Microsoft + ClaudeOne partner for the cloud you run and the AI you put on top of it.
Avalon Web ServicesMicrosoft · Claude · Security
Avalon CloudSec · MCP

Your Microsoft 365 security posture, in the assistant you already run.

Avalon CloudSec Security Intelligence MCP is a remote MCP server at mcp.awservices.org. It gives Copilot Studio, Claude, or any MCP-capable client eight curated, read-only questions about a Microsoft 365 tenant — answered live from Microsoft Graph, scoped to the tenants each person is entitled to, and never stored by us.

01 · What it answers

Eight tools, one job

get_security_postureOne call, seven domainsAggregate posture with per-domain status and findings.
assess_secure_scoreMicrosoft Secure ScoreCurrent and previous score, change over time, and control profiles.
assess_conditional_accessConditional Access hygienePolicy coverage gaps such as legacy auth and admin MFA.
assess_privileged_accessPrivileged rolesPermanent versus eligible assignments; PIM where licensed.
assess_mfa_postureMFA registrationCoverage across users; administrators without MFA called out.
assess_identity_riskIdentity ProtectionRisky users, risky sign-ins and risk detections; needs Entra ID P2.
assess_device_complianceIntune devicesCompliance state and stale devices; needs Intune.
assess_defender_incidentsDefender XDROpen incidents by severity; needs Defender XDR.

Every tool is read-only by construction — there is no write path in the service, so neither an operator error nor a compromise of the service can change a policy, dismiss an alert, or touch a user in your tenant. Results carry a structured status per domain, so a tenant without Entra ID P2, Intune or Defender XDR gets an honest license_required rather than a misleading zero.

02 · Who it is for

Security teams and the MSPs that serve them

A security lead can ask their assistant for the tenant's posture in plain language and get an answer grounded in live Graph data, not a screenshot from last quarter. A managed service provider can do the same across every customer tenant they are entitled to, from one connection, without a separate login per customer — each answer is scoped to exactly the tenants that customer has granted.

03 · How it connects

Standard OAuth, your identity provider

Add https://mcp.awservices.org/v1/cloudsec as a remote MCP server in your client. The client discovers our authorization server, and sign-in federates to your own Microsoft Entra ID — there is no separate Avalon password. Tokens are scoped to mcp:read cloudsec:read and nothing broader.

04 · Onboarding

Two steps, one of them yours

1. Consent. A Global Administrator of your tenant grants the Avalon CloudSec Graph application its ten read-only permissions — the consent screen lists every one, and our privacy notice explains what each is used for. Replace the placeholder with your tenant ID or verified domain:

https://login.microsoftonline.com/{your-tenant-id}/adminconsent
  ?client_id=e1eee717-f6e9-4a72-8339-ea65979a424e
  &redirect_uri=https://mcp.awservices.org/onboarding/consent-complete

2. Entitlement. Consent alone switches nothing on. Send your tenant ID to support@awservices.org with the names of the people who should have access, and we activate the entitlement. Until then, requests for your tenant are declined.

You can withdraw consent at any time from your own Entra admin center. That ends access immediately and needs nothing from us.

05 · Commercials

Priced per tenant, quoted on request

Subscriptions are per tenant, month to month, with an MSP tier for operators who manage several. We quote rather than publish list prices while the service is in its first release — write to sales@awservices.org with how many tenants you operate. The terms of use cover availability, data handling and termination.

06 · Documents

The rest of the paperwork