B

Bod 25 01 Csa Microsoft Policy MCP

This project is a Microsoft 365 security configuration management server that implements the security control requirements of CISA BOD 25-01. It provides security functions such as identity authentication management, multi-factor authentication, and application control through the Microsoft Graph API.
2 points
7

What is the CISA M365 MCP Server?

This is a Model Context Protocol (MCP) server specifically designed for Microsoft 365. It automates the implementation of the security control requirements in the BOD 25-01 directive issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The server integrates with your Microsoft 365 tenant through the Microsoft Graph API, helping you easily configure and manage security settings.

How to use the CISA M365 MCP Server?

You can interact with the server through simple JSON commands, and it will automatically perform complex security configuration tasks. The server provides a variety of preset tools, such as blocking legacy authentication, configuring multi-factor authentication (MFA), and managing privileged roles.

Use cases

It is particularly suitable for U.S. government agencies and contractors that need to comply with CISA security requirements, as well as any organization that values the security configuration of Microsoft 365. IT administrators can use it to quickly check the compliance status and fix non-compliant items.

Main features

Legacy authentication controlAutomatically disable insecure legacy authentication protocols to reduce the attack surface
Risk-based access controlAutomatically block high-risk accounts based on the user's risk level
MFA managementConfigure anti-phishing multi-factor authentication methods and policies
Application controlRestrict the application registration and consent process to prevent malicious applications
Privileged role managementManage privileged roles such as global administrators and implement the principle of least privilege
Compliance reportingGenerate detailed compliance status reports showing the implementation of each control

Advantages and limitations

Advantages
Automatically implement complex security controls, saving administrators' time
Preset CISA compliance configurations to reduce the risk of configuration errors
Centrally manage all key security settings
Provide clear compliance status reports
Deeply integrate with the Microsoft Graph API
Limitations
Requires Microsoft 365 administrator permissions
Only supports controls related to CISA BOD 25-01
Some advanced customizations may require direct use of the Graph API

How to use

Install the server
Install the server through the Smithery platform or manually
Configure the Azure AD application
Create an application in the Azure portal and grant the necessary API permissions
Set environment variables
Configure the tenant ID, client ID, and client secret
Start the server
Build and start the MCP server

Usage examples

Quick compliance checkA new administrator needs to quickly understand the CISA compliance status of the current tenant
Emergency security fixIt is found that legacy authentication protocols are still allowed and need to be disabled immediately
Privileged role managementIt is necessary to reduce the number of global administrators and configure an approval process

Frequently asked questions

Is this server an official CISA product?
What permissions are required to use this server?
Which settings will the server modify?
How to roll back changes?
Which Microsoft 365 versions are supported?

Related resources

Official CISA BOD 25-01 documentation
The original directive document issued by CISA
Microsoft Graph API documentation
Official documentation for the Microsoft Graph API
GitHub repository
Project source code
Smithery installation guide
Guide for installing through the Smithery platform
Installation
Copy the following command to your Client for configuration
{
  "mcpServers": {
    "cisa-m365": {
      "command": "node",
      "args": ["path/to/cisa-m365/build/index.js"],
      "env": {
        "TENANT_ID": "your-tenant-id",
        "CLIENT_ID": "your-client-id",
        "CLIENT_SECRET": "your-client-secret"
      }
    }
  }
}
Note: Your key is sensitive information, do not share it with anyone.
Featured MCP Services
D
Duckduckgo MCP Server
Certified
The DuckDuckGo Search MCP Server provides web search and content scraping services for LLMs such as Claude.
Python
831
4.3 points
M
Markdownify MCP
Markdownify is a multi-functional file conversion service that supports converting multiple formats such as PDFs, images, audio, and web page content into Markdown format.
TypeScript
1.7K
5 points
N
Notion Api MCP
Certified
A Python-based MCP Server that provides advanced to-do list management and content organization functions through the Notion API, enabling seamless integration between AI models and Notion.
Python
144
4.5 points
G
Gitlab MCP Server
Certified
The GitLab MCP server is a project based on the Model Context Protocol that provides a comprehensive toolset for interacting with GitLab accounts, including code review, merge request management, CI/CD configuration, and other functions.
TypeScript
89
4.3 points
F
Figma Context MCP
Framelink Figma MCP Server is a server that provides access to Figma design data for AI programming tools (such as Cursor). By simplifying the Figma API response, it helps AI more accurately achieve one - click conversion from design to code.
TypeScript
6.7K
4.5 points
U
Unity
Certified
UnityMCP is a Unity editor plugin that implements the Model Context Protocol (MCP), providing seamless integration between Unity and AI assistants, including real - time state monitoring, remote command execution, and log functions.
C#
568
5 points
C
Context7
Context7 MCP is a service that provides real-time, version-specific documentation and code examples for AI programming assistants. It is directly integrated into prompts through the Model Context Protocol to solve the problem of LLMs using outdated information.
TypeScript
5.2K
4.7 points
G
Gmail MCP Server
A Gmail automatic authentication MCP server designed for Claude Desktop, supporting Gmail management through natural language interaction, including complete functions such as sending emails, label management, and batch operations.
TypeScript
285
4.5 points
AIbase
Zhiqi Future, Your AI Solution Think Tank
© 2025AIbase