Join Microsoft 365 MCP Server
README.md
<p align="center">
<img src="https://img.shields.io/badge/Microsoft%20365-0078D4?style=for-the-badge&logo=microsoft&logoColor=white" alt="Microsoft 365">
<img src="https://img.shields.io/badge/MCP%20Protocol-00A9CE?style=for-the-badge&logo=data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCI+PHBhdGggZmlsbD0id2hpdGUiIGQ9Ik0xMiAyTDIgN2wxMCA1IDEwLTV6Ii8+PC9zdmc+" alt="MCP">
<img src="https://img.shields.io/badge/Docker-2496ED?style=for-the-badge&logo=docker&logoColor=white" alt="Docker">
<img src="https://img.shields.io/badge/TypeScript-3178C6?style=for-the-badge&logo=typescript&logoColor=white" alt="TypeScript">
</p>
<h1 align="center">๐ Join Microsoft 365 MCP Server</h1>
<p align="center">
<strong>The Ultimate AI-Powered Gateway to Microsoft 365</strong><br>
<strong>Der ultimative KI-gestรผtzte Zugang zu Microsoft 365</strong>
</p>
<p align="center">
A powerful Model Context Protocol (MCP) server enabling AI assistants to seamlessly interact with Microsoft 365 services through the Graph API.<br>
Ein leistungsstarker Model Context Protocol (MCP) Server, der KI-Assistenten ermรถglicht, nahtlos mit Microsoft 365-Diensten รผber die Graph API zu interagieren.
</p>
<p align="center">
<a href="#-overview--รผbersicht">Overview</a> โข
<a href="#-quick-start--schnellstart">Quick Start</a> โข
<a href="#-features--funktionen">Features</a> โข
<a href="#-super-tools--super-tools">Super Tools</a> โข
<a href="#-tool-categories--tool-kategorien">Tools</a> โข
<a href="#-configuration--konfiguration">Configuration</a> โข
<a href="#-security--sicherheit">Security</a>
</p>
---
## ๐ Table of Contents / Inhaltsverzeichnis
- [Overview / รbersicht](#-overview--รผbersicht)
- [Quick Start / Schnellstart](#-quick-start--schnellstart)
- [Features / Funktionen](#-features--funktionen)
- [Super Tools / Super-Tools](#-super-tools--super-tools)
- [Tool Categories / Tool-Kategorien](#-tool-categories--tool-kategorien)
- [Intelligent Discovery System](#-intelligent-discovery-system)
- [Configuration / Konfiguration](#-configuration--konfiguration)
- [Authentication Methods / Authentifizierungsmethoden](#-authentication-methods--authentifizierungsmethoden)
- [Security & Compliance / Sicherheit & Compliance](#-security--compliance--sicherheit--compliance)
- [API Reference / API-Referenz](#-api-reference--api-referenz)
---
## ๐ Overview / รbersicht
### English
The **Join Microsoft 365 MCP Server** transforms how AI assistants interact with Microsoft 365. Instead of simple API wrappers, it provides an **intelligent layer** that understands context, learns from usage patterns, and executes complex multi-step operations seamlessly.
**Key Innovations:**
- **Super Tools Mode**: Consolidates 126+ individual tools into 11 unified "Super-Tools" for easier LLM decision-making
- **Microsoft 365 Unified Search**: Primary search tool that searches across all M365 content and suggests specific tools to use next
- **Dual Timezone Display**: Shows both server local time and UTC for all calendar events and emails
- **Quick Summary Lists**: Comprehensive overview lists at the top of responses to ensure no item is overlooked
- **Intelligent Learning System**: Adapts and improves based on usage patterns
- **Read-Only Mode**: Safe exploration without write operations
### Deutsch
Der **Join Microsoft 365 MCP Server** revolutioniert die Art, wie KI-Assistenten mit Microsoft 365 interagieren. Statt einfacher API-Wrapper bietet er eine **intelligente Schicht**, die Kontext versteht, aus Nutzungsmustern lernt und komplexe Multi-Step-Operationen nahtlos ausfรผhrt.
**Wichtige Innovationen:**
- **Super-Tools-Modus**: Konsolidiert 126+ einzelne Tools zu 11 vereinheitlichten "Super-Tools" fรผr einfachere LLM-Entscheidungen
- **Microsoft 365 Unified Search**: Primรคres Suchtool, das alle M365-Inhalte durchsucht und spezifische Tools fรผr die weitere Nutzung vorschlรคgt
- **Dual-Zeitzonen-Anzeige**: Zeigt sowohl Server-Lokalzeit als auch UTC fรผr alle Kalendertermine und E-Mails
- **Schnellรผbersichtslisten**: Umfassende รbersichtslisten am Anfang von Antworten, damit kein Element รผbersehen wird
- **Intelligentes Lernsystem**: Passt sich an und verbessert sich basierend auf Nutzungsmustern
- **Read-Only-Modus**: Sichere Erkundung ohne Schreiboperationen
### Why Choose This Server? / Warum diesen Server wรคhlen?
| Feature / Funktion | Traditional APIs / Traditionelle APIs | Join MS365 MCP Server |
| ---------------------------------------------- | ------------------------------------------------- | ---------------------------------------------------------------- |
| Context Understanding / Kontextverstรคndnis | โ None / Keines | โ
Deep semantic understanding / Tiefes semantisches Verstรคndnis |
| Multi-step Operations / Multi-Step-Operationen | โ Manual orchestration / Manuelle Orchestrierung | โ
Automatic chaining / Automatische Verkettung |
| Learning System / Lernsystem | โ Static / Statisch | โ
Adaptive learning from usage / Adaptives Lernen aus Nutzung |
| Natural Language / Natรผrliche Sprache | โ Not supported / Nicht unterstรผtzt | โ
Ask questions naturally / Fragen natรผrlich stellen |
| Tool Consolidation / Tool-Konsolidierung | โ 126+ individual tools / 126+ einzelne Tools | โ
11 Super-Tools / 11 Super-Tools |
| Timezone Display / Zeitzonen-Anzeige | โ Single timezone / Einzelne Zeitzone | โ
Local + UTC / Lokal + UTC |
| Result Overview / Ergebnisรผbersicht | โ Detailed only / Nur detailliert | โ
Quick summary + details / Schnellรผbersicht + Details |
---
## โก Quick Start / Schnellstart
### Prerequisites / Voraussetzungen
**English:**
- **Docker** and **Docker Compose**
- A Microsoft 365 account (personal, work, or school)
- Azure AD App Registration (for production use)
**Deutsch:**
- **Docker** und **Docker Compose**
- Ein Microsoft 365-Konto (privat, geschรคftlich oder Schulkonto)
- Azure AD App-Registrierung (fรผr Produktionseinsatz)
### ๐ณ Docker Deployment / Docker-Bereitstellung
#### Option 1: Docker Compose (Recommended / Empfohlen)
```bash
# 1. Create configuration file / Konfigurationsdatei erstellen
cp stack.env.example stack.env
# 2. Configure your Azure AD credentials in stack.env
# Konfigurieren Sie Ihre Azure AD-Anmeldedaten in stack.env
nano stack.env
# 3. Start the server / Server starten
docker compose up -d
# For standalone mode (without Traefik):
# Fรผr Standalone-Modus (ohne Traefik):
docker compose --profile standalone up -d
```
#### Option 2: Docker Run
```bash
# Pull the image / Image herunterladen
docker pull aijoin/join-ms-365-mcp-server:latest
# Run with environment variables / Mit Umgebungsvariablen ausfรผhren
docker run -d \
--name ms365-mcp \
-p 3000:3000 \
-e MS365_MCP_CLIENT_ID=your-client-id \
-e MS365_MCP_TENANT_ID=your-tenant-id \
-e MS365_MCP_USE_SUPER_TOOLS=true \
-v ./data:/app/data \
aijoin/join-ms-365-mcp-server:latest \
--http 3000 -v
```
### MCP Client Integration / MCP-Client-Integration
**English:** Connect your AI assistant to the running server:
**Deutsch:** Verbinden Sie Ihren KI-Assistenten mit dem laufenden Server:
```json
{
"mcpServers": {
"ms365": {
"url": "https://your-server.com/mcp",
"transportType": "streamable-http"
}
}
}
```
### First Authentication / Erste Authentifizierung
**English:** Simply ask your AI assistant: _"Log me into Microsoft 365"_ - the server will guide you through device code authentication.
**Deutsch:** Fragen Sie einfach Ihren KI-Assistenten: _"Melde mich bei Microsoft 365 an"_ - der Server fรผhrt Sie durch die Device-Code-Authentifizierung.
---
## ๐ฏ Features / Funktionen
### Core Capabilities / Kernfunktionen
| Capability / Funktion | Description / Beschreibung |
| -------------------------------- | --------------------------------------------------------------- |
| **11 Super-Tools** | Consolidated interface replacing 126+ individual tools |
| **Microsoft 365 Unified Search** | Primary search tool across all M365 content |
| **90+ Individual Tools** | Comprehensive coverage of Microsoft 365 services (classic mode) |
| **Intelligent Search** | Cross-product search with semantic understanding |
| **Deep Research** | Multi-step reasoning for complex questions |
| **Learning System** | Improves over time based on usage patterns |
| **Dual Timezone Display** | Server local time + UTC for all dates/times |
| **Quick Summary Lists** | Overview lists to ensure nothing is missed |
| **Download Links** | Generate direct download links for files |
| **Microsoft Loop Support** | Loop file detection and content extraction |
| **Read-Only Mode** | Safe exploration without write operations |
| **Preset Filtering** | Load only the tools you need |
### Supported Microsoft 365 Services / Unterstรผtzte Microsoft 365-Dienste
<table>
<tr>
<td width="25%">
**๐ง Outlook**
- Email management / E-Mail-Verwaltung
- Folder organization / Ordnerorganisation
- Attachments / Anhรคnge
- Drafts / Entwรผrfe
</td>
<td width="25%">
**๐
Calendar**
- Events & meetings / Termine & Besprechungen
- Scheduling / Terminplanung
- Recurring events / Wiederkehrende Termine
- Meeting times / Besprechungszeiten
</td>
<td width="25%">
**๐ OneDrive**
- File operations / Dateioperationen
- Folder management / Ordnerverwaltung
- Sharing / Freigabe
- Download/Upload
</td>
<td width="25%">
**๐ฌ Teams**
- Chats & messages / Chats & Nachrichten
- Channels / Kanรคle
- Team management / Teamverwaltung
- Transcripts / Transkripte
</td>
</tr>
<tr>
<td>
**๐ SharePoint**
- Sites & lists / Websites & Listen
- Document libraries / Dokumentbibliotheken
- Site search / Websitesuche
- Permissions / Berechtigungen
</td>
<td>
**๐ Excel**
- Worksheet operations / Arbeitsblattoperationen
- Range manipulation / Bereichsmanipulation
- Charts / Diagramme
- Formatting / Formatierung
</td>
<td>
**โ
Tasks**
- To-Do lists / Aufgabenlisten
- Planner tasks / Planner-Aufgaben
- Task assignment / Aufgabenverteilung
- Due dates / Fรคlligkeitsdaten
</td>
<td>
**๐ OneNote**
- Notebooks
- Sections & pages / Abschnitte & Seiten
- Content creation / Inhaltserstellung
- Search / Suche
</td>
<td>
**๐ Microsoft Loop**
- Loop file detection / Loop-Datei-Erkennung
- Collaborative documents / Kollaborative Dokumente
- Content extraction / Inhalts-Extraktion
- Fluid format parsing / Fluid-Format-Parsing
</td>
</tr>
</table>
---
## ๐ Super Tools / Super-Tools
### English
**Super-Tools Mode** consolidates 126+ individual tools into 11 unified "Super-Tools". Each Super-Tool accepts an `action` parameter to specify the operation, making it much easier for LLMs to choose the right tool.
**Enable Super-Tools Mode:**
```bash
# Via environment variable / รber Umgebungsvariable
MS365_MCP_USE_SUPER_TOOLS=true
# Or via Docker / Oder รผber Docker
docker run -d \
-e MS365_MCP_USE_SUPER_TOOLS=true \
aijoin/join-ms-365-mcp-server:latest \
--http 3000
```
### Deutsch
**Super-Tools-Modus** konsolidiert 126+ einzelne Tools zu 11 vereinheitlichten "Super-Tools". Jedes Super-Tool akzeptiert einen `action`-Parameter zur Spezifikation der Operation, was es fรผr LLMs viel einfacher macht, das richtige Tool zu wรคhlen.
**Super-Tools-Modus aktivieren:**
```bash
# รber Umgebungsvariable
MS365_MCP_USE_SUPER_TOOLS=true
# Oder รผber Docker
docker run -d \
-e MS365_MCP_USE_SUPER_TOOLS=true \
aijoin/join-ms-365-mcp-server:latest \
--http 3000
```
### Super-Tools List / Super-Tools-Liste
| # | Tool | Description / Beschreibung |
| ----- | ------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **0** | `search` | ๐ **PRIMARY** - Microsoft 365 Unified Search across emails, calendar, files, SharePoint, Teams. Returns results and suggests which specific tools to use next. |
| 1 | `email` | ๐ง Unified email operations: list, get, folders, attachments, search, send, reply, delete, move |
| 2 | `calendar` | ๐
Calendar operations: list, get, view, calendars, create-event, update-event, delete-event |
| 3 | `teams` | ๐ฌ Teams, Channels, Chats: list-teams, get-team, channels, channel-messages, chats, chat-messages |
| 4 | `files` | ๐ OneDrive files: drives, list, get, download, search, root |
| 5 | `tasks` | โ
To-Do & Planner: todo-lists, todo-tasks, planner-tasks, create-todo, update-todo, delete-todo |
| 6 | `contacts` | ๐ฅ Contacts & Users: list-contacts, get-contact, list-users, current-user |
| 7 | `meetings` | ๐ฅ Online Meetings: list-meetings, get-meeting, transcripts, recordings |
| 8 | `sharepoint` | ๐ SharePoint: search-sites, get-site, site-drives, site-lists |
| 9 | `notes` | ๐ OneNote: notebooks, sections, pages, page-content, search-pages |
| 10 | `assistant` | ๐ค Smart operations: ask, search, my-day, my-week, person-info, project-overview, follow-ups |
### Example Usage / Beispielverwendung
**English:**
```json
{
"tool": "search",
"arguments": {
"query": "Project Alpha meeting notes",
"entityTypes": ["message", "event", "driveItem"],
"size": 10
}
}
```
**Deutsch:**
```json
{
"tool": "search",
"arguments": {
"query": "Projekt Alpha Besprechungsnotizen",
"entityTypes": ["message", "event", "driveItem"],
"size": 10
}
}
```
### Read-Only Mode Support / Read-Only-Modus-Unterstรผtzung
**English:** All Super-Tools respect the `READ_ONLY` environment variable. Write operations (send, create, update, delete) are automatically blocked with clear error messages when read-only mode is enabled.
**Deutsch:** Alle Super-Tools respektieren die `READ_ONLY` Umgebungsvariable. Schreiboperationen (send, create, update, delete) werden automatisch blockiert mit klaren Fehlermeldungen, wenn der Read-Only-Modus aktiviert ist.
```bash
# Enable read-only mode / Read-Only-Modus aktivieren
READ_ONLY=1
# or / oder
MS365_MCP_READ_ONLY=true
```
---
## ๐ Dual Timezone Display / Dual-Zeitzonen-Anzeige
### English
All calendar events and emails now display **both server local time and UTC** for easy reference:
```
โฐ 10:30 (UTC: 09:30)
```
**Features:**
- Server local time (primary display)
- UTC time (for reference)
- Combined display format: `HH:MM (UTC: HH:MM)`
- ISO 8601 UTC timestamps in structured data
### Deutsch
Alle Kalendertermine und E-Mails zeigen jetzt **sowohl Server-Lokalzeit als auch UTC** zur einfachen Referenz:
```
โฐ 10:30 (UTC: 09:30)
```
**Funktionen:**
- Server-Lokalzeit (primรคre Anzeige)
- UTC-Zeit (zur Referenz)
- Kombiniertes Anzeigeformat: `HH:MM (UTC: HH:MM)`
- ISO 8601 UTC-Zeitstempel in strukturierten Daten
### Example Output / Beispielausgabe
**Calendar Event / Kalendertermin:**
```
๐
Montag, 28.01.2026 (1 Termin)
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐ป Kickoff-Briefing
โฐ 10:30 (UTC: 09:30) - 11:30 (UTC: 10:30) (1h)
๐ Conference Room A
```
**Email / E-Mail:**
```
๐ฌ Project Update
โฐ 09:15 (UTC: 08:15)
๐ค Von: Max Mรผller <max@example.com>
```
---
## ๐ Quick Summary Lists / Schnellรผbersichtslisten
### English
To ensure **no calendar event or email is overlooked**, all responses now include a **Quick Summary List** at the top, followed by the detailed view.
**Calendar Quick Summary:**
```
๐ SCHNELLรBERSICHT ALLER TERMINE:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
1. ๐ป 28.01.2026 10:30 (UTC: 09:30) | Kickoff-Briefing
2. ๐ 28.01.2026 14:00 (UTC: 13:00) | Team Meeting
3. ๐ป 28.01.2026 16:30 (UTC: 15:30) | Client Call
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐ DETAILANSICHT:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
**Email Quick Summary:**
```
๐ SCHNELLรBERSICHT ALLER E-MAILS:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
1. ๐ฌ๐ 28.01.2026 09:15 (UTC: 08:15) | Max Mรผller | Projekt Update...
2. ๐ญ 27.01.2026 18:30 (UTC: 17:30) | Anna Schmidt | Meeting Notizen
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐ DETAILANSICHT:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
### Deutsch
Um sicherzustellen, dass **kein Kalendertermin oder E-Mail รผbersehen wird**, enthalten alle Antworten jetzt eine **Schnellรผbersichtsliste** am Anfang, gefolgt von der Detailansicht.
**Kalender-Schnellรผbersicht:**
```
๐ SCHNELLรBERSICHT ALLER TERMINE:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
1. ๐ป 28.01.2026 10:30 (UTC: 09:30) | Kickoff-Briefing
2. ๐ 28.01.2026 14:00 (UTC: 13:00) | Team Meeting
3. ๐ป 28.01.2026 16:30 (UTC: 15:30) | Client Call
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐ DETAILANSICHT:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
**E-Mail-Schnellรผbersicht:**
```
๐ SCHNELLรBERSICHT ALLER E-MAILS:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
1. ๐ฌ๐ 28.01.2026 09:15 (UTC: 08:15) | Max Mรผller | Projekt Update...
2. ๐ญ 27.01.2026 18:30 (UTC: 17:30) | Anna Schmidt | Meeting Notizen
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐ DETAILANSICHT:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
---
## ๐ Tool Categories / Tool-Kategorien
### ๐ Authentication Tools / Authentifizierungs-Tools
Secure authentication with multi-account support / Sichere Authentifizierung mit Multi-Account-Unterstรผtzung.
| Tool | Description / Beschreibung | Notes / Hinweise |
| ---------------- | --------------------------------------------------------------------------- | -------------------------------------------------------------------------- |
| `login` | Authenticate via device code flow / Authentifizierung รผber Device-Code-Flow | Required before using other tools / Erforderlich vor Nutzung anderer Tools |
| `logout` | Log out from Microsoft account / Von Microsoft-Konto abmelden | Clears cached tokens / Lรถscht gecachte Tokens |
| `verify-login` | Check authentication status / Authentifizierungsstatus prรผfen | Non-interactive verification / Nicht-interaktive Verifizierung |
| `list-accounts` | List cached Microsoft accounts / Gecachte Microsoft-Konten auflisten | Multi-account support / Multi-Account-Unterstรผtzung |
| `select-account` | Switch between accounts / Zwischen Konten wechseln | Seamless account switching / Nahtloser Kontenwechsel |
| `remove-account` | Remove account from cache / Konto aus Cache entfernen | Clean up stored credentials / Gespeicherte Anmeldedaten bereinigen |
### ๐ง Email & Communication Tools / E-Mail- & Kommunikations-Tools
Complete email management and shared mailbox support / Vollstรคndige E-Mail-Verwaltung und Shared-Mailbox-Unterstรผtzung.
#### Personal Email / Persรถnliche E-Mail
| Tool | Description / Beschreibung | Parameters |
| --------------------------- | ------------------------------------------------------------ | -------------------------------------- |
| `list-mail-messages` | List emails with filtering / E-Mails mit Filterung auflisten | `top`, `filter`, `search`, `orderby` |
| `get-mail-message` | Get full email content / Vollstรคndigen E-Mail-Inhalt abrufen | `messageId` |
| `send-mail` | Send new email / Neue E-Mail senden | `to`, `subject`, `body`, `attachments` |
| `create-draft-email` | Create email draft / E-Mail-Entwurf erstellen | `to`, `subject`, `body` |
| `delete-mail-message` | Delete email / E-Mail lรถschen | `messageId` |
| `move-mail-message` | Move email to folder / E-Mail in Ordner verschieben | `messageId`, `folderId` |
| `list-mail-folders` | List all mail folders / Alle E-Mail-Ordner auflisten | - |
| `list-mail-folder-messages` | List messages in folder / Nachrichten in Ordner auflisten | `folderId` |
#### Super-Tool: `email`
**English:** Unified email operations with action-based interface:
```json
{
"tool": "email",
"arguments": {
"action": "list",
"top": 25,
"search": "Project Alpha"
}
}
```
**Available actions:** `list`, `get`, `folders`, `child-folders`, `attachments`, `search`, `send`, `reply`, `delete`, `move`
**Deutsch:** Vereinheitlichte E-Mail-Operationen mit aktionsbasierter Schnittstelle:
```json
{
"tool": "email",
"arguments": {
"action": "list",
"top": 25,
"search": "Projekt Alpha"
}
}
```
**Verfรผgbare Aktionen:** `list`, `get`, `folders`, `attachments`, `search`, `send`, `reply`, `delete`, `move`
### ๐
Calendar Tools / Kalender-Tools
Full calendar management with meeting scheduling / Vollstรคndige Kalenderverwaltung mit Besprechungsplanung.
| Tool | Description / Beschreibung | Parameters |
| ----------------------- | -------------------------------------------------- | -------------------------------------- |
| `list-calendars` | List all calendars / Alle Kalender auflisten | - |
| `list-calendar-events` | List events / Termine auflisten | `top`, `filter`, `orderby` |
| `get-calendar-event` | Get event details / Termindetails abrufen | `eventId` |
| `create-calendar-event` | Create new event / Neuen Termin erstellen | `subject`, `start`, `end`, `attendees` |
| `update-calendar-event` | Update event / Termin aktualisieren | `eventId`, `updates` |
| `delete-calendar-event` | Delete event / Termin lรถschen | `eventId` |
| `get-calendar-view` | Get calendar view / Kalenderansicht abrufen | `startDateTime`, `endDateTime` |
| `find-meeting-times` | Find available slots / Verfรผgbare Zeitslots finden | `attendees`, `duration` |
#### Super-Tool: `calendar`
**English:** Unified calendar operations:
```json
{
"tool": "calendar",
"arguments": {
"action": "view",
"startDateTime": "2026-01-28T00:00:00Z",
"endDateTime": "2026-01-29T00:00:00Z"
}
}
```
**Available actions:** `list`, `get`, `view`, `calendars`, `specific-calendar`, `create-event`, `update-event`, `delete-event`
**Deutsch:** Vereinheitlichte Kalender-Operationen:
```json
{
"tool": "calendar",
"arguments": {
"action": "view",
"startDateTime": "2026-01-28T00:00:00Z",
"endDateTime": "2026-01-29T00:00:00Z"
}
}
```
**Verfรผgbare Aktionen:** `list`, `get`, `view`, `calendars`, `specific-calendar`, `create-event`, `update-event`, `delete-event`
### ๐ File & Drive Tools / Datei- & Laufwerk-Tools
OneDrive file management with upload/download capabilities / OneDrive-Dateiverwaltung mit Upload/Download-Funktionen.
| Tool | Description / Beschreibung | Parameters |
| -------------------------------- | ------------------------------------------------------ | --------------------------------- |
| `list-drives` | List available drives / Verfรผgbare Laufwerke auflisten | - |
| `get-drive-root-item` | Get drive root folder / Laufwerks-Stammordner abrufen | `driveId` |
| `list-folder-files` | List files in folder / Dateien im Ordner auflisten | `folderId`, `top` |
| `download-onedrive-file-content` | Download file content / Dateiinhalt herunterladen | `itemId` |
| `upload-file-content` | Update file content / Dateiinhalt aktualisieren | `itemId`, `content` |
| `upload-new-file` | Upload new file / Neue Datei hochladen | `folderId`, `fileName`, `content` |
| `delete-onedrive-file` | Delete file / Datei lรถschen | `itemId` |
### ๐ฌ Microsoft Teams Tools / Microsoft Teams-Tools
> **Note / Hinweis:** Requires `--org-mode` flag (work/school accounts only) / Erfordert `--org-mode` Flag (nur Geschรคfts-/Schulkonten)
| Tool | Description / Beschreibung | Parameters |
| ----------------------- | --------------------------------------------------------- | -------------------------------- |
| `list-chats` | List all chats / Alle Chats auflisten | `top` |
| `get-chat` | Get chat details / Chat-Details abrufen | `chatId` |
| `list-chat-messages` | List messages in chat / Nachrichten im Chat auflisten | `chatId`, `top` |
| `send-chat-message` | Send chat message / Chat-Nachricht senden | `chatId`, `content` |
| `list-joined-teams` | List teams you're in / Teams auflisten, in denen Sie sind | - |
| `list-team-channels` | List team channels / Team-Kanรคle auflisten | `teamId` |
| `list-channel-messages` | List channel messages / Kanalnachrichten auflisten | `teamId`, `channelId` |
| `send-channel-message` | Send channel message / Kanalnachricht senden | `teamId`, `channelId`, `content` |
### ๐ Search & Discovery Tools / Such- & Discovery-Tools
Powerful cross-product search capabilities / Leistungsstarke produktรผbergreifende Suchfunktionen.
#### Super-Tool: `search` (PRIMARY / PRIMรR)
**English:** The **recommended first tool** for exploring Microsoft 365 content. Searches across emails, calendar, files, SharePoint, Teams, and suggests which specific tools to use next.
**Deutsch:** Das **empfohlene erste Tool** zur Erkundung von Microsoft 365-Inhalten. Durchsucht E-Mails, Kalender, Dateien, SharePoint, Teams und schlรคgt vor, welche spezifischen Tools als nรคchstes zu verwenden sind.
```json
{
"tool": "search",
"arguments": {
"query": "Project Alpha meeting notes",
"entityTypes": ["message", "event", "driveItem"],
"size": 10
}
}
```
**Entity Types:** `message`, `event`, `driveItem`, `site`, `list`, `listItem`, `chatMessage`, `person`
**Response includes:**
- Search results grouped by entity type
- Tool suggestions for next steps
- Total hits count
- Formatted results with metadata
### ๐ง Intelligent Compound Tools / Intelligente Verbund-Tools
These **intelligent tools** automatically chain multiple API calls to answer complex contextual questions / Diese **intelligenten Tools** verkettet automatisch mehrere API-Aufrufe, um komplexe kontextuelle Fragen zu beantworten.
| Tool | What It Does / Was es tut | Example Query / Beispielabfrage |
| --------------------------- | ---------------------------------------------------------------------------------- | ------------------------------------------------------------------------- |
| `find-messages-with-person` | Find all Teams chats with a person / Findet alle Teams-Chats mit einer Person | "What did I discuss with John?" / "Worรผber habe ich mit John gesprochen?" |
| `find-emails-with-person` | Find all email threads with a person / Findet alle E-Mail-Threads mit einer Person | "Show emails from Sarah" / "Zeige E-Mails von Sarah" |
| `find-meetings-with-person` | Find past & future meetings / Findet vergangene & zukรผnftige Besprechungen | "When did I meet with Mike?" / "Wann habe ich mich mit Mike getroffen?" |
| `discover-project` | Find all project-related content / Findet alle projektbezogenen Inhalte | "Everything about Project Apollo" / "Alles รผber Projekt Apollo" |
| `discover-person` | Comprehensive person profile / Umfassendes Personenprofil | "Who is John Smith?" / "Wer ist John Smith?" |
| `get-my-week-summary` | Weekly productivity digest / Wรถchentliche Produktivitรคtszusammenfassung | "What did I accomplish this week?" / "Was habe ich diese Woche erreicht?" |
---
## ๐ฌ Intelligent Discovery System
### English
The server features a sophisticated **Search-First Strategy** with multiple intelligent components:
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ User Question โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ NLP Enhancer โ
โ โข Entity extraction โข Intent classification โ
โ โข Synonym expansion โข Query refinement โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Search-First Strategy โ
โ โข Microsoft Search API (emails, files, chats, events) โ
โ โข Learning-informed entity type selection โ
โ โข Automatic query refinement if no results โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Entity Extractor โ
โ โข Identifies sites, teams, users, files โ
โ โข Extracts relevant keywords โ
โ โข Maps to specific product queries โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Data Aggregator โ
โ โข Deduplication โข Relevance sorting โ
โ โข LLM-optimized formatting โข Source tracking โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Learning System โ
โ โข Records successful patterns โข Updates confidence โ
โ โข Learns entity type preferences โข User feedback โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
### Deutsch
Der Server verfรผgt รผber eine ausgeklรผgelte **Search-First-Strategie** mit mehreren intelligenten Komponenten:
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Benutzerfrage โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ NLP Enhancer โ
โ โข Entitรคts-Extraktion โข Intent-Klassifizierung โ
โ โข Synonym-Erweiterung โข Abfrage-Verfeinerung โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Search-First-Strategie โ
โ โข Microsoft Search API (E-Mails, Dateien, Chats, Termine) โ
โ โข Lernbasierte Entitรคtstyp-Auswahl โ
โ โข Automatische Abfrage-Verfeinerung bei keinen Ergebnissen โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Entity Extractor โ
โ โข Identifiziert Websites, Teams, Benutzer, Dateien โ
โ โข Extrahiert relevante Schlรผsselwรถrter โ
โ โข Mappt auf spezifische Produktabfragen โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Data Aggregator โ
โ โข Deduplizierung โข Relevanz-Sortierung โ
โ โข LLM-optimierte Formatierung โข Quellen-Tracking โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Lernsystem โ
โ โข Zeichnet erfolgreiche Muster auf โข Aktualisiert Konfidenz โ
โ โข Lernt Entitรคtstyp-Prรคferenzen โข Benutzer-Feedback โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
---
## โ Configuration / Konfiguration
### Docker Command Options / Docker-Befehlsoptionen
| Option | Description / Beschreibung | Example / Beispiel |
| --------------------------- | ------------------------------------------------------------------------------------------------ | ---------------------------------- |
| `--org-mode` | Enable organization mode (Teams, SharePoint) / Organisationsmodus aktivieren (Teams, SharePoint) | `--org-mode` |
| `--read-only` | Disable write operations / Schreiboperationen deaktivieren | `--read-only` |
| `--http [port]` | Start HTTP server (default: 3000) / HTTP-Server starten (Standard: 3000) | `--http 8080` |
| `--preset <name>` | Load specific tool presets / Spezifische Tool-Presets laden | `--preset mail,calendar` |
| `--enabled-tools <pattern>` | Filter tools by regex / Tools nach Regex filtern | `--enabled-tools "excel\|contact"` |
| `--toon` | Enable TOON format (30-60% token savings) / TOON-Format aktivieren (30-60% Token-Ersparnis) | `--toon` |
| `--discovery` | Start with discovery tools only / Nur mit Discovery-Tools starten | `--discovery` |
| `--cloud <type>` | Cloud environment (global/china) / Cloud-Umgebung (global/china) | `--cloud china` |
| `-v` | Enable verbose logging / Ausfรผhrliches Logging aktivieren | `-v` |
### Environment Variables / Umgebungsvariablen
| Variable | Description / Beschreibung | Default |
| --------------------------- | ------------------------------------------------------------------------------- | --------------------------- |
| `MS365_MCP_CLIENT_ID` | Azure AD app client ID | **Required / Erforderlich** |
| `MS365_MCP_TENANT_ID` | Azure AD tenant ID | `common` |
| `MS365_MCP_CLIENT_SECRET` | Client secret (confidential apps) / Client-Geheimnis (vertrauliche Apps) | - |
| `MS365_MCP_USE_SUPER_TOOLS` | Enable Super-Tools mode / Super-Tools-Modus aktivieren | `false` |
| `MS365_MCP_ORG_MODE` | Enable organization mode / Organisationsmodus aktivieren | `false` |
| `MS365_MCP_OUTPUT_FORMAT` | Output format (`json`/`toon`) / Ausgabeformat (`json`/`toon`) | `json` |
| `MS365_MCP_CLOUD_TYPE` | Cloud environment / Cloud-Umgebung | `global` |
| `MS365_MCP_KEYVAULT_URL` | Azure Key Vault URL | - |
| `MS365_MCP_MAX_RESULTS` | Maximum search results / Maximale Suchergebnisse | `500` |
| `MS365_MCP_ANONYMIZE_PII` | Anonymize PII in knowledge base storage / PII in Wissensdatenbank anonymisieren | `true` |
| `READ_ONLY` | Enable read-only mode / Read-Only-Modus aktivieren | `false` |
> **Security Warning / Sicherheitswarnung**: Setting `MS365_MCP_ANONYMIZE_PII=false` disables the automatic removal of personally identifiable information (email addresses, phone numbers, IDs, etc.) before storing data in the knowledge base. This is **NOT recommended in production** and may violate GDPR/DSGVO compliance. Only disable for development or debugging purposes. / Das Setzen von `MS365_MCP_ANONYMIZE_PII=false` deaktiviert die automatische Entfernung von personenbezogenen Daten (E-Mail-Adressen, Telefonnummern, IDs, etc.) vor der Speicherung in der Wissensdatenbank. Dies wird **in der Produktion NICHT empfohlen** und kann gegen DSGVO-Compliance verstoรen. Nur fรผr Entwicklung oder Debugging deaktivieren.
> | `LOG_LEVEL` | Logging level / Logging-Level | `info` |
> | `SILENT` | Disable console output / Konsolenausgabe deaktivieren | `false` |
### Docker Run Examples / Docker-Run-Beispiele
```bash
# Basic HTTP server / Grundlegender HTTP-Server
docker run -d -p 3000:3000 aijoin/join-ms-365-mcp-server:latest --http 3000
# Organization mode with Super-Tools / Organisationsmodus mit Super-Tools
docker run -d -p 3000:3000 \
-e MS365_MCP_CLIENT_ID=your-client-id \
-e MS365_MCP_TENANT_ID=your-tenant-id \
-e MS365_MCP_USE_SUPER_TOOLS=true \
aijoin/join-ms-365-mcp-server:latest \
--http 3000 --org-mode -v
# Read-only mode with Super-Tools / Read-Only-Modus mit Super-Tools
docker run -d -p 3000:3000 \
-e MS365_MCP_USE_SUPER_TOOLS=true \
-e READ_ONLY=1 \
aijoin/join-ms-365-mcp-server:latest \
--http 3000
```
---
## ๐ Authentication Methods / Authentifizierungsmethoden
### 1. Device Code Flow (Default / Standard)
**English:** Interactive authentication for users:
1. Call the `login` tool
2. Visit the provided URL and enter the code
3. Call `verify-login` to confirm
**Deutsch:** Interaktive Authentifizierung fรผr Benutzer:
1. Rufen Sie das `login` Tool auf
2. Besuchen Sie die bereitgestellte URL und geben Sie den Code ein
3. Rufen Sie `verify-login` auf, um zu bestรคtigen
### 2. OAuth Authorization Code Flow (HTTP Mode)
**English:** For web applications and remote servers:
- Exposes OAuth endpoints at `/auth/*`
- Requires `Authorization: Bearer <token>` for MCP requests
- Supports MCP OAuth 2.1 with Dynamic Client Registration
**Deutsch:** Fรผr Webanwendungen und Remote-Server:
- Stellt OAuth-Endpunkte unter `/auth/*` bereit
- Erfordert `Authorization: Bearer <token>` fรผr MCP-Anfragen
- Unterstรผtzt MCP OAuth 2.1 mit Dynamic Client Registration
### 3. Bring Your Own Token (BYOT)
**English:** For integration with existing OAuth systems:
```bash
docker run -d -p 3000:3000 \
-e MS365_MCP_OAUTH_TOKEN=your_token \
aijoin/join-ms-365-mcp-server:latest \
--http 3000
```
**Deutsch:** Fรผr die Integration mit bestehenden OAuth-Systemen:
```bash
docker run -d -p 3000:3000 \
-e MS365_MCP_OAUTH_TOKEN=your_token \
aijoin/join-ms-365-mcp-server:latest \
--http 3000
```
---
## ๐ Azure AD App Permissions / Azure AD App-Berechtigungen
### Delegate Permissions Overview / รbersicht der Delegate Permissions
**English:** The following Microsoft Graph Delegate Permissions are required for the Azure AD App Registration. These permissions allow the server to access Microsoft 365 services on behalf of the signed-in user.
**Deutsch:** Die folgenden Microsoft Graph Delegate Permissions sind fรผr die Azure AD App-Registrierung erforderlich. Diese Berechtigungen ermรถglichen es dem Server, im Namen des angemeldeten Benutzers auf Microsoft 365-Dienste zuzugreifen.
### Personal Account Permissions / Persรถnliche Kontoberechtigungen
These permissions work with personal Microsoft accounts (Outlook.com, Hotmail, etc.) and work/school accounts:
| Permission | Description / Beschreibung | Required For / Erforderlich fรผr |
| ---------------------------------- | ---------------------------------------------------------- | ------------------------------------------------------------ |
| `User.Read` | Read user profile / Benutzerprofil lesen | Basic functionality / Grundfunktionalitรคt |
| `People.Read` | Read people / Personen lesen | Contact search / Kontaktsuche |
| `Mail.Read` | Read mail / E-Mails lesen | Email reading / E-Mail-Lesen |
| `Mail.ReadWrite` | Read and write mail / E-Mails lesen und schreiben | Email management / E-Mail-Verwaltung |
| `Mail.Send` | Send mail / E-Mails senden | Send email / E-Mails senden |
| `Calendars.Read` | Read calendars / Kalender lesen | Calendar viewing / Kalender anzeigen |
| `Calendars.ReadWrite` | Read and write calendars / Kalender lesen und schreiben | Calendar management / Kalenderverwaltung |
| `Contacts.Read` | Read contacts / Kontakte lesen | Contact viewing / Kontakte anzeigen |
| `Contacts.ReadWrite` | Read and write contacts / Kontakte lesen und schreiben | Contact management / Kontaktverwaltung |
| `Files.Read` | Read files / Dateien lesen | OneDrive read / OneDrive lesen |
| `Files.Read.All` | Read all files / Alle Dateien lesen | Cross-user file access / Benutzerรผbergreifender Dateizugriff |
| `Files.ReadWrite` | Read and write files / Dateien lesen und schreiben | OneDrive management / OneDrive-Verwaltung |
| `Tasks.Read` | Read tasks / Aufgaben lesen | To-Do read / To-Do lesen |
| `Tasks.ReadWrite` | Read and write tasks / Aufgaben lesen und schreiben | To-Do management / To-Do-Verwaltung |
| `Notes.Read` | Read OneNote / OneNote lesen | OneNote viewing / OneNote anzeigen |
| `Notes.Create` | Create OneNote / OneNote erstellen | OneNote creation / OneNote-Erstellung |
| `OnlineMeetings.Read` | Read online meetings / Online-Besprechungen lesen | Meeting information / Besprechungsinformationen |
| `OnlineMeetingTranscript.Read.All` | Read meeting transcripts / Besprechungstranskripte lesen | Transcript access / Transkript-Zugriff |
| `OnlineMeetingRecording.Read.All` | Read meeting recordings / Besprechungsaufzeichnungen lesen | Recording access / Aufzeichnungs-Zugriff |
### Organization Mode Permissions / Organisationsmodus-Berechtigungen
These permissions require work/school accounts and the `--org-mode` flag:
| Permission | Description / Beschreibung | Required For / Erforderlich fรผr |
| ------------------------- | ----------------------------------------------------------------- | ----------------------------------------------------------- |
| `User.Read.All` | Read all users / Alle Benutzer lesen | User directory / Benutzerverzeichnis |
| `Mail.Read.Shared` | Read shared mailboxes / Freigegebene Postfรคcher lesen | Shared mailbox access / Zugriff auf freigegebene Postfรคcher |
| `Mail.Send.Shared` | Send from shared mailboxes / Von freigegebenen Postfรคchern senden | Send as shared mailbox / Senden als freigegebenes Postfach |
| `Calendars.Read.Shared` | Read shared calendars / Freigegebene Kalender lesen | Shared calendar access / Zugriff auf freigegebene Kalender |
| `Chat.Read` | Read chats / Chats lesen | Teams chat reading / Teams-Chat lesen |
| `ChatMessage.Read` | Read chat messages / Chat-Nachrichten lesen | Teams message reading / Teams-Nachrichten lesen |
| `ChatMessage.Send` | Send chat messages / Chat-Nachrichten senden | Teams message sending / Teams-Nachrichten senden |
| `Team.ReadBasic.All` | Read basic team info / Grundlegende Team-Informationen lesen | Teams listing / Teams auflisten |
| `TeamMember.Read.All` | Read team members / Teammitglieder lesen | Team member access / Zugriff auf Teammitglieder |
| `Channel.ReadBasic.All` | Read basic channel info / Grundlegende Kanal-Informationen lesen | Channel listing / Kanรคle auflisten |
| `ChannelMessage.Read.All` | Read all channel messages / Alle Kanalnachrichten lesen | Channel message reading / Kanalnachrichten lesen |
| `ChannelMessage.Send` | Send channel messages / Kanalnachrichten senden | Channel message sending / Kanalnachrichten senden |
| `Sites.Read.All` | Read all SharePoint sites / Alle SharePoint-Websites lesen | SharePoint access / SharePoint-Zugriff |
### Permission Configuration / Berechtigungskonfiguration
**English:** To configure these permissions in Azure Portal:
1. Go to **Azure Active Directory** โ **App registrations**
2. Select your app registration
3. Navigate to **API permissions**
4. Click **Add a permission** โ **Microsoft Graph** โ **Delegated permissions**
5. Add all required permissions from the tables above
6. Click **Grant admin consent** (for organization permissions)
**Deutsch:** Um diese Berechtigungen im Azure-Portal zu konfigurieren:
1. Gehen Sie zu **Azure Active Directory** โ **App-Registrierungen**
2. Wรคhlen Sie Ihre App-Registrierung aus
3. Navigieren Sie zu **API-Berechtigungen**
4. Klicken Sie auf **Berechtigung hinzufรผgen** โ **Microsoft Graph** โ **Delegierte Berechtigungen**
5. Fรผgen Sie alle erforderlichen Berechtigungen aus den obigen Tabellen hinzu
6. Klicken Sie auf **Administratorzustimmung erteilen** (fรผr Organisationsberechtigungen)
### Minimal Permission Set / Minimaler Berechtigungssatz
**English:** For read-only access, you can use a minimal set:
- `User.Read`
- `Mail.Read`
- `Calendars.Read`
- `Files.Read`
- `Tasks.Read`
- `Contacts.Read`
- `Notes.Read`
**Deutsch:** Fรผr schreibgeschรผtzten Zugriff kรถnnen Sie einen minimalen Satz verwenden:
- `User.Read`
- `Mail.Read`
- `Calendars.Read`
- `Files.Read`
- `Tasks.Read`
- `Contacts.Read`
- `Notes.Read`
> **Note / Hinweis:** The server automatically requests only the permissions needed based on enabled tools. Use `--preset` or `--enabled-tools` to limit the permission scope. / Der Server fordert automatisch nur die Berechtigungen an, die basierend auf aktivierten Tools benรถtigt werden. Verwenden Sie `--preset` oder `--enabled-tools`, um den Berechtigungsumfang einzuschrรคnken.
---
## ๐ Security & Compliance / Sicherheit & Compliance
### Security Features / Sicherheitsfunktionen
- โ
**OAuth 2.1 / PKCE** - Secure token handling / Sichere Token-Verwaltung
- โ
**Token validation** - Verified against Microsoft Graph / Gegen Microsoft Graph verifiziert
- โ
**Secure storage** - Persistent volume for credentials / Persistenter Datentrรคger fรผr Anmeldedaten
- โ
**Read-only mode** - Safe exploration without modifications / Sichere Erkundung ohne รnderungen
- โ
**Input validation** - Zod schema validation on all inputs / Zod-Schema-Validierung fรผr alle Eingaben
- โ
**Rate limiting** - Configurable request limits / Konfigurierbare Anfragelimits
- โ
**HTTPS/TLS** - Traefik integration for production / Traefik-Integration fรผr Produktion
### Compliance
- **ISO 27001** - Information security management / Informationssicherheitsmanagement
- **GDPR/DSGVO** - Data protection by design / Datenschutz durch Design
- **OWASP** - Security best practices / Sicherheitsbest Practices
---
## ๐ Query Dashboard / Abfrage-Dashboard
### English
The Query Dashboard provides a secure web interface to view and analyze all user queries. This feature enables auditing, analytics, and debugging of MCP tool usage.
**Features:**
- ๐ **Real-time Statistics** - Total queries, unique users, success rates
- ๐ **Query Search & Filtering** - Filter by tool, user, date, status
- ๐ **Hourly Activity Charts** - Visual query distribution over 24 hours
- ๐ **Password Protected** - Secure access via environment variable
- ๐ฅ **GDPR Data Export** - Export user data for data portability
- ๐๏ธ **GDPR Erasure** - Delete user data (Right to be Forgotten)
### Deutsch
Das Query Dashboard bietet eine sichere Weboberflรคche zur Anzeige und Analyse aller Benutzerabfragen. Diese Funktion ermรถglicht Auditierung, Analysen und Debugging der MCP-Tool-Nutzung.
**Funktionen:**
- ๐ **Echtzeit-Statistiken** - Gesamtabfragen, eindeutige Benutzer, Erfolgsraten
- ๐ **Abfrage-Suche & Filterung** - Nach Tool, Benutzer, Datum, Status filtern
- ๐ **Stรผndliche Aktivitรคtsdiagramme** - Visuelle Abfrageverteilung รผber 24 Stunden
- ๐ **Passwortgeschรผtzt** - Sicherer Zugriff รผber Umgebungsvariable
- ๐ฅ **DSGVO-Datenexport** - Benutzerdaten fรผr Datenportabilitรคt exportieren
- ๐๏ธ **DSGVO-Lรถschung** - Benutzerdaten lรถschen (Recht auf Vergessenwerden)
### Enabling the Dashboard / Dashboard aktivieren
```bash
# In stack.env or docker-compose environment
# In stack.env oder docker-compose Umgebung
DASHBOARD_PASSWORD=your-secure-password-here
```
Access the dashboard at: `https://your-server.com/dashboard` / Zugriff auf das Dashboard unter: `https://your-server.com/dashboard`
---
## ๐ API Reference / API-Referenz
### MCP Client Configuration / MCP-Client-Konfiguration
#### OpenWebUI / Remote Clients
```json
{
"mcpServers": {
"ms365": {
"url": "https://your-server.com/mcp",
"transportType": "streamable-http"
}
}
}
```
#### Local Development / Lokale Entwicklung
```json
{
"mcpServers": {
"ms365": {
"url": "http://localhost:3000/mcp",
"transportType": "streamable-http"
}
}
}
```
### Tool Response Format / Tool-Antwortformat
All tools return MCP-compliant responses / Alle Tools geben MCP-konforme Antworten zurรผck:
```typescript
interface McpToolResult {
content: Array<{
type: 'text' | 'image' | 'resource';
text?: string;
data?: string;
mimeType?: string;
uri?: string;
}>;
isError?: boolean;
}
```
---
## ๐ณ Docker Deployment / Docker-Bereitstellung
### Production with Traefik / Produktion mit Traefik
```yaml
# docker-compose.yml
services:
ms365-mcp-server:
image: aijoin/join-ms-365-mcp-server:latest
container_name: ms365-mcp
restart: unless-stopped
env_file:
- stack.env
command: ['--http', '3000', '-v']
volumes:
- ./data:/app/data
labels:
- 'traefik.enable=true'
- 'traefik.http.routers.ms365-mcp.rule=Host(`ms365-mcp.yourdomain.com`)'
- 'traefik.http.routers.ms365-mcp.entrypoints=websecure'
- 'traefik.http.routers.ms365-mcp.tls.certresolver=myresolver'
networks:
- web
networks:
web:
external: true
```
### Build from Source / Aus Quellcode erstellen
```bash
# Clone the repository / Repository klonen
git clone https://github.com/michelfritzschjoin/join-ms-365-mcp-server.git
cd join-ms-365-mcp-server
# Build the image / Image erstellen
docker build -t ms365-mcp-server .
# Run / Ausfรผhren
docker run -p 3000:3000 ms365-mcp-server --http 3000
```
---
## ๐ค Contributing / Beitragen
**English:**
1. Fork the repository
2. Run `npm install`
3. Generate client: `npm run generate`
4. Make changes
5. Run verification: `npm run verify`
6. Submit PR
**Deutsch:**
1. Repository forken
2. `npm install` ausfรผhren
3. Client generieren: `npm run generate`
4. รnderungen vornehmen
5. Verifizierung ausfรผhren: `npm run verify`
6. PR einreichen
---
## ๐ License / Lizenz
All Rights Reserved ยฉ 2026 Join GmbH
---
## ๐ Support / Support
- ๐ [Issues](https://github.com/michelfritzschjoin/join-ms-365-mcp-server/issues)
---
## โน๏ธ Version Information / Versionsinformationen
**English:** The version is automatically read from `package.json` at runtime. The displayed version in the banner and CLI is always synchronized with the package version - no manual updates required.
**Deutsch:** Die Version wird automatisch zur Laufzeit aus `package.json` gelesen. Die angezeigte Version im Banner und CLI ist immer mit der Paketversion synchronisiert - keine manuellen Updates erforderlich.
---
<p align="center">
<strong>Built with โค๏ธ by Join GmbH</strong><br>
<strong>Mit โค๏ธ erstellt von Join GmbH</strong>
</p>
This server cannot be deployed
Maintenance
ActivityInactive
ResponsivenessNo issues