PluginBench
MCP Server
Active
MIT

Microsoft Entra SCIM MCP Server

io.github.darrenjrobinson/entra-scim-mcp

What is the Microsoft Entra SCIM MCP server?

Microsoft Entra SCIM 2.0 Provisioning API: user and group lifecycle, with a local mock.

How to install Microsoft Entra SCIM

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • ENTRA_TENANT_ID

    Directory (tenant) GUID. Required to authenticate against a live tenant; not needed for ENTRA_SCIM_DRY_RUN or ENTRA_SCIM_STATIC_TOKEN, which supply their own placeholder.

  • ENTRA_CLIENT_ID

    App registration (client) GUID. Required to authenticate against a live tenant; not needed for ENTRA_SCIM_DRY_RUN or ENTRA_SCIM_STATIC_TOKEN.

  • ENTRA_CLIENT_SECRET
    secret

    Client secret value. For a live tenant set exactly one of ENTRA_CLIENT_SECRET or ENTRA_CLIENT_CERT_PATH; a certificate is preferred for anything long-lived.

  • ENTRA_CLIENT_CERT_PATH

    Path to a PEM holding the certificate and its private key. Set exactly one of ENTRA_CLIENT_SECRET or ENTRA_CLIENT_CERT_PATH.

  • ENTRA_CLIENT_CERT_PASSWORD
    secret

    Password for the PEM, if it is encrypted.

  • ENTRA_SCIM_BASE_URL

    Override the SCIM base URL (default https://graph.microsoft.com/rp/scim). Point it at the bundled mock to try the tools without a tenant.

  • ENTRA_SCIM_STATIC_TOKEN
    secret

    Use a fixed bearer token instead of Azure AD. Refuses any microsoft.com/microsoft.us host and requires ENTRA_SCIM_BASE_URL; intended for the local mock only.

  • ENTRA_SCIM_DRY_RUN

    Set to 1 to run every client-side validation and return the request that would have been sent, without sending it or acquiring a token.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "entra-scim-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "entra-scim-mcp"
      ],
      "env": {
        "ENTRA_TENANT_ID": "<YOUR_ENTRA_TENANT_ID>",
        "ENTRA_CLIENT_ID": "<YOUR_ENTRA_CLIENT_ID>",
        "ENTRA_CLIENT_SECRET": "<YOUR_ENTRA_CLIENT_SECRET>",
        "ENTRA_CLIENT_CERT_PATH": "<YOUR_ENTRA_CLIENT_CERT_PATH>",
        "ENTRA_CLIENT_CERT_PASSWORD": "<YOUR_ENTRA_CLIENT_CERT_PASSWORD>",
        "ENTRA_SCIM_BASE_URL": "<YOUR_ENTRA_SCIM_BASE_URL>",
        "ENTRA_SCIM_STATIC_TOKEN": "<YOUR_ENTRA_SCIM_STATIC_TOKEN>",
        "ENTRA_SCIM_DRY_RUN": "<YOUR_ENTRA_SCIM_DRY_RUN>"
      }
    }
  }
}

Related MCP servers

Interactive Entra ID identity relationship visualization — the 2003 polyarchy, live as an MCP App

0
JavaScript
MIT
View repository →

Tracks documented and undocumented Microsoft Graph API schema changes, with an MCP Apps visualiser

0
TypeScript
MIT
View repository →

A Model Context Protocol (MCP) server for the Have I Been Pwned (HIBP) API

5
JavaScript
MIT
View repository →

Search Merill's Weekly Microsoft AI Roundup (msai.ms) archive — curated weekly Microsoft AI news

0
TypeScript
MIT
View repository →

MCP server exposing Untappd API tools for AI agents — full v4 read API coverage

0
TypeScript
View repository →

MCP server for weather with reasoning — umbrella advice, outdoor checks, city comparisons.

0
Python
MIT
View repository →