Key Takeaways
- The early-access MCP server lets IT teams query endpoint data, create reports, initiate deployments, and build automations through supported AI assistants.
- Existing permissions, OAuth authentication, audit logging, connection visibility, and revocation controls apply to MCP interactions.
- Early access is free across all subscription tiers, with Claude support available through Anthropic’s Connectors Directory and more marketplaces planned.
PDQ is giving system administrators a conversational route into endpoint management. The Salt Lake City-based business recently announced early access to its Model Context Protocol (MCP) server, connecting approved functions with Claude, Microsoft Copilot, VS Code, and other MCP-compatible tools.
Administrators can describe an operational goal instead of manually assembling the corresponding filters, reports, and deployment steps. Queries could identify every device missing Google Chrome, find endpoints that have not checked in during the last 30 days, count devices still running Windows 10, or locate machines missing Zoom. Depending on the user’s permissions, the assistant could then initiate a deployment.
That shift from navigation to intent could shorten routine workflows. It also moves AI assistants beyond summarization and into actions that change managed environments, which raises the stakes for identity, authorization, and oversight.
“IT teams shouldn’t have to spend their time translating a straightforward goal into the right combination of clicks, filters, and reports,” said the VP of product. “PDQ’s MCP server gives admins a more flexible way to investigate their environments and take action while keeping permissions, authentication, and auditing firmly under their control.”
MCP is an open standard for exposing approved data and software capabilities to AI applications through a consistent interface. Anthropic introduced the protocol to reduce the need for separate integrations between each AI assistant and each external system. APIs still sit underneath many MCP implementations, but MCP helps an assistant discover available functions and select them in response to a user’s stated objective.
While easier discovery is useful, it can also make consequential functions easier to invoke. In endpoint management, a vaguely worded request or incorrectly interpreted target group could affect many devices, raising questions about who is permitted to ask questions and act on the answers.
The platform's design addresses that issue by carrying existing administrator-defined permissions into MCP interactions. Administrators can assign read-only, reporting, deployment, or administrative access, determining what each user and AI integration can see and do. Connections use OAuth authentication, while supported actions are recorded in the audit log with both the initiating user and AI client identified.
Administrators can also inspect active MCP connections and revoke access through the application settings. Those controls align with the broader risk-management emphasis in the NIST AI Risk Management Framework, which encourages organizations to define governance, map system context, measure risks, and manage them throughout an AI system’s use.
Still, identity controls do not resolve every concern. AI-connected operational systems face issues such as prompt injection, excessive permissions, unintended tool use, and exposure of sensitive context. The OWASP GenAI Security Project provides guidance on risks involving large language model applications, including insecure outputs and overreliance. For IT leaders assessing the new MCP server, that suggests starting with narrow permissions, monitoring logs, and testing prompts against noncritical device groups before widening access.
The MCP server does not replace the existing interface. Administrators can continue using the standard experience for devices, deployments, software, vulnerabilities, and related operations. MCP instead becomes another interaction layer, particularly useful when an administrator wants a quick answer, an interactive Patch Tuesday HTML report, or an endpoint task incorporated into a larger AI-assisted workflow.
Early access is available at no additional charge to customers across all subscription tiers. Claude users can find the integration through Anthropic’s Connectors Directory, and the company plans to support additional AI marketplaces. Packaging and broader availability after early access have not yet been announced.
For the software provider, which was founded in 2001 and serves over 33,000 customers managing Windows and macOS devices, the launch extends AI from assistance into controlled execution. The real test will be whether administrators find that conversational access saves time without obscuring the scope of an action. The platform's permission inheritance, authentication, auditing, and revocation features provide a structured starting point for integrating AI-assisted workflows.
⬇️