IT self-service and lifecycle automation

Self-service for users and AI agents. Administrators stay in control.

AZExecute helps IT teams handle application requests, rotate credentials, renew certificates, and publish routine operations as self-service. Users and AI agents request the work; administrators define access, approvals, and how it runs across Azure and on-premises systems.

  • Data remains in Denmark or Sweden across multiple locations
  • Entra ID + Azure RBAC native
  • Cloud, Azure Arc + on-premises
AZExecute / Operations overview Renewals. Schedules. Outcomes.
Dashboard detail showing application renewals, scheduled work, recent runs, and automation health
See what needs attention and how your automation is running. Example data · open the full dashboard

Fits your Microsoft environment

Put your existing identity and automation to work.

Microsoft Entra IDAzure RBACAzure AutomationAzure ArcOn-premises agents

Application governance

Application requests with
the right information from the start.

Replace back-and-forth tickets with a guided request for an Entra application or API access. Collect its purpose and owners, route the required approvals, and provision the application after approval.

Explore application requests
New application request with guided Identity, Owners, API access, and Review steps Application request summary ready for review
Give requesters a clear form and approvers the details they need to decide.

Keep credentials current after provisioning

Rotate client secrets and update configured destinations such as Key Vault, Azure DevOps, and GitHub Actions. Reduce the manual work of replacing credentials across connected systems.

Explore secret rotation

See which applications need attention

Review ownership and credential lifetime risks in application reports, so administrators can follow up on missing owners and long-lived secrets.

Explore application management

Certificate automation

Renew certificates.
Deploy them where they are needed.

Take recurring certificate work off the calendar. Automate ACME issuance, DNS validation, and renewal, then use a deployment workflow to deliver the certificate to configured servers and services.

Explore certificate automation
Certificate overview with lifetime remaining, automatic renewal date, domains, and DNS authorization
Keep expiry dates, automatic renewal, and DNS authorization in view. Example data.
  • ACME issuance and renewal
  • Automated DNS validation
  • Post-renewal deployment
Let's EncryptGlobalSign AtlasDigiCert CertCentralActalisCustom ACME v2

Hybrid automation

Let support run the task.
Keep control of how it runs.

Turn scripts, runbooks, and integrations into published tasks with guided inputs. Support staff and users can run the operations you allow, without needing an administrator to perform each task.

Explore the automation engine
Automation workflow showing parallel PowerShell steps and their execution order Example execution timeline showing completed and running deployment steps
Define the workflow once, then follow each run through live status and output. Separate example runs shown.

Start with a task your team handles repeatedly

  • Restart a serviceLet support select an allowed server and run a configured recovery task.
  • Update a DNS recordCollect validated inputs and apply the change through your workflow.
  • Run a deploymentTrigger an Azure DevOps pipeline and follow the execution result.

Shared controls

The same controls, whoever starts the request.

Users in the portal and AI agents through MCP use the same governed operations. Access, approvals, and execution history stay connected.

Identity and access

Roles and resource permissions determine what each user or agent can do.

Approval rules

Required approvals apply before an operation can run.

Recorded results

Follow execution status and review the outcome in the audit history.

AI agents

Give your assistant a way to get the work done.

Let an agent find applications, submit requests, and run published tasks through MCP. It can act with the signed-in user's access or an assigned agent identity, subject to the applicable permissions and approvals.

Connect through Microsoft Foundry or another compatible MCP client with Microsoft Entra authentication.

Explore MCP for AI agents

Requests an assistant can help with

  • Show my applications.

    Use delegated access to work in the signed-in user's context.

  • Request an application for our new service.

    Collect the required information and submit it for review.

  • Run the published diagnostics task.

    Start a task the caller is allowed to run and check its result.

Illustrative requests; available actions depend on your configured tasks and access.

Getting started

Start with one recurring task.

Choose an application request, a certificate renewal, or an operation that keeps returning to the support queue. Set it up, review the results, and expand from there.

Connect what you need

Sign in with Entra ID and configure the integrations or agents needed for your first use case.

Define who can do what

Set up the inputs, access, approvals, and automation for the operation.

Publish and follow the results

Make it available to the intended users, review execution history, and reuse what works.

Read the setup guide

What could your team stop doing manually?

Start with the free plan and explore the fit for your team.

An unhandled error has occurred. Reload 🗙