api-patterns
3CX's native PBX MCP server: the per-PBX endpoint shape (every PBX is its own FQDN and its own OAuth authorization server — there is no shared mcp.3cx.com),…
CIPP's tenant-baseline enforcement model: the Report/Alert/Remediate standards modes and how to roll them out, on-demand standards evaluation, Best Practice Analyser reports, and SPF/DKIM/DMARC domain health results with their remediation actions.
$ npx -y skills add wyre-technology/msp-claude-plugins --skill standards --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/standardsContext preview
The summary Claude sees to decide when to auto-load this skill.
CIPP's tenant-baseline enforcement model: the Report/Alert/Remediate standards modes and how to roll them out, on-demand standards evaluation, Best Practice Analyser reports, and SPF/DKIM/DMARC domain health results with their remediation actions.
name: "cipp-standards" description: "CIPP's tenant-baseline enforcement model: the Report/Alert/Remediate standards modes and how to roll them out, on-demand standards evaluation, Best Practice Analyser reports, and SPF/DKIM/DMARC domain health results with their remediation actions." when_to_use: >- When auditing standards compliance, running BPA reports, checking domain authentication health, or detecting tenants drifting from configured baselines. Use when: cipp standards, bpa, best practice analyser, best practice analyzer, run standards check, domain health, dmarc, dkim, spf, tenant baseline, compliance drift, or secure score.
Standards are CIPP's mechanism for declaring "this is what every tenant we manage should look like" and continuously enforcing it. The Best Practice Analyser (BPA) is the read side — it shows you where current tenant state diverges from CIPP's recommended baseline. Domain health is a complementary check focused on email authentication.
"baseline", "drift", and "secure score" but measure different things against different templates; a tenant can be CIPP-compliant and Inforcer-drifted at once. Use `inforcer-baseline-alignment`.
standards and do not appear in BPA output; use `cipp-security`.
queue those alerts land in is `cipp-alerts`.
cross-vendor method for comparing tenants to a baseline and deciding what to remediate is `compliance-pack-standards-drift`; this skill is the CIPP standards engine it reads.
cipp_list_standards(tenantFilter='contoso.onmicrosoft.com')
Returns the list of standards configured for the tenant: which standards are enabled, what action each takes (`Report`, `Alert`, `Remediate`), and current compliance status. Use `tenantFilter='allTenants'` for a portfolio-wide view.
cipp_run_standards_check(tenantFilter='contoso.onmicrosoft.com')
Triggers an on-demand standards evaluation. CIPP runs this on a schedule, but force a fresh run after deploying a new standard or remediating a finding to confirm the fix took.
cipp_list_bpa(tenantFilter='contoso.onmicrosoft.com')
Returns the latest Best Practice Analyser report — every CIPP-recommended check with `Pass`/`Fail`/`Warn` status across categories (Security, Identity, Mail, SharePoint, Teams, Intune). The most useful single call for tenant health.
cipp_list_domain_health(tenantFilter='contoso.onmicrosoft.com')
Per-domain SPF, DKIM, DMARC, MX, and DNSSEC results. Run for any tenant where mail authentication is suspect or before/after migrating mail.
A "standard" in CIPP has three modes:
| Mode | Behavior | |------|----------| | `Report` | Check only; show in BPA | | `Alert` | Check + raise alert when out of compliance | | `Remediate` | Check + auto-fix when out of compliance |
The progression for an MSP rolling out a new baseline is typically `Report` → `Alert` → `Remediate` over weeks, with the longest dwell in `Alert` to validate that auto-remediation will be safe.
bpa = cipp_list_bpa(tenantFilter)
fails = [check for check in bpa if check['status'] == 'Fail']
domain = cipp_list_domain_health(tenantFilter)
broken_dmarc = [d for d in domain if d.get('dmarcPass') is not True]A tenant with > 5 BPA failures or any broken DMARC needs a remediation plan, not just a report.
all_tenants_standards = cipp_list_standards(tenantFilter='allTenants')
Compare the standards each tenant has enabled against the MSP's master baseline list. Tenants missing a baseline standard usually mean the standard was deployed *after* the tenant onboarded and never backfilled.
Before you change a tenant's identity or mail config:
1. `cipp_list_bpa` — capture current state 2. Make the change 3. `cipp_run_standards_check` to force a fresh evaluation 4. `cipp_list_bpa` again — diff against pre-change capture
| Result | Meaning | Action | |--------|---------|--------| | SPF: missing | No SPF record at all | Add `v=spf1 include:spf.protection.outlook.com -all` | | SPF: too many lookups | Record exceeds 10-DNS-lookup limit | Flatten or consolidate `include:` directives | | DKIM: not configured | Default DKIM signing disabled | Enable in Defender / Exchange Admin | | DMARC: `p=none` | Reporting only, no enforcement | Move to `p=quarantine` after monitoring | | DMARC: missing | No DMARC record | Add `v=DMARC1; p=none; rua=mailto:dmarc@...` to start |
One command to supercharge Claude Code for MSP workflows. Then restart Claude Code. That's it. Documentation: mcp.wyre.ai
Repo: wyre-technology/msp-claude-plugins
3CX's native PBX MCP server: the per-PBX endpoint shape (every PBX is its own FQDN and its own OAuth authorization server — there is no shared mcp.3cx.com),…
3CX's live-operations surface: read-only visibility into active calls, recordings, voicemail, department and queue membership, and forwarding/presence…
3CX's read-only directory surface: resolving a caller by email or by exact extension, searching the PBX's own phonebooks, searching contacts synced from an…
3CX's system-and-configuration surface: server time, PBX event log and application log search, service status, database schema and the read-only SELECT-only…
Abnormal Security abuse mailbox cases: user-reported email submissions, case statuses and judgments, the case lifecycle, bulk and remediation actions, and…
Abnormal Security message analysis: message retrieval, email header inspection, attachments, sender reputation, delivery context, and SPF/DKIM/DMARC…