Microsoft Intune MCP Server
for AI Agents
Connect your AI agent to StackOne's Microsoft Intune MCP server and give it 43 MCP tools out of the box. Auth, tool execution, and security all managed.
Coverage
43 Agent Actions
Create, read, update, and delete across Microsoft Intune — and extend your agent's capabilities with custom actions.
Authentication
Agent Tool Authentication
Per-user OAuth in one call. Your Microsoft Intune MCP server gets session-scoped tokens with zero credentials stored on your infra.
Agent Auth →Security
Agent Protection
Every Microsoft Intune tool response scanned for prompt injection in milliseconds — 88.7% accuracy, all running on CPU.
Prompt Injection Defense →Performance
Max Agent Context. Min Cost.
Free up to 96% of your agent's context window to enhance reasoning and reduce cost, on every Microsoft Intune call.
Tools Discovery →What is the Microsoft Intune MCP Server?
A Microsoft Intune MCP server lets AI agents read and write Microsoft Intune data through the Model Context Protocol — Anthropic's open standard for connecting LLMs to external tools. StackOne's Microsoft Intune MCP server ships with 43 pre-built actions, fully extensible via the Connector Builder — plus managed authentication, prompt injection defense, observability, and agent execution runtime. Connect it from MCP clients like Claude Desktop, Claude Code, Cursor, Goose, and VS Code, or from agent frameworks like OpenAI Agents SDK, LangChain, and Vercel AI SDK.
All Microsoft Intune MCP Tools
Every action from Microsoft Intune's API, ready for your agent. Create, read, update, and delete — scoped to exactly what you need.
Managed Devices
- List Managed Devices
Retrieve a list of managed devices from Microsoft Intune
- Get Managed Device
Retrieve the properties of a specific managed device by ID
- Delete Managed Device
Delete a managed device from Intune
Device Compliance Policys
- Get Device Compliance Policy
Retrieve the properties of a specific device compliance policy by ID
- Delete Device Compliance Policy
Delete a device compliance policy from Microsoft Intune
Device Configurations
- List Device Configurations
Retrieve a list of device configurations from Microsoft Intune
- Get Device Configuration
Retrieve the properties of a specific device configuration by ID
- Delete Device Configuration
Delete a device configuration from Microsoft Intune
Mobile Apps
- List Mobile Apps
Retrieve a list of mobile apps from Microsoft Intune
- Get Mobile App
Retrieve the properties of a specific mobile app by ID
Role Definitions
- Create Role Definition
Create a new custom Intune role definition
- List Role Definitions
Retrieve a list of Intune role definitions from Microsoft Intune
- Get Role Definition
Retrieve the properties of a specific Intune role definition by ID
- Update Role Definition
Update the properties of an Intune role definition
- Delete Role Definition
Delete an Intune role definition
Device Enrollment Configurations
- List Device Enrollment Configurations
Retrieve a list of device enrollment configurations from Microsoft Intune
- Get Device Enrollment Configuration
Retrieve the properties of a specific device enrollment configuration by ID
Detected Apps
- List Detected Apps
Retrieve a list of detected apps from Microsoft Intune
- Get Detected App
Retrieve the properties of a specific detected app by ID
Other (24)
- Get Device Category
Retrieve the device category of a managed device
- List Device Compliance Policies
Retrieve a list of device compliance policies from Microsoft Intune
- List Mobile App Categories
Retrieve a list of mobile app categories from Microsoft Intune
- Get Mobile App Category
Retrieve the properties of a specific mobile app category by ID
- List Role Assignments
Retrieve a list of role assignments for a specific role definition
- List Detected App Managed Devices
Retrieve the managed devices that have a specific detected app installed
- Sync Device
Synchronize a managed device with Intune
- Set Enrollment Priority
Set the priority of a device enrollment configuration
- Retire Managed Device
Retire a device, removing company data while keeping personal data
- Wipe Managed Device
Wipe a managed device, removing all data from the device
- Remote Lock
Remotely lock a managed device
- Reset Passcode
Reset the passcode on a managed device
- Reboot Device
Reboot a managed device immediately
- Shut Down Device
Shut down a managed device
- Locate Device
Locate a managed device
- Bypass Activation Lock
Bypass activation lock on a managed Apple device
- Disable Lost Mode
Disable lost mode on a managed device
- Clean Windows Device
Clean a Windows device with option to retain user data
- Windows Defender Scan
Trigger a Windows Defender scan on a managed device
- Windows Defender Update Signatures
Update Windows Defender antivirus signatures on a managed device
- Assign Device Compliance Policy
Assign a device compliance policy to groups
- Assign Device Configuration
Assign a device configuration to groups
- Assign Mobile App
Assign a mobile app to groups
- Assign Device Enrollment Configuration
Assign a device enrollment configuration to groups
Set Up Your Microsoft Intune MCP Server in Minutes
One endpoint. Any framework. Your agent is talking to Microsoft Intune in under 10 lines of code.
Agent Frameworks
{
"mcpServers": {
"stackone": {
"command": "npx",
"args": [
"-y",
"mcp-remote@latest",
"https://api.stackone.com/mcp?x-account-id=<account_id>",
"--header",
"Authorization: Basic <YOUR_BASE64_TOKEN>"
]
}
}
}Check More developer MCP Servers
113+ actions
62+ actions
61+ actions
54+ actions
50+ actions
31+ actions
19+ actions
Platform Resources
MCP Code Mode: Keeping Tool Responses Out of Agent Context
Anthropic's code_execution processes data already in context. Custom MCP code mode keeps raw tool responses in a sandbox. 14K tokens vs 500.
11 min
Comparing BM25, TF-IDF, and Hybrid Search for MCP Tool Discovery
Benchmarking BM25, TF-IDF, and hybrid search for MCP tool discovery across 916 tools. The 80/20 TF-IDF/BM25 hybrid hits 21% Top-1 accuracy in under 1ms.
10 min
Indirect Prompt Injection Defense for MCP Tools: A Technical Guide
MCP tools that read emails, CRM records, and tickets are indirect prompt injection vectors. Here's how we built a two-tier defense that scans tool results in ~11ms.
12 min
MCP vs A2A: Architecture, Security, and When to Use Each
MCP vs A2A: what each protocol standardizes, how they differ, their shared security risks including indirect prompt injection, and when to use one, both, or a hybrid architecture.
12 min
MCP vs API: What 200+ Connector Builds Taught Us
MCP wraps APIs, it doesn't replace them. After building 200+ connectors that serve both, here's when each approach wins.
14 min read
Microsoft Intune MCP Server FAQ
Does StackOne have a Microsoft Intune MCP server?
Microsoft Intune MCP server vs direct API integration — what's the difference?
How does Microsoft Intune authentication work for AI agents?
origin_owner_id.Are Microsoft Intune MCP tools vulnerable to prompt injection?
What is the context bloat of a Microsoft Intune agent and how do I avoid it?
Can I limit which actions my Microsoft Intune agent can access?
Can I create custom agent actions for my Microsoft Intune MCP server?
When should I NOT use a Microsoft Intune MCP server?
What AI frameworks and AI clients does the StackOne Microsoft Intune MCP server support?
Put your AI agents to work
All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.