{"versionId":"fc28b604-6ae5-4d31-2ae9-08def342dbdd","articleId":"edc12a74-f057-4ac3-2e32-08deb787de13","title":"M365 Tools MCP server | Admin guide","tags":["MCP","System admin","All articles"],"content":"<html><head></head><body><main role=\"main\">\n<section>\n<p>This guide explains how system administrators can set up the M365 Tools MCP server in Theta Assist.</p>\n<p>Use this guide when you need broader Microsoft 365 capability than the standard built-in connectors provide.</p>\n<p>See also:</p>\n<ul>\n<li><a href=\"https://help.thetaassist.ai/article/connectors-and-mcp\" target=\"_blank\" rel=\"noopener\">Connectors | Admin guide</a></li>\n<li><a href=\"https://help.thetaassist.ai/article/authentication-configurations-admin-guide\" target=\"_blank\" rel=\"noopener\">Authentication configurations | Admin guide</a></li>\n<li><a href=\"https://help.thetaassist.ai/article/mcp-servers-admin-guide\" target=\"_blank\" rel=\"noopener\">MCP servers | Admin guide</a></li>\n<li><a href=\"https://help.thetaassist.ai/article/adding-connectors-to-your-assistant\" target=\"_blank\" rel=\"noopener\">Adding tools and connectors to your assistant</a></li>\n<li><a href=\"https://help.thetaassist.ai/article/connect-microsoft-365-apps-like-outlook-and-teams\" target=\"_blank\" rel=\"noopener\">Connect Microsoft 365 apps like Outlook and Teams</a></li>\n<li><a href=\"https://help.thetaassist.ai/article/planner-mcp-tool-admin-guide\" target=\"_blank\" rel=\"noopener\">Planner MCP tool | Admin guide</a></li>\n</ul>\n<p>The M365 Tools MCP server provides broader Microsoft 365 access than the standard built-in connectors. It gives assistants access to email, calendars, Teams, chats, files, SharePoint, OneDrive, people, recent files, <a href=\"https://help.thetaassist.ai/article/use-microsoft-planner-in-theta-assist\" target=\"_blank\" rel=\"noopener\">Planner</a>, and Excel workbook data.</p>\n<div class=\"mce-toc\">\n<h2>Quick links</h2>\n<ul>\n<li><a href=\"#overview\">Overview</a></li>\n<li><a href=\"#m365-tools-vs-standard-microsoft-connectors\">M365 Tools vs standard Microsoft connectors</a></li>\n<li><a href=\"#built-in-theta-assist-mcp-server\">Built-in Theta Assist MCP server</a></li>\n<li><a href=\"#what-the-m365-tools-mcp-server-can-do\">What the M365 Tools MCP server can do</a>\n<ul>\n<li><a href=\"#email-and-mailboxes\">Email and mailboxes</a></li>\n<li><a href=\"#calendar-and-meetings\">Calendar and meetings</a></li>\n<li><a href=\"#files-and-documents\">Files and documents</a></li>\n<li><a href=\"#teams-and-chats\">Teams and chats</a></li>\n<li><a href=\"#people-and-profile-data\">People and profile data</a></li>\n</ul>\n</li>\n<li><a href=\"#available-tools\">Available tools</a>\n<ul>\n<li><a href=\"#email-tools\">Email</a></li>\n<li><a href=\"#calendar-and-meeting-tools\">Calendar and meetings</a></li>\n<li><a href=\"#file-search-onedrive-and-sharepoint-tools\">File search, OneDrive and SharePoint</a></li>\n<li><a href=\"#teams-tools\">Teams</a></li>\n<li><a href=\"#people-profile-and-productivity-tools\">People, profile and productivity</a></li>\n<li><a href=\"#excel-tools\">Excel</a></li>\n</ul>\n</li>\n<li><a href=\"#excel-editing-safety-and-workspace-restrictions\">Excel editing safety and workspace restrictions</a></li>\n<li><a href=\"#excel-workbook-support-and-limitations\">Excel workbook support and limitations</a></li>\n<li><a href=\"#admin-setup-overview\">Admin setup overview</a></li>\n<li><a href=\"#app-registration-permissions\">App registration permissions</a>\n<ul>\n<li><a href=\"#required-permissions\">Required permissions</a></li>\n</ul>\n</li>\n<li><a href=\"#extra-permissions-if-you-already-use-standard-microsoft-connectors\">Extra permissions if you already use standard Microsoft connectors</a>\n<ul>\n<li><a href=\"#why-these-permissions-are-needed\">Why these permissions are needed</a></li>\n</ul>\n</li>\n<li><a href=\"#suggested-rollout-approach\">Suggested rollout approach</a></li>\n<li><a href=\"#notes\">Notes</a></li>\n</ul>\n</div>\n<h2 id=\"overview\">Overview</h2>\n<p>The M365 Tools MCP server allows Theta Assist to work with Microsoft Graph data using delegated user access. In most cases, this means the assistant acts only within the permissions of the signed-in user.</p>\n<p>Compared with the standard Microsoft 365 connectors, this MCP server supports a wider range of actions, including:</p>\n<ul>\n<li>reading emails and attachments</li>\n<li>reading calendars and shared calendars</li>\n<li>retrieving Teams meeting transcripts</li>\n<li>searching across OneDrive, SharePoint and Teams files</li>\n<li>reading Teams channel posts and chat messages</li>\n<li>looking up people and directory details</li>\n<li>listing recent and shared files</li>\n<li>reading Excel worksheets, ranges, tables, and charts</li>\n<li>rendering Excel charts as inline images in chat</li>\n<li>editing supported Excel workbooks inside the <a href=\"https://help.thetaassist.ai/article/save-files-to-microsoft-365-with-theta-assist\" target=\"_blank\" rel=\"noopener\">configured AIWorkSpace folder </a>when enabled by an administrator</li>\n<li>sending an email to the signed-in user</li>\n<li>drafting a new email or reply to an existing email, ready to review and send in Outlook</li>\n<li>working with Planner tasks (<a href=\"https://help.thetaassist.ai/article/planner-mcp-tool-admin-guide\" target=\"_blank\" rel=\"noopener\">see separate setup guide</a>)</li>\n</ul>\n<h2 id=\"m365-tools-vs-standard-microsoft-connectors\">M365 Tools vs standard Microsoft connectors</h2>\n<table style=\"border-collapse: collapse; width: 100%;\">\n<tbody>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><strong>Option</strong></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><strong>Where admins set it up</strong></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><strong>Best for</strong></td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Standard Microsoft connectors</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><strong>Admin &gt; Tools &gt; Connectors</strong></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Simpler built-in Microsoft access with narrower, mostly read-focused capability</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">M365 Tools MCP server</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><strong>Admin &gt; Tools &gt; MCP Servers</strong></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Broader Microsoft 365 capability with a wider set of actions and deeper Graph-based access, including richer Excel workbook support</td>\n</tr>\n</tbody>\n</table>\n<p>If the standard Microsoft connectors already meet your needs, see <a href=\"https://help.thetaassist.ai/article/connectors-and-mcp\" target=\"_blank\" rel=\"noopener\">Connectors | Admin guide</a>.</p>\n<p>If you need broader Microsoft 365 capability, use M365 Tools.</p>\n<h2 id=\"built-in-theta-assist-mcp-server\">Built-in Theta Assist MCP server</h2>\n<p>The M365 Tools MCP tool is a built-in Theta Assist MCP server.</p>\n<p>You do not need to manually enter a custom MCP endpoint URL for this integration.</p>\n<p>To add the M365 Tools MCP tool:</p>\n<ol>\n<li>Go to <strong>Admin &gt; Tools &gt; MCP Servers</strong>.</li>\n<li>Click the green <strong>+ Theta Assist MCP Server</strong> button.</li>\n<li>Select the <strong>M365 Tools</strong> option.</li>\n<li>Attach the appropriate Microsoft authentication configuration.</li>\n<li>Set the approval policy and save.</li>\n</ol>\n<p><img src=\"https://portal.helpfruit.com/api/images/0d5220bc9ad14992d05108dccd460f35/files/M365%20tool.png?width=1000&amp;height=\" alt=\"M365 Tools listed as a built-in Theta Assist MCP server option.\"></p>\n<h2 id=\"what-the-m365-tools-mcp-server-can-do\">What the M365 Tools MCP server can do</h2>\n<h3 id=\"email-and-mailboxes\">Email and mailboxes</h3>\n<p>The server can:</p>\n<ul>\n<li>list email messages</li>\n<li>fetch full message content</li>\n<li>download email attachments</li>\n<li>search for shared or delegated mailboxes</li>\n<li>create draft emails</li>\n<li>create draft replies to existing messages</li>\n<li>send an email to self</li>\n</ul>\n<h3 id=\"calendar-and-meetings\">Calendar and meetings</h3>\n<p>The server can:</p>\n<ul>\n<li>search calendar events</li>\n<li>read calendar attachments</li>\n<li>retrieve Teams meeting transcripts from meeting join links</li>\n</ul>\n<h3 id=\"files-and-documents\">Files and documents</h3>\n<p>The server can:</p>\n<ul>\n<li>search across Microsoft 365 files</li>\n<li>browse OneDrive and SharePoint folders</li>\n<li>download supported files</li>\n<li>read Excel workbook content by worksheet, range, table, and chart</li>\n<li>render Excel charts as inline images in chat</li>\n<li>edit supported Excel workbooks inside the configured AIWorkSpace folder when enabled</li>\n<li>read SharePoint Lists</li>\n</ul>\n<h3 id=\"teams-and-chats\">Teams and chats</h3>\n<p>The server can:</p>\n<ul>\n<li>list joined Teams and channels</li>\n<li>read channel conversations and replies</li>\n<li>list personal and group chats</li>\n<li>search Teams messages</li>\n</ul>\n<h3 id=\"people-and-profile-data\">People and profile data</h3>\n<p>The server can:</p>\n<ul>\n<li>return the signed-in user profile</li>\n<li>look up colleagues</li>\n<li>find relevant people and contacts</li>\n<li>list recent, used, and shared files</li>\n</ul>\n<h2 id=\"available-tools\">Available tools</h2>\n<p>The M365 Tools MCP server includes tools across email, calendar, files, Teams, people, and Excel.</p>\n<h3 id=\"email-tools\">Email</h3>\n<ul>\n<li><code>ta_m365_list_emails</code></li>\n<li><code>ta_m365_get_email</code></li>\n<li><code>ta_m365_get_email_attachment</code></li>\n<li><code>ta_m365_find_mailbox</code></li>\n<li><code>ta_m365_create_draft_email</code></li>\n<li><code>ta_m365_create_draft_reply</code></li>\n<li><code>ta_m365_send_email_to_self</code></li>\n</ul>\n<h3 id=\"calendar-and-meeting-tools\">Calendar and meetings</h3>\n<ul>\n<li><code>ta_m365_get_calendar_events</code></li>\n<li><code>ta_m365_get_calendar_attachment</code></li>\n<li><code>ta_m365_get_meeting_transcript</code></li>\n</ul>\n<h3 id=\"file-search-onedrive-and-sharepoint-tools\">File search, OneDrive and SharePoint</h3>\n<ul>\n<li><code>ta_m365_search_files</code></li>\n<li><code>ta_m365_onedrive_search</code></li>\n<li><code>ta_m365_onedrive_list</code></li>\n<li><code>ta_m365_onedrive_download</code></li>\n<li><code>ta_m365_sharepoint_find_site</code></li>\n<li><code>ta_m365_sharepoint_get_drives</code></li>\n<li><code>ta_m365_sharepoint_search</code></li>\n<li><code>ta_m365_sharepoint_list</code></li>\n<li><code>ta_m365_sharepoint_download</code></li>\n<li><code>ta_m365_sharepoint_find_list</code></li>\n<li><code>ta_m365_sharepoint_get_list_schema</code></li>\n<li><code>ta_m365_sharepoint_query_list</code></li>\n</ul>\n<h3 id=\"teams-tools\">Teams</h3>\n<ul>\n<li><code>ta_m365_teams_list_joined</code></li>\n<li><code>ta_m365_teams_list_channels</code></li>\n<li><code>ta_m365_teams_channel_files_root</code></li>\n<li><code>ta_m365_teams_group_drive</code></li>\n<li><code>ta_m365_teams_get_channel_messages</code></li>\n<li><code>ta_m365_teams_get_channel_replies</code></li>\n<li><code>ta_m365_teams_list_chats</code></li>\n<li><code>ta_m365_teams_get_chat_messages</code></li>\n<li><code>ta_m365_teams_search_messages</code></li>\n</ul>\n<h3 id=\"people-profile-and-productivity-tools\">People, profile and productivity</h3>\n<ul>\n<li><code>ta_m365_get_user</code></li>\n<li><code>ta_m365_find_people</code></li>\n<li><code>ta_m365_recent_files</code></li>\n<li><code>ta_m365_send_email_to_self</code></li>\n</ul>\n<h3 id=\"excel-tools\">Excel</h3>\n<p>Excel support uses Microsoft's supported Graph Workbook API.</p>\n<p>Reading tools:</p>\n<ul>\n<li><code>ta_m365_excel_get_worksheets</code></li>\n<li><code>ta_m365_excel_read_range</code></li>\n<li><code>ta_m365_excel_list_tables</code></li>\n<li><code>ta_m365_excel_list_charts</code></li>\n<li><code>ta_m365_excel_get_chart_image</code></li>\n</ul>\n<p>Editing tools:</p>\n<ul>\n<li><code>ta_m365_excel_update_range</code></li>\n<li><code>ta_m365_excel_add_table_row</code></li>\n<li><code>ta_m365_excel_add_worksheet</code></li>\n<li><code>ta_m365_excel_create_table</code></li>\n</ul>\n<h2 id=\"excel-editing-safety-and-workspace-restrictions\">Excel editing safety and workspace restrictions</h2>\n<p>Excel editing is protected by two separate controls.</p>\n<ol>\n<li><strong>Admin switch.</strong> The existing <strong>Enable AIWorkSpace file writes</strong> setting in <strong>Admin &gt; M365 Tool Settings</strong> also controls whether Excel editing tools are available. When this setting is off, Excel editing tools are not offered to the assistant. Excel reading tools are unaffected.</li>\n<li><strong>Location restriction.</strong> Even when Excel editing is enabled, the assistant can only edit workbooks stored inside the configured workspace folder, which is <strong>AIWorkSpace</strong> by default, or one of its subfolders.</li>\n</ol>\n<p>If the assistant attempts to edit a workbook outside the configured workspace folder, the request is refused and no change is made.</p>\n<p>This matches the existing workspace file write behaviour, so administrators manage one consistent safe area for assistant-created or assistant-edited files. <a href=\"https://help.thetaassist.ai/article/save-files-to-microsoft-365-with-theta-assist\" target=\"_blank\" rel=\"noopener\">Learn more</a></p>\n<h2 id=\"excel-workbook-support-and-limitations\">Excel workbook support and limitations</h2>\n<ul>\n<li>Only modern <code>.xlsx</code> workbooks are supported.</li>\n<li>Legacy <code>.xls</code> workbooks are not supported.</li>\n<li>Workbooks must be stored in OneDrive for Business, SharePoint, or Teams.</li>\n<li>Personal Microsoft accounts and consumer OneDrive are not supported.</li>\n<li>Changes are saved directly to the workbook.</li>\n</ul>\n<h2 id=\"admin-setup-overview\">Admin setup overview</h2>\n<p>To set up the M365 Tools MCP server:</p>\n<ol>\n<li>Create or update a Microsoft Entra ID app registration.</li>\n<li>Add the required Microsoft Graph permissions.</li>\n<li>Grant admin consent where required.</li>\n<li>Reuse or create a Microsoft authentication configuration in Theta Assist.</li>\n<li>Go to <strong>Admin &gt; Tools &gt; MCP Servers</strong>.</li>\n<li>Click the green <strong>+ Theta Assist MCP Server</strong> button.</li>\n<li>Select <strong>M365 Tools</strong>.</li>\n<li>Choose the authentication configuration.</li>\n<li>Review <strong>Admin &gt; M365 Tool Settings</strong> if you want to enable Excel editing or change the workspace folder name.</li>\n<li>Set approval policy and access controls.</li>\n<li>Test with a limited admin or pilot group first.</li>\n</ol>\n<p>For shared authentication setup guidance, see <a href=\"https://help.thetaassist.ai/article/authentication-configurations-admin-guide\" target=\"_blank\" rel=\"noopener\">Authentication configurations | Admin guide</a>.</p>\n<p>For general MCP setup guidance, see <a href=\"https://help.thetaassist.ai/article/mcp-servers-admin-guide\" target=\"_blank\" rel=\"noopener\">MCP servers | Admin guide</a>.</p>\n<h2 id=\"app-registration-permissions\">App registration permissions</h2>\n<blockquote>\n<p><strong>Important:</strong> If you already have an app registration for the existing Microsoft 365 connectors, you can usually extend that same app registration by adding the extra permissions. The next section shows the main differences.</p>\n</blockquote>\n<h3 id=\"required-permissions\">Required permissions</h3>\n<table style=\"border-collapse: collapse; width: 100%;\">\n<tbody>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><strong>Permission</strong></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><strong>Type</strong></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><strong>Purpose</strong></td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Calendars.Read</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read user calendars</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Calendars.Read.Shared</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read user and shared calendars</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Channel.ReadBasic.All</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read the names and descriptions of channels</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>ChannelMessage.Read.All</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read user channel messages</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>ChannelSettings.Read.All</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read the names, descriptions, and settings of channels</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Chat.Read</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read user chat messages</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Contacts.Read</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read user contacts</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Directory.Read.All</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read directory data</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Files.Read</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read user files, including Excel workbook reading</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Files.Read.All</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read all files that user can access</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Files.ReadWrite</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read and edit supported files, including Excel workbooks in the configured AIWorkSpace folder</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Group.Read.All</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read all groups</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Mail.Read</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read user mail</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Mail.ReadWrite</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read and write access to user mail</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Mail.Send</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Send mail as a user</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>MailboxSettings.Read</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read user mailbox settings</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>offline_access</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Maintain access to data you have given it access to</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>OnlineMeetingRecording.Read.All</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read all recordings of online meetings</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>OnlineMeetings.Read</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read user's online meetings</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>OnlineMeetingTranscript.Read.All</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read all transcripts of online meetings</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>openid</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Sign users in</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>People.Read.All</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read all users' relevant people lists</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Presence.Read.All</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read presence information of all users in your organisation</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>profile</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">View users' basic profile</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Sites.Read.All</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read items in all site collections</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Tasks.Read</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read user's tasks and task lists</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>Team.ReadBasic.All</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read the names and descriptions of teams</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>User.Read</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Sign in and read user profile</td>\n</tr>\n<tr>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\"><code>User.ReadBasic.All</code></td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Delegated</td>\n<td style=\"border: 1px solid #ccc; padding: 2px; text-align: left; vertical-align: top;\">Read all users' basic profiles</td>\n</tr>\n</tbody>\n</table>\n<p>For Excel workbooks, reading requires <code>Files.Read</code>. Editing requires <code>Files.ReadWrite</code>.</p>\n<h2 id=\"extra-permissions-if-you-already-use-standard-microsoft-connectors\">Extra permissions if you already use standard Microsoft connectors</h2>\n<p>If your organisation already uses the standard Microsoft 365 connectors, the following are the main additional permissions typically needed for the M365 Tools MCP server:</p>\n<ul>\n<li><code>Calendars.Read.Shared</code></li>\n<li><code>ChannelSettings.Read.All</code></li>\n<li><code>Directory.Read.All</code></li>\n<li><code>Files.Read.All</code></li>\n<li><code>Files.ReadWrite</code></li>\n<li><code>Group.Read.All</code></li>\n<li><code>Mail.ReadWrite</code></li>\n<li><code>Mail.Send</code></li>\n<li><code>MailboxSettings.Read</code></li>\n<li><code>OnlineMeetingRecording.Read.All</code></li>\n<li><code>OnlineMeetings.Read</code></li>\n<li><code>OnlineMeetingTranscript.Read.All</code></li>\n<li><code>People.Read.All</code></li>\n<li><code>Presence.Read.All</code></li>\n<li><code>Tasks.Read</code></li>\n<li><code>User.ReadBasic.All</code></li>\n</ul>\n<h3 id=\"why-these-permissions-are-needed\">Why these permissions are needed</h3>\n<p>These additional permissions enable broader MCP functionality such as:</p>\n<ul>\n<li>shared calendar access</li>\n<li>Teams transcript access</li>\n<li>wider file discovery across Microsoft 365</li>\n<li>people and directory lookups</li>\n<li>sending mail to self</li>\n<li>richer Teams and organisational context</li>\n<li>Excel workbook editing inside the configured workspace folder</li>\n<li>Planner-related access where relevant</li>\n</ul>\n<p>For Planner permissions and further details, see <a href=\"https://help.thetaassist.ai/article/planner-mcp-tool-admin-guide\" target=\"_blank\" rel=\"noopener\">Planner MCP tool | Admin guide</a>.</p>\n<h2 id=\"suggested-rollout-approach\">Suggested rollout approach</h2>\n<p>For initial rollout,we recommend you:</p>\n<ul>\n<li>extend your existing Microsoft app registration rather than creating a duplicate one</li>\n<li>grant the additional permissions listed above</li>\n<li>create a separate Theta Assist authentication configuration for the M365 MCP server if you want to keep it separate from the built-in connectors</li>\n<li>optionally set the MCP server approval policy to <strong>Always require approval</strong> during testing</li>\n<li>restrict access using Access Profiles if only some assistant authors should be able to add the server</li>\n<li>review <strong>Admin &gt; M365 Tool Settings</strong> and decide whether to leave <strong>Enable AIWorkSpace file writes</strong> off or enable it for controlled writing and editing files in&nbsp;SharePoint &amp; OneDrive</li>\n<li>add a new assistant with the tool and validate scenarios such as email access, calendar search, transcript retrieval, file search, Teams retrieval, Excel reading, chart rendering, draft email flows, and Excel editing inside the workspace folder</li>\n<li>confirm that file saving and editing is refused outside the configured workspace folder</li>\n</ul>\n<h2 id=\"notes\">Notes</h2>\n<ul>\n<li>All access is based on delegated permissions, so the assistant can only act on data the signed-in user already has access to.</li>\n<li>The permission set for this MCP server is broader than the standard connector setup and should be reviewed by your Microsoft 365 administrator and security team.</li>\n<li>If you already use Microsoft connectors in Theta Assist, this is typically an extension of your existing setup, not a full rebuild.</li>\n</ul>\n</section>\n</main></body></html>","description":"Set up the M365 Tools MCP server in Theta Assist to give assistants secure access to Microsoft 365 data such as email, calendars, Teams, SharePoint, OneDrive and Excel workbooks.","isMarkdown":false,"publishedOnUtc":"2026-08-14T01:45:06.0644612","modifiedOnUtc":"2026-05-21T22:25:30.6830162"}