PnP PowerShell MCP Server
Officialby pnp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| PNP_MCP_READONLY | No | Set to true to refuse any command that would change Microsoft 365. Allowed verbs: Get-, Export-, Test-, Convert-/ConvertTo-/ConvertFrom-, Read-, Measure-, Connect-/Disconnect-, Find-, Format-, Resolve-, Write-, Search-, Show-, Compare-, plus pipeline shaping (Select-, Where-, Sort-, Group-, ForEach-, Out-, Join-, Split-). Refused: Set-, Remove-, Add-, New-, Clear-, Invoke-, Update-, Move-, Enable-/Disable-, Grant-/Revoke-, Copy-, Import-, Restore-, Reset-, Rename-, Start-/Stop-, Register-/Unregister-, and every other change verb — along with indirectly invoked commands, native executables, and state-changing method calls such as ExecuteQuery. Local file output (Out-File, Export-*) is still permitted. | false |
| PNP_MCP_RECORD_DIR | No | Testing only. Writes a scrubbed fixture for every command the server runs, into this directory. | |
| PNP_MCP_REPLAY_DIR | No | Testing only. Answers every command from recorded fixtures in this directory instead of running it, so the server never reaches Microsoft 365. It announces itself on stderr when set. | |
| PNP_MCP_ALLOW_SETUP | No | Set to true to let pnp_setup_environment install the PnP.PowerShell module for the current user. Left unset, that tool changes nothing and returns the Install-Module command for you to run by hand. It never installs anything else, signs in, or touches the tenant. | false |
| PNP_SCRIPT_SAMPLES_PATH | No | Your own script samples, searched alongside the community index and ranked ahead of a community sample that matches about as well. A ;-separated list of full folder paths of .ps1 files, pnp/script-samples clones, and https:// or ssh:// Git URLs. pnp_save_script_sample writes to the first plain folder listed. | |
| PNP_MCP_MAX_OUTPUT_CHARS | No | Largest tool response returned, in characters. A JSON result set over the cap is summarised — true row count, field names, and as many whole rows as fit, plus a cursor for pnp_get_result_page — so the response stays complete and parseable. Anything else is truncated to its first whole lines with a note saying how much was dropped. Values below 2000 are ignored, since the note itself would leave no room for output. | 50000 |
| PNP_MCP_CONFIRM_DESTRUCTIVE | No | Set to false to run destructive commands (Remove-*, Clear-*, ...) without asking for confirmation. This is the only way to bypass the gate: there is no tool parameter that lets the model approve its own destructive command, so on a client that cannot show a confirmation prompt, destructive commands are simply blocked. | true |
| PNP_MCP_COMMAND_TIMEOUT_SECONDS | No | Wall-clock limit for a single pnp_run_command call. On timeout the session is terminated and the connection is lost. | 600 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
No tools | |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
This server cannot be deployed
Maintenance
ActivityActive
ResponsivenessResponsive