Intune
LiveDevice inventory, compliance, configuration policies, and apps as concise read tools, plus approval-gated writes like device sync and retire.
Model Context Protocol for Microsoft 365 admins
Approved, audited, five minutes to set up. Connect Claude, Copilot, or any MCP client to your tenant through one URL. Reads work out of the box - every write goes through a human approval queue with a full audit trail.
EU-hosted on Azure. A Circle of Bytes ApS product, Denmark.
https://mcp.tenantmcp.com/mcpNo agents to host, no scripts to maintain. Grant consent once, paste one URL, and keep control of every change.
An admin approves TenantMCP in your tenant with read-only Microsoft Graph permissions to start. Write permissions are a separate, later consent - nothing can change your tenant until you ask for it.
Add https://mcp.tenantmcp.com/mcp as an MCP server in Claude, Claude Code, Copilot Studio, or any MCP client, and sign in with Microsoft. Your assistant can now answer questions about your tenant.
When the AI proposes a change, it never runs inline. It lands in your approval queue for a human to review and approve or reject. Every decision is recorded in the audit trail.
Actionable, admin-focused toolsets - not raw API breadth. Intune is live now. More modules are on the way.
Device inventory, compliance, configuration policies, and apps as concise read tools, plus approval-gated writes like device sync and retire.
Assigned versus available licensing, cost visibility, and gated reclaim and downgrade actions.
Users, groups, and Conditional Access reads with carefully gated group membership writes.
Compliance and audit signal, surfaced for your assistant in read-first form.
Launch pricing during early access. Prices are subject to change.
€0
Read-only, for trying it out.
~€29/ admin / month
Write actions with approvals and audit export.
Launch pricing shown per admin, per month, and may change as TenantMCP leaves early access.
No. TenantMCP is read-only by default. Any write action the AI proposes is never executed inline - it is queued as a pending action for a human admin to approve or reject in the portal, and the decision is recorded in the audit trail.
Your first admin consent grants read-only Microsoft Graph permissions. Write permissions are a separate, incremental consent that you grant only when you decide to enable gated write actions. You are always one step ahead of what the tool can do.
TenantMCP runs on Azure in EU datacenters. We relay Microsoft 365 data on demand rather than warehousing your tenant contents. What we store is the operational record: approval decisions and audit metadata about who did what and when. We are GDPR-aware and keep those records so you have a defensible trail.
Any client that speaks the Model Context Protocol. That includes Claude and Claude Code, Copilot Studio, and other MCP-capable assistants. You add one server URL and sign in with Microsoft.
Intune is live, with device, compliance, policy, and app read tools plus approval-gated writes. Licenses, Entra, and Purview modules are on the roadmap.
Join early access and we will help you onboard. An admin grants read-only consent, you paste the server URL into your MCP client, and you are answering questions about your tenant in minutes. Enabling writes is an extra consent step whenever you are ready.
Reads by default. Writes behind a human. A full audit trail either way.