Skip to content

Identity and secrets

Directory, governance, and secret-management systems an agent can inspect and change. 10 integrations, 274 tools.

Tool names below are the fully qualified names an agent sees once the integration is connected. Where an integration offers more than one connection, the names shown use the primary connection’s prefix; connecting through another variant prefixes its tools with that variant’s own integration ID instead. See Tool Catalog for how tools are granted and named.

22 tools. Connect with OAuth 2.0 client credentials.

ToolDescriptionArguments
cisco-secure-access_create_application_listCreate a new application list for grouping cloud applications in policiesrequired name
optional application_ids
cisco-secure-access_create_destination_listCreate a new destination list (block or allow list) with optional initial destinationsrequired name
optional destinations, is_global
cisco-secure-access_create_internal_networkCreate a new internal network with IP address, prefix length, and optional site/tunnel associationrequired name, ip_address, prefix_length
optional site_id, tunnel_id
cisco-secure-access_create_private_resourceCreate a new private resource for ZTNA access with addresses and protocolsrequired name, addresses
optional description, protocols
cisco-secure-access_delete_application_listDelete an application list by IDrequired application_list_id
cisco-secure-access_delete_destination_listDelete a destination list by IDrequired destination_list_id
cisco-secure-access_delete_private_resourceDelete a private resource by IDrequired resource_id
cisco-secure-access_get_activityGet security activity events (DNS, proxy, firewall, ZTNA, intrusion) within a time range with filteringrequired from_time, to_time
optional categories, domains, ip, limit, offset, verdict
cisco-secure-access_get_application_listGet a specific application list by ID including its member applicationsrequired application_list_id
cisco-secure-access_get_destination_listGet a specific destination list by ID including its metadata and destination countrequired destination_list_id
cisco-secure-access_get_dns_activityGet DNS-specific activity events with domain, category, and verdict filtering within a time rangerequired from_time, to_time
optional categories, domains, limit, offset, verdict
cisco-secure-access_get_internal_networkGet a specific internal network by ID including its IP range and site associationrequired network_id
cisco-secure-access_get_private_resourceGet a specific private resource by ID including its addresses, protocols, and configurationrequired resource_id
cisco-secure-access_investigate_domainGet domain security status, risk categorization, and content categories for a single domainrequired domain
cisco-secure-access_investigate_domains_bulkBulk domain lookup — get security status and categorization for up to 1000 domains at oncerequired domains
cisco-secure-access_list_application_listsList cloud application lists used to group apps for policy enforcementoptional limit, page
cisco-secure-access_list_destination_listsList all Cisco Secure Access destination lists (block/allow lists of domains, URLs, and IPs) with paginationoptional limit, page
cisco-secure-access_list_internal_networksList internal networks (subnets) configured in Cisco Secure Accessoptional limit, page
cisco-secure-access_list_private_resourcesList private resources/applications configured for ZTNA (Zero Trust Network Access)optional limit, page
cisco-secure-access_list_roaming_computersList enrolled roaming computers/devices with their DNS and internet security statusoptional limit, page
cisco-secure-access_manage_destinationsAdd or remove destinations (domains/URLs/IPs) in a destination list. Use action=‘add’ with destinations, or action=‘remove’ with destination_idsrequired destination_list_id, action
optional destination_ids, destinations
cisco-secure-access_update_destination_listUpdate a destination list’s namerequired destination_list_id
optional name

30 tools. Connect with API key.

ToolDescriptionArguments
cyberark-privilege-cloud_activate_platformActivate a target platform so it can be used for new accounts.required platform_id
cyberark-privilege-cloud_add_safe_memberGrant a user, group, or role access to a safe with specific permissions.required safe_name, member_name, permissions
optional member_type
cyberark-privilege-cloud_change_account_passwordInitiate a CPM-managed password change for an account. The CPM will generate and set a new password on the target.required account_id
cyberark-privilege-cloud_create_accountProvision a new privileged account in CyberArk. Requires a safe name and platform ID at minimum.required safe_name, platform_id
optional address, name, properties, secret, secret_type, user_name
cyberark-privilege-cloud_create_safeCreate a new safe in CyberArk for storing privileged accounts.required safe_name
optional description, managing_cpm, number_of_days_retention
cyberark-privilege-cloud_deactivate_platformDeactivate a target platform to prevent it from being assigned to new accounts.required platform_id
cyberark-privilege-cloud_delete_accountDelete a privileged account from CyberArk by its unique ID.required account_id
cyberark-privilege-cloud_delete_platformDelete a target platform from CyberArk by its numeric ID.required platform_id
cyberark-privilege-cloud_delete_safeDelete a safe from CyberArk by its name.required safe_name
cyberark-privilege-cloud_duplicate_platformDuplicate an existing target platform with a new name.required platform_id, name
optional description
cyberark-privilege-cloud_export_platformExport a platform as a base64-encoded ZIP package.required platform_id
cyberark-privilege-cloud_get_accountGet full details of a privileged account by its unique ID.required account_id
cyberark-privilege-cloud_get_platformGet full details of a platform by its ID.required platform_id
cyberark-privilege-cloud_get_safeGet full details of a safe by its name.required safe_name
cyberark-privilege-cloud_get_safe_memberGet details of a specific member of a safe.required safe_name, member_name
cyberark-privilege-cloud_get_sessionGet full details of a privileged session recording by its ID.required session_id
cyberark-privilege-cloud_import_platformImport a platform from a ZIP package by reference. Pass source_url: a short-lived signed download URL minted by the mint_upload_url tool. The server fetches the ZIP bytes from source_url (binary-safe) and imports the platform.required source_url
cyberark-privilege-cloud_list_accountsList and search privileged accounts in CyberArk. Supports filtering by safe name, username, address, and platform.optional filter_query, limit, offset, safe_name, search
cyberark-privilege-cloud_list_live_sessionsList currently active (live) privileged sessions.optional limit, offset, search
cyberark-privilege-cloud_list_platformsList platforms available in CyberArk with optional search and type filter.optional platform_type, search
cyberark-privilege-cloud_list_safe_membersList all members (users, groups, roles) with access to a safe.required safe_name
optional filter_query
cyberark-privilege-cloud_list_safesList safes in CyberArk with optional search and pagination.optional limit, offset, search
cyberark-privilege-cloud_list_session_activitiesList all activities (commands, keystrokes) within a session recording.required session_id
cyberark-privilege-cloud_list_sessionsList privileged session recordings with optional search and pagination.optional limit, offset, search
cyberark-privilege-cloud_reconcile_account_passwordReconcile (sync) the password between CyberArk and the target system. Used when passwords are out of sync.required account_id
cyberark-privilege-cloud_remove_safe_memberRemove a member from a safe, revoking all their permissions.required safe_name, member_name
cyberark-privilege-cloud_update_accountUpdate an existing account using JSON Patch operations (RFC 6902). Example: [{‘op’: ‘replace’, ‘path’: ‘/address’, ‘value’: ‘10.0.0.1’}]required account_id, operations
cyberark-privilege-cloud_update_safeUpdate an existing safe’s configuration (description, CPM, retention).required safe_name
optional description, managing_cpm, number_of_days_retention
cyberark-privilege-cloud_update_safe_memberUpdate a safe member’s permissions.required safe_name, member_name, permissions
cyberark-privilege-cloud_verify_account_passwordVerify that the password stored in CyberArk matches the actual password on the target system.required account_id

10 tools. Connect with API key.

ToolDescriptionArguments
delinea-secret-server_change_secret_passwordRotate (change) the password on a secret. If new_password is omitted, Secret Server generates one according to the secret’s password policy.required secret_id
optional new_password
delinea-secret-server_checkin_secretCheck in a previously checked-out secret, ending exclusive access so other users can use it. Optionally force check-in (requires the ‘Force Check In’ permission).required secret_id
optional comment, force_check_in
delinea-secret-server_checkout_secretCheck out a secret that requires exclusive checkout before its credentials can be used. After checkout, call get_secret to read the value, then checkin_secret when finished.required secret_id
delinea-secret-server_create_secretCreate a new secret in a folder from a secret template. items is the list of template field values, e.g. [{‘fieldName’: ‘Password’, ‘itemValue’: ’…’, ‘slug’: ‘password’}].required name, folder_id, secret_template_id, items
optional site_id
delinea-secret-server_get_folderGet details of a folder by its ID, including child folders.required folder_id
delinea-secret-server_get_secretRetrieve a secret by ID, including its field values (e.g. username/password). For secrets that require a comment to view, pass comment. Use get_secret_summary to inspect metadata without exposing field values.required secret_id
optional comment
delinea-secret-server_get_secret_summaryGet non-sensitive summary metadata for a secret (name, folder, template, checkout/approval status) without returning field values.required secret_id
delinea-secret-server_search_foldersSearch and browse folders in Delinea Secret Server by free text and/or parent folder.optional only_root_folders, parent_folder_id, search_text, skip, take
delinea-secret-server_search_secretsSearch and list secrets in Delinea Secret Server by free text and/or folder. Returns secret metadata (id, name, folder), not field values — use get_secret to read the actual credentials.optional folder_id, include_subfolders, search_text, skip, take
delinea-secret-server_update_secretUpdate an existing secret. Pass the full secret object (as returned by get_secret) with your modifications applied — Secret Server expects the complete object on update (GET, modify, then update).required secret_id, secret

14 tools. Connect with API key.

ToolDescriptionArguments
doppler_create_configCreate a new branch config under a project environment. Requires a Personal or CLI token (Service Tokens cannot create configs).required project, environment, name
doppler_create_environmentCreate a new environment in a project (e.g., development, staging, production). Requires a Personal or CLI token (Service Tokens cannot create environments).required project, name, slug
optional personal_configs
doppler_create_projectCreate a new project in the Doppler workspace. Requires a Personal or CLI token (Service Tokens are scoped to a single config and cannot create projects).required name
optional description
doppler_delete_secretDelete a single secret from a config by name. Works with Service Tokens scoped to the target config.required project, config, name
doppler_get_activity_logGet details of a single activity log entry by IDrequired log
doppler_get_configGet details of a single config by project and config namerequired project, config
doppler_get_projectGet details of a single project by its slug identifierrequired project
doppler_get_secretGet a single secret’s value and metadata by namerequired project, config, name
doppler_list_activity_logsList activity logs for the workspace with optional paginationoptional fetch_all, page, per_page
doppler_list_configsList configs for a project, optionally filtered by environmentrequired project
optional environment, fetch_all, page, per_page
doppler_list_environmentsList all environments for a given project (e.g., development, staging, production)required project
doppler_list_projectsList all projects in the Doppler workspace with optional paginationoptional fetch_all, page, per_page
doppler_list_secretsList all secrets in a config. Returns an object with a ‘secrets’ array; each entry includes the secret name alongside the fields returned by the Doppler API (typically raw value, computed value, and note).required project, config
optional include_dynamic_secrets, include_managed_secrets
doppler_set_secretSet a single secret in a config (upsert). Works with Service Tokens scoped to the target config.required project, config, name, value

34 tools. Available as 4 connections: Microsoft Entra ID (OAuth 2.0), Microsoft Entra ID (Application) (OAuth 2.0 client credentials), Microsoft Entra ID (GCC High) (OAuth 2.0), Microsoft Entra ID (GCC High, Application) (OAuth 2.0 client credentials).

ToolDescriptionArguments
microsoft-entra-id_disable_user_accountDisable a user account so the user cannot sign in. Primary containment action for a compromised account; reverse it with enable_user_account.required user_id
microsoft-entra-id_enable_user_accountEnable a previously disabled user account so the user can sign in again.required user_id
microsoft-entra-id_evaluate_conditional_accessAnswer what conditional access would do for a sign-in that has not happened: the What If tool. Requires who is signing in — pass user_id (an object id or userPrincipalName) or service_principal_id.optional applied_policies_only, authentication_context_value, client_app_type, country, device_platform, include_applications, ip_address, service_principal_id, service_principal_risk_level, sign_in_risk_level, user_action, user_id, user_risk_level
microsoft-entra-id_get_authentication_sla_attainmentRead Microsoft Entra authentication SLA attainment by calendar month for this tenant.—
microsoft-entra-id_get_conditional_access_impact_summaryCount what conditional access actually did over a time window: how many sign-ins each policy allowed, blocked, or did not apply to, including report-only policies.optional application, days_back, group_by, max_records, policy_ids, user_principal_name
microsoft-entra-id_get_conditional_access_policyGet one conditional access policy by id, including its conditions and grant controls. Locations and authentication strengths appear as GUIDs; resolve them with list_named_locations and list_authentication_strengths.required policy_id
optional select
microsoft-entra-id_get_directory_audit_detailsGet one directory audit entry by id, with its full target-resource list.required directory_audit_id
optional select
microsoft-entra-id_get_directory_objects_by_idsResolve directory object ids to the objects themselves, in one call, for ids that came back from audit logs or group listings.required ids
optional types
microsoft-entra-id_get_directory_roleGet one directory role by object id or role template id. Only roles activated in the tenant are returned.optional role_id, role_template_id, select
microsoft-entra-id_get_groupGet one group by object id. Use list_groups to find an id from a name.required group_id
optional select
microsoft-entra-id_get_sign_in_detailsGet one sign-in event by id, including its status, device and location detail.required sign_in_id
optional select
microsoft-entra-id_get_userGet one directory user by object id or user principal name. Use list_users to find an id first when only a name is known.required user_id
optional select
microsoft-entra-id_get_user_inplace_hold_statusGet the in-place hold policies applied to a user, for legal hold and retention checks.required user_id
microsoft-entra-id_get_user_registration_detailsGet one user’s registered authentication methods and capabilities.required user_id
microsoft-entra-id_get_users_registered_by_methodCount users registered for each authentication method across the tenant, scoped by user type and directory role — for example how many privileged admins have registered a phishing-resistant method.optional included_user_roles, included_user_types
microsoft-entra-id_list_adfs_application_activityList AD FS relying parties with their sign-in volume and whether each can be migrated to Microsoft Entra ID, for planning an AD FS migration. Aggregated over the given period.optional period, skip_token
microsoft-entra-id_list_app_credential_sign_in_activityList each application credential — secret, certificate, or federated identity credential — with when it was last used to sign in and when it expires, so stale and expiring credentials can be found.optional filter_query, order_by, skip_token, top
microsoft-entra-id_list_application_sign_in_summaryList per-application sign-in counts with their success or failure status, to see which applications users are actually signing in to and where sign-ins are erroring.optional filter_query, order_by, skip_token, top
microsoft-entra-id_list_authentication_strengthsList authentication strength policies and the method combinations each accepts. Conditional access grant controls reference these by GUID, so call this to read what a policy actually requires.optional filter_query, order_by, select, top
microsoft-entra-id_list_conditional_access_policiesList conditional access policies with their state (enabled, disabled, or report-only).optional filter_query, order_by, select, skip_token, top
microsoft-entra-id_list_directory_auditsList directory audit entries — who changed what in the directory. Narrow with a filter such as ‘activityDateTime ge 2026-08-01T00:00:00Z’ before widening. When has_more is true, pass next_skip_token back as skip_token.optional filter_query, order_by, select, skip_token, top
microsoft-entra-id_list_directory_recommendationsList Microsoft Entra recommendations for this tenant — best-practice findings and Identity Secure Score improvements, with their status and priority. Filter on status to see only what is still open.optional filter_query, order_by, skip_token, top
microsoft-entra-id_list_directory_role_membersList the principals holding a directory role, identified by object id or role template id.optional role_id, role_template_id, select
microsoft-entra-id_list_directory_rolesList the directory roles activated in the tenant. A role that has never been activated does not appear.optional expand, filter_query, select
microsoft-entra-id_list_group_membersList a group’s members. Members can be users, groups, devices or service principals; set member_type to narrow to one kind.required group_id
optional count, expand, filter_query, member_type, order_by, search, select, skip_token, top
microsoft-entra-id_list_group_ownersList a group’s owners. Set owner_type to narrow to one directory kind.required group_id
optional count, expand, filter_query, owner_type, search, select, skip_token, top
microsoft-entra-id_list_groupsList groups in the directory. When has_more is true, pass next_skip_token back as skip_token.optional count, display_name_starts_with, expand, filter_query, mail_enabled, mail_nickname_starts_with, order_by, search, security_enabled, select, skip_token, top
microsoft-entra-id_list_named_locationsList named locations (IP ranges and country lists). Conditional access policies reference these by GUID, so call this to read what a policy’s location conditions actually mean.optional filter_query, order_by, select, skip_token, top
microsoft-entra-id_list_provisioning_object_summaryList provisioning events, which record identities synchronised into and out of the directory. When has_more is true, pass next_skip_token back as skip_token.optional count, filter_query, order_by, skip_token, top
microsoft-entra-id_list_service_principal_sign_in_activityList when each service principal last signed in, so unused ones can be found and retired. Covers delegated and app-only flows, as client and as resource. Filter with app_id eq '<guid>' for one application.optional filter_query, order_by, skip_token, top
microsoft-entra-id_list_sign_insList sign-in log entries. Graph charges for the span the query covers, so a large top over a wide period is slow enough to time out: keep top small, or bound the period with filter_query, and do not do neither.optional count, filter_query, select, skip_token, top
microsoft-entra-id_list_user_app_role_assignmentsList the application role assignments held by a user, which is how app access is granted in Entra ID.required user_id
optional count, filter_query, order_by, select, skip_token, top
microsoft-entra-id_list_user_registration_detailsList which authentication methods each user has registered, for multifactor and passwordless coverage reporting.optional filter_query
microsoft-entra-id_list_usersList directory users. The starts-with parameters match a prefix; search matches anywhere in a name or mail. When has_more is true, pass next_skip_token back as skip_token.optional account_enabled, count, display_name_starts_with, filter_query, mail_starts_with, order_by, search, select, skip_token, top, user_principal_name_starts_with

23 tools. Available as 2 connections: Microsoft Entra ID Governance (OAuth 2.0), Microsoft Entra ID Governance (GCC High) (OAuth 2.0).

ToolDescriptionArguments
entra-id-governance_activate_lifecycle_workflowRun a lifecycle workflow on-demand for specific users. Use this to trigger onboarding, role change, or offboarding processes immediately.required workflow_id, user_ids
entra-id-governance_apply_access_review_decisionsApply the decisions of a completed access review instance. This enforces the approve/deny decisions by adding or removing access.required definition_id, instance_id
entra-id-governance_create_access_package_assignment_requestCreate an access package assignment request to grant or revoke a user’s access to a package. Supports self-service requests and admin-driven assignments.required request_type
optional access_package_id, assignment_id, assignment_policy_id, justification, target_user_id
entra-id-governance_create_group_assignment_requestCreate a group assignment request to directly assign, activate (JIT), or deactivate privileged group membership or ownership.required action, principal_id, group_id, access_id
optional expiration_date_time, expiration_duration, expiration_type, justification, start_date_time
entra-id-governance_create_group_eligibility_requestCreate a group eligibility request to make a user eligible for privileged group membership or ownership (or remove/extend/renew eligibility).required action, principal_id, group_id, access_id
optional expiration_date_time, expiration_duration, expiration_type, justification, start_date_time
entra-id-governance_create_role_assignment_requestCreate a role assignment request to directly assign, activate (JIT), or deactivate a privileged Entra role. Use selfActivate to activate an eligible role with justification.required action, principal_id, role_definition_id
optional expiration_date_time, expiration_duration, expiration_type, justification, start_date_time
entra-id-governance_create_role_eligibility_requestCreate a role eligibility request to make a user eligible for a privileged Entra role (or remove/extend/renew eligibility). Eligible users can then activate the role via JIT when needed.required action, principal_id, role_definition_id
optional expiration_date_time, expiration_duration, expiration_type, justification, start_date_time
entra-id-governance_get_access_packageGet details of a specific access package by ID, including its description and catalog.required access_package_id
entra-id-governance_get_access_review_definitionGet details of a specific access review definition, including its scope, reviewers, and recurrence settings.required definition_id
entra-id-governance_get_lifecycle_workflowGet details of a specific lifecycle workflow including its tasks, execution conditions, and scope.required workflow_id
entra-id-governance_list_access_package_assignmentsList current access package assignments. Shows which users have been granted access to which packages and the assignment state.optional access_package_id, filter_query, skip, top
entra-id-governance_list_access_package_catalogsList access package catalogs. Catalogs are containers that group related access packages.optional filter_query, skip, top
entra-id-governance_list_access_packagesList access packages with optional filtering by catalog. Access packages bundle resources (groups, apps, sites) that users can request access to.optional catalog_id, filter_query, skip, top
entra-id-governance_list_access_review_decisionsList decisions for a specific access review instance. Shows who was reviewed and what decision was made (Approve, Deny, NotReviewed).required definition_id, instance_id
optional filter_query, skip, top
entra-id-governance_list_access_review_definitionsList access review schedule definitions. Access reviews periodically verify that users still need access to resources.optional filter_query, skip, top
entra-id-governance_list_access_review_instancesList review instances for a given access review definition. Each instance represents a specific review period.required definition_id
optional filter_query, skip, top
entra-id-governance_list_group_assignment_schedulesList who has active privileged group membership or ownership. Shows both permanent and time-bound active group assignments.optional access_id, group_id, principal_id, skip, top
entra-id-governance_list_group_eligibility_schedulesList who is eligible for privileged group membership or ownership. Shows JIT-eligible group assignments that users can activate when needed.optional access_id, group_id, principal_id, skip, top
entra-id-governance_list_lifecycle_workflow_runsList execution history for a lifecycle workflow. Shows when the workflow ran, how many users were processed, and the outcome.required workflow_id
optional filter_query, skip, top
entra-id-governance_list_lifecycle_workflowsList lifecycle workflows for automating identity processes. Workflows can be categorized as joiner (onboarding), mover (role change), or leaver (offboarding).optional category, filter_query, skip, top
entra-id-governance_list_role_assignment_schedulesList who currently has active privileged Entra role assignments. Shows both permanent and time-bound active assignments.optional principal_id, role_definition_id, skip, top
entra-id-governance_list_role_definitionsList available Entra directory role definitions (e.g., Global Administrator, User Administrator). Use this to find role definition IDs needed for PIM operations. This endpoint does not support pagination — it always returns the full list.optional filter_query
entra-id-governance_list_role_eligibility_schedulesList who is currently eligible for which privileged Entra roles. Shows JIT-eligible assignments that users can activate when needed.optional principal_id, role_definition_id, skip, top

14 tools. Available as 4 connections: Microsoft Intune (OAuth 2.0), Microsoft Intune (Application) (OAuth 2.0 client credentials), Microsoft Intune (GCC High) (OAuth 2.0), Microsoft Intune (GCC High, Application) (OAuth 2.0 client credentials).

ToolDescriptionArguments
microsoft-intune_get_compliance_policyGet a single device compliance policy by ID, including its configured settings and rulesrequired policy_id
microsoft-intune_get_device_configurationGet a single device configuration profile by ID, including its platform-specific settingsrequired configuration_id
microsoft-intune_get_managed_deviceGet a single Intune managed device by ID, including hardware details, OS info, compliance state, and enrollment informationrequired device_id
microsoft-intune_get_mobile_appGet a single managed mobile app by ID, including detailed metadata such as publisher, version, and install status summaryrequired app_id
microsoft-intune_list_compliance_policiesList Intune device compliance policies that define rules devices must meet to be considered compliant. Returns {value: […], ‘@odata.nextLink’: …} when more pages are available.optional skip, top
microsoft-intune_list_compliance_policy_device_statusesList per-device compliance status for a specific policy, showing which devices are compliant, noncompliant, or in error. Returns {value: […], ‘@odata.nextLink’: …} when more pages are available.required policy_id
optional skip, top
microsoft-intune_list_device_configuration_device_statusesList per-device status for a device configuration profile, showing which devices have successfully applied the configuration. Returns {value: […], ‘@odata.nextLink’: …} when more pages are available.required configuration_id
optional skip, top
microsoft-intune_list_device_configurationsList Intune device configuration profiles that define settings and restrictions applied to managed devices. Returns {value: […], ‘@odata.nextLink’: …} when more pages are available.optional skip, top
microsoft-intune_list_managed_devicesList Intune managed devices with filtering by device name, OS, compliance state, management agent, and user principal name. Returns {value: […], ‘@odata.nextLink’: …} when more pages are available.optional compliance_state, device_name, management_agent, operating_system, skip, top, user_principal_name
microsoft-intune_list_mobile_app_device_statusesList per-device install status for a specific mobile app, showing which devices have the app installed, pending, or failed. Uses the beta Graph API endpoint. Returns {value: […]}.required app_id
optional skip, top
microsoft-intune_list_mobile_appsList Intune managed mobile apps with filtering by display name and app type (e.g., iOS store app, Windows app). Returns {value: […], ‘@odata.nextLink’: …} when more pages are available.optional app_type, display_name, skip, top
microsoft-intune_retire_managed_deviceRetire a managed device, removing company data and management profiles while keeping personal data intactrequired device_id
microsoft-intune_sync_managed_deviceTrigger a sync on a managed device, forcing it to check in with Intune for the latest policies and configurationsrequired device_id
microsoft-intune_wipe_managed_deviceWipe (factory reset) a managed device, removing all data. Optionally keep enrollment data or user data.required device_id
optional keep_enrollment_data, keep_user_data

44 tools. Credentials are supplied in the connection settings.

ToolDescriptionArguments
okta-private-key_activate_applicationActivate an Okta applicationrequired app_id
okta-private-key_activate_policyActivate an Okta policyrequired policy_id
okta-private-key_activate_policy_ruleActivate a specific Okta policy rulerequired policy_id, rule_id
okta-private-key_activate_userActivate or reactivate an Okta user. Reactivates deprovisioned (deactivated) users via the same endpoint. By default (send_email=false) Okta returns an activation URL instead of emailing the user.required user_id
optional send_email
okta-private-key_add_user_to_groupAdd an Okta user to a specific Okta grouprequired group_id, user_id
okta-private-key_assign_user_to_applicationAssign an Okta user to an application, optionally with app-specific credentials and profilerequired app_id, user_id
optional credentials, profile
okta-private-key_create_applicationCreate a new Okta applicationrequired app_config
optional activate
okta-private-key_create_groupCreate a new Okta grouprequired profile
okta-private-key_create_policyCreate a new Okta policyrequired policy_data
okta-private-key_create_policy_ruleCreate a new rule under a specific Okta policyrequired policy_id, rule_data
okta-private-key_create_userCreate a new Okta userrequired profile
okta-private-key_deactivate_applicationDeactivate an Okta applicationrequired app_id
okta-private-key_deactivate_policyDeactivate an Okta policyrequired policy_id
okta-private-key_deactivate_policy_ruleDeactivate a specific Okta policy rulerequired policy_id, rule_id
okta-private-key_deactivate_userDeactivate an Okta user so it can no longer access applicationsrequired user_id
okta-private-key_delete_applicationPermanently delete an Okta application. This is destructive and cannot be undone.required app_id
okta-private-key_delete_deactivated_userPermanently delete a previously deactivated Okta userrequired user_id
okta-private-key_delete_groupPermanently delete an Okta group. This is destructive and cannot be undone.required group_id
okta-private-key_delete_policyDelete an Okta policy. This is destructive and cannot be undone.required policy_id
okta-private-key_delete_policy_ruleDelete an Okta policy rule. This is destructive and cannot be undone.required policy_id, rule_id
okta-private-key_expire_passwordExpire an Okta user’s password, forcing a change at next sign-inrequired user_id
okta-private-key_get_applicationRetrieve a specific Okta application by IDrequired app_id
optional expand
okta-private-key_get_groupRetrieve a specific Okta group by IDrequired group_id
okta-private-key_get_logsRetrieve Okta system logs with optional filtering and pagination supportoptional after, fetch_all, filter_query, limit, q, since, until
okta-private-key_get_policyRetrieve a specific Okta policy by IDrequired policy_id
okta-private-key_get_policy_ruleRetrieve a specific Okta policy rule by IDrequired policy_id, rule_id
okta-private-key_get_userRetrieve a specific Okta user by IDrequired user_id
okta-private-key_get_user_profile_attributesReturn the profile attribute names found on a sample user in this Okta org. Returns an empty list if the org has no users.—
okta-private-key_list_applicationsList Okta applications with optional filtering and pagination supportoptional after, expand, filter_query, include_non_deleted, limit, q
okta-private-key_list_group_appsList applications assigned to a specific Okta grouprequired group_id
okta-private-key_list_group_usersList users assigned to a specific Okta grouprequired group_id
optional after, fetch_all, limit
okta-private-key_list_groupsList Okta groups with optional search, filter, and pagination supportoptional after, fetch_all, filter_query, limit, q, search
okta-private-key_list_policiesList Okta policies for a specific policy typerequired policy_type
optional after, limit, q, status
okta-private-key_list_policy_rulesList rules for a specific Okta policyrequired policy_id
okta-private-key_list_usersList Okta users with optional search, filter, and pagination supportoptional after, fetch_all, filter_query, limit, q, search
okta-private-key_remove_user_from_groupRemove an Okta user from a specific Okta grouprequired group_id, user_id
okta-private-key_reset_passwordGenerate a password reset for an Okta user. By default (send_email=true) Okta emails the reset link and returns no link; set send_email=false to return a resetPasswordUrl instead.required user_id
optional send_email
okta-private-key_suspend_userSuspend an active Okta user, blocking sign-in while preserving the accountrequired user_id
okta-private-key_unsuspend_userUnsuspend a suspended Okta user, returning the account to active statusrequired user_id
okta-private-key_update_applicationUpdate an existing Okta applicationrequired app_id, app_config
okta-private-key_update_groupUpdate an existing Okta grouprequired group_id, profile
okta-private-key_update_policyUpdate an existing Okta policyrequired policy_id, policy_data
okta-private-key_update_policy_ruleUpdate an existing Okta policy rulerequired policy_id, rule_id, rule_data
okta-private-key_update_userPartially update an Okta user profile using Okta’s POST semanticsrequired user_id, profile

59 tools. Connect with OAuth 2.0 client credentials.

ToolDescriptionArguments
sailpoint_activate_certification_campaignActivate a SailPoint certification campaign to start the review process. The campaign deadline must be in the future. Once activated, reviewers receive their certification tasks. Requires CERT_ADMIN or ORG_ADMIN role.required id
optional time_zone
sailpoint_approve_access_requestApprove a pending access request approval. Only the owner of the approval and ORG_ADMIN users can perform this action.required approvalId
optional comment
sailpoint_cancel_access_requestCancel a pending access request. Can only cancel requests that have not passed the approval step. Users with ORG_ADMIN role or the original requestor can cancel.required accountActivityId, comment
sailpoint_check_sod_violationsCheck SOD violations for an identity and access references. This API initiates a SOD policy verification asynchronously and returns a request ID that can be used to check the status.required identityId, accessRefs
sailpoint_create_access_profileCreate a new SailPoint access profile. Access profiles group entitlements from a single source. SOURCE_SUBADMIN or ORG_ADMIN must be associated with the source.required name, owner, source
optional accessRequestConfig, description, enabled, entitlements, provisioningCriteria, requestable, revokeRequestConfig, segments
sailpoint_create_access_requestSubmit an access request to grant or revoke access in SailPoint. Supports roles, access profiles, and entitlements. Requests are processed asynchronously.required requestedFor, requestedItems
optional clientMetadata, requestType
sailpoint_create_certification_campaignCreate a new SailPoint certification campaign. Requires CERT_ADMIN or ORG_ADMIN role.required name, type
optional autoRevokeAllowed, correlatedStatus, deadline, description, emailNotificationEnabled, filter, machineAccountCampaignInfo, mandatoryCommentRequirement, recommendationsEnabled, roleCompositionCampaignInfo, searchCampaignInfo, sourceOwnerCampaignInfo, sunsetCommentsRequired
sailpoint_create_roleCreate a new SailPoint role. Roles bundle access profiles and entitlements for assignment to identities. ROLE_SUBADMIN users can only create roles with access profiles from sources they administer.required name, owner
optional accessProfiles, accessRequestConfig, description, enabled, entitlements, membership, requestable, revokeRequestConfig, segments
sailpoint_create_sod_policyCreate a new SailPoint SOD (Segregation of Duties) policy. Requires ORG_ADMIN role. Defines conflicting access criteria that should not be held by the same identity.required name, conflictingAccessCriteria
optional compensatingControls, correctionAdvice, description, externalPolicyReference, ownerRef, scheduled, state, tags, violationOwnerAssignmentConfig
sailpoint_create_sourceCreate a new SailPoint source/application. Requires idn:source:manage scope and SOURCE_ADMIN or ORG_ADMIN rights. The source defines a connection to an external system for identity data.required name, owner, connector
optional authoritative, cluster, connectorAttributes, connectorClass, deleteThreshold, description, features, provision_as_csv, schemas, type
sailpoint_create_workflowCreate a new SailPoint workflow for automation and process management.required name, owner
optional definition, description, enabled, trigger
sailpoint_delete_access_profileDelete a SailPoint access profile. Must not be in use by applications, lifecycle states, or roles.required id
sailpoint_delete_roleDelete a SailPoint role by ID.required id
sailpoint_delete_sod_policyDelete a SailPoint SOD policy. Requires ORG_ADMIN role. Supports soft delete (logical=true, recoverable) and hard delete (logical=false, permanent).required id
optional logical
sailpoint_delete_sourceDelete a SailPoint source/application. Requires idn:source:manage scope and SOURCE_ADMIN or ORG_ADMIN rights.required id
sailpoint_delete_workflowDelete a SailPoint workflow by ID.required id
sailpoint_disable_accountDisable a SailPoint account. Submits an asynchronous task to disable the account and returns the task ID for tracking.required id
optional externalVerificationId, forceProvisioning
sailpoint_enable_accountEnable a SailPoint account. Submits an asynchronous task to enable the account and returns the task ID for tracking.required id
optional externalVerificationId, forceProvisioning
sailpoint_forward_access_requestForward an access request approval to a new owner. Only the owner of the approval and ORG_ADMIN users can perform this action.required approvalId, newOwnerId, comment
sailpoint_get_access_profileGet a SailPoint access profile by its ID. Returns detailed information about a specific access profile.required id
sailpoint_get_accountGet a single SailPoint account by ID using v2025 API. Returns detailed information about a specific account.required id
sailpoint_get_certification_campaignGet a single SailPoint certification campaign by ID. Returns full campaign details including status, deadline, and configuration.required id
sailpoint_get_identityGet a single identity by ID using v2025 API. Returns detailed information about a specific identity.required id
sailpoint_get_identity_profileGet a single identity profile by ID. This API returns a single identity profile by its ID.required id
sailpoint_get_isc_run_contextRead-only ISC run-context diagnostics. Returns recent task results so an operator can see current run state before taking action. No mutations. Reads the experimental v2025 task-status endpoint.optional filters, limit
sailpoint_get_job_statusPoll an account aggregation job by ID and return its status and progress (NEW/CHANGED/DELETED account counts). Read-only.required id
sailpoint_get_roleGet a role by ID. A user with ROLE_SUBADMIN authority may only call this API if all access profiles included in the role are associated to sources with management workgroups of the ROLE_SUBADMIN is a member of.required id
sailpoint_get_sod_policyGet a specified SOD (Segregation of Duties) policy by its ID. Requires role of ORG_ADMIN.required id
sailpoint_get_sourceGet a single source by ID using v2025 API. Returns detailed information about a specific source including SSO/MFA configuration.required id
sailpoint_get_task_statusPoll a SailPoint task by ID and return its status (completed, failed, or running). Read-only. Covers account/entitlement aggregation and other background tasks. The upstream v2025 task-status endpoint is experimental.required id
sailpoint_get_workflowGet a single workflow by ID using v2025 API. Returns detailed information about a specific workflow including its definition and configuration.required id
sailpoint_list_access_profile_entitlementsGet a list of an access profile’s entitlements. A SOURCE_SUBADMIN user must have access to the source associated with the specified access profile.required id
optional count, filters, limit, offset, sorters
sailpoint_list_access_profilesGet a list of SailPoint access profiles. Note: When you filter for access profiles that have the ”+” symbol in their names, the response is blank.optional count, filters, for_segment_ids, for_subadmin, include_unsegmented, limit, offset, sorters
sailpoint_list_access_request_statusGet SailPoint access request statuses with optional filtering and pagination using v2025 API. Any user can get the status of their own access requests. ORG_ADMIN is required to get statuses for other users.optional assigned-to, count, filters, limit, offset, regarding-identity, request-state, requested-by, requested-for, sorters
sailpoint_list_account_entitlementsGet entitlements for a specific account using v3 API. Returns all entitlements associated with the specified account.required accountId
optional count, filters, limit, offset, sorters
sailpoint_list_accountsGet a list of SailPoint accounts with optional filtering, sorting, and pagination support using v2025 API. IMPORTANT: To get ALL account data, make multiple tool calls with the required offset values to paginate through all results.optional count, filters, limit, offset, sorters
sailpoint_list_certification_campaignsGet a list of SailPoint certification campaigns with optional filtering, sorting, and pagination.optional count, filters, limit, offset, sorters
sailpoint_list_completed_approvalsGet a list of completed access request approvals with optional filtering, sorting, and pagination. ORG_ADMIN users can view all completed approvals. Non-ORG_ADMIN users can only view their own.optional count, filters, limit, offset, owner-id, sorters
sailpoint_list_identitiesGet a list of identities with optional filtering, sorting, and pagination support using v2025 API. By default, returns only correlated identities (defaultFilter=CORRELATED_ONLY).optional count, defaultFilter, filters, limit, offset, sorters
sailpoint_list_identity_profilesGet a list of identity profiles. This API returns a list of identity profiles based on the specified query parameters with optional filtering, sorting, and pagination.optional count, filters, limit, offset, sorters
sailpoint_list_pending_approvalsGet a list of pending access request approvals with optional filtering, sorting, and pagination. ORG_ADMIN users can view all pending approvals. Non-ORG_ADMIN users can only view their own.optional count, filters, limit, offset, owner-id, sorters
sailpoint_list_role_assigned_identitiesList identities assigned a role. This API lists all identities assigned to a specific role with optional filtering, sorting, and pagination.required id
optional count, filters, limit, offset, sorters
sailpoint_list_rolesGet a list of Roles. This API returns a list of Roles with optional filtering, sorting, and pagination support. IMPORTANT: To get ALL role data, make multiple tool calls with different offset values to paginate through all results.optional count, filters, for_segment_ids, for_subadmin, include_unsegmented, limit, offset, sorters
sailpoint_list_sod_policiesGet a list of all SOD (Segregation of Duties) policies. Requires role of ORG_ADMIN.optional count, filters, limit, offset, sorters
sailpoint_list_sourcesGet a list of sources/applications for inventory and configuration management using v2025 API. IMPORTANT: To get ALL source data, make multiple tool calls with different offset values to paginate through all results.optional count, filters, limit, offset, sorters
sailpoint_list_task_resultsList completed/historical SailPoint task results with optional filtering, sorting, and pagination. Read-only. The upstream v2025 task-status endpoint is experimental.optional count, filters, limit, offset, sorters
sailpoint_list_workflowsGet a list of workflows for automation and process management using v2025 API.optional count, filters, limit, offset, sorters
sailpoint_patch_access_profileUpdate an existing SailPoint access profile using JSON Patch (RFC 6902). Patchable fields: name, description, enabled, owner, requestable, accessRequestConfig, revokeRequestConfig, segments, entitlements, provisioningCriteria, source.required id, operations
sailpoint_patch_roleUpdate an existing SailPoint role using JSON Patch (RFC 6902).required id, operations
sailpoint_patch_sod_policyUpdate an existing SailPoint SOD policy using JSON Patch (RFC 6902). Requires ORG_ADMIN role.required id, operations
sailpoint_patch_sourceUpdate an existing SailPoint source using JSON Patch (RFC 6902). Requires idn:source:manage scope and SOURCE_ADMIN or ORG_ADMIN rights.required id, operations
sailpoint_patch_workflowUpdate an existing SailPoint workflow using JSON Patch (RFC 6902). Patchable fields: name, owner, description, enabled, definition, trigger.required id, operations
sailpoint_reject_access_requestReject a pending access request approval. Only the owner of the approval and ORG_ADMIN users can perform this action.required approvalId
optional comment
sailpoint_reprocess_identity_jmlReprocess identity JML lifecycle state (recalculate attributes, role assignments, provisioning, manager relationships) for one or more identities. Guardrail: single identity or a capped batch only; unbounded batches are rejected.required identity_ids
sailpoint_rerun_source_aggregationRe-run a source account aggregation. Guardrails: source_id must be in allowed_source_ids (allowlist), DELTA aggregation by default, and FULL (unoptimized) aggregation requires approve_full_aggregation=true.required source_id, allowed_source_ids
optional aggregation_type, approve_full_aggregation
sailpoint_retry_failed_jobRetry a failed source aggregation job.required source_id, allowed_source_ids, failure_status, attempt
sailpoint_searchSearch across SailPoint objects using Elasticsearch syntax. Supports searching identities, roles, access profiles, entitlements, events, and account activities. Powerful tool for querying across all SailPoint data.required indices
optional count, includeNested, limit, offset, query, queryDsl, searchAfter, sort
sailpoint_test_workflowTest a SailPoint workflow by executing it with mock trigger input. Useful for validating workflow logic before enabling.required id, input
sailpoint_unlock_accountUnlock a SailPoint account. Submits an asynchronous task to unlock the account and returns the task ID for tracking. Requires idn:accounts-provisioning:manage scope for forceProvisioning.required id
optional externalVerificationId, forceProvisioning

24 tools. Connect with Basic auth.

ToolDescriptionArguments
saviynt_bulk_upload_usersBulk create/update users from a CSV in Saviynt (uploadUserRequest). Sent as multipart/form-data with the CSV file plus option flags.required csv_content
optional checkrules, delimiter, generate_email, generate_system_username, zero_day_provisioning
saviynt_complete_provisioning_taskComplete one or more Saviynt provisioning tasks and verify the outcome. A single task with no extra fields completes via completetask; multiple tasks, or a comment/ticket/metadata, complete via updateTasks (updatetype=completetask).required task_ids
optional comments, provisioning_metadata, ticket_id, verify
saviynt_create_userCreate a user in Saviynt (createUser). Core attributes are named params; pass arbitrary extra attributes via attributes.required username
optional attributes, email, firstname, lastname, statuskey, systemusername, validateagainstpolicy
saviynt_decide_access_requestAct on a pending Saviynt access request: approve, reject, or cancel (discontinue) it. Approve and reject both need both identifiers of the pending request: its requestkey and its requestid, as returned by list_access_requests.required request_key, action
optional reason, request_id
saviynt_discontinue_provisioning_taskDiscontinue one or more Saviynt provisioning tasks that are still new or pending, recording comments on each task’s history, then verify their status. Irreversible: a discontinued task cannot be completed later.required task_ids, comments
optional discontinue_associated, verify
saviynt_fetch_job_metadataFetch metadata and run history for a Saviynt job (fetchJobMetadata). Read-only; complements get_job_status for completion detail.required jobname
optional jobgroup, jobstartdate, triggername
saviynt_get_access_requestGet one access request’s detail with optional approval and user-access sections.required request_id
optional include, response_format, username
saviynt_get_job_statusGet the current status of a Saviynt job trigger (checkJobStatus). Read-only; use to poll a trigger fired via the run_* tools. Returns errorCode/msg.required jobname, jobgroup
optional triggername
saviynt_get_provisioning_task_statusGet the status of a single Saviynt provisioning task by id (checkTaskStatus). Read-only.required taskid
saviynt_get_tasksList provisioning tasks in Saviynt via fetchTasks. status is required (the API has no ERROR value, so errored tasks are not queryable here).required status
optional endpoint, max_results, offset, task_type, username
saviynt_get_user_accessFetch one user’s profile, access, and in-flight work as one view.required username
optional endpoint, include, max_per_section, response_format
saviynt_list_access_requestsList Saviynt access-request history as summary rows (fetchRequestHistory): one row per request with its requestkey, requestid, requestor, status, and dates.optional max_results, offset, order, request_id, requested_for, sort, status, username
saviynt_list_certification_campaignsList certification campaigns in Saviynt (campaigns pending certification). Optionally scope to a certifier username; supports max/offset pagination.optional max_results, offset, username
saviynt_list_usersList or search users in Saviynt Enterprise Identity Cloud. Filter by username and limit the returned attributes; supports max/offset pagination. Use manager to list one manager’s direct reports in a single call.optional manager, max_results, offset, user_response_fields, username
saviynt_process_identity_rulesFire a Saviynt identity-rules processing job trigger (runJobTrigger). Async: the trigger is queued, not awaited — poll get_job_status / fetch_job_metadata for completion.required jobname, jobgroup, triggername
optional create_job_if_does_not_exist, value_map
saviynt_query_entitlementsQuery entitlements in Saviynt Enterprise Identity Cloud. Filter by entitlement type and endpoint (application), restrict returned fields, and paginate with max/offset.optional endpoint, entitlement_response_fields, entitlement_type, max_results, offset
saviynt_run_identity_refreshFire a Saviynt identity-refresh job trigger (runJobTrigger). Async: the trigger is queued, not awaited — poll get_job_status / fetch_job_metadata for completion. jobname/jobgroup/triggername are tenant-specific and caller-supplied.required jobname, jobgroup, triggername
optional create_job_if_does_not_exist, value_map
saviynt_run_source_import_or_aggregationFire a Saviynt source-import / aggregation job trigger (runJobTrigger). Async: the trigger is queued, not awaited — poll get_job_status / fetch_job_metadata for completion.required jobname, jobgroup, triggername
optional create_job_if_does_not_exist, value_map
saviynt_run_ws_retry_jobFire the Saviynt WSRETRY job trigger to retry failed provisioning tasks (runJobTrigger). Async: poll get_job_status / fetch_job_metadata for completion.required triggername
optional create_job_if_does_not_exist, jobgroup, jobname, security_systems, task_types
saviynt_submit_access_requestSubmit an access request in Saviynt (requestAccess) — request one or more entitlements/accounts for a user. The endpoint apiName is version-dependent: a 404 may mean this tenant uses a different apiName.required username, requestor, requestaccess
optional comments
saviynt_submit_user_update_requestSubmit a governed user-update request in Saviynt (updateUserRequest) — routed through request workflow rather than applied directly. The endpoint apiName is version-dependent: a 404 may mean this tenant uses a different apiName.required username, attributes
saviynt_update_sav_role_membersAdd users to, or remove users from, a Saviynt SAV role (the platform roles that control what a user can do in Saviynt itself, not application access).required sav_role, usernames, action
saviynt_update_userUpdate an existing Saviynt user (updateUser). username identifies the record; changed attributes are supplied via attributes.required username, attributes
saviynt_upsert_user_groupCreate a Saviynt user group or modify an existing one (createUpdateUserGroup handles both). usergroup_name identifies the group.required usergroup_name
optional add_members, attributes, description, remove_members