Outlook MCP Server: Email and Calendar in Claude and Copilot
Two official routes put Outlook mail and calendar behind MCP: Claude’s Microsoft 365 connector and Microsoft’s Work IQ Mail and Calendar servers, which Copilot Studio agents and coding agents use. What each can do, the Entra permissions behind them, delegated vs application access, admin consent, setup, and safe uses.
7 min read
There are two official ways to reach Outlook mail and calendar over MCP. Claude’s Microsoft 365 connector, run by Anthropic, reads Outlook alongside SharePoint, OneDrive and Teams, and sends or changes things only when an administrator turns write tools on. Microsoft’s own Work IQ Mail and Work IQ Calendar servers, in preview, give Copilot Studio agents, Microsoft Foundry agents and coding agents such as Claude Code tools to search, draft, send, reply, delete and schedule. Both need a work or school account in a Microsoft Entra tenant, and both run on Microsoft Graph permissions an administrator consents to. The choice that matters most is not which server, but which permissions it holds and which of its actions wait for a person.
Which route fits
- You use Claude and want Outlook, Teams and files in one place: Claude’s Microsoft 365 connector, covered in depth in Claude with Microsoft 365. This post looks only at its mail and calendar permissions.
- You build agents in Copilot Studio or Microsoft Foundry: the Work IQ Mail and Calendar servers from Microsoft’s tools catalog.
- You want Outlook inside Claude Code, GitHub Copilot CLI or VS Code: the same Work IQ servers, through an app registration of your own.
- You use ChatGPT: its Outlook Email and Outlook Calendar apps, which OpenAI documents in its help center.
One name causes confusion. Microsoft MCP Server for Enterprise sounds like the general Microsoft Graph MCP server, but it answers read-only directory questions about users, groups and devices, not mail. What Microsoft does and does not ship for tasks is in Microsoft To Do and MCP.
Claude’s connector: the mail and calendar permissions
Anthropic’s admin guide, set up the Microsoft 365 connector (opens in a new tab), lists every Graph permission the connector requests, and all of them are delegated. For reading, the Outlook ones are Mail.Read, Mail.ReadBasic, Mail.Read.Shared for shared mailboxes you can open, MailboxSettings.Read, Calendars.Read and Calendars.Read.Shared. Write tools add a second set:
Mail.Send: send and forward email.Mail.ReadWrite: create, update and delete drafts, and move and label messages.Calendars.ReadWrite: create, update, delete and respond to calendar events.MailboxSettings.ReadWrite: manage categories, inbox rules and automatic replies.
That list is also a set of switches. In the Entra admin center, under Enterprise applications, the “M365 MCP Server for Claude” app shows each granted permission, and an admin can revoke one; a tool that needs it then fails with “Failed to call tool.” Revoking Mail.Send and MailboxSettings.ReadWrite while keeping Mail.ReadWrite leaves Claude able to draft replies but unable to send them or set up a forwarding rule. Setting “Assignment required?” to Yes on both of the connector’s apps limits it to the users and groups you add.
Microsoft’s Work IQ Mail and Calendar servers
Microsoft’s Work IQ MCP overview (opens in a new tab) marks the servers as a preview feature and says a Microsoft 365 Copilot license is required. Admins allow or block each server for the whole organization in the Microsoft 365 admin center, and tool calls can be traced in Microsoft Defender’s Advanced Hunting.
The Work IQ Mail reference (opens in a new tab) lists ten tools, whose full names start with mcp_MailTools_graph_mail_. They include createMessage for a draft, sendMail, sendDraft, reply, replyAll, searchMessages, updateMessage and deleteMessage. Read the descriptions closely: reply and replyAll send at once, so drafting a reply means createMessage. Work IQ Calendar has tools to list and get events, check schedules, find meeting times, create, update, delete, accept and decline, and cancel, which notifies attendees. Microsoft warns that preview tool names and parameters might change.
In Copilot Studio
- Open your agent, go to the Tools tab and select Add tool.
- Choose Model Context Protocol, search for mail, and select Work IQ Mail.
- Create a new connection and sign in.
- Test it, and allow the Work IQ tool to connect when asked. Repeat for Work IQ Calendar.
In Claude Code
Coding agents need an app registration in your tenant that acts as the client. In the Entra admin center, create one under App registrations, note its client and tenant IDs, add the WorkIQ-MailServer API permission and consent to it, and add http://localhost:8080/callback as a Mobile and desktop redirect URI. Then put this in a project’s .mcp.json, start Claude Code there, and sign in from /mcp:
{
"mcpServers": {
"WorkIQ-MailServer": {
"type": "http",
"url": "https://agent365.svc.cloud.microsoft/agents/tenants/{tenantId}/servers/mcp_MailTools",
"oauth": { "clientId": "{clientId}", "callbackPort": 8080 }
}
}
}By default in Entra ID any user can register an app, and user consent must be enabled for this flow to work. If your tenant has locked either down, which is common, it is a request to your administrator.
Delegated vs application permissions
Every route above uses delegated permissions: the assistant acts as a signed-in user and, as Microsoft’s Graph permissions overview (opens in a new tab) puts it, “can’t access anything the signed-in user couldn’t access.” Application permissions are the other kind. They work with no user present, and the app can access any data the permission covers across the organization, so an app-only Mail.Read grant reaches every mailbox, not one. Microsoft calls them highly privileged and recommends delegated permissions from a least-privilege perspective whenever they meet the need.
- An assistant working for one person: delegated, always. Its reach then equals that person’s, so connect it as someone whose mailbox and shared mailboxes match the job.
- A background agent that must watch a shared inbox with nobody signed in: application permissions may be the only way. Scope them to named mailboxes with RBAC for Applications in Exchange Online (opens in a new tab), which replaces Application Access Policies, rather than granting tenant-wide mail access.
- Split read from write.
Mail.ReadwithoutMail.Sendis a very different risk from both together.
Admin consent
Who can approve depends on the kind of permission. Microsoft’s guide to granting tenant-wide admin consent (opens in a new tab) says a Privileged Role Administrator can consent to any permission, while a Cloud Application Administrator, AI Administrator or Application Administrator can consent to anything except Graph application permissions. You grant it from Enterprise applications or App registrations, under the app’s permissions, or with a URL of the form https://login.microsoftonline.com/{organization}/adminconsent?client_id={client-id}.
Read the list before you press Grant. Consent covers the whole tenant, and a permission added later needs consent again, which is the moment to ask whether Mail.Send is really needed.
Safe uses
Mail is written by other people, which makes an inbox the classic channel for indirect prompt injection. Choose jobs where a planted instruction has nothing worth doing:
- Triage: “Summarize unread mail in the Projects folder since Monday, grouped by who needs an answer. Do not send, move or delete anything.”
- Drafts: “Draft a reply to the latest message from the vendor and leave it in Drafts.” With Work IQ, check it used a draft tool, not
reply. - Meeting prep: “List tomorrow’s meetings with the most recent thread for each.”
- Scheduling suggestions: “Find three times next week when Priya and I are both free. Do not create or change any events.”
Sending, replying, forwarding and deleting mail, canceling or declining meetings, and changing inbox rules or automatic replies are for a person to approve, one at a time, seeing the full action. Wherever your client lets you set a tool to ask for approval, set these tools that way. Requests found in mail can become tasks on a board instead of actions; Gmail and Google Calendar MCP shows a prompt for that, and on fenbs each task the assistant files is recorded in the history under its name.
Related
What a sign-in grants and how it ends: how MCP sign-in works. Habits for any connection: MCP security best practices. Connecting a board to Claude: the MCP docs page.