# Outlook Semantic MCP – Features

This page describes user-facing features of the Outlook Semantic MCP Server: what is supported, what is not, and any setup required. For per-tool input/output reference, see [Tools](https://docs.unique.ai/it-operators/integrations-connectors/outlook-semantic-mcp/outlook-semantic-mcp-technical-reference/outlook-semantic-mcp-tools). For environment variables and deployment configuration, see [Configuration](https://docs.unique.ai/it-operators/integrations-connectors/outlook-semantic-mcp/outlook-semantic-mcp-operator-manual/outlook-semantic-mcp-configuration).

### Deployment modes

The MCP server operates in two modes controlled by the [`MCP_BACKEND`](https://docs.unique.ai/it-operators/integrations-connectors/outlook-semantic-mcp/outlook-semantic-mcp-operator-manual/outlook-semantic-mcp-configuration) environment variable. Several features behave differently depending on which mode is active:

| Mode | `MCP_BACKEND` value | How it works |
| --- | --- | --- |
| **Mode A** | `microsoft_graph_and_unique_api` | Emails are ingested into the Unique knowledge base after a user connects. `search_emails` runs semantic search (Unique KB) and KQL keyword search (Microsoft Graph) in parallel. |
| **Mode B** | `microsoft_graph` | No email ingesting. `search_emails` queries Microsoft Graph directly using KQL keyword search only. |

Where a feature works the same in both modes, this page says so once. Where behaviour differs, Mode A and Mode B are called out separately.

## Email Search

**Mode A (`microsoft_graph_and_unique_api`)**

- `search_emails` runs semantic search against the Unique knowledge base and a KQL keyword search against Microsoft Graph simultaneously, then merges and deduplicates results.

- Folder filtering is supported: pass folder IDs (from `list_mailboxes_and_directories`) or well-known folder names (e.g. `Inbox`) to narrow results to a specific folder.

- A `syncWarning` is returned while the initial full sync is still in progress — results may be incomplete until it finishes.

**Mode B (`microsoft_graph`)**

- `search_emails` queries Microsoft Graph directly using KQL keyword search only. No knowledge base interaction occurs.

- Folder filtering is supported via the `directories` field on each `msGraphKeywordSearchQueries` entry. Pass a well-known folder name (e.g. `Inbox`) or a folder ID from `list_mailboxes_and_directories`. This works for the user's own mailbox and for fully delegated mailboxes (Full Access).

- Search is **not supported** for mailboxes where the user only has folder-level (partial) access — Microsoft Graph requires full mailbox access for `$search` queries.

**What's not supported (both modes)**

- Calendar, task, or file data — only mail is in scope.

## Draft Creation

Available in both modes. Behaviour is identical.

**What's supported**

- Create draft emails in the signed-in user's Drafts folder via `create_draft_email`, with subject, body, recipients (To, CC, BCC), and attachments.

- The draft is not sent automatically — the tool response includes a `webLink` for the user to open and send from Outlook.

- Attachments can be provided as base64-encoded data URIs or Unique content URIs (cluster-local mode only).

**What's not supported**

- Sending email directly from the MCP — drafts must be sent manually by the user.

- Creating drafts in another user's mailbox (delegated or otherwise).

## Contact Resolution

Available in both modes. Behaviour is identical.

**What's supported**

- Look up contacts in the signed-in user's Microsoft contacts directory via `lookup_contacts`.

- Returns display names and email addresses for address resolution.

**What's not supported**

- Organisation-wide directory queries beyond what the `People.Read` scope exposes. If a contact is not in the signed-in user's personal contacts or the People API result set, it will not appear.

## Mailbox & Folder Listing

**Mode A (`microsoft_graph_and_unique_api`)**

- List own mailboxes and their full folder tree via `list_mailboxes_and_directories`.

- When [`DELEGATED_ACCESS_SCAN`](https://docs.unique.ai/it-operators/integrations-connectors/outlook-semantic-mcp/outlook-semantic-mcp-operator-manual/outlook-semantic-mcp-configuration) is enabled, delegated mailboxes also appear alongside the user's own (marked with `isOwn: false`).

- Folder IDs returned by this tool can be passed to `search_emails` to narrow results to a specific folder.

**Mode B (`microsoft_graph`)**

- `list_mailboxes_and_directories` is available and returns the user's own folder tree plus any fully delegated mailboxes. Folder IDs returned here can be passed to the `directories` field of `msGraphKeywordSearchQueries` in `search_emails` to narrow results to a specific folder.

**What's not supported**

- Searching in mailboxes where the user only has folder-level (partial) access in Mode B — Microsoft Graph does not support `$search` against such mailboxes.

## Delegated Access

Delegated access lets a user search another user's mailbox when Microsoft Exchange has granted them access. The MCP server detects these relationships automatically via background scans controlled by [`DELEGATED_ACCESS_SCAN`](https://docs.unique.ai/it-operators/integrations-connectors/outlook-semantic-mcp/outlook-semantic-mcp-operator-manual/outlook-semantic-mcp-configuration) — no per-user configuration is needed beyond enabling that setting. Detection only works when **both the owner and the delegate have connected the MCP**.

### What's supported

Three delegation configurations are supported:

1. **Exchange admin grants Full Access (Read & Manage)**
   - An Exchange administrator grants a user Full Access to another user's mailbox via the Exchange admin center or PowerShell.

2. **User shares specific folders via Outlook desktop**
   - A user shares individual folders with another user directly from Outlook desktop, without Exchange admin involvement.

3. **Shared inbox configured as a normal mailbox**
   - A Microsoft 365 shared mailbox configured with a sign-in-eligible password. Every user who needs access must have Full Access delegation granted.

### What's not supported

- **Microsoft 365 shared mailboxes not configured as a normal mailbox** — shared mailboxes that have not been configured with a sign-in-eligible password and an MCP login are not detected or ingested.
- **Application-permission based access** — the MCP uses delegated permissions only (acting on behalf of a signed-in user).

### Setup

**1. Exchange admin grants Full Access**

**Option A — Exchange admin center (GUI)**
1. Open the [Microsoft 365 admin center](https://admin.microsoft.com/) and navigate to **Exchange admin center**.
2. Go to **Recipients → Mailboxes** and select the target mailbox.
3. Open the **Delegation** tab.
4. Under **Full Access**, click **Edit** and add the delegate user.

**Option B — PowerShell**
```powershell
Add-MailboxPermission `
  -Identity "owner@example.com" `
  -User "delegate@example.com" `
  -AccessRights FullAccess `
  -InheritanceType All
```

**2. User shares specific folders (no admin needed)**

Requires [`DELEGATED_ACCESS_SCAN=granular_access`](https://docs.unique.ai/it-operators/integrations-connectors/outlook-semantic-mcp/outlook-semantic-mcp-operator-manual/outlook-semantic-mcp-configuration) and Mode A.

**3. Shared inbox configured as a normal inbox**

1. In the [Microsoft 365 admin center](https://admin.microsoft.com/), open the shared mailbox and **enable sign-in** by assigning it a password.
2. Grant **Full Access** to every user who needs delegated search access.
3. Connect the MCP using the **shared-inbox account** itself so its emails are ingested into the Unique knowledge base.

### Behavior

For a detailed description of how delegated access works at runtime, see the existing FAQ entries:

**Quick reference:**

|  | Mode A (`microsoft_graph_and_unique_api`) | Mode B (`microsoft_graph`) |
| --- | --- | --- |
| **Full Access delegation** | Supported — delegate searches owner's ingested emails | Supported — live keyword search against owner's mailbox |
| **Folder-level delegation** | Supported (`granular_access` only) | Not supported |
| **Folder filtering** | Supported in `granular_access` | Supported for own mailbox only |
| **Ingestion** | Owner's inbox only | No ingestion |
| **Revocation detection** | Background scan: discovery (every 12 h), verification (every 4 h) | Immediate (live Graph query) |

## Known Limitations

### Search does not work for mailboxes where a colleague shared folders without granting Full Access (Mode B only)

**Symptom:** When a colleague has shared one or more folders with you (but has not granted you Full Access to their entire mailbox), `search_emails` in Mode B returns no results from that mailbox.
