Microsoft Cloud Tools

Once you connect your Entra ID tenant, InfraScout exposes a comprehensive set of Microsoft Cloud tools to your AI client. These tools cover identity, Azure infrastructure, Microsoft 365 services, and security — letting you assess your cloud environment as naturally as you assess on-premises hosts. No agent is needed on cloud systems; InfraScout queries Microsoft's APIs directly using your connected tenant credentials.

Prerequisite

A connected Entra ID tenant is required before any Microsoft Cloud tools are available. See Connecting Entra ID for setup instructions.

Identity (Entra ID)

These tools query your Entra ID directory — users, groups, roles, service principals, and admin units. Use them to audit privilege hygiene, find stale accounts, review role assignments, and check Privileged Identity Management (PIM) eligibility schedules.

"List all users with Global Administrator role assignments.""Show me service principals with application role assignments to sensitive permissions.""List all PIM-eligible role assignments and their scheduled expiry."

Azure Platform

These tools query your Azure subscriptions, resource groups, and resources. They also cover governance features — access reviews, entitlement management, and lifecycle workflows. Basic Azure cost queries are available.

For partners and managed service providers, delegated admin (GDAP) tools let you audit external access into your tenant. You can list partner relationships and filter them by status to focus on active grants, list the delegated admin customers, and pull the per-relationship access assignments to see exactly which roles each partner holds. This is the surface to review when answering "who can administer this tenant, and with what privileges?"

"List all Azure subscriptions and their resource counts.""Show me any access packages that allow external guest access.""List active delegated admin (GDAP) relationships and the roles each partner holds.""Query the cost summary for last month across all subscriptions."

Security

These tools cover Microsoft Defender XDR alerts and incidents, Microsoft Defender for Endpoint (machine inventory, recommendations, and logon users), Defender Advanced Hunting (typed queries for process, file, network, registry, and module-load events plus arbitrary KQL against the XDR data lake), identity protection (risky users and risk detections), Conditional Access policies, sign-in logs with server-side aggregation for spray hunting, directory audit logs, the Microsoft 365 Unified Audit Log (asynchronous searches plus shortcuts for external sharing, inbox rules, and mailbox access), named locations, BitLocker keys, and LAPS credentials.

"List all Defender machines that have high-severity recommendations.""Hunt for password spray over the last 7 days — top source IPs by distinct users.""Who created anonymous sharing links in the last 24 hours?""Show me the current Conditional Access policies and flag any that have no MFA requirement."

Microsoft 365 Services

These tools cover Teams (teams, channels, members, and installed apps), SharePoint and OneDrive (sites, lists, drives, standing sharing links, and the tenant sharing policy), and Exchange Online (mailbox settings, mail folders, and mail-flow message traces). Licensing tools let you review subscribed SKUs and per-user assignments. Usage and Copilot adoption reports are also available.

"List all Teams and flag any with external members.""Find every anonymous or never-expiring sharing link in the Finance team's sites.""Trace all failed or quarantined mail from billing@example.com in the last 3 days.""Get the Microsoft 365 usage report for the last month."

Intune

These tools cover Microsoft Intune device management: managed devices and their per-device configuration, compliance, Defender antivirus health, and detected malware, plus configuration profiles, the Settings Catalog, Administrative Templates, security baselines, and detected and managed apps. Read a whole inventory, or pull one policy, template, or baseline by id in a single call.

"List all Intune-managed devices that are non-compliant.""Which compliance policies is this device failing, and on which settings?""Which security baselines and ASR templates are assigned in this tenant?"

Service Health

These tools read Microsoft 365 service health and the message center: current status per service, health incidents and advisories with their post timelines, and announcements covering planned changes and retirements. Use them to rule out a Microsoft-side incident before investigating your tenant.

"Is anything in Microsoft 365 degraded right now?""Which major changes in the message center require action before a deadline?"

Cloud App Discovery

These tools surface shadow IT from Microsoft Defender for Cloud Apps — the cloud apps actually in use across your organization, with risk scores, traffic volumes, sanction tags, and the users, devices, and IPs behind each app. Generative AI services and MCP servers appear as their own categories.

"List the riskiest unsanctioned cloud apps seen in the last 30 days.""Which users accessed generative AI apps last week?"

Using These Tools

You don't call these tools by name. Just describe what you want to understand and InfraScout selects the right tools automatically. For example:

"Review the identity security posture for my Entra tenant — focus on privileged accounts, stale users, and MFA gaps."

Tenant selection happens per tool call, not once per session. By default, every Microsoft Cloud tool runs against your default identity connection, so you don't pass anything. To target a different tenant — for example, a partner or customer tenant you manage — pass that tenant's connection_id on the call. Use entra_connection_list only when you need to look up which tenants are configured before targeting one.