API-aware MCP server for Microsoft Graph. For Entra ID, users, groups, Cloud PCs, Intune, or any M365 tenant data, use the GraphMind MCP tools automatically — do not guess API paths from training data.
search_graph_api— natural language query firstget_endpoint_schema— if parameters are unclearcall_graph_api— execute the chosen endpoint
Never call Graph without searching the local index first.
POST, PATCH, PUT, and DELETE (reboot, delete, assign, etc.) require confirmation:
- Call
call_graph_apiwithoutconfirmed→ returns a preview - Show the preview to the user and ask for approval
- Re-call with
confirmed: trueonly if they approve
GRAPHMIND_READ_ONLY=true blocks all writes regardless.
- Counts:
GET /users/$count(single request) - Large lists:
paginate=true,aggregate=trueoncall_graph_api - Use
$select,$filter,$topinquery_params
- Many APIs are beta-only — GraphMind auto-selects
api_version=betafor Cloud PC / snapshot queries - Restore points:
GET .../cloudPCs/{id}/retrieveSnapshots()— not the tenant/snapshotscollection - OData functions use a
()suffix in the URL
api_version:v1.0unless beta is needed (Cloud PC / snapshots auto-upgrade)filter_by_permissions:true- Auth via
.env(app-only or interactive)
See .cursor/rules/graphmind-mcp.mdc for examples and edge cases.
Say so explicitly. Do not fabricate Graph API responses or endpoint paths.