Skip to main content The #1 agentic semantic tool search: 91.6% first-try accuracy on S1 Search Bench Explore Tool Discovery
Live 43 Actions

Microsoft Intune MCP Server
for AI Agents

Connect your AI agent to StackOne's Microsoft Intune MCP server and give it 43 MCP tools out of the box. Auth, tool execution, and security all managed.

Microsoft Intune logo
Microsoft Intune MCP Server
Built by StackOne StackOne
DrataGPLocalyzeFlipMindtoolsScreenloop

Coverage

43 Agent Actions

Create, read, update, and delete across Microsoft Intune — and extend your agent's capabilities with custom actions.

Authentication

Agent Tool Authentication

Per-user OAuth in one call. Your Microsoft Intune MCP server gets session-scoped tokens with zero credentials stored on your infra.

Agent Auth →

Security

Agent Protection

Every Microsoft Intune tool response scanned for prompt injection in milliseconds — 88.7% accuracy, all running on CPU.

Prompt Injection Defense →

Performance

Max Agent Context. Min Cost.

Free up to 96% of your agent's context window to enhance reasoning and reduce cost, on every Microsoft Intune call.

Tools Discovery →

What is the Microsoft Intune MCP Server?

A Microsoft Intune MCP server lets AI agents read and write Microsoft Intune data through the Model Context Protocol — Anthropic's open standard for connecting LLMs to external tools. StackOne's Microsoft Intune MCP server ships with 43 pre-built actions, fully extensible via the Connector Builder — plus managed authentication, prompt injection defense, observability, and agent execution runtime. Connect it from MCP clients like Claude Desktop, Claude Code, Cursor, Goose, and VS Code, or from agent frameworks like OpenAI Agents SDK, LangChain, and Vercel AI SDK.

All Microsoft Intune MCP Tools

Every action from Microsoft Intune's API, ready for your agent. Create, read, update, and delete — scoped to exactly what you need.

Managed Devices

  • List Managed Devices

    Retrieve a list of managed devices from Microsoft Intune

  • Get Managed Device

    Retrieve the properties of a specific managed device by ID

  • Delete Managed Device

    Delete a managed device from Intune

Device Compliance Policys

  • Get Device Compliance Policy

    Retrieve the properties of a specific device compliance policy by ID

  • Delete Device Compliance Policy

    Delete a device compliance policy from Microsoft Intune

Device Configurations

  • List Device Configurations

    Retrieve a list of device configurations from Microsoft Intune

  • Get Device Configuration

    Retrieve the properties of a specific device configuration by ID

  • Delete Device Configuration

    Delete a device configuration from Microsoft Intune

Mobile Apps

  • List Mobile Apps

    Retrieve a list of mobile apps from Microsoft Intune

  • Get Mobile App

    Retrieve the properties of a specific mobile app by ID

Role Definitions

  • Create Role Definition

    Create a new custom Intune role definition

  • List Role Definitions

    Retrieve a list of Intune role definitions from Microsoft Intune

  • Get Role Definition

    Retrieve the properties of a specific Intune role definition by ID

  • Update Role Definition

    Update the properties of an Intune role definition

  • Delete Role Definition

    Delete an Intune role definition

Device Enrollment Configurations

  • List Device Enrollment Configurations

    Retrieve a list of device enrollment configurations from Microsoft Intune

  • Get Device Enrollment Configuration

    Retrieve the properties of a specific device enrollment configuration by ID

Detected Apps

  • List Detected Apps

    Retrieve a list of detected apps from Microsoft Intune

  • Get Detected App

    Retrieve the properties of a specific detected app by ID

Other (24)

  • Get Device Category

    Retrieve the device category of a managed device

  • List Device Compliance Policies

    Retrieve a list of device compliance policies from Microsoft Intune

  • List Mobile App Categories

    Retrieve a list of mobile app categories from Microsoft Intune

  • Get Mobile App Category

    Retrieve the properties of a specific mobile app category by ID

  • List Role Assignments

    Retrieve a list of role assignments for a specific role definition

  • List Detected App Managed Devices

    Retrieve the managed devices that have a specific detected app installed

  • Sync Device

    Synchronize a managed device with Intune

  • Set Enrollment Priority

    Set the priority of a device enrollment configuration

  • Retire Managed Device

    Retire a device, removing company data while keeping personal data

  • Wipe Managed Device

    Wipe a managed device, removing all data from the device

  • Remote Lock

    Remotely lock a managed device

  • Reset Passcode

    Reset the passcode on a managed device

  • Reboot Device

    Reboot a managed device immediately

  • Shut Down Device

    Shut down a managed device

  • Locate Device

    Locate a managed device

  • Bypass Activation Lock

    Bypass activation lock on a managed Apple device

  • Disable Lost Mode

    Disable lost mode on a managed device

  • Clean Windows Device

    Clean a Windows device with option to retain user data

  • Windows Defender Scan

    Trigger a Windows Defender scan on a managed device

  • Windows Defender Update Signatures

    Update Windows Defender antivirus signatures on a managed device

  • Assign Device Compliance Policy

    Assign a device compliance policy to groups

  • Assign Device Configuration

    Assign a device configuration to groups

  • Assign Mobile App

    Assign a mobile app to groups

  • Assign Device Enrollment Configuration

    Assign a device enrollment configuration to groups

Set Up Your Microsoft Intune MCP Server in Minutes

One endpoint. Any framework. Your agent is talking to Microsoft Intune in under 10 lines of code.

Agent Frameworks

Claude Desktop
{
  "mcpServers": {
    "stackone": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote@latest",
        "https://api.stackone.com/mcp?x-account-id=<account_id>",
        "--header",
        "Authorization: Basic <YOUR_BASE64_TOKEN>"
      ]
    }
  }
}

Check More developer MCP Servers

Microsoft Intune MCP Server FAQ

Does StackOne have a Microsoft Intune MCP server?
Yes. StackOne offers a hosted Microsoft Intune MCP server with 43 pre-built actions, and every action is tested and QA'd by StackOne. Connect it to Claude, Cursor, and any other MCP client, or to any agent framework through the AI Action SDK. It ships with managed agent authentication, prompt injection defense, and tool discovery with server-side execution that preserve your agent's context window and keep reasoning performance.
Microsoft Intune MCP server vs direct API integration — what's the difference?
A Microsoft Intune MCP server and direct API integration serve different use cases. Direct API integration is for software-to-software — backend code calling Microsoft Intune. A Microsoft Intune MCP server is for AI agents — MCP clients like Claude and Cursor, plus framework agents built with OpenAI, LangChain, or Vercel AI — discovering and calling Microsoft Intune at runtime. StackOne provides both.
How does Microsoft Intune authentication work for AI agents?
Microsoft Intune authentication for AI agents works through a StackOne Connect Session. Create one via the dashboard or the SDK — you get an auth link and ready-to-paste config for Claude Desktop, Cursor, and other MCP clients. Your user authenticates their own Microsoft Intune account; StackOne handles token exchange, storage, and refresh. Credentials never reach the LLM, and each user is isolated via origin_owner_id.
Are Microsoft Intune MCP tools vulnerable to prompt injection?
Yes — Microsoft Intune MCP tools can be vulnerable to indirect prompt injection. Any tool that reads user-written content — documents, messages, tickets, records, or free-text fields — is a potential vector. StackOne Defender scans every tool response before it enters the agent's context — regex patterns in ~1ms, then a MiniLM classifier in ~4ms. 88.7% accuracy, CPU-only.
What is the context bloat of a Microsoft Intune agent and how do I avoid it?
Context bloat happens when Microsoft Intune tool schemas and API responses eat your Microsoft Intune agent's memory, preventing it from reasoning effectively. A single Microsoft Intune query can return a massive JSON response, and connecting multiple tools compounds the problem. Tools Discovery and Code Mode reduce context bloat — loading only relevant tools per query and keeping raw responses out of the agent's context.
Can I limit which actions my Microsoft Intune agent can access?
Yes — you can limit which actions your Microsoft Intune agent can access directly from the StackOne dashboard. Toggle actions on or off, or restrict them to specific accounts, with no code changes to your agent. Session tokens can be scoped to exact actions so if one leaks, exposure stays contained.
Can I create custom agent actions for my Microsoft Intune MCP server?
Yes — you can create custom agent actions for your Microsoft Intune MCP server using Connector Builder. It's an integration agent your coding assistant (Claude Code, Cursor, or Copilot) can invoke to research Microsoft Intune's API, generate production-ready connector YAML, test against the live API, and validate before you ship.
When should I NOT use a Microsoft Intune MCP server?
Skip a Microsoft Intune MCP server if your integration is purely software-to-software — direct Microsoft Intune API integration is simpler when no AI agent is involved. For deterministic, compliance-critical operations (financial transactions, regulatory reporting), direct API gives you predictable behavior without agent-driven decision-making. MCP shines when AI agents need to dynamically discover and call Microsoft Intune actions at runtime.
What AI frameworks and AI clients does the StackOne Microsoft Intune MCP server support?
The StackOne Microsoft Intune MCP server supports both. MCP clients (paste-and-go apps): Claude Desktop, Claude Code, Cursor, VS Code, Goose. Agent frameworks (code SDKs you build with): OpenAI Agents SDK, Anthropic, Vercel AI, Google ADK, CrewAI, Pydantic AI, LangChain, LangGraph, Azure AI Foundry.

Put your AI agents to work

All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.