EnterpriseMCP

MCP.Pizza Chef: microsoft

This server lets your AI assistant query Microsoft Entra identity and directory data using natural language. It works with apps like Claude, ChatGPT, and VS Code, enabling you to check users, groups, devices, security settings, and application info without manual API calls. Setup involves registering an app in your Microsoft tenant and granting permissions, then connecting your AI client. It currently supports read-only data access for enterprise IT insights.

Other

Use This MCP server To

Check user and group membership in Microsoft Entra Find which devices are compliant or inactive Review application owners and permissions See who has privileged directory roles Get security posture details like authentication methods Track license usage and stale resources Investigate sign-in and audit telemetry

README

Microsoft MCP Server for Enterprise Logo Microsoft MCP Server for Enterprise

⚠️ If Visual Studio Code displays the error Error getting token from server metadata: Error: Cannot force new registration for a non-dynamic authentication provider., change "microsoft-authentication.implementation" from "msal" to "msal-no-broker" in your Settings.

Overview

Built on the open Model Context Protocol, the public preview of Microsoft MCP Server for Enterprise lets AI agents access Microsoft Entra data by converting natural language queries into Microsoft Graph API calls. Developers and IT administrators use it to query Microsoft Entra data from their AI-powered workflows.

Full Documentation: Overview of Microsoft MCP Server for Enterprise

MCP Server Provisioning (execute once per tenant)

To set up the MCP Server for your tenant:

  1. Provision the MCP Server. In Graph Explorer, send:
    POST https://graph.microsoft.com/v1.0/servicePrincipals
    Body: { "appId": "e8c77dc2-69b3-43f4-bc51-3213c9d915b4" }

  2. Register a new app, representing the MCP Client.
    Set the appropriate Redirect URI (also called Reply URL) depending on the client. For example:
    Claude Desktop needs https://claude.ai/api/mcp/auth_callback,
    ChatGPT generates a different one for each client using the format: https://chatgpt.com/connector/oauth/<random_chars>,
    Microsoft Foundry generates a different Redirect URI for each connector using the format: https://<random_chars>.<region>.azurecontainerapps.io/rest/oauth2-credential/callback

    Redirect URI type matters in Microsoft Entra. If you add the URI under Web, Entra treats the app as a confidential client. Use that for apps that run on a server and can protect credentials (like Copilot Studio). At sign-in, Entra expects that app to authenticate with a client_secret or a certificate-based client_assertion.
    If you add the URI under Mobile and desktop applications or another public-client platform, Entra treats the app as a public client. Use that for desktop, CLI, or device apps that cannot keep a secret (like ChatGPT or Claude). These apps usually use the authorization code flow with PKCE instead of a client secret.

  3. Associate the MCP permissions (MCP.<Microsoft_Graph_Scope>) between the MCP Server and the MCP Client
    Associate MCP Client Permissions

Info Table

EnterpriseMCP FAQ

Can I use this to query Microsoft Entra identity and directory data?
Yes — it lets your AI access Microsoft Entra data like users, groups, and devices with read-only queries.
Can I use this with ChatGPT or Claude?
Yes — it works with Claude.ai, Claude Desktop, ChatGPT, VS Code, and other MCP-compatible clients.
Do I need an API key or special account?
You need to register an MCP Client app in your Microsoft tenant and grant permissions; no separate API key is required.
How hard is it to set up?
Setup is mostly one-click through your Microsoft tenant and VS Code, with some configuration steps.
Does it support write or admin actions?
Currently, it supports read-only queries for enterprise IT data.
What if I get authentication errors in VS Code?
Change the Microsoft authentication setting from 'msal' to 'msal-no-broker' in VS Code settings.