Microsoft MCP Server for Enterprisevf.sr

listing.by · home.legend.verified

Query Microsoft Entra tenant data such as users, groups, apps and devices in natural language through Microsoft Graph.

state.auth.long (state.auth.title)Streamable HTTP

listing.connect

listing.explain.oauth

https://mcp.svc.cloud.microsoft/enterprise

listing.note.oauth

listing.share.h

listing.share.p

mcp.tc/i/microsoft-entra

listing.about

Microsoft MCP Server for Enterprise lets an AI agent read Microsoft Entra data by turning natural language questions into Microsoft Graph API calls. It covers read-only identity and directory scenarios: users, groups, applications, devices, Conditional Access, directory roles, sign-in and audit logs, and license usage.

It runs as a hosted streamable HTTP endpoint at https://mcp.svc.cloud.microsoft/enterprise and is in public preview. Users sign in with Microsoft Entra. An admin must first provision the server in the tenant and register an MCP client app with the required MCP scopes. Dynamic client registration is not supported.

listing.can

  • Find Microsoft Graph calls that match a described intent
  • Run read-only Microsoft Graph queries within the signed-in user's roles
  • Inspect user, group, application and device data in Entra
  • Review Conditional Access, authentication methods and privileged roles
  • Check device compliance and stale devices
  • Look up sign-in and audit telemetry and license usage

listing.tools

listing.notools.oauth

listing.prompts

  • Which service principals in our tenant have no owner?

  • List users who hold a privileged directory role through group assignment.

  • Show devices that have not signed in for 90 days.

  • Which Conditional Access policies apply to guest users?

listing.setup.h

listing.setup.oauth

Claude Code

  1. Run this in a terminal, in your project folder:
claude mcp add --transport http microsoft-entra https://mcp.svc.cloud.microsoft/enterprise
  1. Start Claude Code, type /mcp, pick microsoft-entra and choose Authenticate. A browser window opens for the Microsoft sign-in.

Add --scope user to make it available in every project, not just this one.

Claude Desktop

  1. Open Settings → Connectors and click Add custom connector.
  2. Name it Microsoft MCP Server for Enterprise and paste this URL:
https://mcp.svc.cloud.microsoft/enterprise
  1. Click Add, then Connect, and sign in when Microsoft asks.

Claude Desktop's JSON config file only starts local servers. Remote servers go through Connectors, and connectors you add on claude.ai show up here too.

claude.ai

  1. Open the connector form on claude.ai. This button fills in the name and URL for you:
  1. Check that the URL reads https://mcp.svc.cloud.microsoft/enterprise and click Add.
  2. Click Connect and sign in when Microsoft asks.

Free plans allow one custom connector. On Team and Enterprise plans an owner adds it under Organization settings → Connectors.

ChatGPT

  1. On chatgpt.com, open Settings → Security and login and turn on Developer mode.
  2. Go to chatgpt.com/plugins and click + to create an app for a remote MCP server.
  3. Paste https://mcp.svc.cloud.microsoft/enterprise as the server URL and choose OAuth. ChatGPT sends you to Microsoft to sign in.

Developer mode is available on the web for Plus, Pro, Business, Enterprise and Education accounts.

Cursor

Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):

mcp.json
{
  "mcpServers": {
    "microsoft-entra": {
      "url": "https://mcp.svc.cloud.microsoft/enterprise"
    }
  }
}

Cursor shows Needs login next to the server. Click it to sign in.

VS Code

Or from a terminal:

code --add-mcp '{"name":"microsoft-entra","type":"http","url":"https://mcp.svc.cloud.microsoft/enterprise"}'

Or commit it to the repo in .vscode/mcp.json:

.vscode/mcp.json
{
  "servers": {
    "microsoft-entra": {
      "type": "http",
      "url": "https://mcp.svc.cloud.microsoft/enterprise"
    }
  }
}

VS Code asks you to sign in the first time the server starts.

Devin Desktop

  1. Add it to ~/.config/devin/mcp_config.json (macOS and Linux) or %APPDATA%\devin\mcp_config.json (Windows):
mcp_config.json
{
  "mcpServers": {
    "microsoft-entra": {
      "serverUrl": "https://mcp.svc.cloud.microsoft/enterprise"
    }
  }
}
  1. Refresh the MCP server list in Cascade and sign in when asked.

Devin Desktop is the new name for Windsurf. It reads serverUrl (or url) for remote servers.

Codex

codex mcp add microsoft-entra --url https://mcp.svc.cloud.microsoft/enterprise
codex mcp login microsoft-entra

Or edit ~/.codex/config.toml directly:

config.toml
[mcp_servers.microsoft-entra]
url = "https://mcp.svc.cloud.microsoft/enterprise"

Gemini CLI

gemini mcp add --transport http microsoft-entra https://mcp.svc.cloud.microsoft/enterprise

Then, inside Gemini CLI, run /mcp auth microsoft-entra to sign in.

This adds it to the current project. Add -s user to use it everywhere.

Any client

Most clients accept this shape. Some name the URL field differently: serverUrl in Devin Desktop, httpUrl in Gemini CLI's settings file.

{
  "mcpServers": {
    "microsoft-entra": {
      "type": "http",
      "url": "https://mcp.svc.cloud.microsoft/enterprise"
    }
  }
}

Zed puts servers under context_servers in its settings. Cline needs "type": "streamableHttp", or it assumes SSE.

Client only starts local servers? Bridge it with npx -y mcp-remote https://mcp.svc.cloud.microsoft/enterprise.

listing.faq

Can I paste mcp.tc/i/microsoft-entra into my MCP client?

No. mcp.tc links are pages, not server addresses. Connect with https://mcp.svc.cloud.microsoft/enterprise, so your client talks to Microsoft MCP Server for Enterprise directly. The sign-in token only works there anyway. The quick link is for sharing: it opens this page, with setup steps for every client.

Does Microsoft MCP Server for Enterprise need an API key or a sign-in?

Yes, you need a Microsoft account. The first time your client connects, it opens Microsoft's sign-in page. The token goes straight to the server's own URL, never through mcp.tc.

Is Microsoft MCP Server for Enterprise a remote or a local server?

Remote. Microsoft hosts it at https://mcp.svc.cloud.microsoft/enterprise, and it speaks Streamable HTTP. There's nothing to install.

What can Microsoft MCP Server for Enterprise do?

You can find Microsoft Graph calls that match a described intent, run read-only Microsoft Graph queries within the signed-in user's roles and inspect user, group, application and device data in Entra.

Which clients can use it?

Any client that supports remote MCP servers: Claude Code, Claude Desktop, claude.ai, ChatGPT in developer mode, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others. The setup steps cover each one.

Who wrote this page?

mcp.tc's robot read Microsoft MCP Server for Enterprise's own metadata (its MCP handshake, tool list and public pages), and an AI model drafted the text from it. A person reviews anything the checks can't confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.

listing.em.h

listing.em.lead listing.em.how

listing.em.badge

em.prev_lightem.prev_dark
Markdown
[![Microsoft MCP Server for Enterprise on mcp.tc](https://mcp.tc/i/microsoft-entra/badge.svg)](https://mcp.tc/i/microsoft-entra)
HTML
<a href="https://mcp.tc/i/microsoft-entra"><img src="https://mcp.tc/i/microsoft-entra/badge.svg" alt="Microsoft MCP Server for Enterprise on mcp.tc" height="20"></a>

listing.em.badge_note

listing.em.widget

HTML
<script src="https://mcp.tc/w/microsoft-entra.js" async></script>

listing.em.widget_note

iframe

HTML
<iframe src="https://mcp.tc/embed/microsoft-entra" title="Microsoft MCP Server for Enterprise on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>

listing.em.iframe_note

JSON

listing.em.json

https://mcp.tc/i/microsoft-entra.json

listing.em.fields

listing.disclaimer_checked