Set-up guide

Connect Microsoft 365 in one sign-in.

Microsoft 365 and Outlook mailboxes cannot be opened with a password any more, and that is not a limitation of this product. Here is what actually connects them to Claude, and why it takes one screen rather than twenty.

  • Time About 2 minutes
  • You will need Your Microsoft sign-in
  • Admin consent Usually not required
Connecting Microsoft 365 to Mailbox MCP with one Microsoft sign-in: a robot holding up a shield with a tick, beside an open mailbox full of letters.
One sign-in, approved by Microsoft

The short version

Sign in to the control panel, choose Add mailbox, pick Microsoft 365, sign in with Microsoft, accept the permissions. That is the whole thing. If you have connected a Gmail mailbox before and are looking for the app password step, there isn't one.

Mechanics

Why a password will not work

On 1 October 2022 Microsoft disabled Basic Authentication for IMAP in Exchange Online. From that date, a username and password stopped being able to open a Microsoft 365 mailbox at all, for every mail client, everywhere, at once.

This catches people out because it does not feel like a policy change. It feels like a broken setting. You know the password is right, you can sign in to Outlook with it, and yet the connection is refused. So the natural assumption is that something is misconfigured, and people go looking for a switch that no longer exists.

There is no switch. The replacement is OAuth: you sign in to Microsoft directly, Microsoft asks whether you agree to let Mailbox MCP use your mailbox, and Mailbox MCP receives a token instead of a password. Your password is never typed into this site and never reaches us.

Worth knowing

This is also why any tool that asks for your Microsoft password to read your mail cannot do what it claims for a Microsoft 365 mailbox. It is describing how mail worked before October 2022.

Why a password cannot open a Microsoft 365 mailbox: the robot turning away a password card at a padlocked mailbox and holding up a sign-in badge instead.
A password gets you nowhere. A sign-in does

Before you start

What you need before you start

Shorter than you are expecting, and three of the six rows are things other guides will tell you to do that you can skip.

  • A Microsoft 365 mailbox work or school account
  • Your Microsoft sign-in password + MFA as usual
  • An app registration of your own not needed
  • Authenticated SMTP switched on not needed
  • Your IT administrator usually not needed
  • Time to allow about 2 minutes

You do not register an application

Most Microsoft 365 connection guides walk you through creating your own app registration in Entra: names, redirect URIs, API permissions, client secrets. You do not need to do any of that. One registration serves every Mailbox MCP customer, so there is no client ID for you to copy and no secret for you to store and later have expire.

Walkthrough

Connect the mailbox, step by step

  1. Add a mailbox in the control panel

    Sign in to Mailbox MCP, choose Add mailbox, and pick Microsoft 365. You are sent to Microsoft to sign in. Nothing has been connected yet and nothing is stored until you finish.

  2. Choose your work or school account

    If Microsoft asks which account you mean, choose Work or school account.

    The trap that catches people

    The same address can exist twice: once as your Microsoft 365 work account and once as a personal Microsoft account someone created years ago. They are different mailboxes. Picking the personal one completes successfully, connects an empty or unfamiliar mailbox, and gives you no error to search for. If the mail Claude reports is not the mail you expect, this is almost always why.

  3. Review the permissions and accept

    Microsoft shows you exactly what is being asked for. Read it, because you should read every one of these, and because knowing what a correct prompt looks like is how you recognise a suspicious one. The next section lists each permission and what it is for.

    The screen names BSolve IT Limited, which is the company behind Mailbox MCP. Seeing a company name you were not expecting is a good reason to stop; seeing that one is correct.

  4. Check the connection

    You are returned to the control panel and the mailbox shows as connected. Ask Claude to list your five most recent messages. If they are the messages you expect, the mailbox is connected and reading it has not marked anything as read.

Permissions

What the permission screen asks for, and why

Five permissions, and this is the complete list. A consent screen asking for more than it needs is worth refusing, which only means anything if the list you were given beforehand was exact, so here is every one with what it is actually for.

Two of them are new. The first three were counted off the real screen on 30 August 2026; the two calendar permissions were added to the request on 2 September 2026 and approved on a real Microsoft tenant the same day. If you connected a mailbox before that date you were not asked for them, and Microsoft does not widen a permission you have already given. Your mail keeps working exactly as it did, and the calendar tools appear once you reconnect the mailbox and approve the longer list. The control panel offers that on the mailbox's connection tab, and describes it as an offer rather than a fault, because it is one.

PermissionWhat it lets us doWhy it is needed
IMAP.AccessAsUser.All Read and write the mail in your mailbox Listing, searching and reading messages, moving them between folders, and flagging them
Mail.Send Send mail as you Sending and replying. Not Mail.Send.Shared: we send as the mailbox owner and never on behalf of anyone else
Calendars.ReadWrite.Shared Read and write your calendar, and calendars shared with you Every calendar tool. The .Shared ending is what lets it read a colleague's diary they have already shared with you; it does not widen what you are allowed to see, because Microsoft decides that and we ask with your own account's rights
MailboxSettings.ReadWrite Read and change your mailbox settings Your timezone and working hours, without which a time cannot be stated or a free slot judged, and your out-of-office reply, which is a mailbox setting rather than a calendar entry
offline_access Keep access after you close the browser Without it the connection would expire in about an hour and you would be signing in again all day

None of these require an administrator to approve them in a normal tenant, which is what makes this a two minute job rather than a support ticket.

The permissions Mailbox MCP asks for: the robot holding a short checklist with ticks on it in front of a mailbox.
Five permissions, and what each is for

The diary

Your calendar comes with the same sign-in

Two of the five permissions above are the calendar ones, and they are on the same screen as the mail ones. You approve once, and the mailbox arrives with its diary already attached. There is no second account, no second connector in your AI client, no CalDAV address to go and find, and nothing extra to pay. Microsoft 365 is the provider where every part of this works, because Graph is one API over both.

What that actually gets you

Read the week and search it by subject, location or organiser. Open one event with everybody invited and how each of them answered. Ask when a group of people are free, or ask Microsoft directly for ranked times a meeting would fit, honouring everybody's working hours and each person's answer to whether they are needed. Block your own time, move it, repeat it. Invite people, add a Teams link, reschedule and tell everybody, or cancel with a message.

Answer an invitation with accept, tentative or decline, and a note to the organiser if you want one. Or decline and propose a different time in the same action, which is the answer a person actually wants to give and which most integrations cannot express at all. Snooze a reminder or dismiss it. File an event under the same categories, and the same colours, you already use in Outlook.

And the out-of-office, which is not a calendar entry at all

Read your automatic reply as it stands, set it for a date range with a different message for people outside your organisation, or turn it off. It is the same setting Outlook writes, so it shows up in Outlook, and it switches itself off at the end of the period exactly as one you set by hand would. That is what the mailbox settings permission is for, and it is the one thing on this surface that lives on the mailbox rather than in the diary.

What still says Microsoft only

A calendar on any other provider connects one of two other ways: a Google sign-in for a Google diary, or a CalDAV address for anything else. Two things are Microsoft 365 and nothing else, on either of those routes: the structured counter-proposal, where declining and suggesting another time is one action the organiser's Outlook understands, and the ranked meeting suggestions, which are Microsoft's own answer rather than a search we run. The out-of-office belongs to that list too: it is a mailbox setting rather than a diary entry, and neither CalDAV nor Google Calendar has an equivalent of it.

How AI calendar scheduling works, end to end.

Sending

Why you do not need Authenticated SMTP

This is the step that stops most Microsoft 365 integrations, and you can skip it entirely.

Microsoft turns off SMTP AUTH by default for tenants created after 2020, because it is a password-spray target. Any tool that sends your mail over SMTP therefore needs somebody to switch Authenticated SMTP back on for your mailbox in the Microsoft 365 admin centre. That usually means asking IT, and plenty of security teams say no on principle, having turned it off deliberately.

Mailbox MCP sends through Microsoft Graph instead. Graph needs no tenant setting changed, files the copy in your Sent Items itself, and preserves threading. So there is nothing to enable, nobody to ask, and one fewer reason for the connection to half-work.

If you have seen this error while trying to make something else work:

535 5.7.139 Authentication unsuccessful, SmtpClientAuthentication is disabled for the Tenant.

That is the wall. It is a tenant policy rather than a bug or a permissions mistake, and it is not something you will meet here, because we do not use that path.

Troubleshooting

If something goes wrong

Microsoft says approval is required

Some organisations do not let staff consent to applications themselves. If you see a message about needing approval or an administrator, your tenant has that setting switched on and an administrator has to approve Mailbox MCP once for your organisation. After that, everyone connects normally. Send them this page and the permission list above; it is the permissions in the table and nothing else.

The mail Claude sees is not your mail

You almost certainly connected a personal Microsoft account with the same address rather than the work or school one. Remove the mailbox in the control panel and add it again, choosing Work or school account at the chooser.

Microsoft warns that the publisher is not verified

Publisher verification is Microsoft confirming that the company behind an application is a real, registered business. Ours is BSolve IT Limited, company 04607330, registered in England and Wales. If you see an unverified warning, treat it the way your own security policy says to: it is a reasonable thing to pause on, and we would rather you did than did not.

Folder names look wrong

Exchange calls them Sent Items, Deleted Items and Junk Email, where most other providers use Sent, Trash and Junk. Nothing is misconfigured; ask for the folder by the name Outlook shows you and it will be found.

Limits

What this connection does not do

  • No shared mailboxes

    Shared and delegated mailboxes are not supported yet. One connection is one mailbox, signed in as its owner. A shared CALENDAR is a different thing and does work: one a colleague has shared with you can be read, and written to where they allowed it.

  • Mail and calendar, nothing else

    No contacts, and no files on a drive. The permissions above cover mail and calendar, and nothing beyond those two.

  • 10 MB a message

    Attachments are capped at 10 MB a message in total, not per file, and the ceiling is ours rather than Microsoft's. A file in your mailbox can use all of it; one the assistant writes itself is far smaller.

  • A file the assistant writes itself

    Only a file the assistant composes itself is small. Files already in the mailbox, at a web address, or uploaded through a one-off link are streamed at send time and never pass through the model.

  • Not a backup tool

    It is not a backup or an export tool, and it cannot recover mail already deleted at Microsoft.

Attribution

Sources

Connect a Microsoft 365 mailbox.

The free tier is 5 calls a day on any mailbox, which is enough to see whether it does what this page says before you pay anything.