Bod 25 01 Csa Microsoft Policy MCP
This project is a Microsoft 365 security configuration management server that implements the security control requirements of CISA BOD 25-01. It provides security functions such as identity authentication management, multi-factor authentication, and application control through the Microsoft Graph API.
rating : 2 points
downloads : 7
What is the CISA M365 MCP Server?
This is a Model Context Protocol (MCP) server specifically designed for Microsoft 365. It automates the implementation of the security control requirements in the BOD 25-01 directive issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The server integrates with your Microsoft 365 tenant through the Microsoft Graph API, helping you easily configure and manage security settings.How to use the CISA M365 MCP Server?
You can interact with the server through simple JSON commands, and it will automatically perform complex security configuration tasks. The server provides a variety of preset tools, such as blocking legacy authentication, configuring multi-factor authentication (MFA), and managing privileged roles.Use cases
It is particularly suitable for U.S. government agencies and contractors that need to comply with CISA security requirements, as well as any organization that values the security configuration of Microsoft 365. IT administrators can use it to quickly check the compliance status and fix non-compliant items.Main features
Legacy authentication controlAutomatically disable insecure legacy authentication protocols to reduce the attack surface
Risk-based access controlAutomatically block high-risk accounts based on the user's risk level
MFA managementConfigure anti-phishing multi-factor authentication methods and policies
Application controlRestrict the application registration and consent process to prevent malicious applications
Privileged role managementManage privileged roles such as global administrators and implement the principle of least privilege
Compliance reportingGenerate detailed compliance status reports showing the implementation of each control
Advantages and limitations
Advantages
Automatically implement complex security controls, saving administrators' time
Preset CISA compliance configurations to reduce the risk of configuration errors
Centrally manage all key security settings
Provide clear compliance status reports
Deeply integrate with the Microsoft Graph API
Limitations
Requires Microsoft 365 administrator permissions
Only supports controls related to CISA BOD 25-01
Some advanced customizations may require direct use of the Graph API
How to use
Install the server
Install the server through the Smithery platform or manually
Configure the Azure AD application
Create an application in the Azure portal and grant the necessary API permissions
Set environment variables
Configure the tenant ID, client ID, and client secret
Start the server
Build and start the MCP server
Usage examples
Quick compliance checkA new administrator needs to quickly understand the CISA compliance status of the current tenant
Emergency security fixIt is found that legacy authentication protocols are still allowed and need to be disabled immediately
Privileged role managementIt is necessary to reduce the number of global administrators and configure an approval process
Frequently asked questions
Is this server an official CISA product?
What permissions are required to use this server?
Which settings will the server modify?
How to roll back changes?
Which Microsoft 365 versions are supported?
Related resources
Official CISA BOD 25-01 documentation
The original directive document issued by CISA
Microsoft Graph API documentation
Official documentation for the Microsoft Graph API
GitHub repository
Project source code
Smithery installation guide
Guide for installing through the Smithery platform
Featured MCP Services

Duckduckgo MCP Server
Certified
The DuckDuckGo Search MCP Server provides web search and content scraping services for LLMs such as Claude.
Python
831
4.3 points

Markdownify MCP
Markdownify is a multi-functional file conversion service that supports converting multiple formats such as PDFs, images, audio, and web page content into Markdown format.
TypeScript
1.7K
5 points

Notion Api MCP
Certified
A Python-based MCP Server that provides advanced to-do list management and content organization functions through the Notion API, enabling seamless integration between AI models and Notion.
Python
144
4.5 points

Gitlab MCP Server
Certified
The GitLab MCP server is a project based on the Model Context Protocol that provides a comprehensive toolset for interacting with GitLab accounts, including code review, merge request management, CI/CD configuration, and other functions.
TypeScript
89
4.3 points

Figma Context MCP
Framelink Figma MCP Server is a server that provides access to Figma design data for AI programming tools (such as Cursor). By simplifying the Figma API response, it helps AI more accurately achieve one - click conversion from design to code.
TypeScript
6.7K
4.5 points

Unity
Certified
UnityMCP is a Unity editor plugin that implements the Model Context Protocol (MCP), providing seamless integration between Unity and AI assistants, including real - time state monitoring, remote command execution, and log functions.
C#
568
5 points

Context7
Context7 MCP is a service that provides real-time, version-specific documentation and code examples for AI programming assistants. It is directly integrated into prompts through the Model Context Protocol to solve the problem of LLMs using outdated information.
TypeScript
5.2K
4.7 points

Gmail MCP Server
A Gmail automatic authentication MCP server designed for Claude Desktop, supporting Gmail management through natural language interaction, including complete functions such as sending emails, label management, and batch operations.
TypeScript
285
4.5 points