Secure Microsoft 365 access for AI agents, without a Copilot license

Mail, calendar, contacts, OneNote, To Do tasks, files, Teams chats and channels, and meeting data via Microsoft Graph, no Copilot license required

Microsoft 365 Graph connects your agents to mail, calendar, contacts, OneNote, Microsoft To Do tasks, and OneDrive files, plus Teams chats, channels, and meeting recordings, transcripts, and attendance data, by calling Microsoft Graph directly with each user's own signed-in token. Every call runs through your policies and is logged for audit. It needs only a standard Microsoft 365 subscription, with no Microsoft 365 Copilot license required.

Credential modes

Microsoft 365 Graph supports bring your own app only. It does not support dynamic client registration, so your organization registers its own Entra app in Azure and supplies the client ID and secret. See Credential modes for how the modes compare.

Before you begin

  • A Microsoft Entra admin able to register an application in your tenant, and to grant admin consent for it. Any user can register an app by default unless your tenant restricts this, but the consent step needs an admin.
  • Administrator access to your Agent Authority workspace, to add the resource.

Setup moves between two consoles. You copy a redirect URI in the Agent Authority console, register an app in Microsoft Entra and grant consent, then return to the console and paste the credentials. Keep both tabs open as you work.

Setup

1. Copy the redirect URI

In the Agent Authority console, go to Resources → Add Resource and select Microsoft 365 Graph. This resource is bring-your-own-app only, so the credentials form opens as soon as you select it, with no mode to pick.

Copy the Redirect URI shown on the form. It includes your tenant's region, so copy it rather than typing it. It takes the form https://oauth.aisecurity.services.<region>.connect.secureauth.com/auth/callback.

Leave this page open. You come back to it in step 4.

2. Register an Entra app in Azure

Sign in to portal.azure.com and go to Microsoft Entra ID → App registrations → New registration.

Register the app

Configure:

  • Name – your preferred name, for example <your-company> AI Gateway - Microsoft 365 Graph
  • Supported account types – Multiple Entra ID tenants, with Allow all tenants as the sub-option, which is the default. Multi-tenant is required because the gateway's OAuth flow uses Microsoft's /common endpoint, which does not accept single-tenant apps.
  • Redirect URI – choose the Web platform and paste the Redirect URI from the form in the Agent Authority console, using the Copy button next to it

Click Register.

Add the API permissions

On the new app's API permissions page, click Add a permission → Microsoft Graph → Delegated permissions, and add the scopes listed under Required scopes.

The three OpenID Connect scopes (offline_access, openid, profile) live under the OpenId permissions section near the bottom of the picker, which is easy to miss because they are not in the main alphabetical list.

Create a client secret

On Certificates & secrets, click New client secret and set an expiry. Copy the secret value immediately, because Microsoft only displays it once. This is your Client Secret.

Then copy the Application (client) ID from the app's Overview page. This is your Client ID.

On the API permissions page, click Grant admin consent for <your tenant> at the top of the permissions list.

Without admin consent, users cannot connect at all

Several of the Teams scopes are not user-consentable, so this step is required rather than optional. Skip it and users fail to connect with an AADSTS65001 consent error.

4. Finish in the console

Back on the Microsoft 365 Graph form in the Agent Authority console, paste the Client ID and Client Secret. Leave Token Endpoint Authentication on Auto-detect. Then click Add.

The resource is added with all tools and scopes pre-configured, and an Admin setup required dialog appears with a Setup guide button linking back to this page.

Upgrading an existing installation

This connector's catalog entry added 13 delegated scopes for Teams chats, channels, and teams. If you installed this resource before Teams support shipped, add the new scopes listed under Required scopes to your existing Entra app registration, then re-grant admin consent.

Existing connections also need to reconnect: the new Teams tools do not appear on a connection until it is re-authenticated.

The Microsoft To Do tools add one more delegated scope, Tasks.ReadWrite. If you installed this resource before To Do support shipped, add Tasks.ReadWrite to your Entra app registration and grant admin consent again. Each user then reconnects once. Until they do, To Do calls fail with a Microsoft Graph 403 error, because the user's token doesn't carry the new scope.

Verify the connection

The gateway syncs the Microsoft 365 tools automatically. To check the connection end to end, ask your agent to run a request:

Show my Microsoft 365 profile

If your name and email come back, the connection is working.

How users connect

Access is per user. Each additional user connects their own Microsoft 365 account the first time their agent calls a Microsoft 365 tool: the gateway returns a sign-in link, the user authorizes once, and the tools work from then on. Go to Connections to manage linked accounts.

Each call uses the signed-in user's own token, so Microsoft 365's own permissions control what they can reach. The gateway does not widen access beyond what the authenticated user could already do in Microsoft 365.

Available tools

All 150 tools ship with the catalog entry, so they appear in tool lists and policy pickers as soon as the resource is installed. Each is a direct pass-through to a Microsoft Graph operation, so the agent composes them the same way it would call Graph.

Mail – search & read

ToolTagsDescription
list_messagesread-onlyList messages in the mailbox, newest first; select/top/filter/search supported
get_messagesread-onlyGet a single message by ID
list_mail_foldersread-onlyList mail folders (Inbox, Drafts, Sent Items, and so on)
list_mail_child_foldersread-onlyList child folders of a mail folder
list_mail_folder_messagesread-onlyList messages within a specific mail folder

Mail – drafts & sending

ToolTagsDescription
create_draftwriteCreate a draft message (send later with send_draft)
send_draftwrite, externalSend an existing draft by ID
send_mailwrite, externalSend a message directly
reply_messagewrite, externalReply to the sender; saved to Sent Items
reply_all_messagewrite, externalReply to all recipients; saved to Sent Items
create_reply_draftwriteCreate a draft reply to the sender, without sending it
create_reply_all_draftwriteCreate a draft reply to all recipients, without sending it
forward_messagewrite, externalForward a message to new recipients

Mail – manage & organize

ToolTagsDescription
update_messagewriteUpdate a message by ID (mark read/unread, flag)
delete_messagedestructiveDelete a message by ID
move_mail_messagewriteMove a message to another folder
create_mail_folderwriteCreate a mail folder
create_mail_child_folderwriteCreate a child folder inside a mail folder
update_mail_folderwriteRename a mail folder
delete_mail_folderdestructiveDelete a mail folder

Mail – inbox rules

ToolTagsDescription
list_mail_rulesread-onlyList inbox message rules
create_mail_rulewrite, externalCreate an inbox rule (conditions and actions)
update_mail_rulewrite, externalUpdate an inbox rule by ID
delete_mail_ruledestructiveDelete an inbox rule by ID

Mail – attachments

ToolTagsDescription
list_attachmentsread-onlyList attachment metadata for a message
get_attachmentread-onlyGet a single attachment (includes base64 content for file attachments)
add_attachmentwriteAdd an attachment to a message or draft (inline, under 3 MB)
delete_attachmentdestructiveDelete an attachment from a message by ID

Calendar – events

ToolTagsDescription
list_eventsread-onlyList event objects in the mailbox
list_calendar_viewread-onlyList events in a time range, with recurrences expanded
get_eventsread-onlyGet a single event's properties
create_eventswrite, externalCreate an event
update_eventwrite, externalUpdate an event by ID
delete_eventdestructive, externalDelete an event by ID
cancel_eventdestructive, externalCancel an organized event, notifying attendees

Calendar – invitations

ToolTagsDescription
accept_eventwrite, externalAccept an event invitation
decline_eventwrite, externalDecline an event invitation
tentatively_accept_eventwrite, externalTentatively accept an event invitation
forward_eventwrite, externalForward an event to additional recipients

Calendar – calendars & scheduling

ToolTagsDescription
list_calendarsread-onlyList the user's calendars
create_calendarwriteCreate a secondary calendar
update_calendarwriteRename or recolor a calendar
delete_calendardestructiveDelete a calendar
get_scheduleread-onlyGet free/busy for one or more people over a window
find_meeting_timesread-onlySuggest meeting times from attendee free/busy

Contacts

ToolTagsDescription
list_contactsread-onlyList personal contacts
get_contactread-onlyGet a single contact by ID
create_contactwriteCreate a contact
update_contactwriteUpdate a contact by ID
delete_contactdestructiveDelete a contact by ID
list_contact_foldersread-onlyList contact folders
create_contact_folderwriteCreate a contact folder
update_contact_folderwriteRename a contact folder
delete_contact_folderdestructiveDelete a contact folder
list_contact_folder_child_foldersread-onlyList child folders of a contact folder
create_contact_child_folderwriteCreate a child folder inside a contact folder
create_contact_in_folderwriteCreate a contact inside a specific folder
list_folder_contactsread-onlyList contacts within a specific folder

Teams meetings

ToolTagsDescription
create_online_meetingwriteCreate a Teams online meeting
get_online_meetingread-onlyGet an online meeting by ID
update_online_meetingwriteUpdate an online meeting by ID
delete_online_meetingdestructiveDelete an online meeting by ID
list_online_meetingsread-onlyFind online meetings; filter by join URL to resolve an ID
list_recordingsread-onlyList recording metadata for an online meeting
list_transcriptsread-onlyList transcripts available for an online meeting
get_transcript_contentread-onlyGet a transcript's content (WebVTT)
list_attendance_reportsread-onlyList attendance reports for a meeting (one per session)
list_attendance_recordsread-onlyList per-attendee attendance records for a report

Teams – chats

ToolTagsDescription
list_chatsread-onlyList the chats the signed-in user is part of
create_chatwriteCreate a new one-on-one or group chat
get_chatread-onlyGet a single chat by ID
list_chat_membersread-onlyList a chat's members
list_chat_messagesread-onlyList messages in a chat
get_chat_messageread-onlyGet a single message or reply from a chat
send_chat_messagewrite, externalSend a message in a chat
reply_to_chat_messagewrite, externalReply to a message in a chat
list_chat_message_repliesread-onlyList replies to a chat message
list_chat_message_hosted_contentsread-onlyList hosted content (for example, inline images) on a chat message
set_chat_message_reactionwriteAdd a reaction to a chat message
unset_chat_message_reactionwriteRemove a reaction from a chat message
list_pinned_chat_messagesread-onlyList messages pinned in a chat
pin_chat_messagewritePin a message in a chat
unpin_chat_messagewriteUnpin a message from a chat

Teams – teams & channels

ToolTagsDescription
list_joined_teamsread-onlyList the teams the signed-in user has joined
list_my_associated_teamsread-onlyList teams the user is associated with, including shared-channel host teams
get_teamread-onlyGet a team by ID
list_team_membersread-onlyList a team's members
list_team_channelsread-onlyList a team's channels
get_team_channelread-onlyGet a single channel by ID
create_team_channelwriteCreate a channel in a team
update_team_channelwriteUpdate a channel's properties
list_channel_messagesread-onlyList messages in a channel
get_channel_messageread-onlyGet a single message from a channel
send_channel_messagewrite, externalSend a message in a channel
reply_to_channel_messagewrite, externalReply to a message in a channel
list_channel_message_repliesread-onlyList replies to a channel message
list_channel_message_hosted_contentsread-onlyList hosted content on a channel message
set_channel_message_reactionwriteAdd a reaction to a channel message
unset_channel_message_reactionwriteRemove a reaction from a channel message
list_channel_tabsread-onlyList the tabs configured in a channel
get_channel_files_folderread-onlyGet the drive folder backing a channel's Files tab
list_my_installed_teams_appsread-onlyList Teams apps installed in the signed-in user's personal scope

OneNote

ToolTagsDescription
list_onenote_notebooksread-onlyList the user's OneNote notebooks
create_onenote_notebookwriteCreate a notebook
get_onenote_notebook_from_web_urlread-onlyResolve a notebook from its web URL
list_onenote_notebook_sectionsread-onlyList the sections in a notebook
create_onenote_sectionwriteCreate a section in a notebook
list_all_onenote_sectionsread-onlyList all sections across notebooks
list_onenote_section_groupsread-onlyList section groups
list_onenote_section_pagesread-onlyList pages in a section
list_onenote_pagesread-onlyList all pages
get_onenote_page_contentread-onlyGet a page's HTML content
delete_onenote_pagedestructiveDelete a page by ID

Microsoft To Do – lists & tasks

Start with list_todo_lists to find a list's ID, then pass it to the task tools. Every user has a default Tasks list.

ToolDescription
list_todo_listsList the user's task lists
get_todo_listGet a single task list by ID
create_todo_listCreate a task list
update_todo_listRename a task list
delete_todo_listDelete a task list and the tasks in it
list_todo_tasksList the tasks in a list, with status, importance, and due dates
get_todo_taskGet a single task by ID
create_todo_taskCreate a task in a list
update_todo_taskUpdate a task, for example to mark it completed or change its due date
delete_todo_taskDelete a task by ID
ToolDescription
list_todo_checklist_itemsList a task's checklist items (subtasks)
get_todo_checklist_itemGet a single checklist item by ID
create_todo_checklist_itemAdd a checklist item to a task
update_todo_checklist_itemCheck off or rename a checklist item
delete_todo_checklist_itemDelete a checklist item
list_todo_linked_resourcesList a task's links back to its source item, such as an email
get_todo_linked_resourceGet a single linked resource by ID
create_todo_linked_resourceLink a task to an item in another app
update_todo_linked_resourceUpdate a linked resource
delete_todo_linked_resourceDelete a linked resource
list_todo_attachmentsList a task's file attachments
get_todo_attachmentGet a single attachment, including its base64 content
add_todo_attachmentAdd a file attachment to a task (inline, under 3 MB)
delete_todo_attachmentDelete an attachment from a task

Files & search (OneDrive + SharePoint)

Read-only file access and search across the user's OneDrive and any SharePoint document libraries they can reach. To search a specific library, resolve its drive-id first. Use list_drives for the user's own OneDrive and list_site_drives for a SharePoint site's document libraries.

ToolTagsDescription
list_drivesread-onlyList the signed-in user's own drives (their OneDrive)
list_site_drivesread-onlyList a SharePoint site's document libraries by site-id
get_drive_root_itemread-onlyGet a drive's root item: the starting point for browsing a library
search_driveread-onlySearch a drive (OneDrive or a SharePoint document library) for files by query
search_folderread-onlySearch within a specific folder for files by query
list_recent_filesread-onlyList the files the user most recently used across OneDrive and SharePoint
list_shared_with_meread-onlyList files and folders shared with the user, including SharePoint items
ToolTagsDescription
list_relevant_peopleread-onlyList the people most relevant to the signed-in user
get_my_presenceread-onlyGet the signed-in user's Teams presence
search_queryread-onlyRun a Microsoft Search query across content types: use entityTypes: ["driveItem"] to find SharePoint & OneDrive documents by keyword

Profile & settings

ToolTagsDescription
user_get_userread-onlyGet the signed-in user's profile
get_mailbox_settingsread-onlyGet time zone, working hours, language, and auto-reply configuration
update_mailbox_settingswrite, externalUpdate mailbox settings (time zone, working hours, auto-reply)

Known limitations

A few Graph operations can't be driven by a pure JSON pass-through tool, so they aren't exposed:

  • OneNote page creation is not available. You can create notebooks and sections and list, read, and delete pages, but creating a page requires a multipart HTML request body that a pass-through tool can't send.
  • Meeting recording content download is not available. list_recordings returns recording metadata; downloading the recording video is a binary stream, not a pass-through call. Transcript content is available via get_transcript_content.
  • Large attachment upload is not available. Uploading files over 3 MB requires a chunked upload session. Attachments under 3 MB work via add_attachment for mail and add_todo_attachment for To Do tasks.
  • To Do open extensions are not exposed. Graph's custom-data extensions on task lists and tasks are a developer feature with no To Do user-facing equivalent, so they're left out.
  • Online-meeting AI insights are not available. Microsoft's Copilot-generated meeting summaries and action items are a beta-only API, not present in the pinned Graph spec this connector generates from.

Required scopes

Add all of these under API permissions as delegated permissions, in step 2. Each tool requests the least-privilege scope Microsoft's own permissions data maps to its operation, and the catalog requests the collapsed union across all 150 tools.

  • openid, profile – sign-in identity
  • offline_access – maintain access when the user is offline
  • User.Read – read the signed-in user's profile
  • Mail.ReadWrite – list, search, read, draft, update, move, and delete mail, folders, and attachments
  • Mail.Send – send mail directly, reply, reply all, and forward
  • Calendars.ReadWrite – read, create, update, delete, cancel, and respond to calendar events and calendars
  • Calendars.Read.Shared – suggest meeting times and read free/busy from attendees' shared calendars
  • Contacts.ReadWrite – read, create, update, and delete contacts and contact folders
  • MailboxSettings.ReadWrite – read and update mailbox settings, and manage inbox rules
  • Notes.ReadWrite – read and create OneNote notebooks, sections, and pages
  • Tasks.ReadWrite – read, create, update, and delete Microsoft To Do task lists, tasks, checklist items, linked resources, and attachments
  • Files.Read.All – list OneDrive drives and SharePoint document libraries, and search and browse their files
  • OnlineMeetings.ReadWrite – create, read, update, and delete the user's online meetings
  • OnlineMeetingTranscript.Read.All – list and read Teams meeting transcripts
  • OnlineMeetingRecording.Read.All – list Teams meeting recordings
  • OnlineMeetingArtifact.Read.All – read meeting attendance reports and records
  • People.Read – read the user's relevant people list
  • Presence.Read – read the user's presence
  • Chat.Create – create new chats
  • Chat.ReadWrite – read and write chat messages
  • ChatMember.Read – list chat members
  • ChatMessage.Send – send and react to chat messages
  • ChannelMessage.Send – send and react to channel messages
  • Team.ReadBasic.All – list and read teams
  • TeamMember.Read.All – list team members
  • Channel.ReadBasic.All – list and read channels
  • Channel.Create – create channels
  • ChannelSettings.ReadWrite.All – update channel properties
  • ChannelMessage.Read.All – read channel messages
  • TeamsTab.Read.All – list a channel's tabs
  • TeamsAppInstallation.ReadForUser – list the user's installed Teams apps

Policy examples

Rules are evaluated top to bottom and the first match wins. Allow rules on their own restrict nothing, your org starts with a seeded Allow all rule, so any tools your allows don't cover still fall through to it. A restrictive recipe needs a catch-all deny scoped to this resource, ordered below the allows. New rules are inserted at the top of the list, so create them in reverse order or drag them into place. See Policies.

  • Read-only access. Allow list_*, get_*, and find_*, then deny * below them.
  • Block sending and replies. Deny send_*, reply_*, and forward_* above any allow rules.
  • Block destructive operations. Deny delete_*, cancel_*, move_*, and update_*.
  • Allow mail triage but block calendar changes. Allow *message*, get_*, and list_*, then deny *event*, then deny * (list_events still reads if you allow it explicitly above the *event* deny).
  • Allow reading Teams meeting artifacts only. Allow list_transcripts, get_transcript_content, list_recordings, and list_attendance_*, then deny *.
  • Allow reading Teams chats and channels, block sending. Allow list_chat*, get_chat*, list_channel*, get_channel*, list_team*, get_team*, list_joined_teams, list_my_*, list_pinned_chat_messages, then deny *.
  • Allow reading To Do tasks only. Allow list_todo_* and get_todo_*, then deny *. The catalog still requests Tasks.ReadWrite at sign-in, so the policy, not the token, is what keeps To Do read-only.
  • Allow full access for a specific agent. Scope an allow rule for * to that agent on this MCP server.
  • Block destructive tools. Add a deny rule with the built-in destructive tag (Tools pill) for this resource (MCP pill).

Tool patterns are case-sensitive and match exactly unless they contain *. This connector's tools are snake_case, for example list_messages.

Next steps

  • Create a policy – start from the read-only pattern in Policy examples above.
  • Connections – manage the Microsoft 365 accounts your users have linked.

On this page