MCP server for Azure Entra PIM — list eligible assignments and activate group/role assignments
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"entra-pim-mcp-server","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
# entra-pim-mcp-server An MCP (Model Context Protocol) server for Azure Entra PIM (Privileged Identity Management). List eligible assignments and activate group or Entra role assignments — all through your MCP-compatible AI client. ## Features - **List eligible PIM assignments** — view all Group and Entra Role assignments you're eligible for, with their activation status - **Activate PIM assignments** — activate group or role assignments by name or ID, with a justification and optional duration - **Automatic browser authentication** — opens your browser automatically when login is needed, with persistent token caching - **No app registration required** — uses the Microsoft Graph PowerShell well-known client ID, no setup needed - **No secrets required** — uses delegated authentication, no client secret necessary ## Prerequisites - Python 3.10 or later (or [uv](https://docs.astral.sh/uv/) to run without installing Python manually) - An Azure Entra ID tenant with PIM enabled ## Environment Variables | Variable | Required | Description | |----------|----------|-------------| | `AZURE_TENANT_ID` | Yes | Your Azure AD tenant ID | ## Usage ### Codex plugin This repository includes a Codex plugin marketplace at `.agents/plugins/marketplace.json`. The marketplace entry points at the repository root as the `entra-pim` plugin. Install it directly from the repository: ```bash codex plugin marketplace add vexxhost/entra-pim-mcp-server --ref main codex plugin add entra-pim@vexxhost-entra-pim ``` The plugin forwards `AZURE_TENANT_ID` from the Codex process environment to the MCP server. For Codex Desktop and the VS Code extension, shell environment variables may not be inherited, so put the tenant ID in `~/.codex/.env` and restart Codex: ```shell export AZURE_TENANT_ID=00000000-0000-0000-0000-000000000000 ``` Use your own Entra tenant ID in place of the placeholder. The plugin does not hardcode a tenant ID because tenant selection is deployment-specific. ### Run di…
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.