Microsoft + ClaudeOne partner for the cloud you run and the AI you put on top of it.
Avalon Web ServicesMicrosoft · Claude · Security
Avalon CloudSec MCP · Support

Getting help with the MCP service.

Support for the Avalon CloudSec Security Intelligence MCP service at mcp.awservices.org runs through one monitored mailbox. This page tells you what to send so the first reply is the useful one.

01 · Contact

Where to write

Product questions, onboarding, entitlement changes and anything that is not working: support@awservices.org.

Security concerns and vulnerability reports, including anything that looks like data from a tenant you should not be able to see: security@awservices.org. Please do not put security findings in a general support thread.

02 · What to include

Send this and we can act on the first reply

  • Your Microsoft Entra tenant ID (Entra admin center → Overview). Never send credentials.
  • The tool name you called and roughly when (with time zone).
  • The requestId or correlationId from the result. Every response carries one, including error responses. It lets us find the exact call in our audit trail without you sending us any of the data it returned.
  • Which MCP client you are using (Copilot Studio, Claude, or another) — sign-in behaviour differs slightly between them.

03 · Common results

What these mean before you write

license_requiredThe tool ran, but your tenant is not licensed for the Microsoft source it reads (Entra ID P1/P2, Intune, or Defender XDR). Nothing is wrong with the connection. The remaining domains still return live data.
TENANT_NOT_ENTITLEDYou signed in successfully, but this account is not yet entitled to a tenant. Admin consent alone does not switch anything on — send us your tenant ID and we will activate the entitlement.
AUTHORIZATION_DENIEDThe tenant you asked about is not one this account may see. Entitlements are per person, per tenant; MSP operators see only the customer tenants granted to them.
HTTP 401 with WWW-AuthenticateThe request carried no valid token. Your MCP client should follow the resource_metadata link in that header and start the sign-in flow. If it keeps happening, remove and re-add the connector.

04 · Ending access

You never need us to disconnect

Revoking the Avalon CloudSec Graph application in your own tenant (Entra admin center → Enterprise applications → Avalon CloudSec Graph → Permissions) ends all access immediately and requires nothing from Avalon. Tell us afterwards if you would like the entitlement records removed as well; the privacy notice describes what those contain.

05 · Documents

Related