Available now MCP Server

Manage Microsoft 365
with plain English.

Intune IQ is an MCP server that connects Claude to your Microsoft 365 tenant. Query users, devices, groups, and licenses — no portal required.

Claude Desktop — Intune IQ
You › Which devices are out of compliance, and who owns them?

▸ intuneiq:list_noncompliant_devices — scanning tenant...

Found 12 devices out of compliance:

DESKTOP-4471X — sarah.chen@contoso.com · Windows 11 · Last sync 6 days ago
MacBook-AWolf — anna.wolf@contoso.com · macOS 14.4 · Last sync 11 days ago
iPhone-JLiu — james.liu@contoso.com · iOS 17.2 · Last sync 23 days ago
... and 9 more.

You › Retire james.liu's iPhone — he left the company.
Built on

Set up once.
Ask forever.

Three steps from zero to querying your live Microsoft 365 tenant from Claude Desktop.

01
🔑

Register an app in Azure

Create an Azure app registration with the Microsoft Graph permissions you need. Admin consent takes 60 seconds in the portal.

TENANT_ID=your-tenant-id
CLIENT_ID=your-app-id
CLIENT_SECRET=your-secret
02
🔌

Connect Intune IQ to Claude

Request early access below and we'll email you repository access plus the step-by-step setup guide — it covers the Azure app registration, environment setup, and the exact Claude Desktop config to add. Setup is currently documented for Windows; macOS is in unreleased beta testing.

03
💬

Ask about supported users, groups and devices

Intune IQ gives Claude 15 tools to query and manage your tenant. Ask in plain English — Claude picks the right tool automatically from that set.

› "Show me devices that are
  out of compliance"


› "Assign E5 license to
  sarah@contoso.com"

15 tools.
Everything you need.

Read-only tools for safe exploration. Write tools with confirmation prompts and local audit logging.

11 Read Tools
🔌
test_connection
Verify the Graph connection and confirm your tenant — run this first
🔍
find_users
Find users by display name — resolves partial names to a UPN
👤
get_user_details
Job title, department, account status, office, phone, country
📋
get_user_licenses
All assigned Microsoft 365 licenses for a user
👥
get_user_groups
Group and team memberships for any user
💻
list_user_devices
All Intune-managed devices registered to a user
🛡️
get_device_compliance
Compliance state, OS, encryption, model, and last sync time
⚠️
list_noncompliant_devices
Devices out of compliance, most recently synced first (up to 100)
🏷️
search_groups
Find Entra ID groups by name or description
👫
get_group_members
All members of a group or distribution list
📊
list_tenant_licenses
Org-wide license inventory — consumed vs available
4 Write Tools Pro
➕
add_group_member
Add a user to an Entra ID group or team — confirmation required
➖
remove_group_member
Remove a user from a group — confirmation required
📝
assign_license
Assign a Microsoft 365 license SKU to a user — confirmation required
🔒
retire_device
Retire an Intune-managed device — confirmation required
Example prompts
Which devices are out of compliance, and who owns them?
→ list_noncompliant_devices
How many E5 licenses have we purchased vs assigned?
→ list_tenant_licenses
Add everyone on the engineering team to the Azure DevOps group
→ get_group_members + add_group_member

Preview changes before execution.

Write tools return a preview by default. Review the target and action before Claude proceeds — Intune IQ shows what will happen, the confirmation step itself is Claude's.

4
Security layers on every write
Preview
Default response until confirm=True
Local
JSON-lines log for executed & previewed calls
60/min
Max calls per tenant (rate limit)
🔐

Confirmation Pattern

Write tools return a PREVIEW by default — no changes are made. Execution requires an explicit confirm=true argument; the AI client (Claude) handles requesting your approval before setting it.

📋

Audit Logging

Tool execution and previews are written to a local JSON-lines audit log with timestamp, tool name, parameters, tenant, and result (SUCCESS, PREVIEW, FAILED, or REJECTED). This log stays on your machine; Intune IQ does not receive it.

✅

Input Validation

All user-supplied values are validated before hitting Microsoft Graph. Invalid UPNs, malformed GUIDs, and empty fields are rejected at the boundary and logged as REJECTED.

⏱️

Rate Limiting

Sliding window rate limiter caps calls at 60 per minute per tenant. Exceeded limits are logged and rejected before any Graph API call is made. Free tier: 100 calls/day.


Simple, honest pricing.

Start free. Upgrade when you need write access.

Free
$0
/mo
For individuals exploring AI-powered IT management. No credit card required.
  • ✓ 11 read + diagnostic tools
  • ✓ 100 calls/day
  • ✓ 1 tenant
  • ✓ Claude Desktop + API access
  • — Write tools
  • — Priority support
Get started free
⚡ Early Access

Get early access.

Intune IQ is available now — install it locally and connect it to Claude Desktop. Payments are coming soon — email us and we'll reach out when billing is wired up.

Request early access by email
This opens your email app — send the message to reach us. We don't collect or store your email on this page.