m365-evidence-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@m365-evidence-mcppull the access review evidence for this quarter"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
m365-evidence-mcp
An MCP server that turns the Microsoft Graph reads an IT auditor keeps repeating into tools any MCP-capable AI client can call. Point it at a tenant with a read-only token and ask for the evidence in plain language instead of clicking through four admin portals.
The four tools cover ITGC classics: security posture, MFA coverage, dormant accounts and privileged access. The model fetches, the auditor concludes.
Tools
Tool | What it does |
| Current Secure Score plus the five weakest controls |
| How many users are MFA registered, and who is not |
| Enabled accounts with no sign-in in the last N days |
| Activated directory roles and who holds them |
Related MCP server: azure-query-mcp
Setup
python3 -m venv .venv
.venv/bin/pip install mcpGet a Graph token. The Azure CLI is the quickest way:
export GRAPH_TOKEN=$(az account get-access-token --resource https://graph.microsoft.com --query accessToken -o tsv)The Access token tab in Graph Explorer works too. Scopes: SecurityEvents.Read.All for the score, Reports.Read.All for MFA coverage, User.Read.All plus AuditLog.Read.All for stale accounts, Directory.Read.All for roles. All of them are read scopes and most need admin consent.
Wire it into Claude Code:
claude mcp add m365evidence -- /path/to/m365-evidence-mcp/.venv/bin/python /path/to/m365-evidence-mcp/server.pyDemo
What it looks like from Claude Code:
> pull the access review evidence for the quarter
⏺ m365evidence · privileged_roles()
Global Administrator (2):
- amir.admin@demo.example
- breakglass@demo.example
Helpdesk Administrator (1):
- sara.support@demo.example
⏺ Two global admins and one of them is the break glass account.
Helpdesk Administrator has a single holder. MFA coverage next?The accounts above are demo data. The format is exactly what the server returns.
Design notes
Read-only by construction. Every tool is a single Graph GET, the annotations declare it, and a token with read scopes could not write anyway. Two layers, both structural.
Evidence, not judgement. Tools return counts with capped name lists, the kind of thing that goes straight into a workpaper. The conclusion stays with whoever reads it.
Nothing touches disk. The token lives in an environment variable and reports are never cached or logged.
Honest notes
Sign-in activity needs Entra ID P1 or better, so
stale_accountscomes back empty on a bare Business Standard tenant.Pagination is capped at ten pages of 999 objects. Fine for a small or midsize tenant, raise the cap in
_get_allfor bigger ones.The logic is tested against canned Graph responses in
test_server.py. Runpython test_server.py.
About
Al Amin Bashir Afara, Dubai · github.com/aminafara123 · linkedin.com/in/aminafara
This server cannot be deployed
Maintenance
Related MCP Connectors
Tenant-scoped evidence intake and controlled AI context over MCP.
Read-only finance and operations controls for AI agents with evidence and safe next actions.
Read-only MCP: free OpenAI security evidence ledger (55 fields) + SaaSDossier release register.
Give AI agents identity, scoped access, trusted context, and verifiable actions through MCP.
Related MCP Servers
- AlicenseAqualityBmaintenanceEnables auditing and monitoring of Microsoft Entra ID security posture, Conditional Access policies, and Zero Trust alignment via Microsoft Graph API.5MIT
- AlicenseAqualityCmaintenanceEnables read-only querying of Azure Log Analytics and Azure Resource Graph through MCP, supporting KQL queries, workspace discovery, and resource inventory exploration with Azure RBAC authentication.52MIT
- FlicenseNot gradedqualityCmaintenanceRead-only MCP server for Microsoft Entra ID (Azure AD) that enables querying user sign-in logs, group memberships, and assigned Microsoft 365 licenses via Microsoft Graph API. Provides security and audit visibility without any write operations.-
- FlicenseNot gradedqualityCmaintenanceRead-only MCP server for querying Microsoft Purview unified audit logs across M365 workloads, wrapping the Graph API's asynchronous audit log search.-