OfficeMCP
Remote Microsoft Graph MCP with delegated OAuth for Microsoft 365 — mail, calendar, OneDrive, SharePoint and Teams.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for OfficeMCP, derived from its capabilities.
AIVSS 9.0 · Critical
View MAESTRO 7-layer threat model →Overview
OfficeMCP is a remote MCP server for Microsoft Graph with delegated OAuth, enabling natural-language interaction with Microsoft 365 services like mail, calendar, OneDrive, SharePoint and Teams. Security surface: delegated Graph scopes give broad access to a user's email, files and chats, making token scope and injection into that content the key concerns.
Key features
- Delegated OAuth to Microsoft Graph
- Mail and calendar tools
- OneDrive/SharePoint file access
- Teams interaction
Use cases
- Manage M365 mail and files via an agent
- Automate calendar and Teams tasks