Identity and secrets
Directory, governance, and secret-management systems an agent can inspect and change. 10 integrations, 274 tools.
Tool names below are the fully qualified names an agent sees once the integration is connected. Where an integration offers more than one connection, the names shown use the primary connection’s prefix; connecting through another variant prefixes its tools with that variant’s own integration ID instead. See Tool Catalog for how tools are granted and named.
Cisco Secure Access
Section titled “Cisco Secure Access”22 tools. Connect with OAuth 2.0 client credentials.
| Tool | Description | Arguments |
|---|---|---|
cisco-secure-access_create_application_list | Create a new application list for grouping cloud applications in policies | required nameoptional application_ids |
cisco-secure-access_create_destination_list | Create a new destination list (block or allow list) with optional initial destinations | required nameoptional destinations, is_global |
cisco-secure-access_create_internal_network | Create a new internal network with IP address, prefix length, and optional site/tunnel association | required name, ip_address, prefix_lengthoptional site_id, tunnel_id |
cisco-secure-access_create_private_resource | Create a new private resource for ZTNA access with addresses and protocols | required name, addressesoptional description, protocols |
cisco-secure-access_delete_application_list | Delete an application list by ID | required application_list_id |
cisco-secure-access_delete_destination_list | Delete a destination list by ID | required destination_list_id |
cisco-secure-access_delete_private_resource | Delete a private resource by ID | required resource_id |
cisco-secure-access_get_activity | Get security activity events (DNS, proxy, firewall, ZTNA, intrusion) within a time range with filtering | required from_time, to_timeoptional categories, domains, ip, limit, offset, verdict |
cisco-secure-access_get_application_list | Get a specific application list by ID including its member applications | required application_list_id |
cisco-secure-access_get_destination_list | Get a specific destination list by ID including its metadata and destination count | required destination_list_id |
cisco-secure-access_get_dns_activity | Get DNS-specific activity events with domain, category, and verdict filtering within a time range | required from_time, to_timeoptional categories, domains, limit, offset, verdict |
cisco-secure-access_get_internal_network | Get a specific internal network by ID including its IP range and site association | required network_id |
cisco-secure-access_get_private_resource | Get a specific private resource by ID including its addresses, protocols, and configuration | required resource_id |
cisco-secure-access_investigate_domain | Get domain security status, risk categorization, and content categories for a single domain | required domain |
cisco-secure-access_investigate_domains_bulk | Bulk domain lookup — get security status and categorization for up to 1000 domains at once | required domains |
cisco-secure-access_list_application_lists | List cloud application lists used to group apps for policy enforcement | optional limit, page |
cisco-secure-access_list_destination_lists | List all Cisco Secure Access destination lists (block/allow lists of domains, URLs, and IPs) with pagination | optional limit, page |
cisco-secure-access_list_internal_networks | List internal networks (subnets) configured in Cisco Secure Access | optional limit, page |
cisco-secure-access_list_private_resources | List private resources/applications configured for ZTNA (Zero Trust Network Access) | optional limit, page |
cisco-secure-access_list_roaming_computers | List enrolled roaming computers/devices with their DNS and internet security status | optional limit, page |
cisco-secure-access_manage_destinations | Add or remove destinations (domains/URLs/IPs) in a destination list. Use action=‘add’ with destinations, or action=‘remove’ with destination_ids | required destination_list_id, actionoptional destination_ids, destinations |
cisco-secure-access_update_destination_list | Update a destination list’s name | required destination_list_idoptional name |
CyberArk Privilege Cloud
Section titled “CyberArk Privilege Cloud”30 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
cyberark-privilege-cloud_activate_platform | Activate a target platform so it can be used for new accounts. | required platform_id |
cyberark-privilege-cloud_add_safe_member | Grant a user, group, or role access to a safe with specific permissions. | required safe_name, member_name, permissionsoptional member_type |
cyberark-privilege-cloud_change_account_password | Initiate a CPM-managed password change for an account. The CPM will generate and set a new password on the target. | required account_id |
cyberark-privilege-cloud_create_account | Provision a new privileged account in CyberArk. Requires a safe name and platform ID at minimum. | required safe_name, platform_idoptional address, name, properties, secret, secret_type, user_name |
cyberark-privilege-cloud_create_safe | Create a new safe in CyberArk for storing privileged accounts. | required safe_nameoptional description, managing_cpm, number_of_days_retention |
cyberark-privilege-cloud_deactivate_platform | Deactivate a target platform to prevent it from being assigned to new accounts. | required platform_id |
cyberark-privilege-cloud_delete_account | Delete a privileged account from CyberArk by its unique ID. | required account_id |
cyberark-privilege-cloud_delete_platform | Delete a target platform from CyberArk by its numeric ID. | required platform_id |
cyberark-privilege-cloud_delete_safe | Delete a safe from CyberArk by its name. | required safe_name |
cyberark-privilege-cloud_duplicate_platform | Duplicate an existing target platform with a new name. | required platform_id, nameoptional description |
cyberark-privilege-cloud_export_platform | Export a platform as a base64-encoded ZIP package. | required platform_id |
cyberark-privilege-cloud_get_account | Get full details of a privileged account by its unique ID. | required account_id |
cyberark-privilege-cloud_get_platform | Get full details of a platform by its ID. | required platform_id |
cyberark-privilege-cloud_get_safe | Get full details of a safe by its name. | required safe_name |
cyberark-privilege-cloud_get_safe_member | Get details of a specific member of a safe. | required safe_name, member_name |
cyberark-privilege-cloud_get_session | Get full details of a privileged session recording by its ID. | required session_id |
cyberark-privilege-cloud_import_platform | Import a platform from a ZIP package by reference. Pass source_url: a short-lived signed download URL minted by the mint_upload_url tool. The server fetches the ZIP bytes from source_url (binary-safe) and imports the platform. | required source_url |
cyberark-privilege-cloud_list_accounts | List and search privileged accounts in CyberArk. Supports filtering by safe name, username, address, and platform. | optional filter_query, limit, offset, safe_name, search |
cyberark-privilege-cloud_list_live_sessions | List currently active (live) privileged sessions. | optional limit, offset, search |
cyberark-privilege-cloud_list_platforms | List platforms available in CyberArk with optional search and type filter. | optional platform_type, search |
cyberark-privilege-cloud_list_safe_members | List all members (users, groups, roles) with access to a safe. | required safe_nameoptional filter_query |
cyberark-privilege-cloud_list_safes | List safes in CyberArk with optional search and pagination. | optional limit, offset, search |
cyberark-privilege-cloud_list_session_activities | List all activities (commands, keystrokes) within a session recording. | required session_id |
cyberark-privilege-cloud_list_sessions | List privileged session recordings with optional search and pagination. | optional limit, offset, search |
cyberark-privilege-cloud_reconcile_account_password | Reconcile (sync) the password between CyberArk and the target system. Used when passwords are out of sync. | required account_id |
cyberark-privilege-cloud_remove_safe_member | Remove a member from a safe, revoking all their permissions. | required safe_name, member_name |
cyberark-privilege-cloud_update_account | Update an existing account using JSON Patch operations (RFC 6902). Example: [{‘op’: ‘replace’, ‘path’: ‘/address’, ‘value’: ‘10.0.0.1’}] | required account_id, operations |
cyberark-privilege-cloud_update_safe | Update an existing safe’s configuration (description, CPM, retention). | required safe_nameoptional description, managing_cpm, number_of_days_retention |
cyberark-privilege-cloud_update_safe_member | Update a safe member’s permissions. | required safe_name, member_name, permissions |
cyberark-privilege-cloud_verify_account_password | Verify that the password stored in CyberArk matches the actual password on the target system. | required account_id |
Delinea Secret Server
Section titled “Delinea Secret Server”10 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
delinea-secret-server_change_secret_password | Rotate (change) the password on a secret. If new_password is omitted, Secret Server generates one according to the secret’s password policy. | required secret_idoptional new_password |
delinea-secret-server_checkin_secret | Check in a previously checked-out secret, ending exclusive access so other users can use it. Optionally force check-in (requires the ‘Force Check In’ permission). | required secret_idoptional comment, force_check_in |
delinea-secret-server_checkout_secret | Check out a secret that requires exclusive checkout before its credentials can be used. After checkout, call get_secret to read the value, then checkin_secret when finished. | required secret_id |
delinea-secret-server_create_secret | Create a new secret in a folder from a secret template. items is the list of template field values, e.g. [{‘fieldName’: ‘Password’, ‘itemValue’: ’…’, ‘slug’: ‘password’}]. | required name, folder_id, secret_template_id, itemsoptional site_id |
delinea-secret-server_get_folder | Get details of a folder by its ID, including child folders. | required folder_id |
delinea-secret-server_get_secret | Retrieve a secret by ID, including its field values (e.g. username/password). For secrets that require a comment to view, pass comment. Use get_secret_summary to inspect metadata without exposing field values. | required secret_idoptional comment |
delinea-secret-server_get_secret_summary | Get non-sensitive summary metadata for a secret (name, folder, template, checkout/approval status) without returning field values. | required secret_id |
delinea-secret-server_search_folders | Search and browse folders in Delinea Secret Server by free text and/or parent folder. | optional only_root_folders, parent_folder_id, search_text, skip, take |
delinea-secret-server_search_secrets | Search and list secrets in Delinea Secret Server by free text and/or folder. Returns secret metadata (id, name, folder), not field values — use get_secret to read the actual credentials. | optional folder_id, include_subfolders, search_text, skip, take |
delinea-secret-server_update_secret | Update an existing secret. Pass the full secret object (as returned by get_secret) with your modifications applied — Secret Server expects the complete object on update (GET, modify, then update). | required secret_id, secret |
Doppler
Section titled “Doppler”14 tools. Connect with API key.
| Tool | Description | Arguments |
|---|---|---|
doppler_create_config | Create a new branch config under a project environment. Requires a Personal or CLI token (Service Tokens cannot create configs). | required project, environment, name |
doppler_create_environment | Create a new environment in a project (e.g., development, staging, production). Requires a Personal or CLI token (Service Tokens cannot create environments). | required project, name, slugoptional personal_configs |
doppler_create_project | Create a new project in the Doppler workspace. Requires a Personal or CLI token (Service Tokens are scoped to a single config and cannot create projects). | required nameoptional description |
doppler_delete_secret | Delete a single secret from a config by name. Works with Service Tokens scoped to the target config. | required project, config, name |
doppler_get_activity_log | Get details of a single activity log entry by ID | required log |
doppler_get_config | Get details of a single config by project and config name | required project, config |
doppler_get_project | Get details of a single project by its slug identifier | required project |
doppler_get_secret | Get a single secret’s value and metadata by name | required project, config, name |
doppler_list_activity_logs | List activity logs for the workspace with optional pagination | optional fetch_all, page, per_page |
doppler_list_configs | List configs for a project, optionally filtered by environment | required projectoptional environment, fetch_all, page, per_page |
doppler_list_environments | List all environments for a given project (e.g., development, staging, production) | required project |
doppler_list_projects | List all projects in the Doppler workspace with optional pagination | optional fetch_all, page, per_page |
doppler_list_secrets | List all secrets in a config. Returns an object with a ‘secrets’ array; each entry includes the secret name alongside the fields returned by the Doppler API (typically raw value, computed value, and note). | required project, configoptional include_dynamic_secrets, include_managed_secrets |
doppler_set_secret | Set a single secret in a config (upsert). Works with Service Tokens scoped to the target config. | required project, config, name, value |
Microsoft Entra ID
Section titled “Microsoft Entra ID”34 tools. Available as 4 connections: Microsoft Entra ID (OAuth 2.0), Microsoft Entra ID (Application) (OAuth 2.0 client credentials), Microsoft Entra ID (GCC High) (OAuth 2.0), Microsoft Entra ID (GCC High, Application) (OAuth 2.0 client credentials).
| Tool | Description | Arguments |
|---|---|---|
microsoft-entra-id_disable_user_account | Disable a user account so the user cannot sign in. Primary containment action for a compromised account; reverse it with enable_user_account. | required user_id |
microsoft-entra-id_enable_user_account | Enable a previously disabled user account so the user can sign in again. | required user_id |
microsoft-entra-id_evaluate_conditional_access | Answer what conditional access would do for a sign-in that has not happened: the What If tool. Requires who is signing in — pass user_id (an object id or userPrincipalName) or service_principal_id. | optional applied_policies_only, authentication_context_value, client_app_type, country, device_platform, include_applications, ip_address, service_principal_id, service_principal_risk_level, sign_in_risk_level, user_action, user_id, user_risk_level |
microsoft-entra-id_get_authentication_sla_attainment | Read Microsoft Entra authentication SLA attainment by calendar month for this tenant. | — |
microsoft-entra-id_get_conditional_access_impact_summary | Count what conditional access actually did over a time window: how many sign-ins each policy allowed, blocked, or did not apply to, including report-only policies. | optional application, days_back, group_by, max_records, policy_ids, user_principal_name |
microsoft-entra-id_get_conditional_access_policy | Get one conditional access policy by id, including its conditions and grant controls. Locations and authentication strengths appear as GUIDs; resolve them with list_named_locations and list_authentication_strengths. | required policy_idoptional select |
microsoft-entra-id_get_directory_audit_details | Get one directory audit entry by id, with its full target-resource list. | required directory_audit_idoptional select |
microsoft-entra-id_get_directory_objects_by_ids | Resolve directory object ids to the objects themselves, in one call, for ids that came back from audit logs or group listings. | required idsoptional types |
microsoft-entra-id_get_directory_role | Get one directory role by object id or role template id. Only roles activated in the tenant are returned. | optional role_id, role_template_id, select |
microsoft-entra-id_get_group | Get one group by object id. Use list_groups to find an id from a name. | required group_idoptional select |
microsoft-entra-id_get_sign_in_details | Get one sign-in event by id, including its status, device and location detail. | required sign_in_idoptional select |
microsoft-entra-id_get_user | Get one directory user by object id or user principal name. Use list_users to find an id first when only a name is known. | required user_idoptional select |
microsoft-entra-id_get_user_inplace_hold_status | Get the in-place hold policies applied to a user, for legal hold and retention checks. | required user_id |
microsoft-entra-id_get_user_registration_details | Get one user’s registered authentication methods and capabilities. | required user_id |
microsoft-entra-id_get_users_registered_by_method | Count users registered for each authentication method across the tenant, scoped by user type and directory role — for example how many privileged admins have registered a phishing-resistant method. | optional included_user_roles, included_user_types |
microsoft-entra-id_list_adfs_application_activity | List AD FS relying parties with their sign-in volume and whether each can be migrated to Microsoft Entra ID, for planning an AD FS migration. Aggregated over the given period. | optional period, skip_token |
microsoft-entra-id_list_app_credential_sign_in_activity | List each application credential — secret, certificate, or federated identity credential — with when it was last used to sign in and when it expires, so stale and expiring credentials can be found. | optional filter_query, order_by, skip_token, top |
microsoft-entra-id_list_application_sign_in_summary | List per-application sign-in counts with their success or failure status, to see which applications users are actually signing in to and where sign-ins are erroring. | optional filter_query, order_by, skip_token, top |
microsoft-entra-id_list_authentication_strengths | List authentication strength policies and the method combinations each accepts. Conditional access grant controls reference these by GUID, so call this to read what a policy actually requires. | optional filter_query, order_by, select, top |
microsoft-entra-id_list_conditional_access_policies | List conditional access policies with their state (enabled, disabled, or report-only). | optional filter_query, order_by, select, skip_token, top |
microsoft-entra-id_list_directory_audits | List directory audit entries — who changed what in the directory. Narrow with a filter such as ‘activityDateTime ge 2026-08-01T00:00:00Z’ before widening. When has_more is true, pass next_skip_token back as skip_token. | optional filter_query, order_by, select, skip_token, top |
microsoft-entra-id_list_directory_recommendations | List Microsoft Entra recommendations for this tenant — best-practice findings and Identity Secure Score improvements, with their status and priority. Filter on status to see only what is still open. | optional filter_query, order_by, skip_token, top |
microsoft-entra-id_list_directory_role_members | List the principals holding a directory role, identified by object id or role template id. | optional role_id, role_template_id, select |
microsoft-entra-id_list_directory_roles | List the directory roles activated in the tenant. A role that has never been activated does not appear. | optional expand, filter_query, select |
microsoft-entra-id_list_group_members | List a group’s members. Members can be users, groups, devices or service principals; set member_type to narrow to one kind. | required group_idoptional count, expand, filter_query, member_type, order_by, search, select, skip_token, top |
microsoft-entra-id_list_group_owners | List a group’s owners. Set owner_type to narrow to one directory kind. | required group_idoptional count, expand, filter_query, owner_type, search, select, skip_token, top |
microsoft-entra-id_list_groups | List groups in the directory. When has_more is true, pass next_skip_token back as skip_token. | optional count, display_name_starts_with, expand, filter_query, mail_enabled, mail_nickname_starts_with, order_by, search, security_enabled, select, skip_token, top |
microsoft-entra-id_list_named_locations | List named locations (IP ranges and country lists). Conditional access policies reference these by GUID, so call this to read what a policy’s location conditions actually mean. | optional filter_query, order_by, select, skip_token, top |
microsoft-entra-id_list_provisioning_object_summary | List provisioning events, which record identities synchronised into and out of the directory. When has_more is true, pass next_skip_token back as skip_token. | optional count, filter_query, order_by, skip_token, top |
microsoft-entra-id_list_service_principal_sign_in_activity | List when each service principal last signed in, so unused ones can be found and retired. Covers delegated and app-only flows, as client and as resource. Filter with app_id eq '<guid>' for one application. | optional filter_query, order_by, skip_token, top |
microsoft-entra-id_list_sign_ins | List sign-in log entries. Graph charges for the span the query covers, so a large top over a wide period is slow enough to time out: keep top small, or bound the period with filter_query, and do not do neither. | optional count, filter_query, select, skip_token, top |
microsoft-entra-id_list_user_app_role_assignments | List the application role assignments held by a user, which is how app access is granted in Entra ID. | required user_idoptional count, filter_query, order_by, select, skip_token, top |
microsoft-entra-id_list_user_registration_details | List which authentication methods each user has registered, for multifactor and passwordless coverage reporting. | optional filter_query |
microsoft-entra-id_list_users | List directory users. The starts-with parameters match a prefix; search matches anywhere in a name or mail. When has_more is true, pass next_skip_token back as skip_token. | optional account_enabled, count, display_name_starts_with, filter_query, mail_starts_with, order_by, search, select, skip_token, top, user_principal_name_starts_with |
Microsoft Entra ID Governance
Section titled “Microsoft Entra ID Governance”23 tools. Available as 2 connections: Microsoft Entra ID Governance (OAuth 2.0), Microsoft Entra ID Governance (GCC High) (OAuth 2.0).
| Tool | Description | Arguments |
|---|---|---|
entra-id-governance_activate_lifecycle_workflow | Run a lifecycle workflow on-demand for specific users. Use this to trigger onboarding, role change, or offboarding processes immediately. | required workflow_id, user_ids |
entra-id-governance_apply_access_review_decisions | Apply the decisions of a completed access review instance. This enforces the approve/deny decisions by adding or removing access. | required definition_id, instance_id |
entra-id-governance_create_access_package_assignment_request | Create an access package assignment request to grant or revoke a user’s access to a package. Supports self-service requests and admin-driven assignments. | required request_typeoptional access_package_id, assignment_id, assignment_policy_id, justification, target_user_id |
entra-id-governance_create_group_assignment_request | Create a group assignment request to directly assign, activate (JIT), or deactivate privileged group membership or ownership. | required action, principal_id, group_id, access_idoptional expiration_date_time, expiration_duration, expiration_type, justification, start_date_time |
entra-id-governance_create_group_eligibility_request | Create a group eligibility request to make a user eligible for privileged group membership or ownership (or remove/extend/renew eligibility). | required action, principal_id, group_id, access_idoptional expiration_date_time, expiration_duration, expiration_type, justification, start_date_time |
entra-id-governance_create_role_assignment_request | Create a role assignment request to directly assign, activate (JIT), or deactivate a privileged Entra role. Use selfActivate to activate an eligible role with justification. | required action, principal_id, role_definition_idoptional expiration_date_time, expiration_duration, expiration_type, justification, start_date_time |
entra-id-governance_create_role_eligibility_request | Create a role eligibility request to make a user eligible for a privileged Entra role (or remove/extend/renew eligibility). Eligible users can then activate the role via JIT when needed. | required action, principal_id, role_definition_idoptional expiration_date_time, expiration_duration, expiration_type, justification, start_date_time |
entra-id-governance_get_access_package | Get details of a specific access package by ID, including its description and catalog. | required access_package_id |
entra-id-governance_get_access_review_definition | Get details of a specific access review definition, including its scope, reviewers, and recurrence settings. | required definition_id |
entra-id-governance_get_lifecycle_workflow | Get details of a specific lifecycle workflow including its tasks, execution conditions, and scope. | required workflow_id |
entra-id-governance_list_access_package_assignments | List current access package assignments. Shows which users have been granted access to which packages and the assignment state. | optional access_package_id, filter_query, skip, top |
entra-id-governance_list_access_package_catalogs | List access package catalogs. Catalogs are containers that group related access packages. | optional filter_query, skip, top |
entra-id-governance_list_access_packages | List access packages with optional filtering by catalog. Access packages bundle resources (groups, apps, sites) that users can request access to. | optional catalog_id, filter_query, skip, top |
entra-id-governance_list_access_review_decisions | List decisions for a specific access review instance. Shows who was reviewed and what decision was made (Approve, Deny, NotReviewed). | required definition_id, instance_idoptional filter_query, skip, top |
entra-id-governance_list_access_review_definitions | List access review schedule definitions. Access reviews periodically verify that users still need access to resources. | optional filter_query, skip, top |
entra-id-governance_list_access_review_instances | List review instances for a given access review definition. Each instance represents a specific review period. | required definition_idoptional filter_query, skip, top |
entra-id-governance_list_group_assignment_schedules | List who has active privileged group membership or ownership. Shows both permanent and time-bound active group assignments. | optional access_id, group_id, principal_id, skip, top |
entra-id-governance_list_group_eligibility_schedules | List who is eligible for privileged group membership or ownership. Shows JIT-eligible group assignments that users can activate when needed. | optional access_id, group_id, principal_id, skip, top |
entra-id-governance_list_lifecycle_workflow_runs | List execution history for a lifecycle workflow. Shows when the workflow ran, how many users were processed, and the outcome. | required workflow_idoptional filter_query, skip, top |
entra-id-governance_list_lifecycle_workflows | List lifecycle workflows for automating identity processes. Workflows can be categorized as joiner (onboarding), mover (role change), or leaver (offboarding). | optional category, filter_query, skip, top |
entra-id-governance_list_role_assignment_schedules | List who currently has active privileged Entra role assignments. Shows both permanent and time-bound active assignments. | optional principal_id, role_definition_id, skip, top |
entra-id-governance_list_role_definitions | List available Entra directory role definitions (e.g., Global Administrator, User Administrator). Use this to find role definition IDs needed for PIM operations. This endpoint does not support pagination — it always returns the full list. | optional filter_query |
entra-id-governance_list_role_eligibility_schedules | List who is currently eligible for which privileged Entra roles. Shows JIT-eligible assignments that users can activate when needed. | optional principal_id, role_definition_id, skip, top |
Microsoft Intune
Section titled “Microsoft Intune”14 tools. Available as 4 connections: Microsoft Intune (OAuth 2.0), Microsoft Intune (Application) (OAuth 2.0 client credentials), Microsoft Intune (GCC High) (OAuth 2.0), Microsoft Intune (GCC High, Application) (OAuth 2.0 client credentials).
| Tool | Description | Arguments |
|---|---|---|
microsoft-intune_get_compliance_policy | Get a single device compliance policy by ID, including its configured settings and rules | required policy_id |
microsoft-intune_get_device_configuration | Get a single device configuration profile by ID, including its platform-specific settings | required configuration_id |
microsoft-intune_get_managed_device | Get a single Intune managed device by ID, including hardware details, OS info, compliance state, and enrollment information | required device_id |
microsoft-intune_get_mobile_app | Get a single managed mobile app by ID, including detailed metadata such as publisher, version, and install status summary | required app_id |
microsoft-intune_list_compliance_policies | List Intune device compliance policies that define rules devices must meet to be considered compliant. Returns {value: […], ‘@odata.nextLink’: …} when more pages are available. | optional skip, top |
microsoft-intune_list_compliance_policy_device_statuses | List per-device compliance status for a specific policy, showing which devices are compliant, noncompliant, or in error. Returns {value: […], ‘@odata.nextLink’: …} when more pages are available. | required policy_idoptional skip, top |
microsoft-intune_list_device_configuration_device_statuses | List per-device status for a device configuration profile, showing which devices have successfully applied the configuration. Returns {value: […], ‘@odata.nextLink’: …} when more pages are available. | required configuration_idoptional skip, top |
microsoft-intune_list_device_configurations | List Intune device configuration profiles that define settings and restrictions applied to managed devices. Returns {value: […], ‘@odata.nextLink’: …} when more pages are available. | optional skip, top |
microsoft-intune_list_managed_devices | List Intune managed devices with filtering by device name, OS, compliance state, management agent, and user principal name. Returns {value: […], ‘@odata.nextLink’: …} when more pages are available. | optional compliance_state, device_name, management_agent, operating_system, skip, top, user_principal_name |
microsoft-intune_list_mobile_app_device_statuses | List per-device install status for a specific mobile app, showing which devices have the app installed, pending, or failed. Uses the beta Graph API endpoint. Returns {value: […]}. | required app_idoptional skip, top |
microsoft-intune_list_mobile_apps | List Intune managed mobile apps with filtering by display name and app type (e.g., iOS store app, Windows app). Returns {value: […], ‘@odata.nextLink’: …} when more pages are available. | optional app_type, display_name, skip, top |
microsoft-intune_retire_managed_device | Retire a managed device, removing company data and management profiles while keeping personal data intact | required device_id |
microsoft-intune_sync_managed_device | Trigger a sync on a managed device, forcing it to check in with Intune for the latest policies and configurations | required device_id |
microsoft-intune_wipe_managed_device | Wipe (factory reset) a managed device, removing all data. Optionally keep enrollment data or user data. | required device_idoptional keep_enrollment_data, keep_user_data |
44 tools. Credentials are supplied in the connection settings.
| Tool | Description | Arguments |
|---|---|---|
okta-private-key_activate_application | Activate an Okta application | required app_id |
okta-private-key_activate_policy | Activate an Okta policy | required policy_id |
okta-private-key_activate_policy_rule | Activate a specific Okta policy rule | required policy_id, rule_id |
okta-private-key_activate_user | Activate or reactivate an Okta user. Reactivates deprovisioned (deactivated) users via the same endpoint. By default (send_email=false) Okta returns an activation URL instead of emailing the user. | required user_idoptional send_email |
okta-private-key_add_user_to_group | Add an Okta user to a specific Okta group | required group_id, user_id |
okta-private-key_assign_user_to_application | Assign an Okta user to an application, optionally with app-specific credentials and profile | required app_id, user_idoptional credentials, profile |
okta-private-key_create_application | Create a new Okta application | required app_configoptional activate |
okta-private-key_create_group | Create a new Okta group | required profile |
okta-private-key_create_policy | Create a new Okta policy | required policy_data |
okta-private-key_create_policy_rule | Create a new rule under a specific Okta policy | required policy_id, rule_data |
okta-private-key_create_user | Create a new Okta user | required profile |
okta-private-key_deactivate_application | Deactivate an Okta application | required app_id |
okta-private-key_deactivate_policy | Deactivate an Okta policy | required policy_id |
okta-private-key_deactivate_policy_rule | Deactivate a specific Okta policy rule | required policy_id, rule_id |
okta-private-key_deactivate_user | Deactivate an Okta user so it can no longer access applications | required user_id |
okta-private-key_delete_application | Permanently delete an Okta application. This is destructive and cannot be undone. | required app_id |
okta-private-key_delete_deactivated_user | Permanently delete a previously deactivated Okta user | required user_id |
okta-private-key_delete_group | Permanently delete an Okta group. This is destructive and cannot be undone. | required group_id |
okta-private-key_delete_policy | Delete an Okta policy. This is destructive and cannot be undone. | required policy_id |
okta-private-key_delete_policy_rule | Delete an Okta policy rule. This is destructive and cannot be undone. | required policy_id, rule_id |
okta-private-key_expire_password | Expire an Okta user’s password, forcing a change at next sign-in | required user_id |
okta-private-key_get_application | Retrieve a specific Okta application by ID | required app_idoptional expand |
okta-private-key_get_group | Retrieve a specific Okta group by ID | required group_id |
okta-private-key_get_logs | Retrieve Okta system logs with optional filtering and pagination support | optional after, fetch_all, filter_query, limit, q, since, until |
okta-private-key_get_policy | Retrieve a specific Okta policy by ID | required policy_id |
okta-private-key_get_policy_rule | Retrieve a specific Okta policy rule by ID | required policy_id, rule_id |
okta-private-key_get_user | Retrieve a specific Okta user by ID | required user_id |
okta-private-key_get_user_profile_attributes | Return the profile attribute names found on a sample user in this Okta org. Returns an empty list if the org has no users. | — |
okta-private-key_list_applications | List Okta applications with optional filtering and pagination support | optional after, expand, filter_query, include_non_deleted, limit, q |
okta-private-key_list_group_apps | List applications assigned to a specific Okta group | required group_id |
okta-private-key_list_group_users | List users assigned to a specific Okta group | required group_idoptional after, fetch_all, limit |
okta-private-key_list_groups | List Okta groups with optional search, filter, and pagination support | optional after, fetch_all, filter_query, limit, q, search |
okta-private-key_list_policies | List Okta policies for a specific policy type | required policy_typeoptional after, limit, q, status |
okta-private-key_list_policy_rules | List rules for a specific Okta policy | required policy_id |
okta-private-key_list_users | List Okta users with optional search, filter, and pagination support | optional after, fetch_all, filter_query, limit, q, search |
okta-private-key_remove_user_from_group | Remove an Okta user from a specific Okta group | required group_id, user_id |
okta-private-key_reset_password | Generate a password reset for an Okta user. By default (send_email=true) Okta emails the reset link and returns no link; set send_email=false to return a resetPasswordUrl instead. | required user_idoptional send_email |
okta-private-key_suspend_user | Suspend an active Okta user, blocking sign-in while preserving the account | required user_id |
okta-private-key_unsuspend_user | Unsuspend a suspended Okta user, returning the account to active status | required user_id |
okta-private-key_update_application | Update an existing Okta application | required app_id, app_config |
okta-private-key_update_group | Update an existing Okta group | required group_id, profile |
okta-private-key_update_policy | Update an existing Okta policy | required policy_id, policy_data |
okta-private-key_update_policy_rule | Update an existing Okta policy rule | required policy_id, rule_id, rule_data |
okta-private-key_update_user | Partially update an Okta user profile using Okta’s POST semantics | required user_id, profile |
SailPoint
Section titled “SailPoint”59 tools. Connect with OAuth 2.0 client credentials.
| Tool | Description | Arguments |
|---|---|---|
sailpoint_activate_certification_campaign | Activate a SailPoint certification campaign to start the review process. The campaign deadline must be in the future. Once activated, reviewers receive their certification tasks. Requires CERT_ADMIN or ORG_ADMIN role. | required idoptional time_zone |
sailpoint_approve_access_request | Approve a pending access request approval. Only the owner of the approval and ORG_ADMIN users can perform this action. | required approvalIdoptional comment |
sailpoint_cancel_access_request | Cancel a pending access request. Can only cancel requests that have not passed the approval step. Users with ORG_ADMIN role or the original requestor can cancel. | required accountActivityId, comment |
sailpoint_check_sod_violations | Check SOD violations for an identity and access references. This API initiates a SOD policy verification asynchronously and returns a request ID that can be used to check the status. | required identityId, accessRefs |
sailpoint_create_access_profile | Create a new SailPoint access profile. Access profiles group entitlements from a single source. SOURCE_SUBADMIN or ORG_ADMIN must be associated with the source. | required name, owner, sourceoptional accessRequestConfig, description, enabled, entitlements, provisioningCriteria, requestable, revokeRequestConfig, segments |
sailpoint_create_access_request | Submit an access request to grant or revoke access in SailPoint. Supports roles, access profiles, and entitlements. Requests are processed asynchronously. | required requestedFor, requestedItemsoptional clientMetadata, requestType |
sailpoint_create_certification_campaign | Create a new SailPoint certification campaign. Requires CERT_ADMIN or ORG_ADMIN role. | required name, typeoptional autoRevokeAllowed, correlatedStatus, deadline, description, emailNotificationEnabled, filter, machineAccountCampaignInfo, mandatoryCommentRequirement, recommendationsEnabled, roleCompositionCampaignInfo, searchCampaignInfo, sourceOwnerCampaignInfo, sunsetCommentsRequired |
sailpoint_create_role | Create a new SailPoint role. Roles bundle access profiles and entitlements for assignment to identities. ROLE_SUBADMIN users can only create roles with access profiles from sources they administer. | required name, owneroptional accessProfiles, accessRequestConfig, description, enabled, entitlements, membership, requestable, revokeRequestConfig, segments |
sailpoint_create_sod_policy | Create a new SailPoint SOD (Segregation of Duties) policy. Requires ORG_ADMIN role. Defines conflicting access criteria that should not be held by the same identity. | required name, conflictingAccessCriteriaoptional compensatingControls, correctionAdvice, description, externalPolicyReference, ownerRef, scheduled, state, tags, violationOwnerAssignmentConfig |
sailpoint_create_source | Create a new SailPoint source/application. Requires idn:source:manage scope and SOURCE_ADMIN or ORG_ADMIN rights. The source defines a connection to an external system for identity data. | required name, owner, connectoroptional authoritative, cluster, connectorAttributes, connectorClass, deleteThreshold, description, features, provision_as_csv, schemas, type |
sailpoint_create_workflow | Create a new SailPoint workflow for automation and process management. | required name, owneroptional definition, description, enabled, trigger |
sailpoint_delete_access_profile | Delete a SailPoint access profile. Must not be in use by applications, lifecycle states, or roles. | required id |
sailpoint_delete_role | Delete a SailPoint role by ID. | required id |
sailpoint_delete_sod_policy | Delete a SailPoint SOD policy. Requires ORG_ADMIN role. Supports soft delete (logical=true, recoverable) and hard delete (logical=false, permanent). | required idoptional logical |
sailpoint_delete_source | Delete a SailPoint source/application. Requires idn:source:manage scope and SOURCE_ADMIN or ORG_ADMIN rights. | required id |
sailpoint_delete_workflow | Delete a SailPoint workflow by ID. | required id |
sailpoint_disable_account | Disable a SailPoint account. Submits an asynchronous task to disable the account and returns the task ID for tracking. | required idoptional externalVerificationId, forceProvisioning |
sailpoint_enable_account | Enable a SailPoint account. Submits an asynchronous task to enable the account and returns the task ID for tracking. | required idoptional externalVerificationId, forceProvisioning |
sailpoint_forward_access_request | Forward an access request approval to a new owner. Only the owner of the approval and ORG_ADMIN users can perform this action. | required approvalId, newOwnerId, comment |
sailpoint_get_access_profile | Get a SailPoint access profile by its ID. Returns detailed information about a specific access profile. | required id |
sailpoint_get_account | Get a single SailPoint account by ID using v2025 API. Returns detailed information about a specific account. | required id |
sailpoint_get_certification_campaign | Get a single SailPoint certification campaign by ID. Returns full campaign details including status, deadline, and configuration. | required id |
sailpoint_get_identity | Get a single identity by ID using v2025 API. Returns detailed information about a specific identity. | required id |
sailpoint_get_identity_profile | Get a single identity profile by ID. This API returns a single identity profile by its ID. | required id |
sailpoint_get_isc_run_context | Read-only ISC run-context diagnostics. Returns recent task results so an operator can see current run state before taking action. No mutations. Reads the experimental v2025 task-status endpoint. | optional filters, limit |
sailpoint_get_job_status | Poll an account aggregation job by ID and return its status and progress (NEW/CHANGED/DELETED account counts). Read-only. | required id |
sailpoint_get_role | Get a role by ID. A user with ROLE_SUBADMIN authority may only call this API if all access profiles included in the role are associated to sources with management workgroups of the ROLE_SUBADMIN is a member of. | required id |
sailpoint_get_sod_policy | Get a specified SOD (Segregation of Duties) policy by its ID. Requires role of ORG_ADMIN. | required id |
sailpoint_get_source | Get a single source by ID using v2025 API. Returns detailed information about a specific source including SSO/MFA configuration. | required id |
sailpoint_get_task_status | Poll a SailPoint task by ID and return its status (completed, failed, or running). Read-only. Covers account/entitlement aggregation and other background tasks. The upstream v2025 task-status endpoint is experimental. | required id |
sailpoint_get_workflow | Get a single workflow by ID using v2025 API. Returns detailed information about a specific workflow including its definition and configuration. | required id |
sailpoint_list_access_profile_entitlements | Get a list of an access profile’s entitlements. A SOURCE_SUBADMIN user must have access to the source associated with the specified access profile. | required idoptional count, filters, limit, offset, sorters |
sailpoint_list_access_profiles | Get a list of SailPoint access profiles. Note: When you filter for access profiles that have the ”+” symbol in their names, the response is blank. | optional count, filters, for_segment_ids, for_subadmin, include_unsegmented, limit, offset, sorters |
sailpoint_list_access_request_status | Get SailPoint access request statuses with optional filtering and pagination using v2025 API. Any user can get the status of their own access requests. ORG_ADMIN is required to get statuses for other users. | optional assigned-to, count, filters, limit, offset, regarding-identity, request-state, requested-by, requested-for, sorters |
sailpoint_list_account_entitlements | Get entitlements for a specific account using v3 API. Returns all entitlements associated with the specified account. | required accountIdoptional count, filters, limit, offset, sorters |
sailpoint_list_accounts | Get a list of SailPoint accounts with optional filtering, sorting, and pagination support using v2025 API. IMPORTANT: To get ALL account data, make multiple tool calls with the required offset values to paginate through all results. | optional count, filters, limit, offset, sorters |
sailpoint_list_certification_campaigns | Get a list of SailPoint certification campaigns with optional filtering, sorting, and pagination. | optional count, filters, limit, offset, sorters |
sailpoint_list_completed_approvals | Get a list of completed access request approvals with optional filtering, sorting, and pagination. ORG_ADMIN users can view all completed approvals. Non-ORG_ADMIN users can only view their own. | optional count, filters, limit, offset, owner-id, sorters |
sailpoint_list_identities | Get a list of identities with optional filtering, sorting, and pagination support using v2025 API. By default, returns only correlated identities (defaultFilter=CORRELATED_ONLY). | optional count, defaultFilter, filters, limit, offset, sorters |
sailpoint_list_identity_profiles | Get a list of identity profiles. This API returns a list of identity profiles based on the specified query parameters with optional filtering, sorting, and pagination. | optional count, filters, limit, offset, sorters |
sailpoint_list_pending_approvals | Get a list of pending access request approvals with optional filtering, sorting, and pagination. ORG_ADMIN users can view all pending approvals. Non-ORG_ADMIN users can only view their own. | optional count, filters, limit, offset, owner-id, sorters |
sailpoint_list_role_assigned_identities | List identities assigned a role. This API lists all identities assigned to a specific role with optional filtering, sorting, and pagination. | required idoptional count, filters, limit, offset, sorters |
sailpoint_list_roles | Get a list of Roles. This API returns a list of Roles with optional filtering, sorting, and pagination support. IMPORTANT: To get ALL role data, make multiple tool calls with different offset values to paginate through all results. | optional count, filters, for_segment_ids, for_subadmin, include_unsegmented, limit, offset, sorters |
sailpoint_list_sod_policies | Get a list of all SOD (Segregation of Duties) policies. Requires role of ORG_ADMIN. | optional count, filters, limit, offset, sorters |
sailpoint_list_sources | Get a list of sources/applications for inventory and configuration management using v2025 API. IMPORTANT: To get ALL source data, make multiple tool calls with different offset values to paginate through all results. | optional count, filters, limit, offset, sorters |
sailpoint_list_task_results | List completed/historical SailPoint task results with optional filtering, sorting, and pagination. Read-only. The upstream v2025 task-status endpoint is experimental. | optional count, filters, limit, offset, sorters |
sailpoint_list_workflows | Get a list of workflows for automation and process management using v2025 API. | optional count, filters, limit, offset, sorters |
sailpoint_patch_access_profile | Update an existing SailPoint access profile using JSON Patch (RFC 6902). Patchable fields: name, description, enabled, owner, requestable, accessRequestConfig, revokeRequestConfig, segments, entitlements, provisioningCriteria, source. | required id, operations |
sailpoint_patch_role | Update an existing SailPoint role using JSON Patch (RFC 6902). | required id, operations |
sailpoint_patch_sod_policy | Update an existing SailPoint SOD policy using JSON Patch (RFC 6902). Requires ORG_ADMIN role. | required id, operations |
sailpoint_patch_source | Update an existing SailPoint source using JSON Patch (RFC 6902). Requires idn:source:manage scope and SOURCE_ADMIN or ORG_ADMIN rights. | required id, operations |
sailpoint_patch_workflow | Update an existing SailPoint workflow using JSON Patch (RFC 6902). Patchable fields: name, owner, description, enabled, definition, trigger. | required id, operations |
sailpoint_reject_access_request | Reject a pending access request approval. Only the owner of the approval and ORG_ADMIN users can perform this action. | required approvalIdoptional comment |
sailpoint_reprocess_identity_jml | Reprocess identity JML lifecycle state (recalculate attributes, role assignments, provisioning, manager relationships) for one or more identities. Guardrail: single identity or a capped batch only; unbounded batches are rejected. | required identity_ids |
sailpoint_rerun_source_aggregation | Re-run a source account aggregation. Guardrails: source_id must be in allowed_source_ids (allowlist), DELTA aggregation by default, and FULL (unoptimized) aggregation requires approve_full_aggregation=true. | required source_id, allowed_source_idsoptional aggregation_type, approve_full_aggregation |
sailpoint_retry_failed_job | Retry a failed source aggregation job. | required source_id, allowed_source_ids, failure_status, attempt |
sailpoint_search | Search across SailPoint objects using Elasticsearch syntax. Supports searching identities, roles, access profiles, entitlements, events, and account activities. Powerful tool for querying across all SailPoint data. | required indicesoptional count, includeNested, limit, offset, query, queryDsl, searchAfter, sort |
sailpoint_test_workflow | Test a SailPoint workflow by executing it with mock trigger input. Useful for validating workflow logic before enabling. | required id, input |
sailpoint_unlock_account | Unlock a SailPoint account. Submits an asynchronous task to unlock the account and returns the task ID for tracking. Requires idn:accounts-provisioning:manage scope for forceProvisioning. | required idoptional externalVerificationId, forceProvisioning |
Saviynt Enterprise Identity Cloud
Section titled “Saviynt Enterprise Identity Cloud”24 tools. Connect with Basic auth.
| Tool | Description | Arguments |
|---|---|---|
saviynt_bulk_upload_users | Bulk create/update users from a CSV in Saviynt (uploadUserRequest). Sent as multipart/form-data with the CSV file plus option flags. | required csv_contentoptional checkrules, delimiter, generate_email, generate_system_username, zero_day_provisioning |
saviynt_complete_provisioning_task | Complete one or more Saviynt provisioning tasks and verify the outcome. A single task with no extra fields completes via completetask; multiple tasks, or a comment/ticket/metadata, complete via updateTasks (updatetype=completetask). | required task_idsoptional comments, provisioning_metadata, ticket_id, verify |
saviynt_create_user | Create a user in Saviynt (createUser). Core attributes are named params; pass arbitrary extra attributes via attributes. | required usernameoptional attributes, email, firstname, lastname, statuskey, systemusername, validateagainstpolicy |
saviynt_decide_access_request | Act on a pending Saviynt access request: approve, reject, or cancel (discontinue) it. Approve and reject both need both identifiers of the pending request: its requestkey and its requestid, as returned by list_access_requests. | required request_key, actionoptional reason, request_id |
saviynt_discontinue_provisioning_task | Discontinue one or more Saviynt provisioning tasks that are still new or pending, recording comments on each task’s history, then verify their status. Irreversible: a discontinued task cannot be completed later. | required task_ids, commentsoptional discontinue_associated, verify |
saviynt_fetch_job_metadata | Fetch metadata and run history for a Saviynt job (fetchJobMetadata). Read-only; complements get_job_status for completion detail. | required jobnameoptional jobgroup, jobstartdate, triggername |
saviynt_get_access_request | Get one access request’s detail with optional approval and user-access sections. | required request_idoptional include, response_format, username |
saviynt_get_job_status | Get the current status of a Saviynt job trigger (checkJobStatus). Read-only; use to poll a trigger fired via the run_* tools. Returns errorCode/msg. | required jobname, jobgroupoptional triggername |
saviynt_get_provisioning_task_status | Get the status of a single Saviynt provisioning task by id (checkTaskStatus). Read-only. | required taskid |
saviynt_get_tasks | List provisioning tasks in Saviynt via fetchTasks. status is required (the API has no ERROR value, so errored tasks are not queryable here). | required statusoptional endpoint, max_results, offset, task_type, username |
saviynt_get_user_access | Fetch one user’s profile, access, and in-flight work as one view. | required usernameoptional endpoint, include, max_per_section, response_format |
saviynt_list_access_requests | List Saviynt access-request history as summary rows (fetchRequestHistory): one row per request with its requestkey, requestid, requestor, status, and dates. | optional max_results, offset, order, request_id, requested_for, sort, status, username |
saviynt_list_certification_campaigns | List certification campaigns in Saviynt (campaigns pending certification). Optionally scope to a certifier username; supports max/offset pagination. | optional max_results, offset, username |
saviynt_list_users | List or search users in Saviynt Enterprise Identity Cloud. Filter by username and limit the returned attributes; supports max/offset pagination. Use manager to list one manager’s direct reports in a single call. | optional manager, max_results, offset, user_response_fields, username |
saviynt_process_identity_rules | Fire a Saviynt identity-rules processing job trigger (runJobTrigger). Async: the trigger is queued, not awaited — poll get_job_status / fetch_job_metadata for completion. | required jobname, jobgroup, triggernameoptional create_job_if_does_not_exist, value_map |
saviynt_query_entitlements | Query entitlements in Saviynt Enterprise Identity Cloud. Filter by entitlement type and endpoint (application), restrict returned fields, and paginate with max/offset. | optional endpoint, entitlement_response_fields, entitlement_type, max_results, offset |
saviynt_run_identity_refresh | Fire a Saviynt identity-refresh job trigger (runJobTrigger). Async: the trigger is queued, not awaited — poll get_job_status / fetch_job_metadata for completion. jobname/jobgroup/triggername are tenant-specific and caller-supplied. | required jobname, jobgroup, triggernameoptional create_job_if_does_not_exist, value_map |
saviynt_run_source_import_or_aggregation | Fire a Saviynt source-import / aggregation job trigger (runJobTrigger). Async: the trigger is queued, not awaited — poll get_job_status / fetch_job_metadata for completion. | required jobname, jobgroup, triggernameoptional create_job_if_does_not_exist, value_map |
saviynt_run_ws_retry_job | Fire the Saviynt WSRETRY job trigger to retry failed provisioning tasks (runJobTrigger). Async: poll get_job_status / fetch_job_metadata for completion. | required triggernameoptional create_job_if_does_not_exist, jobgroup, jobname, security_systems, task_types |
saviynt_submit_access_request | Submit an access request in Saviynt (requestAccess) — request one or more entitlements/accounts for a user. The endpoint apiName is version-dependent: a 404 may mean this tenant uses a different apiName. | required username, requestor, requestaccessoptional comments |
saviynt_submit_user_update_request | Submit a governed user-update request in Saviynt (updateUserRequest) — routed through request workflow rather than applied directly. The endpoint apiName is version-dependent: a 404 may mean this tenant uses a different apiName. | required username, attributes |
saviynt_update_sav_role_members | Add users to, or remove users from, a Saviynt SAV role (the platform roles that control what a user can do in Saviynt itself, not application access). | required sav_role, usernames, action |
saviynt_update_user | Update an existing Saviynt user (updateUser). username identifies the record; changed attributes are supplied via attributes. | required username, attributes |
saviynt_upsert_user_group | Create a Saviynt user group or modify an existing one (createUpdateUserGroup handles both). usergroup_name identifies the group. | required usergroup_nameoptional add_members, attributes, description, remove_members |
