-placeholder"
}

README badge

README badge for microsoft/github-copilot-for-azure/azure-app-onboard