Skip to main content
Version: Latest

Microsoft Outlook connector

The Microsoft Outlook connector exposes the Microsoft Graph Mail API as a set of MCP tools (list / read / send / reply / forward / move / delete mail, plus folder navigation) through the PolicyArc gateway. Every tool call carries the caller's own Microsoft OAuth token, so Outlook's per-user permissions and mailbox boundaries apply naturally.

Prerequisite

You must have the Microsoft Entra ID identity provider connected first. The connector reuses the same Entra app registration — make sure it has the Microsoft Graph Mail.Read, Mail.ReadWrite, and Mail.Send delegated permissions granted (Step 7 of the Microsoft IDP setup).


Step 1 — Open the Add Connector screen​

Open Resources → Add connector (or click Pick a connector from the environment dashboard).

In the Unlocked by your identity providers section, the Microsoft Outlook template will show a green border once the Microsoft IDP is connected.

Connector list — Microsoft Outlook ready

Click Microsoft Outlook.


Step 2 — Connect​

Microsoft Outlook's setup form opens on the Authentication mode, pre-filled with entra_refresh (recommended). Two modes are available:

  • entra_refresh (default) — PolicyArc uses the refresh token obtained at sign-in to mint a per-user Graph token at call time. Works alongside any other Microsoft connector (OneDrive, Teams, Azure DevOps) in the same session with a single sign-in. No separate gateway app required.
  • idp_passthrough — forwards your Microsoft sign-in token straight to Graph. Use this only when every Microsoft connector you run targets Microsoft Graph (Mail, OneDrive, Teams) and the sign-in is audienced for Graph. Don't combine it with Azure DevOps or with entra_refresh connectors.

Leave it on entra_refresh unless you specifically want the direct-passthrough path, then click Connect.

Microsoft Outlook setup screen


Step 3 — Confirm the connector​

After connecting, you'll see the connector's status screen with the 12 available Mail tools (list_folders, list_subfolders, list_messages, get_message, list_attachments, send_mail, create_draft, update_message, delete_message, move_message, reply_message, forward_message). The connector is policy-governed from the first request.

You can return to this view any time from the Resources menu by clicking View on the Microsoft Outlook entry.


What's next​

The Mail tools are now on your gateway. Pick an MCP client to wire up: