Intune
LiveDevice inventory, compliance, configuration policies, and apps as concise read tools, plus approval-gated writes: sync, retire, wipe, remote lock, passcode reset, and reboot.
Model Context Protocol for Microsoft 365 admins
Approved, audited, five minutes to set up. Connect Claude, Copilot, or any MCP client to your tenant through one URL. Reads work out of the box - every write goes through a human approval queue with a full audit trail.
EU-hosted on Azure. A Circle of Bytes ApS product, Denmark.
https://mcp.tenantmcp.com/mcpNo agents to host, no scripts to maintain. Grant consent once, paste one URL, and keep control of every change.
An admin approves TenantMCP in your tenant. The Microsoft consent screen requests read and write Graph permissions, but write tools stay switched off until an admin turns them on in the portal - nothing can change your tenant until you enable writes, and every write still needs approval.
Add https://mcp.tenantmcp.com/mcp as an MCP server in Claude, Claude Code, Copilot Studio, or any MCP client, and sign in with Microsoft. Your assistant can now answer questions about your tenant.
When the AI proposes a change, it never runs inline. It lands in your approval queue for a human to review and approve or reject. Every decision is recorded in the audit trail.
Actionable, admin-focused toolsets - not raw API breadth. Intune, Entra, and Purview are live; Licenses is in preview.
Device inventory, compliance, configuration policies, and apps as concise read tools, plus approval-gated writes: sync, retire, wipe, remote lock, passcode reset, and reboot.
Assigned versus available licensing, cost visibility, and gated reclaim and downgrade actions.
Conditional Access coverage and gaps, privileged role holders, app-credential and stale-app hygiene, guest access, and risky users as read tools.
Unified audit-log search, admin activity, sign-in risk, eDiscovery cases, and DLP alerts, surfaced read-only for your assistant.
Launch pricing during early access. Prices are subject to change.
€0
Read-only, for trying it out.
~€29/ admin / month
Write actions with approvals and audit export.
Launch pricing shown per admin, per month, and may change as TenantMCP leaves early access.
No. TenantMCP is read-only by default. Any write action the AI proposes is never executed inline - it is queued as a pending action for a human admin to approve or reject in the portal, and the decision is recorded in the audit trail.
The Microsoft admin-consent screen requests read and write Microsoft Graph permissions for TenantMCP. Granting it gives TenantMCP the capability, but the write tools stay switched off: no write tool is visible or callable to your assistant until an administrator explicitly enables write actions in the portal, and after that every individual write still has to be approved by a human in the approval queue. Three layers stand between an assistant and a change to your tenant: the admin consent, the portal opt-in, and the per-action approval.
TenantMCP runs on Azure in EU datacenters. We relay Microsoft 365 data on demand rather than warehousing your tenant contents. What we store is the operational record: approval decisions and audit metadata about who did what and when. We are GDPR-aware and keep those records so you have a defensible trail.
Any client that speaks the Model Context Protocol. That includes Claude and Claude Code, Copilot Studio, and other MCP-capable assistants. You add one server URL and sign in with Microsoft.
Intune, Entra, and Purview are live: device, identity, and compliance read tools plus approval-gated writes (device actions, group membership, and licence reclaim). The Licenses FinOps module is in preview.
Join early access and we will help you onboard. An admin grants consent, you paste the server URL into your MCP client, and you are answering questions about your tenant in minutes. Your tenant stays read-only until an admin enables write actions in the portal, and even then every write is approved by a human.
Reads by default. Writes behind a human. A full audit trail either way.