lokka

MCP.Pizza Chef: merill

Administrators can ask about users, groups, devices, sign-in rules and Azure spending in ordinary sentences, and make changes too — creating a group with a joining rule, spotting sign-in policies that forgot the emergency account, or checking which device settings apply to a particular team. It works in Claude Desktop, VS Code and other compatible apps, with a one-click install offered for VS Code. Signing in as yourself needs nothing beyond approving access; running it unattended needs your own registered app.

Data
Other

Use This MCP server To

Create a security group with a rule based on department Find sign-in policies that left out the emergency account Check which device settings apply to one team See which Azure service cost the most last month Look up a person's account details and assigned licences Review who has access to a sensitive group

README

Lokka

npm version downloads downloads per month GitHub stars license

Lokka is a model-context-protocol server for the Microsoft Graph and Azure RM APIs that allows you to query and manage your Azure and Microsoft 365 tenants with AI.

Lokka Demo - user create demo

Please see Lokka.dev for how to use Lokka with your favorite AI model and chat client.

Lokka lets you use Claude Desktop, or any MCP Client, to use natural language to accomplish things in your Azure and Microsoft 365 tenant through the Microsoft APIs.

e.g.:

  • Create a new security group called 'Sales and HR' with a dynamic rule based on the department attribute.
  • Find all the conditional access policies that haven't excluded the emergency access account
  • Show me all the Intune device configuration policies assigned to the 'Call center' group
  • What was the most expensive service in Azure last month?

How does Lokka work?

Authentication Methods

Lokka now supports multiple authentication methods to accommodate different deployment scenarios:

Interactive Auth

For user-based authentication with interactive login, you can use the following configuration:

This is the simplest config and uses the default Lokka app.

{
  "mcpServers": {
    "Lokka-Microsoft": {
      "command": "npx",
      "args": ["-y", "@merill/lokka"]
    }
  }
}

lokka FAQ

Is this still maintained?
Yes. The project is active, with changes landing in mid-2026 and a published package that is updated regularly.
Which apps does it work in?
Claude Desktop and VS Code are both documented, VS Code even has a one-click install button, and other compatible apps work too.
Do I need a key?
Not for the simplest setup, where you sign in as yourself and approve access. Unattended use needs your own registered app with a certificate or secret.
Can I use this to audit our sign-in rules?
Yes. You can ask which policies miss an exclusion or apply to a given group and get a readable answer back.
Can it change my tenant, not just read it?
Yes. It can create and update things, and it is limited to whatever permissions you have consented to, so grant carefully.
How hard is the setup?
You paste a few lines into your app's settings, or press the install button in VS Code, so no programming is required.
Does it use preview features?
By default it uses Microsoft's preview version for newer capabilities, and one setting forces everything onto the stable version instead.
Does it cover Azure as well as Microsoft 365?
Yes, it reaches both Microsoft Graph and Azure resource management, so questions about cost and cloud resources work too.