ms-graph-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ms-graph-mcpcreate user alice@contoso.com with license"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
graph-mcp
Microsoft Graph MCP server — exposes Azure Entra ID user and license management as MCP tools over HTTP-SSE.
Overview
This server implements the Model Context Protocol (HTTP-SSE transport) and wraps the Microsoft Graph API. It is designed for gateway mode: the caller obtains an Azure access token via OAuth and passes it per-request through a header. The server itself holds no credentials.
Related MCP server: EntraID MCP Server
Quick Start
Docker (recommended)
docker compose up --buildThe server starts on http://localhost:8080.
Local (uv)
uv sync
python -m graph_mcpHealth Check
curl http://localhost:8080/health
# {"status": "ok", "service": "graph-mcp", "transport": "http"}No token is required for the health endpoint.
Authentication
Every request to /mcp must include a valid Azure access token:
X-Ms-Graph-Token: <access_token>The token must be issued for the https://graph.microsoft.com/.default scope with the permissions listed per tool below. OAuth acquisition is handled by the caller — this server only forwards the token to Graph API.
Missing or invalid tokens return 401 Unauthorized.
Environment Variables
Variable | Default | Description |
|
| Listening port |
|
| Listening host |
|
| Override for sovereign clouds (GCC High, DoD, China 21Vianet) |
MCP Endpoint
POST http://localhost:8080/mcpConnect your MCP client with:
Transport:
http(Streamable HTTP / SSE)Header:
X-Ms-Graph-Token: <access_token>
Tools
Tool | 功能 | Required Scope |
| 按 UPN 或邮箱查询 Entra ID 用户是否存在 |
|
| 创建新的 Entra ID 用户,同时设置 usage_location 以便后续分配许可 |
|
| 读取用户完整资料,含 manager 与已分配许可 |
|
| 更新用户属性(仅传入的字段会改动); |
|
| 管理员重置用户密码,下次登录强制改密 |
|
| 注销用户所有登录会话,强制重新登录 |
|
| 设置用户的 manager |
|
| 列出用户已注册的 MFA 认证方式 |
|
| 将用户加入一个或多个组,已在组内则幂等跳过 |
|
| 将用户移出一个或多个组,不在组内则幂等跳过 |
|
| 列出用户直接所属的组 |
|
| 按显示名搜索/列出 Entra ID 组 |
|
| 查询租户已订阅 SKU 的许可库存与剩余数量 |
|
| 为用户分配和/或移除指定 SKU 许可(Graph 的 assignLicense 接口一次调用同时支持增删,两者合并进这一个 tool) |
|
| 以指定用户身份发送邮件,支持 To / CC / BCC 及 HTML 正文 |
|
Typical Workflows
Onboarding:
1. graph_check_user_exists → 查重,确认账号不存在
2. graph_create_user → 建号并设置 usage_location
3. graph_assign_groups → 分配组
4. graph_check_license_stock → 检查许可库存
5. graph_assign_license → 配许可
6. graph_send_mail → 发送通知邮件(可选)Offboarding:
1. graph_update_user(account_enabled=false) → 立即禁止新登录
2. graph_revoke_sessions → 注销已有会话(旧 token 在到期前仍可能短暂有效,两步搭配才是彻底离职)
3. graph_assign_license(remove_sku_ids=...) → 收回许可
4. graph_remove_group_member → 移出各个组Known Gaps
graph_remove_group_member、graph_revoke_sessions、graph_update_user的account_enabled参数、graph_assign_license的remove_sku_ids参数都是新加的,尚未随真实 Graph 租户测试过——上线前建议先用一个可牺牲的测试账号走一遍完整离职流程再信任。graph_revoke_sessions不是瞬时生效:调用前已签发的 access token 在过期前仍然有效(通常 ~1 小时),所以离职场景务必同时调graph_update_user(account_enabled=false),不要只调一个。
Sovereign Cloud Support
Set GRAPH_BASE_URL to override the default endpoint:
Cloud | Base URL |
Public (default) |
|
US Government GCC High |
|
US Government DoD |
|
China (21Vianet) |
|
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityCmaintenanceEnables management of Microsoft 365 users, licenses, and groups through Microsoft Graph API. Supports user provisioning, license assignment, group management, and automated M365 administration workflows.2MIT
- Alicense-qualityCmaintenanceA FastMCP server for interacting with Microsoft Entra ID via the Microsoft Graph API, enabling management of users, groups, sign-in logs, MFA, applications, devices, conditional access, and more.MIT
- AlicenseBqualityCmaintenanceMCP server for Microsoft Teams that exposes 73 tools to manage teams, channels, chats, messages, meetings, planner, calendar, apps, tabs, scheduling, search, and authentication via the Graph API.7311MIT
- AlicenseAqualityCmaintenanceEnables identity provisioning and management for Microsoft 365/Entra ID via Microsoft Graph, including user creation, license assignment, group membership management, and more, with a focus on least-privilege and idempotency.18Apache 2.0
Related MCP Connectors
Official Microsoft MCP Server to query Microsoft Entra data using natural language
MCP server exposing the Backtest360 engine API as tools for AI agents.
The official MCP Server from Mia-Platform to interact with Mia-Platform Console
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/MSPbotsAI/ms-graph-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server