{
 "categories": [
  "identity",
  "enterprise"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-08-30",
   "fact": "homepage",
   "note": "Microsoft presents Entra ID as cloud identity and access management, formerly Azure Active Directory, with Free, P1, and P2 editions.",
   "source": "https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-id",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "license",
   "note": "Paid P1 and P2 plans sit above a Free edition bundled with Azure and Microsoft 365. API access still follows tenant licensing.",
   "source": "https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-id",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.api.exists",
   "note": "Microsoft Graph provides REST APIs at graph.microsoft.com. Entra ID is listed under Enterprise Mobility and Security.",
   "source": "https://learn.microsoft.com/en-us/graph/overview",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.api.kinds[0]",
   "note": "The documented interface is REST.",
   "source": "https://learn.microsoft.com/en-us/graph/overview",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.api.auth[0]",
   "note": "Delegated OAuth 2.0 authorization-code access lets an application call Graph on behalf of a signed-in user within that user's privileges.",
   "source": "https://learn.microsoft.com/en-us/graph/auth-v2-user",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.api.auth[1]",
   "note": "App-only client-credentials access requires administrator-consented application permissions.",
   "source": "https://learn.microsoft.com/en-us/graph/auth-v2-service",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.api.coverage",
   "note": "Graph user, group, and application resources cover directory CRUD. Sensitive writes remain role-locked.",
   "source": "https://learn.microsoft.com/en-us/graph/api/resources/users",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.sdk.exists",
   "note": "Microsoft publishes generated Graph SDKs for C#, Go, Java, TypeScript and JavaScript, PHP, PowerShell, and Python.",
   "source": "https://learn.microsoft.com/en-us/graph/sdks/sdks-overview",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.mcp.first_party",
   "note": "Microsoft documents the Microsoft MCP Server for Enterprise at https://mcp.svc.cloud.microsoft/enterprise as a public-preview remote MCP that translates requests into read-only Graph calls.",
   "source": "https://learn.microsoft.com/en-us/graph/mcp-server/overview",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.cli.exists",
   "note": "The official cross-platform Microsoft Graph PowerShell SDK wraps the Graph schema as generated cmdlets and replaces Azure AD PowerShell and MSOnline.",
   "source": "https://learn.microsoft.com/en-us/powershell/microsoftgraph/overview",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.extensibility.scripting[0]",
   "note": "Custom REST applications call Microsoft Graph under delegated or application identities.",
   "source": "https://learn.microsoft.com/en-us/graph/overview",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.extensibility.webhooks",
   "note": "Graph change notifications support webhooks, Event Hubs, and Event Grid for users and groups.",
   "source": "https://learn.microsoft.com/en-us/graph/change-notifications-overview",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.data_access.export[0]",
   "note": "Graph GET operations return directory objects as JSON.",
   "source": "https://learn.microsoft.com/en-us/graph/api/resources/users",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "modalities.data_access.import[0]",
   "note": "Graph POST, PATCH, and DELETE create, update, and remove authorized directory objects.",
   "source": "https://learn.microsoft.com/en-us/graph/api/resources/users",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "verdict.scores.api",
   "note": "Directory Graph coverage is unusually complete for a cloud IAM product. Tenant consent, RBAC, and sensitive-action locks stay inside the score.",
   "source": "https://learn.microsoft.com/en-us/graph/api/resources/users",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "verdict.scores.mcp",
   "note": "Official hosted MCP is a limited vendor preview: read-only, 100 rpm per user, global cloud only, delegated only.",
   "source": "https://learn.microsoft.com/en-us/graph/mcp-server/overview",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "verdict.scores.cli",
   "note": "Graph PowerShell exposes the generated Graph schema as cmdlets with noninteractive app authentication and structured objects.",
   "source": "https://learn.microsoft.com/en-us/powershell/microsoftgraph/overview",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "freshness.watch[0].url",
   "note": "Opened and verified as the current Microsoft MCP Server for Enterprise overview, including preview, read-only, 100 rpm, and national-cloud exclusions.",
   "source": "https://learn.microsoft.com/en-us/graph/mcp-server/overview",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "freshness.watch[1].url",
   "note": "Opened and verified as the current tenant-provisioning guide, including delegated-only MCP and MCP.* scopes.",
   "source": "https://learn.microsoft.com/en-us/graph/mcp-server/get-started",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "freshness.watch[2].url",
   "note": "Opened and verified as the current Microsoft Graph overview.",
   "source": "https://learn.microsoft.com/en-us/graph/overview",
   "tier": "declared"
  },
  {
   "date": "2026-08-30",
   "fact": "freshness.watch[3].url",
   "note": "Opened and verified as the current Microsoft Graph PowerShell overview.",
   "source": "https://learn.microsoft.com/en-us/powershell/microsoftgraph/overview",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-08-30",
  "volatility": "high",
  "watch": [
   {
    "type": "mcp",
    "url": "https://learn.microsoft.com/en-us/graph/mcp-server/overview"
   },
   {
    "type": "docs",
    "url": "https://learn.microsoft.com/en-us/graph/mcp-server/get-started"
   },
   {
    "type": "docs",
    "url": "https://learn.microsoft.com/en-us/graph/overview"
   },
   {
    "type": "docs",
    "url": "https://learn.microsoft.com/en-us/powershell/microsoftgraph/overview"
   }
  ]
 },
 "homepage": "https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-id",
 "id": "microsoft-entra-id",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": "unknown"
  },
  "api": {
   "auth": [
    "oauth2-delegated",
    "oauth2-app-only"
   ],
   "coverage": "full",
   "docs": "https://learn.microsoft.com/en-us/graph/overview",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": true
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "api-json",
    "powershell-objects"
   ],
   "import": [
    "api-json",
    "powershell-objects"
   ]
  },
  "extensibility": {
   "scripting": [
    "microsoft-graph",
    "graph-powershell",
    "graph-sdks"
   ],
   "webhooks": true
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Microsoft Graph and Graph PowerShell cover directory administration without browser control.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": true,
   "languages": [
    "csharp",
    "go",
    "java",
    "javascript",
    "php",
    "powershell",
    "python"
   ],
   "official": true
  }
 },
 "name": "Microsoft Entra ID",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "okta",
   "active-directory-ds",
   "id-porten"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Microsoft",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 9,
   "cli": 8,
   "computer_use": null,
   "integrations": null,
   "mcp": 6,
   "overall": 9,
   "rpa": null
  },
  "summary": "Microsoft Entra ID is automatable today through Microsoft Graph. The public REST endpoint at graph.microsoft.com covers tenant users, groups, applications, devices, and related directory operations with create, read, update, and delete. OAuth supports delegated access on behalf of a signed-in admin and unattended app-only client-credentials access. Application permissions always need admin consent. Entra RBAC and sensitive-action role locks still apply to passwords, UPN, enable or disable, and delete. Official Graph SDKs cover C#, Go, Java, JavaScript, PHP, PowerShell, and Python. Graph PowerShell is the strongest command path and is Microsoft's replacement for Azure AD PowerShell and MSOnline. The first-party Microsoft MCP Server for Enterprise is a public-preview, read-only, delegated, global-cloud remote MCP at https://mcp.svc.cloud.microsoft/enterprise. It translates natural language into Graph GETs, is capped at 100 calls per minute per user, and cannot write directory objects. This identity is not on-prem Active Directory Domain Services and not the Microsoft 365 Admin Center. Computer-use viability is unassessed. API scores 9 and is the best path because writes and unattended app-only live there, not on MCP.\n"
 }
}