MCP server for CIPP — M365 multi-tenant management for MSPs (users, tenants, policies).
CIPP_CLIENT_SECRETOAuth apprequiredEntra ID client secret for the CIPP application
Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
cipp_list_tenantsList all tenants managed in CIPPList all tenants managed in CIPP
No input schema was published for this tool.
cipp_get_tenant_detailsGet detailed information about a specific tenantGet detailed information about a specific tenant
No input schema was published for this tool.
cipp_list_usersList users in a tenantList users in a tenant
No input schema was published for this tool.
cipp_create_user⚠ HIGH-IMPACT. Creates a new user account in the tenant, which grants⚠ HIGH-IMPACT. Creates a new user account in the tenant, which grants
No input schema was published for this tool.
cipp_edit_userprivileged⚠ HIGH-IMPACT. Edits an existing user's properties, which can include⚠ HIGH-IMPACT. Edits an existing user's properties, which can include
No input schema was published for this tool.
cipp_disable_user⚠ HIGH-IMPACT. Disables a user account, blocking sign-in. Reversible by⚠ HIGH-IMPACT. Disables a user account, blocking sign-in. Reversible by
No input schema was published for this tool.
cipp_reset_password⚠ HIGH-IMPACT. Resets a user's password, invalidating their current⚠ HIGH-IMPACT. Resets a user's password, invalidating their current
No input schema was published for this tool.
cipp_reset_mfa⚠ HIGH-IMPACT. Resets all MFA methods for a user, requiring them to⚠ HIGH-IMPACT. Resets all MFA methods for a user, requiring them to
No input schema was published for this tool.
cipp_revoke_sessions⚠ HIGH-IMPACT. Revokes all active sessions for a user, forcing them to⚠ HIGH-IMPACT. Revokes all active sessions for a user, forcing them to
No input schema was published for this tool.
cipp_offboard_user⚠ DESTRUCTIVE — IRREVERSIBLE. Queues CIPP's offboarding job for a user.⚠ DESTRUCTIVE — IRREVERSIBLE. Queues CIPP's offboarding job for a user.
No input schema was published for this tool.
cipp_bec_checkRun a Business Email Compromise check on a userRun a Business Email Compromise check on a user
No input schema was published for this tool.
cipp_list_mfa_usersList users and their MFA status in a tenantList users and their MFA status in a tenant
No input schema was published for this tool.
cipp_list_user_devicesList devices enrolled by a userList devices enrolled by a user
No input schema was published for this tool.
cipp_list_user_groupsList groups a user is a member ofList groups a user is a member of
No input schema was published for this tool.
cipp_list_groupsList groups in a tenantList groups in a tenant
No input schema was published for this tool.
cipp_create_group⚠ HIGH-IMPACT. Creates a new group in the tenant, which can be used for⚠ HIGH-IMPACT. Creates a new group in the tenant, which can be used for
No input schema was published for this tool.
cipp_list_mailboxesList mailboxes in a tenantList mailboxes in a tenant
No input schema was published for this tool.
cipp_list_mailbox_permissionsList permissions on a specific mailboxList permissions on a specific mailbox
No input schema was published for this tool.
cipp_list_mailbox_usageReport mailbox and online-archive sizes across a tenant, largest first, withReport mailbox and online-archive sizes across a tenant, largest first, with
No input schema was published for this tool.
cipp_get_mailbox_usageReport the primary mailbox size and online-archive size for a single mailbox, withReport the primary mailbox size and online-archive size for a single mailbox, with
No input schema was published for this tool.
cipp_set_out_of_office⚠ HIGH-IMPACT. Configures the out-of-office / auto-reply for a mailbox,⚠ HIGH-IMPACT. Configures the out-of-office / auto-reply for a mailbox,
No input schema was published for this tool.
cipp_set_email_forwarding⚠ HIGH-IMPACT. Configures email forwarding on a mailbox, silently⚠ HIGH-IMPACT. Configures email forwarding on a mailbox, silently
No input schema was published for this tool.
cipp_list_conditional_access_policiesList Conditional Access policies for a tenantList Conditional Access policies for a tenant
No input schema was published for this tool.
cipp_list_named_locationsList named locations (trusted IPs) for a tenantList named locations (trusted IPs) for a tenant
No input schema was published for this tool.
cipp_list_enterprise_appsNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_standardsList compliance standards configured for a tenantList compliance standards configured for a tenant
No input schema was published for this tool.
cipp_run_standards_checkTrigger a standards compliance check for a tenantTrigger a standards compliance check for a tenant
No input schema was published for this tool.
cipp_list_standard_templatesList the CIPP Standards Templates configured across the partner tenant.List the CIPP Standards Templates configured across the partner tenant.
No input schema was published for this tool.
cipp_get_tenant_driftReport standards drift — settings that deviate from a tenant's assignedReport standards drift — settings that deviate from a tenant's assigned
No input schema was published for this tool.
cipp_get_tenant_alignmentReport each tenant's alignment percentage against its assigned StandardsReport each tenant's alignment percentage against its assigned Standards
No input schema was published for this tool.
cipp_create_standard_template⚠ HIGH-IMPACT. Creates or updates a CIPP Standards Template (upsert by⚠ HIGH-IMPACT. Creates or updates a CIPP Standards Template (upsert by
No input schema was published for this tool.
cipp_delete_standard_templateprivileged⚠ HIGH-IMPACT. Permanently deletes a CIPP Standards Template by ID.⚠ HIGH-IMPACT. Permanently deletes a CIPP Standards Template by ID.
No input schema was published for this tool.
cipp_list_bpaGet Best Practice Analyser results for a tenantGet Best Practice Analyser results for a tenant
No input schema was published for this tool.
cipp_list_domain_healthCheck domain health (DMARC, DKIM, SPF) for a tenantCheck domain health (DMARC, DKIM, SPF) for a tenant
No input schema was published for this tool.
cipp_list_licensesList license assignments and usage for a tenantList license assignments and usage for a tenant
No input schema was published for this tool.
cipp_list_csp_licensesList all CSP licenses across tenantsList all CSP licenses across tenants
No input schema was published for this tool.
cipp_list_audit_logsList audit log entries for a tenantList audit log entries for a tenant
No input schema was published for this tool.
cipp_list_alert_queueList queued alerts across all tenantsList queued alerts across all tenants
No input schema was published for this tool.
cipp_list_gdap_rolesList available GDAP (Granular Delegated Admin Privileges) rolesList available GDAP (Granular Delegated Admin Privileges) roles
No input schema was published for this tool.
cipp_list_gdap_invitesList pending GDAP relationship invitesList pending GDAP relationship invites
No input schema was published for this tool.
39 of 40 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
MCP server for CIPP — M365 multi-tenant management for MSPs (users, tenants, policies).
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.