BOD-25-01-CSA-Microsoft-Policy-MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| CLIENT_ID | Yes | Your Azure AD application client ID | |
| TENANT_ID | Yes | Your Azure AD tenant ID | |
| CLIENT_SECRET | Yes | Your Azure AD application client secret |
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| block_legacy_authB | Block legacy authentication (MS.AAD.1.1v1) |
| block_high_risk_usersB | Block users detected as high risk (MS.AAD.2.1v1) |
| block_high_risk_signinsB | Block sign-ins detected as high risk (MS.AAD.2.3v1) |
| enforce_phishing_resistant_mfaC | Enforce phishing-resistant MFA for all users (MS.AAD.3.1v1) |
| enforce_alternative_mfaB | Enforce alternative MFA method if phishing-resistant MFA not enforced (MS.AAD.3.2v1) |
| configure_authenticator_contextB | Configure Microsoft Authenticator to show login context (MS.AAD.3.3v1) |
| complete_auth_methods_migrationC | Set Authentication Methods Manage Migration to Complete (MS.AAD.3.4v1) |
| enforce_privileged_mfaB | Enforce phishing-resistant MFA for privileged roles (MS.AAD.3.6v1) |
| restrict_app_registrationB | Allow only administrators to register applications (MS.AAD.5.1v1) |
| restrict_app_consentB | Allow only administrators to consent to applications (MS.AAD.5.2v1) |
| configure_admin_consentC | Configure admin consent workflow for applications (MS.AAD.5.3v1) |
| restrict_group_consentB | Prevent group owners from consenting to applications (MS.AAD.5.4v1) |
| disable_password_expiryB | Disable password expiration (MS.AAD.6.1v1) |
| configure_global_adminsC | Configure Global Administrator role assignments (MS.AAD.7.1v1) |
| enforce_granular_rolesB | Enforce use of granular roles instead of Global Administrator (MS.AAD.7.2v1) |
| enforce_cloud_accountsB | Enforce cloud-only accounts for privileged users (MS.AAD.7.3v1) |
| enforce_pamB | Enforce PAM system for privileged role assignments (MS.AAD.7.5v1) |
| configure_global_admin_approvalB | Configure approval requirement for Global Administrator activation (MS.AAD.7.6v1) |
| configure_role_alertsC | Configure alerts for privileged role assignments (MS.AAD.7.7v1) |
| configure_admin_alertsC | Configure alerts for Global Administrator activation (MS.AAD.7.8v1) |
| get_policy_statusB | Get current status of all CISA M365 security policies |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
Latest Blog Posts
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/DynamicEndpoints/Automated-BOD-25-01-CISA-Microsoft-Policies-MCP'
If you have feedback or need assistance with the MCP directory API, please join our Discord server