Microsoft Graph MCP Server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Microsoft Graph MCP Serverassign a Microsoft 365 E3 license to john.doe@company.com"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
✨ Ask things like
"Onboard Jordan Lee to Sales with an E3 license." "Which licenses do we have, and how many are free?" "Who's in the Finance group?" "Find everyone called Taylor." "Move Sam from Marketing to Sales." "Who has access to the Projects SharePoint site? Give Alex read access."
Related MCP server: Microsoft Graph MCP Server
⚙️ How it works, and what it needs
The server signs in as an app registration with MSAL's client-credentials flow, with no user sign-in, and calls Microsoft Graph with that app-only token. What it can do is exactly what the application permissions you grant that app allow.
Area | Tools | Application permission |
Users (4) |
|
|
Licenses (2) |
|
|
Groups (4) |
|
|
SharePoint (9) |
|
|
✎ = changes your tenant. New users get a temporary password and must change it at first sign-in, unless you say otherwise.
🚀 Setup
1. Register an app in the Entra admin center: go to App registrations → New registration. Then:
add the application permissions from the table above for the areas you want, and grant admin consent;
create a client secret;
note the tenant ID and client ID.
AZURE_SETUP.md walks through it step by step. Add the Sites.* permissions if you want the SharePoint tools.
2. Install. You need Python 3.10+ and uv.
git clone https://github.com/ry-ops/microsoft-graph-mcp-server
cd microsoft-graph-mcp-server
uv sync3. Connect Claude Desktop. Add this to claude_desktop_config.json: ~/Library/Application Support/Claude/ on macOS, or %APPDATA%\Claude\ on Windows. There's a copy in claude_desktop_config.example.json.
{
"mcpServers": {
"microsoft-graph": {
"command": "uv",
"args": ["--directory", "/absolute/path/to/microsoft-graph-mcp-server", "run", "mcp_graph_server.py"],
"env": {
"MICROSOFT_TENANT_ID": "your-tenant-id",
"MICROSOFT_CLIENT_ID": "your-client-id",
"MICROSOFT_CLIENT_SECRET": "your-client-secret"
}
}
}
}Quit and reopen Claude Desktop to load it. There are worked examples in EXAMPLES.md, a short version in QUICKSTART.md, and the design in PROJECT_OVERVIEW.md.
🔒 Security
Grant only the permissions you'll use. For a look-only assistant, use the
.Read.Allvariants and leave SharePointFullControlout.App-only tokens are powerful. They act across the whole tenant, not as one person. Keep the client secret in your MCP client's
envor a secrets manager, and rotate it.Keep your MCP client's tool approval on. Creating users, assigning licenses and changing site access take effect immediately.
🤝 Agent-to-agent (A2A)
agent-card.json describes the server's skills, inputs and authentication for other agents to discover.
🩺 Troubleshooting
Set MICROSOFT_TENANT_ID, MICROSOFT_CLIENT_ID and MICROSOFT_CLIENT_SECRET in the env block.
The app is missing an application permission for that tool, or admin consent wasn't granted. Check the table above.
Add Sites.Read.All, plus Sites.FullControl.All for the site-permission tools, and grant admin consent again.
🙌 Contributors
SharePoint site management was contributed by @caffeinebounce in #1. Thank you!
License
MIT. See LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Manage Microsoft 365 email, calendar, contacts and inbox rules via the Graph API with OAuth 2.0.
*Updated June 17th 2025** Manage your Microsoft 365 services effortlessly. Create and manage distr…
Permissioned access to Outlook, OneDrive and Teams via the user's own Microsoft account
Manage repositories, users, releases, and automate GitHub workflows
Related MCP Servers
- AlicenseBqualityNot gradedmaintenanceProvides comprehensive management of Microsoft 365 services including Exchange, SharePoint, Teams, Azure AD, Intune device management, security & compliance frameworks, and universal access to 1000+ Microsoft Graph API endpoints with advanced features like batch operations, delta queries, and real-time webhooks.5015-
- AlicenseNot gradedqualityFmaintenanceEnables AI assistants to interact with Microsoft 365 services (users, mail, calendar, files) via Microsoft Graph API.38 npm1MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI assistants and automation tools to manage Microsoft 365, Entra ID, and Intune resources through 32 tools for user/device/file management and infrastructure monitoring.7MIT
- AlicenseAqualityBmaintenanceEnables identity provisioning and management for Microsoft 365/Entra ID via Microsoft Graph, including user creation, license assignment, group membership management, and more, with a focus on least-privilege and idempotency.18Apache 2.0