Microsoft 365

Let your agents read and write Outlook mail and calendar and read contacts, each member signed in with their own Microsoft work or school account.

Overview

Microsoft 365 is a ready-made connector. An organization admin registers an app in Microsoft Entra once and enters it in the 2kw.ai console; agent authors then add one connector URL to their agents, and each member connects their own account in the chat app.

AreaWhat an agent can do
ProfileRead the signed-in member's profile
MailList folders, list and read messages, create drafts, send, reply, reply all, forward
CalendarList calendars and events, find meeting times, create and update events, accept, decline or tentatively accept invitations
ContactsList and read contacts

An agent cannot delete or move anything, read attachments, or reach OneDrive, SharePoint, Teams or To Do. Every tool that writes sends something to other people, so it runs only with a person's approval or an exact automatic-approval rule; see Approvals.

Before you start

  • A Microsoft Entra role that may register applications in your tenant, such as Application Developer or Application Administrator.
  • The Admin or Owner role in your 2kw.ai organization.
  • Members sign in with work or school accounts of that tenant. Personal Microsoft accounts are not supported.

Register the app in Microsoft Entra

1

Create the app registration

In the Microsoft Entra admin center, open Identity → Applications → App registrations and choose New registration.

  • Name: anything your members recognize, for example 2kw.ai agents. They see it when they sign in.
  • Supported account types: Accounts in this organizational directory only.
  • Redirect URI: platform Web, value https://chat.2kw.ai/connectors/callback.

Choose Register.

2

Add the Microsoft Graph permissions

Open API permissions → Add a permission → Microsoft Graph → Delegated permissions and add these five:

PermissionUsed for
User.ReadWho the member is
Mail.ReadWriteReading mail and creating drafts
Mail.SendSending, replying and forwarding
Calendars.ReadWriteReading and changing events
Contacts.ReadReading contacts

None of them needs admin consent: each member agrees when they connect. To spare them that prompt, an Entra admin can choose Grant admin consent for the tenant. At sign-in, members also see Maintain access to data you have given it access to: it lets 2kw.ai renew their sign-in without asking again.

3

Create a client secret

Open Certificates & secrets → Client secrets → New client secret, pick an expiry and choose Add. Copy the secret's Value right away; Entra shows it only once. The Secret ID is not needed.

Put a reminder in your calendar a few weeks before the expiry. See When the secret expires.

4

Copy the two IDs

On the app's Overview, copy the Application (client) ID and the Directory (tenant) ID.

Enable it in the console

Open Connectors in the console's sidebar and choose Add Microsoft 365. Enter the directory (tenant) ID, the application (client) ID and the client secret value, and keep the token endpoint auth method at client_secret_post unless your app requires client_secret_basic. Then choose Enable.

The dialog approves the hosts m365.mcp.2kw.ai and login.microsoftonline.com for your organization and registers your app for your tenant, showing each step as it goes. Approving those hosts lets agents reach any connector on the first and the sign-in pages of any Microsoft Entra tenant on the second; only your tenant gets a registration.

  • Running it again picks up where it stopped: a step that is already done is skipped.
  • A registration for your tenant already exists, for example from an earlier run: the dialog shows its client ID and auth method next to the ones you entered, and you choose Use existing registration or Replace credentials. Replacing asks every member connected through the old one to sign in again.
  • Your organization has reached its limit of approved hosts: the dialog stops and says so. Remove a host you no longer need under Connectors → Approved public hosts and run it again.

Once the steps are done, the dialog shows your connector URL and tests it:

https://m365.mcp.2kw.ai/t/{tenant-id}/mcp

The tenant ID in the URL is lowercase. Choose Connect in the test result to sign in as yourself and see the tools.

Add it to an agent

Give the connector URL to your agent authors. In the console's agent editor they add a connector on the approved host m365.mcp.2kw.ai with the path /t/{tenant-id}/mcp, or declare it on the agent version:

{
  "type": "mcp",
  "server_label": "m365",
  "server_url": "https://m365.mcp.2kw.ai/t/{tenant-id}/mcp",
  "server_description": "The member's Outlook mail, calendar and contacts"
}

Levels per tool, approvals and the rest work as for any connector; see Connectors.

What members see

  • Connecting. A member connects on the chat app's Connectors page or from the card a paused chat shows. Microsoft's sign-in page opens in a new tab, lists the permissions above unless an admin already granted them, and returns to the chat.
  • Acting. An agent reads as the member. Before it sends, creates or changes anything, the member approves the call, unless the author set an exact automatic-approval rule for that tool.
  • Disconnecting. Disconnecting deletes the member's sign-in in 2kw.ai. Microsoft offers no way to revoke it from outside, so at Microsoft it stays valid until it expires, or until the member removes the app under My Apps or an Entra admin revokes their sessions.

When the secret expires

Once the client secret has expired, every member's connection needs a reconnect, and reconnecting fails until an admin enters a new secret. Create a new secret in Entra (step 3 above), then either run Add Microsoft 365 again and choose Replace credentials, or edit the registration under Connectors → OAuth clients. Every member connected through it signs in again.

Was this page helpful?