# Microsoft MCP Server for Enterprise

> Query Microsoft Entra tenant data such as users, groups, apps and devices in natural language through Microsoft Graph.

- Listing: https://mcp.tc/i/microsoft-entra
- Connect: use the server's own URL `https://mcp.svc.cloud.microsoft/enterprise` (OAuth sign-in at the server); clients connect to it directly. The listing link is a page, not an MCP endpoint.
- Type: remote (Streamable HTTP)
- Auth: OAuth sign-in
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: Microsoft
- Verified: yes, mcp.tc checked that this is the official server (https://mcp.tc/verify). It says who runs the server, not that it is safe.
- Homepage: <https://learn.microsoft.com/graph/mcp-server/overview>
- Repository: <https://github.com/microsoft/EnterpriseMCP>

## About

Microsoft MCP Server for Enterprise lets an AI agent read Microsoft Entra data by turning natural language questions into Microsoft Graph API calls. It covers read-only identity and directory scenarios: users, groups, applications, devices, Conditional Access, directory roles, sign-in and audit logs, and license usage.

It runs as a hosted streamable HTTP endpoint at https://mcp.svc.cloud.microsoft/enterprise and is in public preview. Users sign in with Microsoft Entra. An admin must first provision the server in the tenant and register an MCP client app with the required MCP scopes. Dynamic client registration is not supported.

## What it can do

- Find Microsoft Graph calls that match a described intent
- Run read-only Microsoft Graph queries within the signed-in user's roles
- Inspect user, group, application and device data in Entra
- Review Conditional Access, authentication methods and privileged roles
- Check device compliance and stale devices
- Look up sign-in and audit telemetry and license usage

## Example prompts

- "Which service principals in our tenant have no owner?"
- "List users who hold a privileged directory role through group assignment."
- "Show devices that have not signed in for 90 days."
- "Which Conditional Access policies apply to guest users?"

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport http microsoft-entra https://mcp.svc.cloud.microsoft/enterprise
```

2. Start Claude Code, type `/mcp`, pick **microsoft-entra** and choose **Authenticate**. A browser window opens for the Microsoft sign-in.

Add `--scope user` to make it available in every project, not just this one.

### Claude Desktop

1. Open **Settings → Connectors** and click **Add custom connector**.

2. Name it **Microsoft MCP Server for Enterprise** and paste this URL:

```url
https://mcp.svc.cloud.microsoft/enterprise
```

3. Click **Add**, then **Connect**, and sign in when Microsoft asks.

Claude Desktop’s JSON config file only starts local servers. Remote servers go through Connectors, and connectors you add on claude.ai show up here too.

### claude.ai

1. Open the connector form on claude.ai. This button fills in the name and URL for you:

[Add to claude.ai](<https://claude.ai/customize/connectors?modal=add-custom-connector&connectorName=Microsoft%20MCP%20Server%20for%20Enterprise&connectorUrl=https%3A%2F%2Fmcp.svc.cloud.microsoft%2Fenterprise>) (opens connector settings)

2. Check that the URL reads `https://mcp.svc.cloud.microsoft/enterprise` and click **Add**.

3. Click **Connect** and sign in when Microsoft asks.

Free plans allow one custom connector. On Team and Enterprise plans an owner adds it under **Organization settings → Connectors**.

### ChatGPT

1. On chatgpt.com, open **Settings → Security and login** and turn on **Developer mode**.

2. Go to `chatgpt.com/plugins` and click **+** to create an app for a remote MCP server.

3. Paste `https://mcp.svc.cloud.microsoft/enterprise` as the server URL and choose **OAuth**. ChatGPT sends you to Microsoft to sign in.

Developer mode is available on the web for Plus, Pro, Business, Enterprise and Education accounts.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=microsoft-entra&config=eyJ1cmwiOiJodHRwczovL21jcC5zdmMuY2xvdWQubWljcm9zb2Z0L2VudGVycHJpc2UifQ%3D%3D>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "microsoft-entra": {
      "url": "https://mcp.svc.cloud.microsoft/enterprise"
    }
  }
}
```

Cursor shows **Needs login** next to the server. Click it to sign in.

### VS Code

[Install in VS Code](<https://vscode.dev/redirect/mcp/install?name=microsoft-entra&config=%7B%22type%22%3A%22http%22%2C%22url%22%3A%22https%3A%2F%2Fmcp.svc.cloud.microsoft%2Fenterprise%22%7D>) (opens VS Code)

Or from a terminal:

```bash
code --add-mcp '{"name":"microsoft-entra","type":"http","url":"https://mcp.svc.cloud.microsoft/enterprise"}'
```

Or commit it to the repo in `.vscode/mcp.json`:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "microsoft-entra": {
      "type": "http",
      "url": "https://mcp.svc.cloud.microsoft/enterprise"
    }
  }
}
```

VS Code asks you to sign in the first time the server starts.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "microsoft-entra": {
      "serverUrl": "https://mcp.svc.cloud.microsoft/enterprise"
    }
  }
}
```

2. Refresh the MCP server list in Cascade and sign in when asked.

Devin Desktop is the new name for Windsurf. It reads `serverUrl` (or `url`) for remote servers.

### Codex

```bash
codex mcp add microsoft-entra --url https://mcp.svc.cloud.microsoft/enterprise
codex mcp login microsoft-entra
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.microsoft-entra]
url = "https://mcp.svc.cloud.microsoft/enterprise"
```

### Gemini CLI

```bash
gemini mcp add --transport http microsoft-entra https://mcp.svc.cloud.microsoft/enterprise
```

Then, inside Gemini CLI, run `/mcp auth microsoft-entra` to sign in.

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients accept this shape. Some name the URL field differently: `serverUrl` in Devin Desktop, `httpUrl` in Gemini CLI’s settings file.

```json
{
  "mcpServers": {
    "microsoft-entra": {
      "type": "http",
      "url": "https://mcp.svc.cloud.microsoft/enterprise"
    }
  }
}
```

Zed puts servers under `context_servers` in its settings. Cline needs `"type": "streamableHttp"`, or it assumes SSE.

Client only starts local servers? Bridge it with `npx -y mcp-remote https://mcp.svc.cloud.microsoft/enterprise`.

## Details

- Server version: 1.0.0
- Last checked: 2026-10-03 (reachable, asks for credentials)
- Listed: 2026-10-03
- Updated: 2026-10-03

---
Source: https://mcp.tc/i/microsoft-entra (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
