GraphPaaS for Claude · MCP server
Ask your
tenant.
Connect GraphPaaS to Claude and ask about licences, devices, identity and spend in plain language. Claude reads the data your dashboard shows, under the same permissions, and can tell you what changed since last week.
Connector URL
https://mcp.graphpaas.com/- Microsoft sign-in
- Your dashboard's access, nothing more
- Read-only towards Microsoft
Connect
Three steps, one minute
Add the connector
In Claude, open Settings → Connectors and choose Add custom connector. On Team and Enterprise an owner adds it once for the whole organisation.
Sign in with Microsoft
Claude opens a GraphPaaS approval page, then Microsoft's sign-in. Use the account you use for the dashboard. No account yet? Sign in to the dashboard once first, or ask your admin to invite you.
Ask
Turn GraphPaaS on in a chat's tools menu and ask in plain language — or start from one of the ready-made reviews in the same menu.
Add custom connector
Name
Remote MCP server URL
↑ The root — no /mcp at the end
Advanced settings · OAuth Client ID / Secret
Claude Code and other clients
Clients that send a header can use an API key instead of signing in. Create one under Settings → Integrations (plans with API access); it is read-only and can be limited to some tenants.
claude mcp add --transport http graphpaas https://mcp.graphpaas.com/ --header "Authorization: Bearer gp_live_…"Ask
The questions the admin centers make you click for
Every answer is a query over your rows, not a guess. On the right, what each question becomes.
“Which paid licences has nobody used in the last 90 days?”
get_metrics licence_waste · where last_activity < 90 days ago
“Who holds Global Administrator permanently, and who is only eligible?”
get_metrics pim · where role = "Global Administrator" · group_by kind
“Which devices turned non-compliant since last week?”
compare_snapshots devices · since 7 days ago · watch compliance_state
“What changed in our OAuth app consents this month?”
compare_snapshots oauth_apps · since the 1st
“Which SharePoint site uses the most storage, and what fills it?”
get_metrics → storage_folders sharepoint_sites · order_by -storage_gb, then the top site folder by folder
“Compare MFA coverage across all our tenants.”
get_metrics mfa_registration · tenant "all" · group_by mfa_registered
“How much did we spend on Azure per service?”
get_metrics bills · group_by service · aggregate sum:cost
“Which Copilot seats were never used?”
get_metrics copilot_usage · where last_activity = null
Or start from a ready-made review
Four reviews ship with the connector. In a chat, open + → GraphPaaS. Each one walks Claude through the right data in the right order and ends with something you can act on.
Licence savings review
licence_reviewUnassigned seats, licences nobody used in 90 days, idle Copilot seats, cheaper plans that still fit and the renewals coming up — as a table of savings, biggest first.
Security posture review
security_reviewMFA gaps, standing admin access, risky third-party apps, open risk detections, external mail forwarding and weak baseline settings — ranked by risk, each with its fix.
Device health review
device_healthCompliance, stale and unencrypted devices, the policy settings behind the failures and Windows 11 readiness — with the five fixes that matter most.
Executive summary
executive_summaryOne page for management: licences, MFA, devices, Secure Score, service incidents and Azure spend — side by side when you run several tenants.
Tools
What Claude gets
Ten general tools instead of one per report, so the connector leaves room in Claude's context for your actual question.
list_tenants()The tenants you can read, with when each last synced.
snapshotlist_domains()The 91 metric domains: licences, identity, devices, storage, mail, Teams, spend.
snapshotdescribe_domain(domain, tenant_id?)A domain's columns and types, how many days of history are stored, and whether your tenant has it — or why not.
snapshotget_metrics(domain, tenant_id?, where?, order_by?, group_by?, aggregate?, columns?, search?, date?, limit?, offset?)Filters, sorts, counts and totals run on our side, so an answer is computed over every row — not guessed from a sample.
snapshotcompare_snapshots(domain, since, until?, tenant_id?, key?, watch?, limit?)What changed between two syncs: rows added, removed and changed, field by field.
snapshotstorage_folders(site_id, folder_id?, onedrive?, tenant_id?, limit?)A SharePoint site or a OneDrive, folder by folder, biggest first.
livelicence_advisor(tenant_id?, state?, window_days?, limit?, offset?)For each licensed user, the cheapest plan in your own price list that still covers what they use, and the yearly saving.
snapshottenant_advisor(tenant_id?, area?, status?)What to fix in a tenant, worst first: our checks with who and what is affected, then Microsoft's Secure Score actions with the points each adds. With "all", every tenant ranked side by side.
snapshothostinger(view, account_id?)Hosting billing and spend over time, domains and VPS health, for organisations that connected Hostinger.
snapshotsync_domain(domain, tenant_id?)Refresh one domain now, like the dashboard's refresh button. Tenant admins only.
queues a syncSecurity
An assistant, not a back door
How tenant isolation works end to end is on the engineering page.
01Same access as your dashboard
Claude reads as you: the same organisation and the same tenants your GraphPaaS user sees. Limited to three tenants in Team settings? So is Claude.
02Read-only towards Microsoft
Answers come from the snapshots GraphPaaS already collected. The one action — refreshing a domain — queues another read; nothing is ever written to your tenant.
03Asked, never guessed
With more than one tenant, Claude has to ask which one you mean. It cannot quietly answer about the wrong customer.
04Your conversation stays with Claude
GraphPaaS only sees the tool calls Claude makes, and answers them. Sign-in tokens are encrypted at rest.
05Revoke at any time
Remove the connector in Claude, or delete the API key in GraphPaaS. Someone removed from your team loses access on their next call.
06Processed in the EU
The MCP server runs on the same EU infrastructure as the rest of GraphPaaS.
Good to know
Is the data live?
Answers come from the latest background sync, which runs every four hours, and Claude says when each answer was collected. Storage browsing reads Microsoft live, and a tenant admin can refresh a domain on demand.
Does it work outside claude.ai?
Yes. Any MCP client that speaks remote servers over HTTP can connect: with Microsoft sign-in where the client supports OAuth, or with a GraphPaaS API key sent as a bearer token.
What if my tenant lacks a licence for something?
Claude is told why — the licence, permission or setting that is missing — instead of being handed an empty table it might read as "all clear".