C

Cisa M365

This project is an M365 MCP server that implements the CISA BOD 25 - 01 security controls. It manages Microsoft 365 security settings through the Microsoft Graph API and provides functions such as blocking legacy authentication, risk - based access control, MFA management, application registration control, and password policy management.
2.5 points
17

What is the CISA M365 MCP Server?

The CISA M365 MCP Server is a tool designed for enterprises to enhance the security of Microsoft 365 according to the BOD 25 - 01 standard issued by CISA. It integrates the Microsoft Graph API to enforce security policies, monitor compliance, and generate detailed reports.

How to use the CISA M365 MCP Server?

First, you need to configure your Azure AD application and ensure you have administrator privileges. Then, enable or disable specific security controls by calling the corresponding API endpoints. For example, you can block legacy authentication or enforce multi - factor authentication.

Use cases

This server is particularly suitable for enterprises that want to improve the security of their Microsoft 365 platform, follow industry best practices, and meet regulatory requirements. It can help enterprises reduce the attack surface and protect sensitive data.

Main features

Block legacy authenticationThis feature can turn off legacy authentication protocols, thereby reducing potential threats.
Risk - based access controlThis feature allows the system to automatically detect high - risk users and block them from logging in.
Multi - factor authentication managementSupports multiple authentication methods, including risk - based MFA.
Application registration and consent controlRestricts who can register new applications and grant application permissions.
Password policy managementAdjusts password complexity rules, such as disabling password expiration.
Privileged role managementLimits the number of global administrators and enforces fine - grained role assignments.

Advantages and limitations

Advantages
Improve the overall security level
Simplify the complex configuration process
Provide comprehensive compliance reports
Limitations
Requires a certain technical background to fully utilize all features
Some advanced features may involve additional costs

How to use

Install the server
Download and set up the CISA M365 MCP Server according to the installation guide.
Configure environment variables
Edit the.env file and add your Azure AD credentials.
Call the API
Use a client tool to call the required API endpoints to perform security controls.

Usage examples

Block legacy authenticationCall this API to prevent any access attempts that rely on legacy authentication protocols.
Enforce multi - factor authenticationEnable more secure authentication mechanisms, such as Windows Hello or FIDO2.

Frequently Asked Questions

How to start using the CISA M365 MCP Server?
Is it necessary to pay to use this server?

Related resources

Official documentation
A detailed operating manual for in - depth understanding of the CISA M365 MCP Server.
GitHub repository
View the source code and contribute.
Installation
Copy the following command to your Client for configuration
{
  "mcpServers": {
    "cisa-m365": {
      "command": "node",
      "args": ["path/to/cisa-m365/build/index.js"],
      "env": {
        "TENANT_ID": "your-tenant-id",
        "CLIENT_ID": "your-client-id",
        "CLIENT_SECRET": "your-client-secret"
      }
    }
  }
}
Note: Your key is sensitive information, do not share it with anyone.
Featured MCP Services
G
Gitlab MCP Server
Certified
The GitLab MCP server is a project based on the Model Context Protocol that provides a comprehensive toolset for interacting with GitLab accounts, including code review, merge request management, CI/CD configuration, and other functions.
TypeScript
85
4.3 points
N
Notion Api MCP
Certified
A Python-based MCP Server that provides advanced to-do list management and content organization functions through the Notion API, enabling seamless integration between AI models and Notion.
Python
140
4.5 points
M
Markdownify MCP
Markdownify is a multi-functional file conversion service that supports converting multiple formats such as PDFs, images, audio, and web page content into Markdown format.
TypeScript
1.7K
5 points
D
Duckduckgo MCP Server
Certified
The DuckDuckGo Search MCP Server provides web search and content scraping services for LLMs such as Claude.
Python
829
4.3 points
F
Figma Context MCP
Framelink Figma MCP Server is a server that provides access to Figma design data for AI programming tools (such as Cursor). By simplifying the Figma API response, it helps AI more accurately achieve one - click conversion from design to code.
TypeScript
6.7K
4.5 points
U
Unity
Certified
UnityMCP is a Unity editor plugin that implements the Model Context Protocol (MCP), providing seamless integration between Unity and AI assistants, including real - time state monitoring, remote command execution, and log functions.
C#
564
5 points
G
Gmail MCP Server
A Gmail automatic authentication MCP server designed for Claude Desktop, supporting Gmail management through natural language interaction, including complete functions such as sending emails, label management, and batch operations.
TypeScript
282
4.5 points
M
Minimax MCP Server
The MiniMax Model Context Protocol (MCP) is an official server that supports interaction with powerful text-to-speech, video/image generation APIs, and is suitable for various client tools such as Claude Desktop and Cursor.
Python
753
4.8 points
AIbase
Zhiqi Future, Your AI Solution Think Tank
© 2025AIbase