GraphPaaS for Claude · MCP server

Ask your
tenant.

Connect GraphPaaS to Claude and ask about licences, devices, identity and spend in plain language. Claude reads the data your dashboard shows, under the same permissions, and can tell you what changed since last week.

Connector URL

https://mcp.graphpaas.com/
  • Microsoft sign-in
  • Your dashboard's access, nothing more
  • Read-only towards Microsoft
Animated example: a question asked in Claude becomes a GraphPaaS tool call; the server checks your access, reads the latest snapshot and returns the rows Claude answers from.
Claude + GraphPaaS · demo tenant

Connect

Three steps, one minute

1

Add the connector

In Claude, open Settings → Connectors and choose Add custom connector. On Team and Enterprise an owner adds it once for the whole organisation.

2

Sign in with Microsoft

Claude opens a GraphPaaS approval page, then Microsoft's sign-in. Use the account you use for the dashboard. No account yet? Sign in to the dashboard once first, or ask your admin to invite you.

3

Ask

Turn GraphPaaS on in a chat's tools menu and ask in plain language — or start from one of the ready-made reviews in the same menu.

Add custom connector

Name

GraphPaaS

Remote MCP server URL

https://mcp.graphpaas.com/

↑ The root — no /mcp at the end

Advanced settings · OAuth Client ID / Secret

Leave empty — Claude registers itself

Claude Code and other clients

Clients that send a header can use an API key instead of signing in. Create one under Settings → Integrations (plans with API access); it is read-only and can be limited to some tenants.

claude mcp add --transport http graphpaas https://mcp.graphpaas.com/ --header "Authorization: Bearer gp_live_…"

Ask

The questions the admin centers make you click for

Every answer is a query over your rows, not a guess. On the right, what each question becomes.

“Which paid licences has nobody used in the last 90 days?”

get_metrics licence_waste · where last_activity < 90 days ago

“Who holds Global Administrator permanently, and who is only eligible?”

get_metrics pim · where role = "Global Administrator" · group_by kind

“Which devices turned non-compliant since last week?”

compare_snapshots devices · since 7 days ago · watch compliance_state

“What changed in our OAuth app consents this month?”

compare_snapshots oauth_apps · since the 1st

“Which SharePoint site uses the most storage, and what fills it?”

get_metrics → storage_folders sharepoint_sites · order_by -storage_gb, then the top site folder by folder

“Compare MFA coverage across all our tenants.”

get_metrics mfa_registration · tenant "all" · group_by mfa_registered

“How much did we spend on Azure per service?”

get_metrics bills · group_by service · aggregate sum:cost

“Which Copilot seats were never used?”

get_metrics copilot_usage · where last_activity = null

Or start from a ready-made review

Four reviews ship with the connector. In a chat, open + → GraphPaaS. Each one walks Claude through the right data in the right order and ends with something you can act on.

GraphPaaS · prompts
  • Licence savings review

    licence_review

    Unassigned seats, licences nobody used in 90 days, idle Copilot seats, cheaper plans that still fit and the renewals coming up — as a table of savings, biggest first.

  • Security posture review

    security_review

    MFA gaps, standing admin access, risky third-party apps, open risk detections, external mail forwarding and weak baseline settings — ranked by risk, each with its fix.

  • Device health review

    device_health

    Compliance, stale and unencrypted devices, the policy settings behind the failures and Windows 11 readiness — with the five fixes that matter most.

  • Executive summary

    executive_summary

    One page for management: licences, MFA, devices, Secure Score, service incidents and Azure spend — side by side when you run several tenants.

Tools

What Claude gets

Ten general tools instead of one per report, so the connector leaves room in Claude's context for your actual question.

list_tenants()

The tenants you can read, with when each last synced.

snapshot
list_domains()

The 91 metric domains: licences, identity, devices, storage, mail, Teams, spend.

snapshot
describe_domain(domain, tenant_id?)

A domain's columns and types, how many days of history are stored, and whether your tenant has it — or why not.

snapshot
get_metrics(domain, tenant_id?, where?, order_by?, group_by?, aggregate?, columns?, search?, date?, limit?, offset?)

Filters, sorts, counts and totals run on our side, so an answer is computed over every row — not guessed from a sample.

snapshot
compare_snapshots(domain, since, until?, tenant_id?, key?, watch?, limit?)

What changed between two syncs: rows added, removed and changed, field by field.

snapshot
storage_folders(site_id, folder_id?, onedrive?, tenant_id?, limit?)

A SharePoint site or a OneDrive, folder by folder, biggest first.

live
licence_advisor(tenant_id?, state?, window_days?, limit?, offset?)

For each licensed user, the cheapest plan in your own price list that still covers what they use, and the yearly saving.

snapshot
tenant_advisor(tenant_id?, area?, status?)

What to fix in a tenant, worst first: our checks with who and what is affected, then Microsoft's Secure Score actions with the points each adds. With "all", every tenant ranked side by side.

snapshot
hostinger(view, account_id?)

Hosting billing and spend over time, domains and VPS health, for organisations that connected Hostinger.

snapshot
sync_domain(domain, tenant_id?)

Refresh one domain now, like the dashboard's refresh button. Tenant admins only.

queues a sync

Security

An assistant, not a back door

How tenant isolation works end to end is on the engineering page.

01Same access as your dashboard

Claude reads as you: the same organisation and the same tenants your GraphPaaS user sees. Limited to three tenants in Team settings? So is Claude.

02Read-only towards Microsoft

Answers come from the snapshots GraphPaaS already collected. The one action — refreshing a domain — queues another read; nothing is ever written to your tenant.

03Asked, never guessed

With more than one tenant, Claude has to ask which one you mean. It cannot quietly answer about the wrong customer.

04Your conversation stays with Claude

GraphPaaS only sees the tool calls Claude makes, and answers them. Sign-in tokens are encrypted at rest.

05Revoke at any time

Remove the connector in Claude, or delete the API key in GraphPaaS. Someone removed from your team loses access on their next call.

06Processed in the EU

The MCP server runs on the same EU infrastructure as the rest of GraphPaaS.

Good to know

Is the data live?

Answers come from the latest background sync, which runs every four hours, and Claude says when each answer was collected. Storage browsing reads Microsoft live, and a tenant admin can refresh a domain on demand.

Does it work outside claude.ai?

Yes. Any MCP client that speaks remote servers over HTTP can connect: with Microsoft sign-in where the client supports OAuth, or with a GraphPaaS API key sent as a bearer token.

What if my tenant lacks a licence for something?

Claude is told why — the licence, permission or setting that is missing — instead of being handed an empty table it might read as "all clear".