Automated-BOD-25-01-CISA-Microsoft-Policies-MCP

Automated-BOD-25-01-CISA-Microsoft-Policies-MCP

3.2

If you are the rightful owner of Automated-BOD-25-01-CISA-Microsoft-Policies-MCP and would like to certify it and/or have it hosted online, please leave a comment on the right or send an email to henry@mcphub.com.

CISA M365 MCP Server is a Model Context Protocol server implementing CISA Binding Operational Directive 25-01 security controls for Microsoft 365.

The CISA M365 MCP Server is designed to help organizations manage and enforce security controls in Microsoft 365 environments, in line with the CISA Binding Operational Directive 25-01. It leverages the Microsoft Graph API to implement and monitor security policies, ensuring compliance with the directive. The server provides a comprehensive suite of tools for managing authentication, access controls, application permissions, and more. It supports detailed compliance reporting and integrates with existing security frameworks to enhance the security posture of Microsoft 365 deployments. The server is built with robust error handling, type-safe argument validation, and token-based authentication to ensure secure and reliable operations.

Features

  • Legacy authentication controls
  • Risk-based access controls
  • Multi-factor authentication management
  • Application registration and consent controls
  • Password policy management

Tools

  1. block_legacy_auth

    Block traditional authentication methods

  2. block_high_risk_users

    Block high-risk users

  3. enforce_phishing_resistant_mfa

    Enforce anti-fishing MFA

  4. configure_global_admins

    Configure global administrator role assignment

  5. get_policy_status

    Get the current status of all security policies