Entra ID SecOps MCP Server
Related Servers
Alternatives to Entra ID SecOps MCP Server
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityFmaintenanceEnables AI agents to query Microsoft Entra data using natural language, converting requests into Microsoft Graph API calls for read-only enterprise IT scenarios.56CC BY-4.0
- AlicenseAqualityBmaintenanceEnables read-only triage of Microsoft Entra ID sign-in and audit logs through fixed tools for sign-in failure analysis, user lookup, directory audits, and daily briefs.721 PyPIMIT
- AlicenseCqualityAmaintenanceEnables read-only auditing of Microsoft Entra ID and Azure RBAC through natural-language questions in VS Code Copilot Chat, returning real tenant data on identities, roles, MFA, app secrets, PIM, conditional access, and privilege changes.4663MIT
- AlicenseAqualityBmaintenanceEnables auditing and monitoring of Microsoft Entra ID security posture, Conditional Access policies, and Zero Trust alignment via Microsoft Graph API.5MIT
- -licenseNot gradedqualityNot gradedmaintenanceProvides secure access to Microsoft Entra ID (Azure AD) resources including users, devices, and applications through Microsoft Graph API. Enables querying organizational data with comprehensive audit logging to Azure Blob Storage.-
- AlicenseNot gradedqualityBmaintenanceEnables security investigation and threat hunting through Microsoft Defender and Entra ID, with 31 tools for KQL queries, alerts, threat intelligence, identity investigation, and advanced threat hunting.MIT
TDQS
Scored across 6 tools
Each tool targets a distinct data source: user identity context, sign-in events, risky user aggregates, individual risk detections, directory audit logs, and conditional access policies. The closely related risky-user and risk-detection tools are explicitly differentiated by scope, so an agent can reliably pick the right one.
All tool names follow a consistent get_<resource> pattern using snake_case: get_user_context, get_user_signins, get_risky_users, get_risk_detections, get_directory_audits, get_conditional_access_policies. The naming convention is uniform and predictable.
Six tools is a tightly scoped set for an Entra ID SecOps investigation server. Each tool covers a necessary aspect of incident investigation without redundancy or bloat.
The tool surface covers the main investigative workflow: identify the user's privilege level, inspect sign-ins, review identity risk, understand specific risk detections, check for malicious directory changes, and evaluate conditional access impacts. No significant operational gap is apparent for the stated SecOps purpose.