Skip to main content
Glama
josimarh

azure-mcp-pilot

by josimarh

get_user_authentication_methods

Read-onlyIdempotent

Fetch a user's authentication methods and MFA/passwordless status in Microsoft Entra ID for identity and access audits.

Instructions

Retorna métodos de autenticação e status de MFA/passwordless de um usuário.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
user_identifierYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

B3/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint, destructiveHint=false and openWorldHint, so the safety profile is covered. The description adds the useful scope note that MFA/passwordless status is included, but says nothing about permissions, return shape, or pagination.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single efficient sentence with no wasted words, and the resource plus returned scope are front-loaded. Nothing extraneous is present.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple read-only single-user lookup with annotations covering safety, the description is adequate. However, with no output schema and a 0%-documented parameter, the identifier format and return contents remain unspecified.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0% and the single required parameter user_identifier has no description anywhere. The phrase 'de um usuário' implies a user reference but does not clarify whether the identifier is an email, UPN, or object ID, which is a real ambiguity for a lookup tool.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (retorna) and resource (métodos de autenticação), plus the scope of MFA/passwordless status for a single user. It is clear on its own, but it does not distinguish itself from siblings like get_authentication_methods_summary or get_authentication_strength_summary.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no guidance on when to use this per-user lookup versus the many authentication-related siblings (get_authentication_methods_summary, list_users_without_mfa, assess_privileged_mfa). The agent must infer usage from the name alone.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools