{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_jp8ys73sjhw2","handle":"entra-pim-mcp-server","url":"https://wellknown.network/agents/entra-pim-mcp-server","links":{"self":"https://wellknown.network/agents/entra-pim-mcp-server/record.json","html":"https://wellknown.network/agents/entra-pim-mcp-server","markdown":"https://wellknown.network/agents/entra-pim-mcp-server/record.md","api":"https://wellknown.network/api/v1/agents/entra-pim-mcp-server","status":"https://wellknown.network/api/v1/agents/entra-pim-mcp-server/status","claim":"https://wellknown.network/agents/entra-pim-mcp-server/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/entra-pim-mcp-server/claim.json","badge":"https://wellknown.network/agents/entra-pim-mcp-server/badge.svg","openapi":"https://wellknown.network/openapi.json"},"ard":{"identifier":"urn:air::server:entra-pim-mcp-server","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"entra-pim-mcp-server","summary":"MCP server for Azure Entra PIM — list eligible assignments and activate group/role assignments","description":"# entra-pim-mcp-server\n\nAn MCP (Model Context Protocol) server for Azure Entra PIM (Privileged Identity Management). List eligible assignments and activate group or Entra role assignments — all through your MCP-compatible AI client.\n\n## Features\n\n- **List eligible PIM assignments** — view all Group and Entra Role assignments you're eligible for, with their activation status\n- **Activate PIM assignments** — activate group or role assignments by name or ID, with a justification and optional duration\n- **Automatic browser authentication** — opens your browser automatically when login is needed, with persistent token caching\n- **No app registration required** — uses the Microsoft Graph PowerShell well-known client ID, no setup needed\n- **No secrets required** — uses delegated authentication, no client secret necessary\n\n## Prerequisites\n\n- Python 3.10 or later (or [uv](https://docs.astral.sh/uv/) to run without installing Python manually)\n- An Azure Entra ID tenant with PIM enabled\n\n## Environment Variables\n\n| Variable | Required | Description |\n|----------|----------|-------------|\n| `AZURE_TENANT_ID` | Yes | Your Azure AD tenant ID |\n\n## Usage\n\n### Codex plugin\n\nThis repository includes a Codex plugin marketplace at `.agents/plugins/marketplace.json`.\nThe marketplace entry points at the repository root as the `entra-pim` plugin.\nInstall it directly from the repository:\n\n```bash\ncodex plugin marketplace add vexxhost/entra-pim-mcp-server --ref main\ncodex plugin add entra-pim@vexxhost-entra-pim\n```\n\nThe plugin forwards `AZURE_TENANT_ID` from the Codex process environment to the MCP server. For Codex Desktop and the VS Code extension, shell environment variables may not be inherited, so put the tenant ID in `~/.codex/.env` and restart Codex:\n\n```shell\nexport AZURE_TENANT_ID=00000000-0000-0000-0000-000000000000\n```\n\nUse your own Entra tenant ID in place of the placeholder. The plugin does not hardcode a tenant ID because tenant selection is deployment-specific.\n\n### Run di…","publisher":null,"homepage":null,"repository":null,"version":"1.0.1","license":null,"protocols":["mcp"],"tags":["mcp"],"pricing":null,"endpoints":[{"url":"pypi:entra-pim-mcp-server","type":"package_pypi","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":null,"attribution":{"kind":"pypi","name":"pypi","summary":"pypi","version":"pypi","description":"pypi"}},"derived":{"capabilities":[{"slug":"security.identity","name":"Identity & Access","confidence":0.871,"provenance":"derived"},{"slug":"dev.terminal","name":"Terminal & Shell","confidence":0.745,"provenance":"derived"}],"categories":["dev","security"],"language":"en"},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"entra-pim-mcp-server","registry":"pypi","observedAt":"2026-09-09T15:23:48.521Z","publishedAt":"2026-07-07T16:26:33.541086Z","latestVersion":"1.0.1"}},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"pypi","key":"entra-pim-mcp-server","url":"https://pypi.org/project/entra-pim-mcp-server/","firstSeenAt":"2026-09-09T15:21:36.077Z","fetchedAt":"2026-09-09T15:21:36.077Z","normalizedAt":"2026-09-09T15:21:36.077Z"}]},"firstSeenAt":"2026-09-09T15:21:36.077Z","updatedAt":"2026-09-09T15:23:48.521Z"}