Microsoft 365 MCP server icon

Microsoft 365

by Microsoft 365

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Productivity7 tools

Anthropic's own connector for SharePoint, OneDrive, Outlook and Teams, not Microsoft's. Read-only until an Entra Global Admin consents to write scopes.

Verified connector

Listed by Anthropic as an Anthropic-built connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect Microsoft 365 via MCP

https://microsoft365.mcp.claude.com/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

Use in Agentman

Connect Microsoft 365 once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Microsoft 365 Tools & Capabilities (7)

sharepoint_search
sharepoint_folder_search
outlook_email_search
outlook_calendar_search
find_meeting_availability
chat_message_search
read_resource

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • Work and school accounts only. No personal Microsoft account can authenticate. Anthropic requires an Entra tenant on a Microsoft Business plan.
  • No writes without two admin actions. Entra consent to the write scopes, plus enabling write tools in Claude. Either one missing means read-only.
  • Teams is permanently read-only. No tool posts a message or changes a Teams setting, whatever is enabled.
  • Attachments are unsupported in write tools. Sending, forwarding and drafting all reject a message carrying one.
  • File and calendar writes are not tagged. Only sent email carries an agent-initiated attribution header, by Anthropic's own note.
  • SharePoint search cannot be scoped to specific sites. It runs tenant-wide under the user's own permissions; Anthropic states site-specific restriction is not supported.
  • Online Archive mailboxes are not searched. Mail search covers the primary mailbox and its Archive folder plus accessible shared mailboxes, but not the separate In-Place Archive, so retention-moved messages are invisible.
  • Limited file formats. Word, Excel, PowerPoint, PDF and plain text open. Other formats, OneNote included, appear in search results but fail on read with a MIME-type error.
  • Location and sign-in frequency Conditional Access policies break it. Anthropic states its server-side requests always appear from 160.79.104.0/21, so such policies block every member until the range is excluded — an exclusion Anthropic warns should never be applied to a device compliance policy.
  • Service principal authentication is unsupported. Access is user-delegated only.
  • Per-user rate limits apply to writes, sends and recipients; Anthropic does not publish the numbers.
  • We could not read tool schemas. The endpoint is OAuth-gated, so tool names come from the directory snapshot and behaviour from Anthropic's documentation. No safety annotations, parameters or descriptions were observable.

Frequently asked questions

No. Anthropic built and operates it. The directory lists Anthropic as the author, the endpoint sits on microsoft365.mcp.claude.com, and Anthropic's own security guide calls it an Anthropic-hosted integration and a secure proxy. Microsoft's role is the identity provider and the Graph API underneath. Anthropic states it completed Microsoft's publisher verification for the two app registrations.

Only after a Microsoft Entra Global Administrator consents to write scopes and an admin turns write tools on. Anthropic's documentation states that without that step the integration is read-only. With write tools enabled it can send email, manage drafts and calendar events, update mailbox settings, and create and update files in OneDrive and SharePoint.

Anthropic documents roughly twenty-eight delegated Graph permissions. The read set covers mail, calendar, Teams chat and channels, meeting recordings and transcripts, OneDrive and SharePoint files, and basic profiles of everyone in the directory. The write set adds five: Mail.Send, Mail.ReadWrite, Calendars.ReadWrite, Files.ReadWrite.All and MailboxSettings.ReadWrite, each consented separately.

Yes, at four levels. No one in a tenant can connect until an Entra Global Administrator grants one-time consent. Admins can set Assignment required on both enterprise applications to limit it to named groups, revoke individual Graph permissions to disable whole product areas, and on Team and Enterprise plans a Claude organization Owner must separately enable it.

Yes, the ones you can already read. Anthropic documents Chat.Read, ChatMessage.Read and ChannelMessage.Read.All among the requested delegated permissions, and chat_message_search searches Teams chat. Access mirrors your own Microsoft 365 permissions, so a private channel you are not a member of stays out of reach. Teams is read-only in both directions — no tool posts.

No. Anthropic states the connector requires a Microsoft Entra tenant tied to a Microsoft Business plan, and that personal accounts such as outlook.com, hotmail.com and live.com cannot authenticate. Anyone trying gets an authentication error. The connector itself is available on every Claude plan, including Free — the gate is the Microsoft account type, not the Claude subscription.

It reads a single file, email or chat message identified by a URI, rather than searching for one. Anthropic's security guide lists its required permission as varying by resource type, so its reach is bounded by whichever Graph scopes your tenant actually consented to. Revoke Sites.Read.All and its SharePoint reads fail alongside the search tools.

Usually a Conditional Access sign-in frequency policy. Anthropic states that after you sign in, its servers exchange tokens on your behalf, and in its testing Entra sees those requests as coming from Anthropic's IP range 160.79.104.0/21 rather than your device or network. Location and sign-in frequency policies therefore hit the connector for everyone in the tenant.

Sources

Server Info

Category
Productivity
Developer
Microsoft 365
Tools
7
Domain
microsoft365.mcp.claude.com

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.

Ready to connect Microsoft 365?

Connect Microsoft 365 once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.