Server data from the Official MCP Registry
MCP server for CIPP — M365 multi-tenant management for MSPs (users, tenants, policies).
About
MCP server for CIPP — M365 multi-tenant management for MSPs (users, tenants, policies).
Security Report
The CIPP MCP server requires explicit credentials (API key or OAuth client-credentials) and its network calls go only to the configured CIPP Function App base URL, which matches its purpose of managing M365 tenants. The visible code shows careful input handling and no exfiltration, shell execution, or hardcoded secrets, though the file is truncated and the tool implementations (e.g., reset_password, offboard_user, set_email_forwarding) carry high-impact privileges that warrant user caution. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity).
3 files analyzed · 5 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: CIPP_API_URL
Environment variable: CIPP_CLIENT_ID
Environment variable: CIPP_CLIENT_SECRET
Environment variable: CIPP_TENANT_ID
Environment variable: MCP_TRANSPORT
Environment variable: AUTH_MODE
Environment variable: LOG_LEVEL
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-wyre-ai-cipp-mcp": {
"env": {
"AUTH_MODE": "your-auth-mode-here",
"LOG_LEVEL": "your-log-level-here",
"CIPP_API_URL": "your-cipp-api-url-here",
"MCP_TRANSPORT": "your-mcp-transport-here",
"CIPP_CLIENT_ID": "your-cipp-client-id-here",
"CIPP_TENANT_ID": "your-cipp-tenant-id-here",
"CIPP_CLIENT_SECRET": "your-cipp-client-secret-here"
},
"args": [
"-y",
"cipp-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
CIPP MCP Server
MCP (Model Context Protocol) server for CIPP — the CyberDrain Improved Partner Portal. Provides AI assistants with structured access to CIPP's M365 multi-tenant management capabilities.
Features
- 46 tools across 12 categories
- Tenant, user, group, and mailbox management
- Mailbox and online-archive size reporting, per tenant or per user
- Per-user Entra ID sign-in logs (status, location, Conditional Access, MFA)
- Security: Conditional Access policies, named locations
- Standards & compliance: BPA, domain health, drift detection
- License reporting (per-tenant and CSP-wide)
- Alerts, audit logs, and scheduled tasks
- GDAP role and invite management
- Stdio and HTTP transport modes
- MCP Gateway compatible
Prerequisites
- Node.js 18+
- A running CIPP deployment
- CIPP API Key (generated from CIPP Settings → API Client Management)
Installation
Via npm (once published)
npx cipp-mcp
From source
git clone https://github.com/WYRE-AI/cipp-mcp
cd cipp-mcp
npm install
npm run build
Configuration
Set these environment variables (or copy .env.example to .env):
| Variable | Required | Description |
|---|---|---|
CIPP_BASE_URL | Yes | Your CIPP Azure Function App URL (e.g. https://cippXXXXX.azurewebsites.net). Do not use the SWA / frontend URL — see Finding your Function App URL. |
CIPP_API_KEY | One of | Static Bearer token. Use this or the OAuth trio below. |
CIPP_TENANT_ID | One of | Entra tenant ID that owns the CIPP API-client app registration. |
CIPP_CLIENT_ID | One of | OAuth client ID issued by CIPP's API Client Management page. |
CIPP_CLIENT_SECRET | One of | OAuth client secret paired with CIPP_CLIENT_ID. |
CIPP_TOKEN_SCOPE | No | Override OAuth scope. Default: api://<clientId>/.default. An explicit value disables the legacy-scope fallback below. |
CIPP_TOKEN_SCOPE_FALLBACK | No | When no explicit scope is set, retry a CIPP HTTP 401 once with the legacy <clientId>/.default scope and reuse whichever audience this client accepts. Default: true. TOKEN_SCOPE_FALLBACK is an alias. Gateway requests can send x-token-scope-fallback. |
CIPP_TOKEN_URL | No | Override OAuth token endpoint (sovereign clouds only). |
MCP_TRANSPORT | No | stdio (default) or http |
MCP_HTTP_PORT | No | Port for HTTP mode (default: 8080) |
LOG_LEVEL | No | error, warn, info (default), or debug |
[!IMPORTANT]
CIPP_BASE_URLmust be the Azure Function App URL — the CIPP-API backend,https://<function-app-name>.azurewebsites.net— not the Static Web App / custom-domain UI URL (e.g.https://cipp.yourdomain.com). The SWA's built-in auth intercepts bearer tokens and redirects them to its interactive login page, so every API call fails. Find the Function App (named likecippXXXXX) in your CIPP resource group in the Azure Portal.
Usage with Claude Desktop
Add to your claude_desktop_config.json:
{
"mcpServers": {
"cipp": {
"command": "node",
"args": ["/path/to/cipp-mcp/dist/entry.js"],
"env": {
"CIPP_BASE_URL": "https://cippXXXXX.azurewebsites.net",
"CIPP_TENANT_ID": "your-entra-tenant-id",
"CIPP_CLIENT_ID": "your-client-id",
"CIPP_CLIENT_SECRET": "your-client-secret"
}
}
}
}
Note:
CIPP_BASE_URLmust be the Azure Function App URL (.azurewebsites.net), not the frontend SWA URL (.azurestaticapps.netor your custom domain). The SWA enforces browser-based auth and will redirect all API requests to a Microsoft login page.
Tools
| Category | Tools |
|---|---|
| Tenants | list_tenants, get_tenant_details |
| Users | list_users, create_user, edit_user, disable_user, reset_password, reset_mfa, revoke_sessions, offboard_user, bec_check, list_mfa_users, list_user_devices, list_user_groups, list_user_signin_logs |
| Groups | list_groups, create_group |
| Mailboxes | list_mailboxes, list_mailbox_permissions, list_mailbox_usage, get_mailbox_usage, set_out_of_office, set_email_forwarding |
| Security | list_conditional_access_policies, list_named_locations |
| Applications | list_enterprise_apps |
| Standards | list_standards, run_standards_check, list_standard_templates, get_tenant_drift, get_tenant_alignment, create_standard_template, delete_standard_template, list_bpa, list_domain_health |
| Licenses | list_licenses, list_csp_licenses |
| Alerts | list_audit_logs, list_alert_queue |
| GDAP | list_gdap_roles, list_gdap_invites |
| Scheduler | list_scheduled_items, add_scheduled_item |
| Core | ping, get_version, list_logs |
Mailbox and archive sizes
list_mailbox_usage reports every mailbox in a tenant — primary size, item
count, quota, percent of quota, and the same four figures for the online
archive — sorted largest first, with tenant-wide totals that cover every
mailbox even when only the top rows are returned.
It requires CIPP's reporting database to have been synced for that tenant.
This is not a design choice: Invoke-ListMailboxes' live Exchange query selects
no size fields at all, so the cache is the only tenant-wide source of sizes.
Sync it from CIPP under Reports → Report Settings. If it has not been synced the
tool says so and names the remedy rather than returning an empty result.
get_mailbox_usage reports the same figures for a single mailbox and reads
live, so it needs no cache. Prefer it when the cache is unavailable or stale.
Two caveats worth knowing:
- Concealed report names blank the tenant-wide sizes. With Reports:
conceal user, group, and site names enabled in the Microsoft 365 admin
centre, Graph's usage report returns 32-character hashes instead of UPNs, so
CIPP's join against the mailbox list matches nothing and every mailbox caches
a size of
0— a tenant that reads as empty rather than as failed.list_mailbox_usagedetects this and returns a warning alongside the totals.get_mailbox_usageis unaffected: it reads the Exchange admin API directly. - Sizes are gigabyte-rounded on the per-user path. CIPP rounds to two
decimal places of a gigabyte before returning, so
get_mailbox_usagebyte counts are accurate to roughly 10 MB. Quotas are exact — they are recovered from the rawGet-Mailboxstring, which carries the true byte count.
User sign-in logs
list_user_signin_logs returns one user's most recent interactive sign-ins,
newest first: time, app, IP, location, success or failure with error code and
reason, client app, Conditional Access status and the policies that evaluated,
the authentication methods Graph recorded (first factor included — whether
MFA was required is authenticationRequirement), device, and risk when
flagged — plus a summary of failures, distinct IPs and countries.
- Accepts a UPN or an object id, and always resolves it first. CIPP filters
Graph on
userId, which is the Entra object id; a UPN there matches nothing and returns an empty page that reads as "this user never signs in". An unresolvable user is an error, not an empty result. - One tenant, one user, one page.
topdefaults to 50 and caps at 1000; a full page carries a warning that older sign-ins may exist.allTenantsis rejected — the endpoint has no all-tenants branch. Tenant-wide sign-ins are CIPP's Sign-Ins report (ListSignIns), which this server does not expose. - Needs Entra ID P1/P2 in the tenant. Graph refuses sign-in log API access otherwise; the tool names the licence gap instead of relaying a generic "Failed to retrieve Sign In report".
CIPP version compatibility
Request bodies are shaped against CIPP's own Invoke-*.ps1 handlers and are
written to satisfy both current and older CIPP builds — where the two differ,
the server sends the form both accept. Three behaviours are worth knowing:
offboard_userreports queued, not completed. CIPP'sExecOffboardUserreturns HTTP 200 the instant the job is created; it never waits for or reports the offboarding result. Confirm the outcome in CIPP's Offboarding view before treating an account as offboarded. The tool refuses a call with no actions selected, since that would otherwise queue a job that succeeds while doing nothing.- Some endpoints report failure under HTTP 200.
EditUser,AddScheduledItemandExecOffboardUserreturn error text inResultsrather than an error status. These tools parseResultsand returnstatus: "failed"; do not treat a 200 as success. - Two parameters need a recent CIPP.
offboard_user'sDisableOneDriveSharingandset_out_of_office'stimezoneare ignored by older builds rather than erroring — so an offboarding that selects onlyDisableOneDriveSharingwill run no actions on an older CIPP.
Authentication Setup
CIPP's API Client Management page provisions an Entra ID app registration and returns an OAuth client ID + client secret (not a long-lived Bearer token). The server exchanges these for a short-lived access token on each request using the OAuth 2.0 client-credentials flow, and caches the token until just before its expiry.
- In CIPP, go to Settings → CIPP Settings → Integrations → CIPP-API
- Create a new API client
- Copy the Client ID and Client Secret — you will not be able to retrieve the secret later
- Configure the server with the Function App URL (see below):
CIPP_BASE_URL=https://cippXXXXX.azurewebsites.net CIPP_TENANT_ID=<your-entra-tenant-id> CIPP_CLIENT_ID=<client-id-from-cipp> CIPP_CLIENT_SECRET=<client-secret-from-cipp>
If you already have a static Bearer token (older CIPP deployments), set
CIPP_API_KEY instead and leave the OAuth variables unset. When both are
provided, CIPP_API_KEY wins.
The access token is requested for api://<clientId>/.default. That is the
Application ID URI CIPP's App Service authentication allows. A token requested
for the bare <clientId>/.default scope has its aud set to the client id
GUID, and App Service auth rejects it with HTTP 401 and an empty body.
Deployments that still expect that legacy audience are handled automatically:
when no explicit scope is configured, a 401 is retried once with the other
automatic audience (api://<clientId>/.default or <clientId>/.default).
The audience that succeeds is reused for later calls from the same client.
If that audience later starts failing with 401, the pin is dropped and the
other audience is tried once, then whichever succeeds is remembered again.
The retry does not run for any other status (403, 500, and so on), and a
single request never tries more than once. Set CIPP_TOKEN_SCOPE to force
a scope, or CIPP_TOKEN_SCOPE_FALLBACK=false (alias TOKEN_SCOPE_FALLBACK,
gateway header x-token-scope-fallback) to skip the retry.
Finding your Function App URL
CIPP runs as an Azure Static Web App (SWA) backed by an Azure Function App.
The SWA URL (your custom domain or *.azurestaticapps.net) enforces browser-only
auth and cannot be used as CIPP_BASE_URL. Use the Function App URL instead.
Self-hosted CIPP: Find the Function App in the Azure portal (look for an App Service
with Kind: functionapp in the same resource group as your SWA), or run:
az staticwebapp show --name <your-swa-name> --resource-group <rg> \
--query "linkedBackends[0].backendResourceId" -o tsv
CIPP-sponsored hosting: Contact the CIPP team for your instance's Function App URL — it is not the same as the URL shown in your browser.
IP Allowlist
CIPP validates each API client against an IPRange field stored in Azure Table Storage.
If your server's public IP is not in this list, you will receive:
Access to this CIPP API endpoint is not allowed, the API Client does not have the required permission
Self-hosted: Add your IP via the CIPP UI (Settings → API Client Management) or
directly in the ApiClients table of your CIPP storage account.
CIPP-sponsored hosting: Ask the CIPP team to add your server's public IP to your API client's allowed range.
License
Apache-2.0 — see LICENSE
Contributing
Issues and PRs welcome. This server is tracked against wyre-technology/msp-claude-plugins#24.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Worldmonitor
Freeby Koala73 · Developer Tools
Live markets, conflicts, country risk, chokepoints, energy, and China decision signals. 93 tools.
Paperclip
Freeby Paperclipai · Developer Tools
Trending hip-hop artist momentum scores across four cultural dimensions.
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
