Bod 25 01 Csa Microsoft Policy MCP
This project is a Microsoft 365 security configuration management server that implements the security control requirements of CISA BOD 25-01. It provides security functions such as identity authentication management, multi-factor authentication, and application control through the Microsoft Graph API.
rating : 2 points
downloads : 7.5K
What is the CISA M365 MCP Server?
This is a Model Context Protocol (MCP) server specifically designed for Microsoft 365. It automates the implementation of the security control requirements in the BOD 25-01 directive issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The server integrates with your Microsoft 365 tenant through the Microsoft Graph API, helping you easily configure and manage security settings.How to use the CISA M365 MCP Server?
You can interact with the server through simple JSON commands, and it will automatically perform complex security configuration tasks. The server provides a variety of preset tools, such as blocking legacy authentication, configuring multi-factor authentication (MFA), and managing privileged roles.Use cases
It is particularly suitable for U.S. government agencies and contractors that need to comply with CISA security requirements, as well as any organization that values the security configuration of Microsoft 365. IT administrators can use it to quickly check the compliance status and fix non-compliant items.Main features
Legacy authentication control
Automatically disable insecure legacy authentication protocols to reduce the attack surface
Risk-based access control
Automatically block high-risk accounts based on the user's risk level
MFA management
Configure anti-phishing multi-factor authentication methods and policies
Application control
Restrict the application registration and consent process to prevent malicious applications
Privileged role management
Manage privileged roles such as global administrators and implement the principle of least privilege
Compliance reporting
Generate detailed compliance status reports showing the implementation of each control
Advantages
Automatically implement complex security controls, saving administrators' time
Preset CISA compliance configurations to reduce the risk of configuration errors
Centrally manage all key security settings
Provide clear compliance status reports
Deeply integrate with the Microsoft Graph API
Limitations
Requires Microsoft 365 administrator permissions
Only supports controls related to CISA BOD 25-01
Some advanced customizations may require direct use of the Graph API
How to use
Install the server
Install the server through the Smithery platform or manually
Configure the Azure AD application
Create an application in the Azure portal and grant the necessary API permissions
Set environment variables
Configure the tenant ID, client ID, and client secret
Start the server
Build and start the MCP server
Usage examples
Quick compliance check
A new administrator needs to quickly understand the CISA compliance status of the current tenant
Emergency security fix
It is found that legacy authentication protocols are still allowed and need to be disabled immediately
Privileged role management
It is necessary to reduce the number of global administrators and configure an approval process
Frequently asked questions
Is this server an official CISA product?
What permissions are required to use this server?
Which settings will the server modify?
How to roll back changes?
Which Microsoft 365 versions are supported?
Related resources
Official CISA BOD 25-01 documentation
The original directive document issued by CISA
Microsoft Graph API documentation
Official documentation for the Microsoft Graph API
GitHub repository
Project source code
Smithery installation guide
Guide for installing through the Smithery platform

Gitlab MCP Server
Certified
The GitLab MCP server is a project based on the Model Context Protocol that provides a comprehensive toolset for interacting with GitLab accounts, including code review, merge request management, CI/CD configuration, and other functions.
TypeScript
16.6K
4.3 points

Notion Api MCP
Certified
A Python-based MCP Server that provides advanced to-do list management and content organization functions through the Notion API, enabling seamless integration between AI models and Notion.
Python
14.8K
4.5 points

Markdownify MCP
Markdownify is a multi-functional file conversion service that supports converting multiple formats such as PDFs, images, audio, and web page content into Markdown format.
TypeScript
23.5K
5 points

Duckduckgo MCP Server
Certified
The DuckDuckGo Search MCP Server provides web search and content scraping services for LLMs such as Claude.
Python
44.9K
4.3 points

Figma Context MCP
Framelink Figma MCP Server is a server that provides access to Figma design data for AI programming tools (such as Cursor). By simplifying the Figma API response, it helps AI more accurately achieve one - click conversion from design to code.
TypeScript
45.4K
4.5 points

Unity
Certified
UnityMCP is a Unity editor plugin that implements the Model Context Protocol (MCP), providing seamless integration between Unity and AI assistants, including real - time state monitoring, remote command execution, and log functions.
C#
20.2K
5 points

Gmail MCP Server
A Gmail automatic authentication MCP server designed for Claude Desktop, supporting Gmail management through natural language interaction, including complete functions such as sending emails, label management, and batch operations.
TypeScript
14.8K
4.5 points

Minimax MCP Server
The MiniMax Model Context Protocol (MCP) is an official server that supports interaction with powerful text-to-speech, video/image generation APIs, and is suitable for various client tools such as Claude Desktop and Cursor.
Python
29.3K
4.8 points




