M365 MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| GIT_SHA | No | Set by the build. Reported by `GET /health` so a probe can assert which commit is running. | |
| FRONTEND_URL | Yes | Base URL of the admin UI, used for post-login redirects. | |
| AZURE_CLIENT_ID | Yes | Entra application (client) ID. | |
| AZURE_TENANT_ID | Yes | Entra directory (tenant) ID. | |
| MCP_INSTANCE_NAME | No | Display name shown in the admin UI, the initialize response, and the generated extension bundle (also derives the bundle's slug and keychain service name). Defaults to M365 MCP. | M365 MCP |
| OAUTH_REDIRECT_URI | Yes | Must match a registered redirect URI exactly. | |
| AZURE_CLIENT_SECRET | Yes | Entra client secret. | |
| MCP_SESSION_HMAC_KEY | No | 64-hex-char key that hashes session tokens at rest. Generate with `openssl rand -hex 32`; never reuse across tenants. Required in production. | |
| M365_MCP_ATTACH_ROOTS | No | Set in the entry's env to change the folders the shim may read local attachment/write_onedrive_file paths from. Defaults to ~/Downloads, ~/Documents and the OneDrive sync folders. | |
| MCP_DATA_ENCRYPTION_KEY | No | 64-hex-char AES-256-GCM key for access tokens and the MSAL cache at rest. Same generation rule. Rotating it signs every user out. Required in production. | |
| DEFAULT_MAIL_DENY_FOLDERS | No | Comma-separated mail folder names always denied, matched by display name, case-insensitively. | |
| DEFAULT_SHAREPOINT_DENY_PATHS | No | Comma-separated SharePoint path prefixes always denied. | |
| AZURE_STORAGE_CONNECTION_STRING | No | Table Storage account. Unset locally falls back to the Azurite emulator. Required in production. | |
| APPLICATIONINSIGHTS_CONNECTION_STRING | No | Forwards console output and exceptions to the tenant's own Application Insights resource. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
No tools | |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessNo issues