mcp-m365-mgmt
Enables AI assistants and automation tools to manage Microsoft 365, Entra ID, and Intune resources through 32 tools for user/device/file management and infrastructure monitoring.
README
Microsoft 365 / Intune MCP Server
A comprehensive Model Context Protocol (MCP) server for managing Microsoft 365, Microsoft Entra ID, and Microsoft Intune resources. This server provides 32 tools for automating user management, device management, file operations, and infrastructure monitoring.
🎯 Overview
This MCP server enables AI assistants and automation tools to interact with:
- Microsoft Entra ID - User and group management
- Microsoft Intune - Device, policy, and application management
- SharePoint & OneDrive - Document creation and management
- Windows Autopilot - Device provisioning
- Microsoft Tunnel - Gateway monitoring
- Mobile Device Management - Android and iOS policies
- App Protection Policies - MAM policies
🚀 Quick Start
Prerequisites
- Python 3.8 or higher
- Azure subscription with appropriate licenses (Intune, Microsoft 365)
- Azure AD application registration with required permissions
Installation
-
Clone or download this repository
git clone <repository-url> cd mcp-entra-server -
Create virtual environment
python -m venv .venv # Windows .venv\Scripts\activate # macOS/Linux source .venv/bin/activate -
Install dependencies
pip install fastmcp azure-identity requests python-docx openpyxl python-pptx odfpy python-dotenv -
Configure environment variables
Create a
.envfile in the project root:# Authentication Mode: "app" or "user" AUTH_MODE=app # Azure Service Principal Credentials (for app mode) AZURE_CLIENT_ID=your-client-id AZURE_TENANT_ID=your-tenant-id AZURE_CLIENT_SECRET=your-client-secret -
Run the server
python entra_server.py
🔐 Azure App Registration Setup
Step 1: Create App Registration
- Go to Azure Portal → Azure Active Directory → App registrations
- Click New registration
- Enter a name (e.g., "MCP Entra Server")
- Set Supported account types to "Single tenant"
- Click Register
Step 2: Create Client Secret
- In your app registration, go to Certificates & secrets
- Click New client secret
- Add a description and select expiration period
- Click Add
- Copy the secret value immediately (you won't see it again)
Step 3: Configure API Permissions
Go to API permissions and add the following Application permissions:
Microsoft Graph Permissions
User & Group Management:
User.ReadWrite.All- Create and manage usersGroup.Read.All- Read groups and membershipsDirectory.Read.All- Read directory data
Device Management:
DeviceManagementManagedDevices.Read.All- Read managed devicesDeviceManagementServiceConfig.Read.All- Read device management configurationDeviceManagementApps.Read.All- Read Intune appsDeviceManagementConfiguration.Read.All- Read device configuration
File Operations:
Sites.ReadWrite.All- Read and write SharePoint sitesFiles.ReadWrite.All- Read and write files
After adding permissions, click Grant admin consent for your tenant.
Step 4: Copy Credentials
From your app registration Overview page, copy:
- Application (client) ID →
AZURE_CLIENT_ID - Directory (tenant) ID →
AZURE_TENANT_ID - Client secret (from step 2) →
AZURE_CLIENT_SECRET
📋 Complete Tool List (32 Tools)
👥 User & Group Management (4 tools)
create_user- Create new users in Microsoft Entra IDget_user_info- Get user details by IDlist_users- List all users in tenantlist_groups- List all groupsget_group_members- Get group membership
📱 Intune Device Management (6 tools)
list_intune_devices- List managed deviceslist_intune_compliance_policies- List compliance policieslist_intune_configuration_policies- List configuration policieslist_intune_filters- List assignment filterslist_intune_scripts- List PowerShell and Shell scriptslist_intune_applications- List mobile applications
🚗 Windows Autopilot (3 tools)
list_autopilot_profiles- List Autopilot deployment profileslist_autopilot_devices- List registered Autopilot deviceslist_enrollment_status_page_profiles- List ESP profiles
📱 Mobile Management (3 tools)
list_android_management_profiles- List Android policies and enrollmentlist_ios_management_profiles- List iOS/iPadOS policies and enrollmentlist_app_protection_policies- List MAM policies
🌐 Infrastructure & Connectivity (4 tools)
list_microsoft_tunnel_sites- List Microsoft Tunnel Gateway siteslist_microsoft_tunnel_servers- List tunnel servers and healthlist_intune_ad_connectors- List AD connectors for Hybrid Joinlist_intune_certificate_connectors- List NDES certificate connectors
📄 File & Document Management (12 tools)
create_file_in_onedrive- Create text files in OneDrivecreate_file_in_sharepoint- Create text files in SharePointlist_sharepoint_sites- List SharePoint sitescreate_word_document- Create Word (.docx) documentscreate_excel_workbook- Create Excel (.xlsx) workbookscreate_powerpoint_presentation- Create PowerPoint (.pptx) filesconvert_file_to_pdf- Convert Office files to PDFcreate_csv_file- Create CSV filesread_csv_file- Read CSV filesexport_powerpoint_slide_as_image- Export slides as imagescreate_odf_document- Create OpenDocument format files
🔧 Configuration Options
Authentication Modes
App Mode (Default) - Service principal authentication
AUTH_MODE=app
- Best for: Automation, unattended scenarios
- Files show as modified by "SharePoint app"
User Mode - Interactive browser authentication
AUTH_MODE=user
- Best for: Interactive use, user context required
- Files show as modified by signed-in user
- Requires user to sign in via browser
MCP Client Integration
Claude Desktop
Add to your Claude Desktop configuration (claude_desktop_config.json):
{
"mcpServers": {
"entra-server": {
"command": "python",
"args": ["C:/path/to/mcp-entra-server/entra_server.py"],
"env": {
"AZURE_CLIENT_ID": "your-client-id",
"AZURE_TENANT_ID": "your-tenant-id",
"AZURE_CLIENT_SECRET": "your-client-secret",
"AUTH_MODE": "app"
}
}
}
}
Other MCP Clients
Use the mcp.json configuration file included in the mcp/ directory.
📖 Usage Examples
List Intune Devices
from entra_server import list_intune_devices
import json
result = list_intune_devices()
print(json.dumps(result, indent=2))
Create User
from entra_server import create_user
result = create_user(
user_principal_name="john.doe@yourtenant.com",
display_name="John Doe",
mail_nickname="john.doe",
password="TempPassword123!",
force_change_password=True
)
Create Word Document in SharePoint
from entra_server import create_word_document, list_sharepoint_sites
# First, get your SharePoint site ID
sites = list_sharepoint_sites()
site_id = sites['sites'][0]['id'] # Use first site
# Create document
result = create_word_document(
location='sharepoint',
location_id=site_id,
file_name='Report.docx',
content='# Project Status\n\nAll systems operational.',
folder_path='Shared Documents'
)
List Microsoft Tunnel Sites
from entra_server import list_microsoft_tunnel_sites
result = list_microsoft_tunnel_sites()
for site in result['tunnel_sites']:
print(f"{site['displayName']}: {site['publicAddress']}")
🔍 Troubleshooting
Permission Errors (403 Forbidden)
Error: Application is not authorized to perform this operation
Solution:
- Check that all required API permissions are added in Azure Portal
- Ensure admin consent has been granted
- Wait 5-10 minutes for permissions to propagate
Authentication Errors
Error: AADSTS700016: Application with identifier was not found
Solution:
- Verify
AZURE_CLIENT_IDandAZURE_TENANT_IDare correct - Check that the app registration exists in your tenant
Error: AADSTS7000215: Invalid client secret
Solution:
- Generate a new client secret in Azure Portal
- Update
AZURE_CLIENT_SECRETin.envfile
File Operation Errors
Error: Resource not found for the segment
Solution:
- Verify the SharePoint site ID or OneDrive user ID is correct
- Use
list_sharepoint_sites()to get valid site IDs - Ensure the folder path exists (e.g., "Shared Documents")
🛡️ Security Best Practices
- Protect credentials: Never commit
.envfile to version control - Use least privilege: Only grant necessary API permissions
- Rotate secrets: Regularly rotate client secrets (recommended: every 6 months)
- Monitor access: Review Azure AD sign-in logs for suspicious activity
- Use managed identities: Consider Azure Managed Identities for production deployments
📦 Deployment Options
Local Development
python entra_server.py
Docker Container
FROM python:3.11-slim
WORKDIR /app
COPY requirements.txt .
RUN pip install -r requirements.txt
COPY . .
CMD ["python", "entra_server.py"]
Azure Container Instance
Deploy as containerized MCP server for cloud-based access.
GitHub Actions / Azure DevOps
Use as automation tool in CI/CD pipelines for tenant management.
📚 Additional Documentation
- TOOLS-SUMMARY.md - Complete tool reference with examples
- AUTHENTICATION.md - Authentication mode details
- Microsoft Graph API Documentation
- FastMCP Documentation
🤝 Contributing
Contributions are welcome! Areas for enhancement:
- Additional Intune policy types
- Bulk operations for users and devices
- Advanced SharePoint operations
- Reporting and analytics capabilities
- Exchange Online integration
- Teams management
📄 License
This project is provided as-is for educational and automation purposes. Ensure compliance with Microsoft licensing terms when using with production tenants.
🆘 Support
For issues and questions:
- Check the troubleshooting section above
- Review Microsoft Graph API documentation
- Verify API permissions and admin consent
- Check Azure AD sign-in logs for detailed errors
🔄 Updates
Version 1.0 (November 2025)
- Initial release with 32 tools
- Support for Entra ID, Intune, SharePoint, OneDrive
- Windows Autopilot integration
- Microsoft Tunnel monitoring
- Mobile device management (Android/iOS)
- App protection policies
- Document creation (Office, CSV, ODF formats)
- File conversion and image export
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。