<div dir="ltr"><span id="gmail-docs-internal-guid-233ff7f1-7fff-b6b4-e852-ccf60eea321b"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:8pt"><span style="font-variant:normal;background-color:transparent;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">The BigFix Platform Team is pleased to announce the availability of the </span><span style="font-variant:normal;background-color:transparent;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);font-weight:700;vertical-align:baseline;white-space:pre-wrap">BigFix Platform MCP Server</span><span style="font-variant:normal;background-color:transparent;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">, a new component that lets you plug your AI assistant of choice directly into BigFix. Through the MCP Server an LLM can retrieve data from your BigFix environment and help you author and run BigFix actions on your endpoints, using natural language. </span><span style="font-variant:normal;background-color:transparent;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">Security controls are provided and enforced on interaction of the LLM with the BigFix Platform, allowing you to tailor the solution to your needs.</span></p><br><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:8pt"><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">AI meets BigFix through an open standard!</span></p><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:8pt"><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">The BigFix Platform MCP Server is built on the </span><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Model Context Protocol (MCP)</span><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">, an open standard that allows AI clients, such as Copilot, to connect to external tools and services through a consistent interface. A MCP server exposes APIs that an AI assistant can call to retrieve data or perform operations in connected systems.</span></p><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:8pt"><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">The BigFix Platform MCP Server introduces a </span><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">managed MCP service for BigFix</span><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap"> that runs in streamable HTTP mode over HTTPS, so it can be reached by any network-accessible MCP client.</span></p><p dir="ltr" style="line-height:1.2;margin-top:8pt;margin-bottom:8pt"><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">What you can do with it</span></p><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:8pt"><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">The new component supports the following BigFix scenarios:</span></p><ul style="margin-top:0px;margin-bottom:0px"><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><span style="font-size:12pt;background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Action lifecycle management: </span><span style="font-size:12pt;background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">list actions, retrieve details and status, inspect and retry downloads, stop actions, create actions, and delete actions.</span></p></li><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><span style="font-size:12pt;background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Custom action authoring: </span><span style="font-size:12pt;background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">author custom actions with the assistance of your LLM.</span></p></li><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><span style="font-size:12pt;background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Fixlet and Task deployment: </span><span style="font-size:12pt;background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">deploy existing Fixlets or Tasks through action creation.</span></p></li><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><span style="font-size:12pt;background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Computer listing: </span><span style="font-size:12pt;background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">list managed computers and retrieve the details of a specific computer.</span></p></li><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><span style="font-size:12pt;background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Fixlet discovery: </span><span style="font-size:12pt;background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">list the Fixlets in a site and retrieve full Fixlet details by site and ID.</span></p></li><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><span style="font-size:12pt;background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Session Relevance evaluation: </span><span style="font-size:12pt;background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">evaluate Session Relevance through BigFix Web Reports or BigFix Explorer</span></p></li></ul><br><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt"><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Secure by default</span></p><br><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:8pt"><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">The BigFix Platform MCP Server is intentionally conservative from a security perspective, with layered guardrails that reduce the risk of autonomously executing destructive operations:</span></p><ul style="margin-top:0px;margin-bottom:0px"><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><span style="font-size:12pt;background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Token-based authentication: </span><span style="font-size:12pt;background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">the service is designed as a token-forwarding gateway. Each MCP request must carry a valid BigFix REST API token in the Authorization header, which is forwarded to the BigFix Platform REST API, so every request runs with the permissions of its own token. This relies on the REST API token support introduced in BigFix 11.0.6. For details, see </span><a href="https://help.hcl-software.com/bigfix/11.0/platform/Platform/Config/c_token_authentication.html" style="text-decoration:none"><span style="font-size:12pt;color:rgb(5,99,193);background-color:transparent;font-variant:normal;text-decoration:underline;vertical-align:baseline;white-space:pre-wrap">Configuring bearer token authentication</span></a><span style="font-size:12pt;background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">.</span></p></li><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><span style="font-size:12pt;background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Strict read-only mode by default: </span><span style="font-size:12pt;background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">write-capable tool families are disabled and hidden unless an administrator explicitly enables them in the server configuration (mcp_server.read_only: false) and the MCP client also opts in on the request with the X-Bes-Mcp-Read-Only: false header.</span></p></li><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><span style="font-size:12pt;background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Human-in-the-Loop protection enabled by default: </span><span style="font-size:12pt;background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">for critical write operations, the AI client is instructed to stop and request explicit user confirmation before sending any payload that triggers persistent modifications to the environment. This protection remains active even when write access is enabled, unless it is explicitly disabled.</span></p></li><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><span style="font-size:12pt;background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">TLS supported natively: </span><span style="font-size:12pt;background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">you can provide your own certificate and key, or let the service automatically generate self-signed certificates in its workspace.</span></p></li></ul><br><p dir="ltr" style="line-height:1.2;margin-top:8pt;margin-bottom:8pt"><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Getting started</span></p><ul style="margin-top:0px;margin-bottom:0px"><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><span style="font-size:12pt;background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Requirements: </span><span style="font-size:12pt;background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">BigFix Platform Version 11.0.6 or later is required</span></p></li><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><span style="font-size:12pt;background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Supported targets: </span><span style="font-size:12pt;background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Windows Server 2022 or later (64-bit) and Red Hat Enterprise Linux 9 or 10 (64-bit).</span></p></li><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><span style="font-size:12pt;background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Installation: </span><span style="font-size:12pt;background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Task 6073: "Install BigFix MCP Server (Version 1.0.0)" is available in BES Support site version 1514 or later. The server can be installed either directly on the BigFix Root Server or on a separate endpoint, as long as that endpoint can reach the Root Server on port 52311. </span></p></li></ul><p dir="ltr" style="line-height:1.2;margin-top:8pt;margin-bottom:8pt"><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-weight:700;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Useful links</span></p><ul style="margin-top:0px;margin-bottom:0px"><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><a href="https://help.hcl-software.com/bigfix/11.0/platform/Platform/MCP/c_introduction.html" style="text-decoration:none"><span style="font-size:12pt;color:rgb(5,99,193);background-color:transparent;font-variant:normal;text-decoration:underline;vertical-align:baseline;white-space:pre-wrap">BigFix MCP Platform documentation</span></a></p></li><li dir="ltr" style="list-style-type:disc;font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:6pt" role="presentation"><a href="https://help.hcl-software.com/bigfix/11.0/platform/Platform/Config/c_token_authentication.html" style="text-decoration:none"><span style="font-size:12pt;color:rgb(5,99,193);background-color:transparent;font-variant:normal;text-decoration:underline;vertical-align:baseline;white-space:pre-wrap">Configuring bearer token authentication (BigFix 11.0.6)</span></a></p></li></ul><br><br><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:8pt"><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">Continue to discuss on the </span><a href="https://forum.bigfix.com/t/the-bigfix-platform-mcp-server-is-now-available/55245" style="text-decoration:none"><span style="font-size:12pt;font-family:"Times New Roman",serif;background-color:transparent;font-variant:normal;text-decoration:underline;vertical-align:baseline;white-space:pre-wrap">forum</span></a></p><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:8pt"><span style="font-size:12pt;font-family:"Times New Roman",serif;color:rgb(0,0,0);background-color:transparent;font-variant:normal;vertical-align:baseline;white-space:pre-wrap">– HCL BigFix – Platform Team</span></p></span><br class="gmail-Apple-interchange-newline"></div>