Module f0_entra_mcp.server · 4 tools (all read-only) · server README
List Entra ID Protection risky users, newest first (requires Entra ID P2).
Defaults to state="active" — only users still at risk. Use state="all" to include dismissed/remediated/confirmed-safe users, which Entra retains indefinitely and which are usually already handled.
| Parameter | Type | Default |
|---|---|---|
limit |
integer |
25 |
state |
"active" | "all" |
"active" |
Used by skills: triage-incident-cross-platform, review-entra-identity-risk
List Entra ID Protection risk detections, newest first (requires Entra ID P2).
Defaults to state="active" — only detections still at risk. Use state="all" to include dismissed/remediated/confirmed-safe detections, which are usually already handled.
| Parameter | Type | Default |
|---|---|---|
limit |
integer |
25 |
state |
"active" | "all" |
"active" |
Used by skills: triage-incident-cross-platform, review-entra-identity-risk
List Conditional Access policies, flagging disabled and report-only ones.
No parameters.
Used by skills: audit-conditional-access
List directory role assignments, highlighting critical privileged roles.
Critical roles first; returns one bounded page with a "more available" note.
| Parameter | Type | Default |
|---|---|---|
limit |
integer |
25 |
Used by skills: review-privileged-access