trmm-exec-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@trmm-exec-mcpRun a read-only PowerShell on agent 'SERVER-01' to collect recent event log errors"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
trmm-exec-mcp
One MCP server for Tactical RMM: Entra-gated reads + a read-only PowerShell
runner. Only members of the assigned Entra security group can connect. It reads
everything on the platform and runs information-gathering PowerShell on any
agent — and refuses anything that changes state. Built on FastMCP 3.x with
Microsoft Entra auth (same stack as odoo-ticket-mcp).
v2 (simplified). The earlier design added a Roam one-time-token approval relay for genuine write/exec. That was more machine than the actual need, so v2 drops the relay, the proposal store, the approver list, and the agent allowlist. Safety now comes from two things: the Entra group (who can connect) and the read-only guard (what a script may do). The old flow lives in git history before the
simplify/readonly-entrabranch.
What keeps it read-only
Arbitrary PowerShell can't be proven read-only, so guard.py
is a strict, defense-in-depth backstop that errs on refusing. Two layers:
Cmdlet verb allowlist — PowerShell cmdlets are
Verb-Noun; only read verbs (Get,Test,Measure,Select, …) pass, so anySet-*,New-*,Remove-*,Stop-*,Restart-*is refused by construction.Dangerous-token denylist — catches state-changing constructs that aren't
Verb-Nouncmdlets (nativedel/reg delete/schtasks, .NET::Delete, redirection to disk) and obfuscation that would defeat layer 1 (iex,-EncodedCommand, Base64 decode,Invoke-Command).
A refusal names the offending token. This is not a sandbox — still point
TRMM_API_KEY at an account whose blast radius you accept.
Related MCP server: entraid-mcp
Auth: Microsoft Entra (resource-server mode)
FastMCP's AzureJWTVerifier + RemoteAuthProvider: the server validates
audience-bound Entra tokens and publishes protected-resource metadata; it never
issues tokens. claude.ai does the OAuth against Entra and connects. nginx in front
does only TLS + the Anthropic IP allowlist. Restrict to the senior engineers via
the Entra app's group assignment (Assignment required = Yes).
Tools
Tool | Kind | Purpose |
| read | Find machines (filter by hostname/type/platform/status). |
| read | Full detail for one agent (hardware, OS, IPs, checks, reboot state). |
| read | Hostname → agent_id (errors if 0/>1). |
| read | TRMM's own audit trail (who did what in TRMM). |
| read | Run information-gathering PowerShell (event logs, services, software, config). Mutating scripts refused. |
Configuration (env only)
Variable | Required | Description |
| ✅ | TRMM API base URL. |
| ✅ | TRMM account key with read + run/send-command. |
| — |
|
| ✅† | Tenant + API app-registration client id. |
| ✅† | Public root (no |
| ✅† | Must equal the App ID URI set in Entra (e.g. the |
| — | Scope config ( |
| — | Container bind (default |
† required when MCP_AUTH_ENABLED=true.
TRMM account
Uses the claude TRMM user, provisioned with read + Send Command
(SendCMDPerms). Put its key in TRMM_API_KEY (via the Portainer stack env,
never in git). The read-only guard limits what a script can do; keep the account
scoped to what the tools need. Treat DCs as extra-sensitive.
Run / deploy
python -m venv .venv && .venv\Scripts\activate
pip install -r requirements.txt
# local (auth off): set TRMM_API_URL, TRMM_API_KEY, MCP_AUTH_ENABLED=false, then:
python -m trmm_exec_mcpProduction: PORTAINER_DEPLOY.md (Git stack + webhook, Entra env, host port) + deploy/nginx-trmm-exec-mcp.conf.
Verify
python -m py_compile trmm_exec_mcp/*.py — clean. The read-only guard has a case
suite (read scripts allowed; mutating/obfuscated/native-destructive refused).
After deploy: /healthz ok, unauthenticated /mcp → 401, and the discovery doc
advertises the https://…/mcp/access_as_user scope (not api://…).
This server cannot be deployed
Maintenance
Related MCP Connectors
Read-only MCP access to a documented IT fleet: state, changes, posture. 15 tools.
Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner.
Read-only IT Health Check, domain security, recommendations, pricing, and draft enquiries.
Read-only finance and operations controls for AI agents with evidence and safe next actions.
Related MCP Servers
- AlicenseBqualityBmaintenanceA read-only MCP server for Microsoft Intune and Entra ID that enables list, get, search, and reporting operations for tenant visibility, audits, troubleshooting, and health reporting without write actions. It includes authentication helpers, report exports, and metadata discovery tools.361MIT
- FlicenseNot gradedqualityCmaintenanceRead-only MCP server for Microsoft Entra ID (Azure AD) that enables querying user sign-in logs, group memberships, and assigned Microsoft 365 licenses via Microsoft Graph API. Provides security and audit visibility without any write operations.-
- AlicenseAqualityCmaintenanceRead-only MCP server for the Action1 RMM REST API, enabling access to endpoints, missing updates, vulnerabilities, installed software, policies, automations, and reports.21Apache 2.0
- AlicenseNot gradedqualityCmaintenanceEnables approved senior engineers to run vetted, read-only audit scripts on Tactical RMM agents from Claude, using a fixed catalog of tools to inspect things like local admins, disk space, and installed software without permitting arbitrary code execution or destructive actions.MIT