Share via


Work IQ MCP overview (preview)

Important

  • This is a preview feature.
  • Preview features aren't meant for production use and might have restricted functionality. These features are subject to supplemental terms of use, and are available before an official release so that customers can get early access and provide feedback.

Add Work IQ MCP to your agents to enhance what they can understand and do. Work IQ is the intelligence layer that grounds Microsoft 365 Copilot and your agents in real-time, shared context across your organization. It enables personalized search, advanced reasoning, and deeper semantic understanding by connecting signals across the Microsoft 365 ecosystem and your business systems. Work IQ applies an extensive understanding of your work to help Microsoft 365 Copilot and your agents deliver insights, recommendations, and actions that closely align with the reality of your business.

Work IQ is built on three tightly integrated layers: Data, Memory, and Inference. These layers work together to give Microsoft 365 Copilot and your agents continuous, contextual understanding of work.

  • Data unifies signals from files, emails, meetings, chats, and business systems across Microsoft 365 to capture how work happens across the organization.
  • Memory builds persistent understanding of how people and teams work, enabling Agent 365–managed agents to stay aligned to priorities and remain consistent across tasks, apps, and sessions.
  • Inference brings together models, skills, and tools so agents can reason and take action—using Work IQ MCP tools—while the Agent 365 control plane ensures those actions remain observable, governed, and compliant. Copilot and your agents don't just understand your work, they actively move it forward.

You can extend your agents by using Work IQ MCP tools in Copilot Studio. These tools connect your agents to the Work IQ service, so you can experience more accurate, relevant, and personalized responses that are grounded in your work, line-of-business, and web data. You can also learn how to connect your agents to Work IQ MCP tools in Microsoft Foundry. To learn more, see the Work IQ MCP overview in Agent 365 documentation.

Important

You must have a Microsoft 365 Copilot license to use Work IQ MCP servers. For more information about licensing and how to set it up, see Microsoft 365 Copilot license.

Work IQ MCP key features

Extend your agents' capabilities by using Work IQ MCP tools that are secure, scalable, and compliant by design. Key features include:

  • Centralized governance: Admins manage Work IQ MCP servers in the Microsoft 365 admin center, and they can allow or block servers across the organization.
  • Enterprise‑grade security: Agents are secure and operate within compliance boundaries through scoped permissions, policy enforcement, and runtime observability.
  • Continuous evaluation: All Work IQ MCP servers undergo rigorous testing across diverse datasets and models to ensure production-grade robustness and consistent performance. The evaluation measures:
    • Accuracy
    • Latency
    • Reliability
  • Integrated developer experience: Tooling infrastructure is built into Microsoft Agent 365 SDK and CLI, Microsoft Foundry, and Copilot Studio.

Security and compliance

Agent 365 gives IT administrators centralized control to manage which MCP servers are available to agents, ensuring that every tool call adheres to organizational policies. Key security and compliance features include:

  • Admin control: Activate or block servers in Microsoft 365 admin center.
  • Scoped access: Grant only the permissions agents need.
  • Observability: Provide full tracing of tool calls for audits and troubleshooting.
  • Policy enforcement: Enforce rate limits, payload checks, and security scans at runtime.

Governance using Microsoft 365 admin center

Admins gain a unified view of all Work IQ MCP tools and other MCP servers through Microsoft 365 admin center. This centralized perspective allows them to oversee, manage, and enforce governance across the entire tools landscape. If admins block a Work IQ MCP tool or MCP server, it blocks access for every user and every agent. Permissions always take precedence over configuration, so IT admins have ultimate authority to maintain security and compliance.

Each Work IQ tool and MCP server is represented by a permission on the Agent 365 application. When an agent is onboarded, the admin grants the required permissions. The agent gains access to the MCP server only after this consent, ensuring that every interaction is secure and fully authorized.

Admins can manage Work IQ MCP tools directly in the Microsoft 365 admin center under the Agents and Tools section to perform the following tasks:

  • View all activated Work IQ MCP servers (Work IQ Mail, Work IQ Calendar, Work IQ Teams, and any custom servers).
  • Allow or block specific servers based on organizational policies.
  • Apply scoped permissions so agents only access what they need.

Note

The ability to allow or disallow tooling and MCP servers in Microsoft 365 admin center might not be available in your region yet.

The Agent 365 control plane ensures that agents only access approved tools, which reduces risk and aligns with compliance requirements.

Observability using Microsoft Defender

Operational transparency is built in. Admins can go to the Microsoft Defender portal, go to Advanced Hunting, and run queries to:

  • Inspect trace logs of tool calls made by agents.
  • Monitor execution details, including which tools were invoked, parameters passed, and outcomes.
  • Detect anomalies or unauthorized usage patterns for proactive security.

Agent 365 provides a secure, centralized gateway for extending your agents with enterprise-ready tools through Work IQ for Microsoft 365 services and custom tooling servers for specialized workflows so developers can build powerful, compliant agents without sacrificing flexibility.

By using centralized governance in the Microsoft 365 admin center and full observability by using Microsoft Defender, organizations maintain control and transparency over every tool call. Integrated into Copilot Studio for low-code builders and Azure AI Foundry for pro-code developers, Agent 365 delivers a consistent, developer-friendly experience backed by rigorous evaluation for accuracy, latency, and reliability.

Agent 365 combines extensibility, security, and compliance to help organizations confidently scale AI agents across productivity and business systems.

Add Work IQ tools to your agents

Get started by learning what steps to take to extend your agents with Work IQ tools in Copilot Studio.

Prerequisites

Before you connect your agent to Work IQ, make sure you have a Microsoft 365 Copilot license.

Connect your agent to Work IQ

Extend your agents with a Work IQ MCP server. These tools connect your agent to the Work IQ service, so it can access real-time work insights and context.

You can connect your agent to multiple Work IQ MCP servers in Copilot Studio. The following steps guide you through the process of adding the Work IQ Mail MCP server to your agent. This server provides your agent with insights and context from your emails, so it can understand and act on email content in a more informed way.

  1. Sign in to Copilot Studio and select or create your agent.

  2. Select the Tools tab and select Add Tool.

    Shows the Create your first tool page in Copilot Studio

  3. On the Add tool page, select Model Context Protocol to see the Work IQ MCPs and other MCP servers.

    Shows the Model Context Protocol options in Copilot Studio

  4. Type mail in the search box.

    Shows the search results for a mail tool in Copilot Studio

  5. Select Work IQ Mail and expand the connection dropdown to select Create New Connection.

    Shows the Work IQ Mail MCP Server in Copilot Studio

  6. Select Create.

  7. Provide your credentials and complete the sign-in process.

  8. Select Add and Configure to complete the process.

  9. Test the agent. Select Test and then type a prompt that requires email context to see the Work IQ Mail tool in action. For example, you can use the following prompt: Send an email to <your test tenant email address> and ask how the hands-on lab is going.

    Shows the test prompt in Copilot Studio

  10. Select Enter.

  11. When asked to allow the Work IQ tool to connect and use services, select Allow.

    Shows the permission prompt for the MCP server

After a few moments, you receive an email.

The agent can now read the email content, understand the context, and respond accordingly. You can repeat these steps to connect your agent to other Work IQ MCP tools, such as Work IQ Calendar or Work IQ Teams, to further enhance its capabilities with insights from meetings, chats, and more.

Shows a list of Work IQ MCP server tools added to an agent