Skip to main content
Glama
MSPbotsAI

ms-graph-mcp

by MSPbotsAI

graph-mcp

Microsoft Graph MCP server — exposes Azure Entra ID user and license management as MCP tools over HTTP-SSE.

Overview

This server implements the Model Context Protocol (HTTP-SSE transport) and wraps the Microsoft Graph API. It is designed for gateway mode: the caller obtains an Azure access token via OAuth and passes it per-request through a header. The server itself holds no credentials.

Related MCP server: EntraID MCP Server

Quick Start

docker compose up --build

The server starts on http://localhost:8080.

Local (uv)

uv sync
python -m graph_mcp

Health Check

curl http://localhost:8080/health
# {"status": "ok", "service": "graph-mcp", "transport": "http"}

No token is required for the health endpoint.

Authentication

Every request to /mcp must include a valid Azure access token:

X-Ms-Graph-Token: <access_token>

The token must be issued for the https://graph.microsoft.com/.default scope with the permissions listed per tool below. OAuth acquisition is handled by the caller — this server only forwards the token to Graph API.

Missing or invalid tokens return 401 Unauthorized.

Environment Variables

Variable

Default

Description

MCP_HTTP_PORT

8080

Listening port

MCP_HTTP_HOST

0.0.0.0

Listening host

GRAPH_BASE_URL

https://graph.microsoft.com/v1.0

Override for sovereign clouds (GCC High, DoD, China 21Vianet)

MCP Endpoint

POST http://localhost:8080/mcp

Connect your MCP client with:

  • Transport: http (Streamable HTTP / SSE)

  • Header: X-Ms-Graph-Token: <access_token>

Tools

Tool

功能

Required Scope

graph_check_user_exists

按 UPN 或邮箱查询 Entra ID 用户是否存在

User.Read.All / Directory.Read.All

graph_create_user

创建新的 Entra ID 用户,同时设置 usage_location 以便后续分配许可

User.ReadWrite.All

graph_get_user

读取用户完整资料,含 manager 与已分配许可

User.Read.All / Directory.Read.All

graph_update_user

更新用户属性(仅传入的字段会改动);account_enabled=false 用于禁用账号(离职场景)

User.ReadWrite.All

graph_reset_password

管理员重置用户密码,下次登录强制改密

User.ReadWrite.All + Password/User Administrator 角色

graph_revoke_sessions

注销用户所有登录会话,强制重新登录

User.ReadWrite.All

graph_assign_manager

设置用户的 manager

User.ReadWrite.All

graph_list_auth_methods

列出用户已注册的 MFA 认证方式

UserAuthenticationMethod.Read.All

graph_assign_groups

将用户加入一个或多个组,已在组内则幂等跳过

GroupMember.ReadWrite.All / Group.ReadWrite.All

graph_remove_group_member

将用户移出一个或多个组,不在组内则幂等跳过

GroupMember.ReadWrite.All / Group.ReadWrite.All

graph_list_user_groups

列出用户直接所属的组

GroupMember.Read.All / Directory.Read.All

graph_list_groups

按显示名搜索/列出 Entra ID 组

Group.Read.All / Directory.Read.All

graph_check_license_stock

查询租户已订阅 SKU 的许可库存与剩余数量

Organization.Read.All

graph_assign_license

为用户分配和/或移除指定 SKU 许可(Graph 的 assignLicense 接口一次调用同时支持增删,两者合并进这一个 tool)

User.ReadWrite.All

graph_send_mail

以指定用户身份发送邮件,支持 To / CC / BCC 及 HTML 正文

Mail.Send

Typical Workflows

Onboarding:

1. graph_check_user_exists   → 查重,确认账号不存在
2. graph_create_user         → 建号并设置 usage_location
3. graph_assign_groups       → 分配组
4. graph_check_license_stock → 检查许可库存
5. graph_assign_license      → 配许可
6. graph_send_mail           → 发送通知邮件(可选)

Offboarding:

1. graph_update_user(account_enabled=false) → 立即禁止新登录
2. graph_revoke_sessions                    → 注销已有会话(旧 token 在到期前仍可能短暂有效,两步搭配才是彻底离职)
3. graph_assign_license(remove_sku_ids=...) → 收回许可
4. graph_remove_group_member                → 移出各个组

Known Gaps

  • graph_remove_group_membergraph_revoke_sessionsgraph_update_useraccount_enabled 参数、graph_assign_licenseremove_sku_ids 参数都是新加的,尚未随真实 Graph 租户测试过——上线前建议先用一个可牺牲的测试账号走一遍完整离职流程再信任。

  • graph_revoke_sessions 不是瞬时生效:调用前已签发的 access token 在过期前仍然有效(通常 ~1 小时),所以离职场景务必同时调 graph_update_user(account_enabled=false),不要只调一个。

Sovereign Cloud Support

Set GRAPH_BASE_URL to override the default endpoint:

Cloud

Base URL

Public (default)

https://graph.microsoft.com/v1.0

US Government GCC High

https://graph.microsoft.us/v1.0

US Government DoD

https://dod-graph.microsoft.us/v1.0

China (21Vianet)

https://microsoftgraph.chinacloudapi.cn/v1.0

A
license - permissive license
-
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    C
    maintenance
    A FastMCP server for interacting with Microsoft Entra ID via the Microsoft Graph API, enabling management of users, groups, sign-in logs, MFA, applications, devices, conditional access, and more.
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables identity provisioning and management for Microsoft 365/Entra ID via Microsoft Graph, including user creation, license assignment, group membership management, and more, with a focus on least-privilege and idempotency.
    18
    Apache 2.0

View all related MCP servers

Related MCP Connectors

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/MSPbotsAI/ms-graph-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server