Microsoft Work IQ MCP Servers Explained

Microsoft ships two generations of Work IQ MCP: one unified server with ten generic tools, and a set of per-app servers for Mail, Calendar, Teams, Word and SharePoint that Copilot Studio now calls legacy. What each does, how to connect a coding agent, what is preview, and why Microsoft’s own licensing pages disagree.

7 min read

Work IQ MCP is Microsoft’s way of giving AI agents access to Microsoft 365 data: mail, calendar, files, Teams chats, people and sites. As of September 30, 2026 it comes in two shapes. The current one is a single Work IQ MCP server with ten generic tools, reached remotely at https://workiq.svc.cloud.microsoft/mcp or run locally with workiq mcp, the command that gives the search term its one-word spelling. The older one is a family of per-app servers in the Agent 365 catalog, including Work IQ Mail, Calendar, Teams, Word and SharePoint, all marked preview, which Copilot Studio now describes as a legacy experience kept for testing and backward compatibility. Both need a work account in a Microsoft Entra tenant and an administrator’s consent.

The unified Work IQ MCP server

Microsoft’s Work IQ MCP overview (opens in a new tab) sums up the design as “Fewer tools, more paths.” Instead of one tool per operation, the tools are verbs and a Microsoft Graph path says what they act on: fetch /me/messages reads mail, create_entity /me/events creates a meeting. New workloads add paths, not tools, so the list stays at ten:

  • Entity tools: fetch, fetch_blob, create_entity, update_entity, delete_entity, do_action (send, copy, move) and call_function (calendar views, search).
  • Copilot tools: ask, which puts a natural-language question to Microsoft 365 Copilot or a named agent, and list_agents.
  • Schema tools: get_schema and search_paths, so the agent looks up a Graph schema when it needs it instead of loading thousands of definitions up front.

The limits are written down in the Work IQ MCP tool reference (opens in a new tab). Every call runs as the signed-in user, with that person’s Microsoft 365 permissions. A separate tenant policy blocks create, update, delete and action requests by default until an administrator allows them. Paths under /me/, /users/ and /sites/ are allowed by default, /authentication/ and /servicePrincipals/ are blocked, and collections return 25 items unless you ask for more, up to 100. Chat messages come back 10 at a time, and file downloads stop at 4 MB by default.

The per-app servers: Mail, Calendar, Teams, Word and SharePoint

The older catalog, reached through Agent 365, has one server per app, each at a tenant-specific address of the form https://agent365.svc.cloud.microsoft/agents/tenants/{tenantId}/servers/<server>. Their tool names are narrower and easier to reason about:

  • Work IQ Mail (mcp_MailTools) and Work IQ Calendar (mcp_CalendarTools): drafting, sending, replying, searching, scheduling and responding to invitations. We cover both, with their permissions and traps, in Outlook MCP server.
  • Work IQ Teams (mcp_TeamsServer): create, read, update and delete chats; post, edit and delete chat messages; list and create channels, post and reply in them, and manage chat and channel members. Messages are plain text only, and Microsoft notes that posting is not idempotent, so a blind retry posts twice.
  • Work IQ Word (mcp_WordServer): four tools. Create a document in the root of the user’s OneDrive from HTML or text, read a document’s text and comments from its sharing link, add a comment, and reply to one. None of them edits the body of an existing document.
  • Work IQ SharePoint (mcp_SharePointRemoteServer): find sites, browse libraries and folders, read and write files of 5 MB or less, move, copy, rename, delete and share files, manage lists, list items and columns, and set sensitivity labels. Deleting a list or a column cannot be undone.
  • Also in the catalog: Work IQ OneDrive, User and Copilot, servers for Dataverse and Dynamics 365, Windows 365 and Fabric IQ Ontology, and a management server for building your own.

Each reference page carries the same warning: these are preview features, and Microsoft might change preview tool names and parameters, so do not hard-code them.

Preview, generally available, or legacy?

Microsoft’s pages give different answers, and it is worth knowing which one you are reading. The Work IQ CLI page (opens in a new tab) says Work IQ reached general availability on June 16, 2026, and that preview CLI builds such as 0.4.x and 0.5.x are no longer supported. At the same time, the microsoft/work-iq repository still says “Public Preview,” Microsoft Foundry’s Work IQ page carries “(preview)” in its title, and Copilot Studio labels its tool “Work IQ (preview).”

The per-app servers are plainer. Copilot Studio’s Work IQ page (opens in a new tab), updated September 28, 2026, says the separate Mail, Teams, OneDrive, SharePoint, User, Copilot, Search, Calendar and Word tools are part of a legacy experience that remains available for testing and backward compatibility, and tells builders not to pick them in place of Work IQ. It also stresses that Work IQ is not a new label for them. If you are starting today, start with the unified server.

Licensing, by name only

Here the pages contradict each other outright. The Agent 365 tooling overview (opens in a new tab), last updated in August, says you must have a Microsoft 365 Copilot license to use Work IQ MCP servers. The newer Work IQ overview, updated September 25, 2026, says Work IQ API access is independent of Microsoft 365 Copilot licensing and billed on usage, with cost controls in the Microsoft 365 admin center. The CLI page lists a usage-based billing plan set up in Copilot Studio as a prerequisite, and Copilot Studio says Work IQ (preview) uses Copilot Credits while the legacy per-app tools use standard Copilot Studio licensing.

The practical reading: the route you use decides the plan it bills against, and your Microsoft 365 administrator is the one who can say which applies to your tenant. We do not quote prices, and neither should any setup guide you follow.

Connect a coding agent

Before anyone connects, an administrator has work to do. A Global Administrator creates the Work IQ service principal once per organization, a usage-based billing plan has to be assigned, and the delegated permission WorkIQAgent.Ask requires admin consent. Write operations stay off until an administrator turns them on in the Microsoft 365 admin center. If you are not an admin, the first sign-in will show a consent request you cannot approve yourself.

After that, the local server is an npm package. Microsoft documents the command; Claude Code’s usual syntax for a local server wraps it. The EULA has to be accepted once before first use:

Work IQ as a local MCP server
# Install the CLI and accept the license once
npm install -g @microsoft/workiq
workiq accept-eula

# Claude Code
claude mcp add workiq -- npx -y @microsoft/workiq mcp

# GitHub Copilot CLI, inside a session
/plugin marketplace add microsoft/work-iq
/plugin install workiq@work-iq

Microsoft also gives a generic entry for clients that read an MCP settings file, and a one-click install for VS Code. Note that its two setup pages name different Copilot CLI marketplaces: the quickstart uses microsoft/work-iq as above, and the CLI page uses github/copilot-plugins with workiq@copilot-plugins.

MCP settings entry from Microsoft’s CLI page
{
  "workiq": {
    "command": "npx",
    "args": ["-y", "@microsoft/workiq", "mcp"],
    "tools": ["*"]
  }
}

To reach one of the per-app servers from Claude Code or VS Code instead, you register an app in Entra and point the client at the tenant URL with its client ID. That walk-through, with the .mcp.json Microsoft publishes, is in Outlook MCP server.

What to let it do

Work IQ reads everything its user can see, and much of that was written by other people: mail from outside, Teams messages, shared documents. That makes it a channel for indirect prompt injection, and the defaults are sensible for that reason. Keep them:

  • Leave writes off at the tenant level until a specific job needs them, and then allow only the paths that job uses.
  • Prefer questions to actions: “What did the vendor ask for in last week’s thread?” rather than “Reply to the vendor.”
  • Keep your client’s approval prompt on for anything that sends, posts, shares or deletes. Sharing a SharePoint file and posting in a channel both reach other people at once.
  • Remember that ask hands the question to Microsoft 365 Copilot, so the answer is Copilot’s summary, not the source. Fetch the message or document when the exact words matter.

Where the follow-up goes

The best use of Work IQ in a coding agent is pulling decisions and requests out of mail and meetings. They still need somewhere to land that is not another inbox. On a fenbs board, an assistant turns each request into a task, a feature, enhancement or bug with a note that says what and why, and the history records that the assistant filed it. A choice made in a meeting belongs on the Decisions and rules page, where the decider is always a person, not the assistant that read the transcript. fenbs keeps it simple: there are no due dates, no sprints and no settable assignee, so dates and owners stay in the conversation where they were agreed.

Related

Claude’s own route to Outlook, Teams and SharePoint: Claude with Microsoft 365. Why Microsoft’s servers do not reach To Do: Microsoft To Do and MCP. Building agents in Microsoft’s low-code tool: Copilot Studio. What a sign-in grants: how MCP sign-in works.

Questions people ask.

What is WorkIQ MCP?

Microsoft’s MCP access to Microsoft 365 data through Work IQ. The current form is one Work IQ MCP server with ten generic tools that act on Microsoft Graph paths, available remotely or locally through the workiq CLI. Older per-app servers for Mail, Calendar, Teams, Word and SharePoint remain available but Copilot Studio calls them legacy.

Is Work IQ MCP generally available or in preview?

Microsoft’s pages disagree. The Work IQ CLI page says Work IQ became generally available on June 16, 2026, while Copilot Studio, Microsoft Foundry and the microsoft/work-iq repository still label it preview. The per-app Mail, Calendar, Teams, Word and SharePoint servers are marked preview.

Do I need a Microsoft 365 Copilot license for Work IQ MCP?

It depends on the page and the route. The Agent 365 overview says a Microsoft 365 Copilot license is required for the Work IQ MCP servers, while the newer Work IQ overview says access is independent of Copilot licensing and billed on usage. Ask your Microsoft 365 administrator which plan applies to your tenant.

Can Work IQ MCP send email or post in Teams?

Only if an administrator allows it. The unified server blocks create, update, delete and action requests by default through tenant policy. When they are allowed, keep a person approving each send or post in your client.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.