Your Microsoft 365 security posture, in the assistant you already run.
Avalon CloudSec Security Intelligence MCP is a remote MCP server at mcp.awservices.org. It gives Copilot Studio, Claude, or any MCP-capable client eight curated, read-only questions about a Microsoft 365 tenant — answered live from Microsoft Graph, scoped to the tenants each person is entitled to, and never stored by us.
01 · What it answers
Eight tools, one job
| get_security_posture | One call, seven domains | Aggregate posture with per-domain status and findings. |
| assess_secure_score | Microsoft Secure Score | Current and previous score, change over time, and control profiles. |
| assess_conditional_access | Conditional Access hygiene | Policy coverage gaps such as legacy auth and admin MFA. |
| assess_privileged_access | Privileged roles | Permanent versus eligible assignments; PIM where licensed. |
| assess_mfa_posture | MFA registration | Coverage across users; administrators without MFA called out. |
| assess_identity_risk | Identity Protection | Risky users, risky sign-ins and risk detections; needs Entra ID P2. |
| assess_device_compliance | Intune devices | Compliance state and stale devices; needs Intune. |
| assess_defender_incidents | Defender XDR | Open incidents by severity; needs Defender XDR. |
Every tool is read-only by construction — there is no write path in the service, so neither an operator error nor a compromise of the service can change a policy, dismiss an alert, or touch a user in your tenant. Results carry a structured status per domain, so a tenant without Entra ID P2, Intune or Defender XDR gets an honest license_required rather than a misleading zero.
02 · Who it is for
Security teams and the MSPs that serve them
A security lead can ask their assistant for the tenant's posture in plain language and get an answer grounded in live Graph data, not a screenshot from last quarter. A managed service provider can do the same across every customer tenant they are entitled to, from one connection, without a separate login per customer — each answer is scoped to exactly the tenants that customer has granted.
03 · How it connects
Standard OAuth, your identity provider
Add https://mcp.awservices.org/v1/cloudsec as a remote MCP server in your client. The client discovers our authorization server, and sign-in federates to your own Microsoft Entra ID — there is no separate Avalon password. Tokens are scoped to mcp:read cloudsec:read and nothing broader.
04 · Onboarding
Two steps, one of them yours
1. Consent. A Global Administrator of your tenant grants the Avalon CloudSec Graph application its ten read-only permissions — the consent screen lists every one, and our privacy notice explains what each is used for. Replace the placeholder with your tenant ID or verified domain:
https://login.microsoftonline.com/{your-tenant-id}/adminconsent
?client_id=e1eee717-f6e9-4a72-8339-ea65979a424e
&redirect_uri=https://mcp.awservices.org/onboarding/consent-complete2. Entitlement. Consent alone switches nothing on. Send your tenant ID to support@awservices.org with the names of the people who should have access, and we activate the entitlement. Until then, requests for your tenant are declined.
You can withdraw consent at any time from your own Entra admin center. That ends access immediately and needs nothing from us.
05 · Commercials
Priced per tenant, quoted on request
Subscriptions are per tenant, month to month, with an MSP tier for operators who manage several. We quote rather than publish list prices while the service is in its first release — write to sales@awservices.org with how many tenants you operate. The terms of use cover availability, data handling and termination.
06 · Documents
The rest of the paperwork
- Privacy notice — what is read, what is kept, for how long
- Terms of use
- Support — what to send us, and what the common results mean
- Acceptable use policy