MCP server for CIPP — M365 multi-tenant management for MSPs (users, tenants, policies).
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
cipp_list_tenantsNo description publishedThis tool published no description. Forge does not invent one.
cipp_get_tenant_detailsNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_usersNo description publishedThis tool published no description. Forge does not invent one.
cipp_create_userNo description publishedThis tool published no description. Forge does not invent one.
cipp_edit_userNo description publishedThis tool published no description. Forge does not invent one.
cipp_disable_userNo description publishedThis tool published no description. Forge does not invent one.
cipp_reset_passwordNo description publishedThis tool published no description. Forge does not invent one.
cipp_reset_mfaNo description publishedThis tool published no description. Forge does not invent one.
cipp_revoke_sessionsNo description publishedThis tool published no description. Forge does not invent one.
cipp_offboard_userNo description publishedThis tool published no description. Forge does not invent one.
cipp_bec_checkNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_mfa_usersNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_user_devicesNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_user_groupsNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_groupsNo description publishedThis tool published no description. Forge does not invent one.
cipp_create_groupNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_mailboxesNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_mailbox_permissionsNo description publishedThis tool published no description. Forge does not invent one.
cipp_set_out_of_officeNo description publishedThis tool published no description. Forge does not invent one.
cipp_set_email_forwardingNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_conditional_access_policiesNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_named_locationsNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_standardsNo description publishedThis tool published no description. Forge does not invent one.
cipp_run_standards_checkNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_standard_templatesNo description publishedThis tool published no description. Forge does not invent one.
cipp_get_tenant_driftNo description publishedThis tool published no description. Forge does not invent one.
cipp_get_tenant_alignmentNo description publishedThis tool published no description. Forge does not invent one.
cipp_create_standard_templateNo description publishedThis tool published no description. Forge does not invent one.
cipp_delete_standard_templateprivilegedNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_bpaNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_domain_healthNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_licensesNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_csp_licensesNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_audit_logsNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_alert_queueNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_gdap_rolesNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_gdap_invitesNo description publishedThis tool published no description. Forge does not invent one.
cipp_list_scheduled_itemsNo description publishedThis tool published no description. Forge does not invent one.
cipp_add_scheduled_itemNo description publishedThis tool published no description. Forge does not invent one.
cipp_pingNo description publishedThis tool published no description. Forge does not invent one.
0 of 40 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
MCP server for CIPP — M365 multi-tenant management for MSPs (users, tenants, policies).
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.