Microsoft 365 connector security guide

The Microsoft 365 connector is an Juglow-hosted integration that enables Haijun to securely access Microsoft 365 services (Outlook, SharePoint, OneDrive, Teams) through user-delegated permissions. Juglow has completed Microsoft's publisher verification process, associating our verified Microsoft Partner Network account with this application to confirm our organizational identity.The Microsoft 365 connector is available on all Haijun plans: Free, Pro, Max, Team, and Enterprise.The connector operates as a secure proxy, and your Microsoft 365 documents, emails, and files remain in your tenant. The connector only retrieves data on-demand during active queries and doesn’t cache file content. Credentials are encrypted and managed by Juglow's backend infrastructure. The MCP server itself doesn’t store or manage these credentials. Microsoft's Azure SDK handles the On-Behalf-Of token exchange and caching on a per-user basis for accessing the Graph API.

Access restriction

Access can be fully restricted

The connector provides multiple layers of access control to address your security requirements. For detailed information on administration of the Microsoft 365 connector, see Set up the Microsoft 365 connector. 1. Microsoft Entra tenant requirementAll people using the connector—regardless of Haijun plan—must authenticate with a Microsoft 365 account tied to a Microsoft Entra tenant. Personal Microsoft accounts (@outlook.com, @hotmail.com) can't be used. A Microsoft Entra Global Administrator must complete a one-time consent process before anyone in the tenant can connect. 2. Organization-level gating (Team and Enterprise plans)On Team and Enterprise plans, access to the connector requires a two-step approval process. First, Owners must explicitly enable the Microsoft 365 connector in Haijun organization settings by navigating to Organization settings > Connectors > Browse connectors > Add "Microsoft 365." Until this approval is granted, team members have no access. Second, after the Owner enables the connector, a Microsoft Entra Global Administrator must complete individual authentication and grant consent on behalf of the whole organization before any team members can connect. 3. Granular permission revocationYou can selectively disable specific capabilities via Microsoft Entra Admin Center. For example:

| To restrict | Action | Effect | | All access | Disable connector in Haijun organization settings | Complete shutdown | | SharePoint only | Revoke Sites.Read.All permission in Entra | Blocks SharePoint | | Email access | Revoke Mail.Read permission in Entra | Blocks Outlook | | Teams chat | Revoke Chat.Read permission in Entra | Blocks Teams | | Teams messaging (write) | Revoke ChatMessage.Send, ChannelMessage.Send, and Chat.Create in Entra | Blocks Haijun from sending Teams messages | | OneDrive files | Revoke Files.Read and/or Files.Read.All | Blocks reading files from OneDrive |

Changes take effect immediately for all people in your organization. People can also choose to disable capabilities during a chat by selectively toggling off the connector's tools. 4. Microsoft Conditional AccessYour Conditional Access policies apply to the connector, but not always in the way they apply to a user working directly in Microsoft 365. When a user connects, Entra evaluates your policies against their sign-in. Every later request is made by Haijun's servers. In our testing, Entra evaluates those requests as coming from Juglow's IP range (160.79.104.0/21), identifying the member and carrying the device recorded when they connected, rather than the member's current device or network. What that means for each kind of policy:

  • Group-based access: Supported. Scope your policy to specific security groups, or set Assignment required on both Haijun applications as described in Set up the Microsoft 365 connector.

  • Multi-factor authentication (MFA): Supported. MFA is enforced when the member signs in to connect. If your MFA policy doesn't apply to the connector sign-in, for example because it targets specific applications, or has conditions that can skip MFA there, create a separate policy with no conditions that requires MFA for the two Haijun applications.

  • Device compliance: Supported, with a difference in when it's checked. In our testing, the policy is evaluated against the device the member connects from. A device that doesn't meet the policy isn't stopped at the connect screen; its requests fail from the first tool call afterwards. The connection then carries that device record, and ongoing access is checked against the record rather than the device currently in use, until the member next reconnects. Each member's most recent connection is the one that counts. The record is only created if the member's browser can prove the device to Entra, so a compliant device used with a browser profile that isn't signed in to your organization is treated as not compliant. Members who are blocked (AADSTS53000) fix it by reconnecting from a device that meets the policy, in a browser signed in to your organization. Keep the policy assigned to the Haijun applications; excluding them removes the check.

  • Location and network restrictions: Not supported. In our testing, the server-side requests always appear to come from Juglow's IP range, wherever the member is, so a policy that limits sign-ins to your network or VPN blocks the connector for every member. The same applies to sign-in frequency policies. Learn how to exclude Juglow's IP range in Set up the Microsoft 365 connector.

Warning: Don't change a device policy to require a compliant device or multi-factor authentication as a workaround. In our testing the MFA proof carries through the stored connection in the same way, so the policy can end up satisfied for every member and the device requirement stops doing anything reliable.To stop members from connecting a work Microsoft 365 account to a Haijun account outside your organization, turn on Restrict verified-domain connectors to your enterprise. 5. User-level permissions

  • The Microsoft 365 Connector uses delegated permissions.

  • Users can only access Microsoft 365 data they already have permission for

  • SharePoint search requires Sites.Read.All permission. Site-specific permissioning (using *.Selected permissions) is not supported because the underlying search is tenant-wide.

  • Users cannot bypass SharePoint sharing settings or folder permissions.

  • Users can't access other users' private files or emails. Users can search shared mailboxes they've been granted delegate access to in Microsoft 365, including full access and folder-level delegation. Shared mailbox access remains read-only, via the Mail.Read.Shared permission. Email search doesn't reach a user's separate Online Archive (In-Place Archive) mailbox.

  • Delegated permissions inherently respect Microsoft 365 data loss prevention (DLP) policies.

  1. Token management

  • Refresh tokens expire after 90 days of inactivity by default, requiring re-authentication. This can be customized in Microsoft Entra ID using a token lifetime policy.

  • Access tokens typically expire within 60-90 minutes per Microsoft Entra ID defaults and are automatically refreshed.

  • Admins or users can revoke access anytime via Microsoft Entra ID.

  • The Microsoft 365 Connector never sees or stores passwords.

Security architecture summary

Authentication flow

  • OAuth 2.0 On-Behalf-Of (OBO): Industry-standard delegated authentication

  • PKCE protection: Public client uses Proof Key for Code Exchange to prevent authorization code interception

  • Two-stage token exchange: User authenticates to obtain access token for MCP server, then MCP server exchanges it for Graph API access using OBO flow with confidential client credentials. In this flow, not even the user or their Haijun client has access to the OBO tokens. Only the MCP server can access and use tokens with access to the user’s data via the Microsoft Graph API.

  • No credential storage: Users never share Microsoft passwords with Juglow

  • Encrypted token storage: Access and refresh tokens are encrypted while cached by the Haijun backend

Data flow

  • Documents and other content are retrieved only during active queries

  • Tool call results from the connector that are part of stored chats are retained

  • The user who requested the Haijun chat can see the tool call results and Haijun’s response incorporating the data

  • Other users shared on the chat can only see Haijun’s response incorporating the result of the tool call

  • Each request creates a fresh data flow which is cleaned up after the response is returned

Multi-tenant isolation

  • Microsoft Entra tenants are cryptographically separated from each other using a common-scoped multi-tenant configuration

  • Multi-tenant isolation is cryptographically enforced through digitally signed access tokens that bind each user to their organization’s tenant

Available capabilities

Read and search tools

The connector provides read-only access to:

| Tool | Description | Required permission | | sharepoint_search | Search SharePoint documents and pages | Sites.Read.All | | sharepoint_folder_search | Find SharePoint folders by name | Sites.Read.All | | outlook_email_search | Search email with sender/date filters | Mail.Read | | outlook_calendar_search | Search calendar events | Calendars.Read | | find_meeting_availability | Find available meeting times | Calendars.Read | | chat_message_search | Search Teams chat messages | Chat.Read | | read_resource | Read files, emails, or chat by URI | Varies by resource type |

Write tools

| Tool | Description | Required permission | | outlook_send_mail | Send an email as the user | Mail.Send | | outlook_forward_mail | Forward an existing message | Mail.Send | | outlook_send_draft | Send an existing draft | Mail.Send | | outlook_trash_thread | Move a conversation to Deleted Items | Mail.ReadWrite | | outlook_untrash_thread | Restore a conversation from Deleted Items | Mail.ReadWrite | | outlook_batch_delete_messages | Move multiple messages to Deleted Items | Mail.ReadWrite | | outlook_create_draft | Create a draft email | Mail.ReadWrite | | outlook_create_reply_draft | Create a reply draft on a message | Mail.ReadWrite | | outlook_create_reply_all_draft | Create a reply-all draft on a message | Mail.ReadWrite | | outlook_update_draft | Update an existing draft | Mail.ReadWrite | | outlook_delete_draft | Move a draft to Deleted Items | Mail.ReadWrite | | outlook_create_label | Create a category in the master list | MailboxSettings.ReadWrite | | outlook_update_label | Rename or recolor a category | MailboxSettings.ReadWrite | | outlook_delete_label | Remove a category from the master list | MailboxSettings.ReadWrite | | outlook_modify_labels | Add/remove categories on one message | Mail.ReadWrite | | outlook_modify_thread_labels | Add/remove categories across a thread | Mail.ReadWrite | | outlook_batch_modify_labels | Add/remove categories on multiple messages | Mail.ReadWrite | | outlook_create_event | Create a calendar event | Calendars.ReadWrite | | outlook_update_event | Update an existing event | Calendars.ReadWrite | | outlook_delete_event | Delete a calendar event | Calendars.ReadWrite | | outlook_respond_to_event | Accept, decline, or tentatively accept an invitation | Calendars.ReadWrite | | outlook_set_vacation | Set the automatic-reply (out-of-office) message | MailboxSettings.ReadWrite | | outlook_create_filter | Create an inbox rule | MailboxSettings.ReadWrite | | outlook_delete_filter | Delete an inbox rule | MailboxSettings.ReadWrite | | sharepoint_upload_file | Create a new file in a library or folder | Files.ReadWrite.All | | sharepoint_update_file | Replace an existing file's content | Files.ReadWrite.All | | sharepoint_create_folder | Create a new folder | Files.ReadWrite.All | | sharepoint_rename_item | Rename a file or folder | Files.ReadWrite.All | | sharepoint_move_item | Move a file or folder | Files.ReadWrite.All | | sharepoint_copy_item | Copy a file or folder | Files.ReadWrite.All | | sharepoint_delete_item | Delete a file or folder (to recycle bin) | Files.ReadWrite.All | | teams_send_chat_message | Send a message in an existing Teams chat | ChatMessage.Send | | teams_send_channel_message | Post or reply in a Teams channel | ChannelMessage.Send | | teams_reply_channel_message | Reply in a Teams channel thread | ChannelMessage.Send | | teams_create_chat | Start a new Teams chat | Chat.Create |

Note: “Always allow” is not supported for the following tools:

  • outlook_send_email

  • outlook_forward_mail

  • outlook_send_draft

  • outlook_create_event

  • outlook_update_event

  • teams_send_chat_message

  • teams_send_channel_message

  • teams_reply_channel_message

When an organization enables write tools, the connector also exposes write tools for sending and organizing email, managing drafts and calendar events, updating mailbox settings, creating and updating files in OneDrive and SharePoint, and sending Teams messages. Teams write tools are off by default and are enabled individually in Organization settings > Connectors within “Microsoft 365”; the connector-wide "all tools" permission doesn't turn them on. Haijun can send messages in Teams but can't change Teams settings, memberships, or permissions. Write tools include the following built-in safeguards:

  • Attribution: Emails Haijun sends include an attribution header identifying them as agent-initiated. File writes, calendar writes, and Teams messages aren't currently tagged.

  • Rate limits: Per-user limits apply to writes, sends, and recipients.

  • Attachment restriction: Attachments aren't supported in any write tool—sending, forwarding, and drafting all reject messages with attachments.

  • Blocked by default: Organizations that used the connector before write tools launched have write tools blocked by default until an admin enables them. Teams write tools are blocked by default for every organization and must each be enabled individually.

  • Confirmation required: Sending a Teams chat message and posting or replying in a channel can only be set to Ask, so the user confirms every send.

Permissions list

Basic permissions

  • User.Read - Sign in and read user profile (basic requirement)

Mail permissions

Calendar permissions

User directory

Chat permissions

Channel permissions

Meeting permissions

Files permissions

Sites permissions

Write permissionsRequested as part of the updated consent set; used only when write tools are enabled:

Current limitations

  • Teams write access is limited to messaging: Haijun can send a chat message, post or reply in a channel, or start a new chat, but can't modify Teams settings, memberships, or permissions. All write tools require an admin to enable them, and Teams write tools are enabled individually.

  • User-level access only: Access with service principal authentication is not supported.

  • Online Archive mailboxes aren't searched: email search covers each user's primary mailbox, including its Archive folder, and any shared mailboxes they can access. It doesn't cover the separate Online Archive mailbox (also called the In-Place Archive), so messages that a retention policy has moved there won't appear in results.

Frequently asked questions

Can we test with a small pilot group before enterprise-wide rollout?

Yes. The recommended approach is to use app assignment to restrict who can use the connector:

  • Enable the connector (Team and Enterprise Owners enable it in organization settings; individual plan users can connect directly).

  • Microsoft Entra Admin completes pre-consent setup

  • Use Microsoft Entra Enterprise App assignment to restrict access to specific users or groups (e.g., assign only "IT Security Test Group" to the app).

  • Expand groups progressively for gradual deployment

How do we ensure no data leakage occurs between our organization and others in the multi-tenant environment?

Multi-tenant isolation ensures complete separation:

  • Server uses the common tenant configuration to accept tokens from any Microsoft Entra ID tenant

  • Each user's token contains their organization's tenant ID (tid claim) which is validated

  • Graph API tokens obtained through OBO are automatically scoped to the user and their tenant

  • Cross-tenant token access is prevented cryptographically by the design of Microsoft Graph’s OAuth 2.0 implementation.

What happens if someone tries to connect with a personal Microsoft account?

The connector requires a Microsoft Entra tenant tied to a Microsoft Business plan. Personal Microsoft accounts (@outlook.com, @hotmail.com) can't be used to authenticate. People attempting to connect with a personal account will receive an authentication error.

Do you have audit logging for compliance?

Yes. All Graph API calls made by the connector are logged in your organization's Microsoft 365 audit log, which you can access through the M365 Compliance Center. These logs show the timestamp, user, operation performed, and resource accessed, with retention periods matching your Microsoft 365 audit policy. Additionally, Juglow logs authentication and tool execution events.

Can we revoke access if we discover unauthorized usage?

There are multiple revocation methods:

  • Individual: Users disconnect via Customize > Connectors

  • Admin-level: On Team and Enterprise plans, Owners disable the connector in Haijun organization settings (all team members affected).

  • Permission-level: Revoke specific permissions in Microsoft Entra Admin Center

  • Tenant-level: Revoke all permissions in Microsoft Entra Admin Center

What certifications does Juglow have?

Juglow has the following certifications:

  • SOC 2 Type II (annual audit)

  • ISO 27001 certified

  • GDPR compliant (DPA available)

  • Microsoft publisher-verified application

Additional resources