Live webinarMeet Elimity MCP: ask your identity data in Claude, ChatGPT or Copilot21 Oct · 4:00 PM CET21 Oct · 4 PM CETSave your seatSave seat
Blog

Your identity data, one prompt away

Jakob Festraets, Head of Delivery at Elimity · Oct 6, 2026

Insights💡

For years, getting a straight answer about who has access to what meant building a report, filing a ticket or waiting for an audit. Today that changes. With Elimity on MCP (Model Context Protocol), you ask Claude, ChatGPT or Copilot, and the answer comes straight from your own identity data.

I lead delivery at Elimity, so I spend a lot of time with the teams that have to answer these questions. This launch comes from what we see with them, and I want to explain why we built it this way.

Why we built this

Elimity is growing in the EU market, and one thing keeps coming back: our customers mainly use Copilot, Claude and similar assistants to get through their workload faster. They write, summarise and analyse with them every day. The assistant is already open on their screen.

We also see how many identity questions banks, manufacturers and other organisations have to answer.

Auditors ask them, security teams ask them, managers ask them. You can build a query for each one, but that takes time most teams do not have. What they need is the answer two clicks away.

So instead of asking people to open one more tool, we brought Elimity to the assistant they already use. That is why we launched Elimity on MCP.

What it looks like

It is fully integrated. Elimity shows up inside the assistant you already work in, with no new login and no new dashboard. You ask in plain language, and you can ask whatever you need, including follow-up questions.

In our demo environment, we asked: "How many admin AD accounts are linked to inactive employees?" The answer came back in about 15 seconds: 2,739 accounts. From there we kept going. "Show me a sample of those accounts." "How does Elimity define an inactive employee?"

Every answer shows the query behind it and the definitions it used, so you can check the number yourself.

Demo environment, illustrative data.

Some typical questions people ask:

  • Which accounts are not linked to an employee?
  • Which admin accounts belong to employees who have left the company?
  • Which accounts have not been used in the last 90 days?
  • Who has privileged access, and who owns those accounts?
  • Which external accounts have admin rights?
  • Which roles have never been reviewed?

How it works

MCP (Model Context Protocol) is an open standard that lets an AI assistant connect to a tool in a controlled way. Instead of copying data into a chat window, the assistant asks Elimity directly, on behalf of the person who is logged in.

Behind the scenes, the assistant does roughly what an analyst would do. It first looks up what your Elimity environment contains: which data sources, which types of entities (accounts, employees, roles) and how they relate to each other. Then it looks at the attributes of the entities that matter for your question, and finally it runs a query that filters, sorts and pages through the results. That is also why it can show you the query and the definitions behind every answer.

Getting started

Connecting your assistant takes a few minutes. The full instructions are in our documentation, but this is the short version.

What you need

  • An MCP server URL. If you use Elimity as SaaS, we host and manage the MCP server for you. Your Elimity account manager gives you the URL. If you run Elimity on-premises, you deploy the MCP server yourself and use your own URL.
  • A license. Elimity on MCP is licensed separately. Your Elimity representative can tell you more.
  • OAuth2 credentials. Sign-in uses OAuth2, so the assistant connects with your own identity rather than a shared account. You need a client ID and secret, unless your assistant supports Dynamic Client Registration, in which case it can register itself.
  • A callback URL. Your authorization server must allow your assistant's callback URL as a redirect URI. For Claude, that is https://claude.ai/api/mcp/auth_callback.

Connect your assistant

Claude (web, desktop, mobile and Cowork)

  1. Go to Settings, then Connectors, then Add custom connector.
  2. Enter the MCP server URL.
  3. Open the advanced settings and enter your OAuth2 client ID and secret.
  4. Save, sign in when asked, and start asking questions.

Claude Code

Add the server from your terminal with:

claude mcp add <name> --transport http --client-id <id>

Claude Code runs on your own machine, so its callback URL is a local one (http://localhost:<port>/callback). Register that URL instead of the one above.

Microsoft Copilot

  1. Open your agent and go to the Tools page.
  2. Choose Add a tool, then New tool, then Model Context Protocol.
  3. Select OAuth 2.0 with manual configuration, and enter your credentials and the endpoints of your authorization server.
  4. Once the connection is created, register the callback URL that Copilot generates for you.

Other assistants

The pattern is always the same: add the server URL, provide the OAuth2 credentials, and register the assistant's callback URL.

Once connected, you are ready to ask your first question.

Built to be verified

Elimity on MCP is read-only. It works with your own roles and stays in your own tenant. The assistant can look at your identity data, but it cannot change anything.

Where it fits

Elimity is an Identity Visibility & Intelligence Platform. We bring identity data from every source together, so you can govern every identity across every system. MCP is a new way into that same data. Want to know more about the platform? Visit www.elimity.com.

See it live

Maarten Decat, our Co-Founder and Product Owner, will walk through it live on October 21st at 4:00 PM CET. Register here. More info on Elimity on MCP: www.elimity.com/mcp.

See Elimity on MCP live, 21 October, 4:00 PM CET

Related article: IAM evidence for NIS2, DORA and ISO 27001 within 15 seconds