Outlook Semantic MCP – Features — Unique AI Documentation
Outlook Semantic MCP – Features
This page describes user-facing features of the Outlook Semantic MCP Server: what is supported, what is not, and any setup required. For per-tool input/output reference, see Tools. For environment variables and deployment configuration, see Configuration.
Deployment modes
The MCP server operates in two modes controlled by the MCP_BACKEND environment variable. Several features behave differently depending on which mode is active:
| Mode | MCP_BACKEND value |
How it works |
|---|---|---|
| Mode A | microsoft_graph_and_unique_api |
Emails are ingested into the Unique knowledge base after a user connects. search_emails runs semantic search (Unique KB) and KQL keyword search (Microsoft Graph) in parallel. |
| Mode B | microsoft_graph |
No email ingesting. search_emails queries Microsoft Graph directly using KQL keyword search only. |
Where a feature works the same in both modes, this page says so once. Where behaviour differs, Mode A and Mode B are called out separately.
Email Search
Mode A (microsoft_graph_and_unique_api)
search_emailsruns semantic search against the Unique knowledge base and a KQL keyword search against Microsoft Graph simultaneously, then merges and deduplicates results.Folder filtering is supported: pass folder IDs (from
list_mailboxes_and_directories) or well-known folder names (e.g.Inbox) to narrow results to a specific folder.A
syncWarningis returned while the initial full sync is still in progress — results may be incomplete until it finishes.
Mode B (microsoft_graph)
search_emailsqueries Microsoft Graph directly using KQL keyword search only. No knowledge base interaction occurs.Folder filtering is supported via the
directoriesfield on eachmsGraphKeywordSearchQueriesentry. Pass a well-known folder name (e.g.Inbox) or a folder ID fromlist_mailboxes_and_directories. This works for the user's own mailbox and for fully delegated mailboxes (Full Access).Search is not supported for mailboxes where the user only has folder-level (partial) access — Microsoft Graph requires full mailbox access for
$searchqueries.
What's not supported (both modes)
- Calendar, task, or file data — only mail is in scope.
Draft Creation
Available in both modes. Behaviour is identical.
What's supported
Create draft emails in the signed-in user's Drafts folder via
create_draft_email, with subject, body, recipients (To, CC, BCC), and attachments.The draft is not sent automatically — the tool response includes a
webLinkfor the user to open and send from Outlook.Attachments can be provided as base64-encoded data URIs or Unique content URIs (cluster-local mode only).
What's not supported
Sending email directly from the MCP — drafts must be sent manually by the user.
Creating drafts in another user's mailbox (delegated or otherwise).
Contact Resolution
Available in both modes. Behaviour is identical.
What's supported
Look up contacts in the signed-in user's Microsoft contacts directory via
lookup_contacts.Returns display names and email addresses for address resolution.
What's not supported
- Organisation-wide directory queries beyond what the
People.Readscope exposes. If a contact is not in the signed-in user's personal contacts or the People API result set, it will not appear.
Mailbox & Folder Listing
Mode A (microsoft_graph_and_unique_api)
List own mailboxes and their full folder tree via
list_mailboxes_and_directories.When
DELEGATED_ACCESS_SCANis enabled, delegated mailboxes also appear alongside the user's own (marked withisOwn: false).Folder IDs returned by this tool can be passed to
search_emailsto narrow results to a specific folder.
Mode B (microsoft_graph)
list_mailboxes_and_directoriesis available and returns the user's own folder tree plus any fully delegated mailboxes. Folder IDs returned here can be passed to thedirectoriesfield ofmsGraphKeywordSearchQueriesinsearch_emailsto narrow results to a specific folder.
What's not supported
- Searching in mailboxes where the user only has folder-level (partial) access in Mode B — Microsoft Graph does not support
$searchagainst such mailboxes.
Delegated Access
Delegated access lets a user search another user's mailbox when Microsoft Exchange has granted them access. The MCP server detects these relationships automatically via background scans controlled by DELEGATED_ACCESS_SCAN — no per-user configuration is needed beyond enabling that setting. Detection only works when both the owner and the delegate have connected the MCP.
What's supported
Three delegation configurations are supported:
Exchange admin grants Full Access (Read & Manage)
- An Exchange administrator grants a user Full Access to another user's mailbox via the Exchange admin center or PowerShell.
User shares specific folders via Outlook desktop
- A user shares individual folders with another user directly from Outlook desktop, without Exchange admin involvement.
Shared inbox configured as a normal mailbox
- A Microsoft 365 shared mailbox configured with a sign-in-eligible password. Every user who needs access must have Full Access delegation granted.
What's not supported
- Microsoft 365 shared mailboxes not configured as a normal mailbox — shared mailboxes that have not been configured with a sign-in-eligible password and an MCP login are not detected or ingested.
- Application-permission based access — the MCP uses delegated permissions only (acting on behalf of a signed-in user).
Setup
1. Exchange admin grants Full Access
Option A — Exchange admin center (GUI)
- Open the Microsoft 365 admin center and navigate to Exchange admin center.
- Go to Recipients → Mailboxes and select the target mailbox.
- Open the Delegation tab.
- Under Full Access, click Edit and add the delegate user.
Option B — PowerShell
Add-MailboxPermission `
-Identity "owner@example.com" `
-User "delegate@example.com" `
-AccessRights FullAccess `
-InheritanceType All
2. User shares specific folders (no admin needed)
Requires DELEGATED_ACCESS_SCAN=granular_access and Mode A.
3. Shared inbox configured as a normal inbox
- In the Microsoft 365 admin center, open the shared mailbox and enable sign-in by assigning it a password.
- Grant Full Access to every user who needs delegated search access.
- Connect the MCP using the shared-inbox account itself so its emails are ingested into the Unique knowledge base.
Behavior
For a detailed description of how delegated access works at runtime, see the existing FAQ entries:
Quick reference:
Mode A (microsoft_graph_and_unique_api) |
Mode B (microsoft_graph) |
|
|---|---|---|
| Full Access delegation | Supported — delegate searches owner's ingested emails | Supported — live keyword search against owner's mailbox |
| Folder-level delegation | Supported (granular_access only) |
Not supported |
| Folder filtering | Supported in granular_access |
Supported for own mailbox only |
| Ingestion | Owner's inbox only | No ingestion |
| Revocation detection | Background scan: discovery (every 12 h), verification (every 4 h) | Immediate (live Graph query) |
Known Limitations
Search does not work for mailboxes where a colleague shared folders without granting Full Access (Mode B only)
Symptom: When a colleague has shared one or more folders with you (but has not granted you Full Access to their entire mailbox), search_emails in Mode B returns no results from that mailbox.