0
/ 100
1 month ago
glama

Join Microsoft 365 MCP Server

Enables AI assistants to seamlessly interact with Microsoft 365 services through the Graph API, featuring super tools, unified search, and intelligent learning.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Reads files from sensitive locations
Touches: /.dockerenv, /.dockerenv
🚨
Known vulnerabilities in dependencies: 1 critical, 4 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 3 credentials: DASHBOARD_PASSWORD, MS365_MCP_CLIENT_SECRET, MS365_MCP_OAUTH_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical4 high1 medium24 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@4.0.18GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

high@modelcontextprotocol/sdk@1.25.3GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

highexpress-rate-limit@8.2.1GHSA-46wh-pxpv-q5gq

express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network

highhono@4.11.7GHSA-88fw-hqm2-52qc

hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

highhono@4.11.7GHSA-q5qw-h33p-qvwr

Hono vulnerable to arbitrary file access via serveStatic vulnerability

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretDASHBOARD_PASSWORDyour-secure-password-here
configENABLED_TOOLS
configFORCE_COLOR
configLOG_FORMAT
configLOG_LEVELLogging level / Logging-Level info
configMS365_MCP_ANONYMIZE_PIIAnonymize PII in knowledge base storage / PII in Wissensdatenbank anonymisieren true
configMS365_MCP_AUTO_QUERY_OPTIMIZATION_ENABLED
configMS365_MCP_CALENDAR_DEFAULT_TIMEZONE
configMS365_MCP_CHAT_MEMORY_ENABLED
configMS365_MCP_CHAT_MEMORY_MAX_HISTORY
configMS365_MCP_CHAT_MEMORY_TTL
configMS365_MCP_CLIENT_IDe =your-client-id \
🔐 secretMS365_MCP_CLIENT_SECRETClient secret (confidential apps) / Client-Geheimnis (vertrauliche Apps) -
configMS365_MCP_CLOUD_TYPECloud environment / Cloud-Umgebung global
configMS365_MCP_CORS_EXPOSED_HEADERS
configMS365_MCP_CORS_HEADERS
configMS365_MCP_CORS_MAX_AGE
configMS365_MCP_CORS_METHODS
configMS365_MCP_CORS_ORIGIN
configMS365_MCP_CORS_ORIGINS
configMS365_MCP_CSP
configMS365_MCP_CSP_DASHBOARD
configMS365_MCP_DEEP_RESEARCH_ITEMS_PER_ITERATION
configMS365_MCP_DEEP_RESEARCH_MAX_DEPTH
configMS365_MCP_ENABLE_DISCOVERY_TOOLS
configMS365_MCP_ENABLE_SELF_REPAIR
configMS365_MCP_FAST_MODE
configMS365_MCP_FORCE_WORK_SCOPES
configMS365_MCP_GRAPH_MAX_RETRIES
configMS365_MCP_GRAPH_REQUEST_TIMEOUT_MS
configMS365_MCP_GRAPH_RETRY_MAX_DELAY_MS
configMS365_MCP_HSTS_MAX_AGE
configMS365_MCP_INTENT_ENTITY_FILTER
configMS365_MCP_KEYVAULT_URLAzure Key Vault URL -
configMS365_MCP_KNOWLEDGE_BASE_PATH
configMS365_MCP_LEARNING_CLUSTER_ENABLED
configMS365_MCP_LEARNING_CLUSTER_THRESHOLD
configMS365_MCP_LEARNING_DECAY_DAYS
configMS365_MCP_LEARNING_DECAY_FACTOR
configMS365_MCP_LEARNING_ENABLED
configMS365_MCP_LEARNING_NLP_ENABLED
configMS365_MCP_MAX_AGGREGATE_ITEMS
configMS365_MCP_MAX_CONCURRENT_TOOLS
configMS365_MCP_MAX_PAGES
configMS365_MCP_MAX_QUERY_VARIANTS
configMS365_MCP_MAX_REPAIR_ATTEMPTS
configMS365_MCP_MAX_RESEARCH_ITERATIONS
configMS365_MCP_MAX_RESPONSE_CHARS
configMS365_MCP_MAX_RESULTSMaximum search results / Maximale Suchergebnisse 500
configMS365_MCP_MIN_RELEVANCE
configMS365_MCP_MULTIQUERY_TIMEOUT
🔐 secretMS365_MCP_OAUTH_TOKENe =your_token \
configMS365_MCP_ORG_MODEEnable organization mode / Organisationsmodus aktivieren false
configMS365_MCP_OUTPUT_FORMATOutput format (json/toon) / Ausgabeformat (json/toon) json
configMS365_MCP_PATTERN_LEARNING_ENABLED
configMS365_MCP_PATTERN_MIN_COUNT
configMS365_MCP_PERMISSIONS_POLICY
configMS365_MCP_QUERY_DECOMPOSITION_ENABLED
configMS365_MCP_QUERY_OPTIMIZATION_CONFIDENCE_THRESHOLD
configMS365_MCP_QUERY_OPTIMIZATION_MIN_PATTERN_COUNT
configMS365_MCP_RATE_LIMIT_MAX_REQUESTS
configMS365_MCP_RATE_LIMIT_WINDOW_MS
configMS365_MCP_READ_ONLY
configMS365_MCP_REFERRER_POLICY
configMS365_MCP_REPAIR_STRATEGIES
configMS365_MCP_RESPONSE_ENVELOPE
configMS365_MCP_RESPONSE_FORMAT
configMS365_MCP_RESPONSE_SUMMARY_FIRST
configMS365_MCP_SEARCH_CROSS_LANGUAGE
configMS365_MCP_SEARCH_DEFAULT_ENTITY_TYPES
configMS365_MCP_SEARCH_INTELLIGENT_MERGE
configMS365_MCP_SEARCH_LEARNED_VARIANTS
configMS365_MCP_SEARCH_MAX_CANDIDATES
configMS365_MCP_SEARCH_MAX_SYNONYM_VARIANTS
configMS365_MCP_SEARCH_PARALLEL_MERGE_COUNT
configMS365_MCP_SEARCH_SIMPLIFIED_FALLBACK
configMS365_MCP_SEARCH_SYNONYM_MERGE_THRESHOLD
configMS365_MCP_SEARCH_USE_OR_QUERY
configMS365_MCP_STOP_ON_ERROR
configMS365_MCP_TENANT_IDe =your-tenant-id \
configMS365_MCP_THINKING_ENABLED
configMS365_MCP_THINKING_LEVEL
configMS365_MCP_X_FRAME_OPTIONS
configNO_COLOR
configQUERY_STORE_DIR
configQUERY_STORE_MAX_QUERIES
configQUERY_STORE_RETENTION_DAYS
configREAD_ONLYEnglish: All Super-Tools respect the environment variable. Write operations (send, create, update, delete) are automatically blocked with clear error messages when read-only mode is enabled.
configSILENTDisable console output / Konsolenausgabe deaktivieren false
configTRUST_PROXY_COUNT
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 9 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/michelfritzschjoin-join-ms-365-mcp-server-122j45)](https://m8ven.ai/mcp/michelfritzschjoin-join-ms-365-mcp-server-122j45)
commit: ebbb537ea363d4e29b6ce4064041dd61f240b71e
code hash: 2c24ac8f1c22cab50dd6a6b59560c47064208a4a3c7be68f3833512321a8697e
verified: 6/24/2026, 9:58:38 AM
view raw JSON →