Microsoft Teams MCP: Connect Teams to Claude Code and Cursor

by Sujay ChoubeyOct 9, 20268 min read
AI AgentsAI Use Case

TL;DR:

  • Connect Microsoft Teams to Claude Code, Claude Desktop, or Cursor using a Teams MCP server in under 10 minutes.

  • Managed access to 1,500+ integrations with 50,000+ tools: OAuth token refresh, Microsoft Graph API authentication, and schema mapping handled for you.

  • Free tier includes 100,000 tool calls per month with no credit card required.

  • Self-hosting one MCP integration is manageable; self-hosting ten is a maintenance burden, once you add Salesforce, GitHub, and Zendesk alongside Teams, schema upkeep, API version changes, and per-team access scoping compound fast.

Connecting an AI agent to Teams is a weekend project. Connecting that same agent to Teams, Salesforce, GitHub, Slack, and forty other business systems, with consistent authentication, usage controls, and audit trails across all of them, is a different problem. Composio gives agents one governed path to act across 1,500+ apps and 50,000+ tools: the agent plans, Composio authorizes the action based on your access policies, executes it through the appropriate API, and returns structured results the LLM can verify.

Authentication, schema mapping, and execution are handled through the Model Context Protocol. Microsoft Graph API access tokens expire after 60 to 90 minutes by default, and across dozens of connected apps, each with its own token lifecycle and OAuth quirks, that refresh logic compounds fast. Composio handles it as part of the execution layer, not as a one-off fix.

What is a Teams MCP server

The Model Context Protocol (MCP) enables AI applications to connect with data sources and tools through a client-server model. Think of it as a universal connector for AI. Instead of hard-coding API integrations for every app, MCP provides a standardized way for LLMs to discover and execute tools.

The Composio Microsoft Teams MCP server acts as the bridge between your AI client (Claude, Cursor, etc.) and your Teams workspace. It gives your agent the ability to send messages, create channels, manage meetings, and search conversation history, all structured actions governed by Composio's execution layer. Microsoft Graph API authentication is handled behind the scenes, so you don't write custom OAuth flows or manage token refresh logic.

Your AI client sends the request, the Composio MCP server routes and executes it, and the result is returned in structured form the LLM can reason over. This execute/verify loop gives agents reliable access to Teams data without you building custom infrastructure. Because Composio builds and maintains the underlying tools, authentication and automatic updates when Microsoft changes their API are managed for you.

How to connect Teams to Claude Code

Here’s the fastest path to connect Microsoft Teams through Composio to Claude Code:

Option 1: Install the Claude Code plugin (recommended)

  1. Open Claude Code.

  2. Run the following commands:

    /plugin marketplace add ComposioHQ/composio-plugin-cc
    /plugin install composio@composio
  3. Follow the prompts to complete the installation and authenticate your connected apps when prompted.

Option 2: Use the Composio CLI

Run:

composio setup --target claude

How to connect Teams to Cursor

1. Install the Composio plugin

Open the Composio plugin in the Cursor marketplace, click Install Composio Plugin for Cursor, and authorize in your browser.

Self-hosted vs managed MCP

Self-hosted limitations: Self-hosting an MCP server for one integration is manageable. The problem is that agents rarely stay at one integration. Once you connect Teams, the next request is Salesforce. Then GitHub. Then Zendesk. Across 10 or 50 integrations, maintaining production-grade tool schemas, handling API version changes, enforcing usage limits, and scoping access per team becomes a permanent operating burden.

MCP does not track token consumption or enforce usage limits out of the box, meaning your agent can invoke tools repeatedly without budget ceilings. Each app ships its own OAuth flow, token refresh behavior, and API versioning cadence. When Salesforce changes an OAuth scope or Slack deprecates an endpoint, your team handles each one manually. Implementing rate limiting, audit logging, and access control from scratch is on you.

Composio advantages: Composio connects agents to 1,500+ apps and 50,000+ tools through a single managed layer, giving agents one governed path to act across business systems. Each team gets its own MCP endpoint scoped to the tools it is permitted to use, with usage caps, rate limiting, and audit trails handled automatically.

The same path handles Teams today and Salesforce tomorrow without new infrastructure on your end. Over 1 million connected accounts and 1B+ tool calls run through this layer. Token refresh and OAuth handling are managed as part of the execution layer, alongside schema maintenance, API version updates, and access control. Composio holds SOC 2 Type II and ISO 27001 certification.

Feature

Self-Hosted MCP

Composio

Rate Limiting

Manual implementation

Configurable per-team rate limits

Authentication

OAuth 2.1 framework requires manual configuration

Composio manages unified auth

Audit Logging

Manual logging required

Composio logs every tool call

Security Certification

None (self-managed)

Composio holds SOC 2 Type II, ISO 27001

Token Budget Enforcement

Manual implementation

Spend caps available on Pro tier and above

Troubleshooting common issues

  • Invalid OAuth token errors: If you see "invalid_token" errors, your OAuth-protected MCP server may have invalidated previously issued tokens after a restart or key rotation. Use the Revoke button in your MCP server config section to delete all stored OAuth tokens and re-authenticate.

  • Redirect URI mismatches: Verify that the OAuth redirect URI in your Azure app registration matches the one specified in your MCP server configuration. Mismatched redirect URIs will prevent users from signing in or cause token exchange to fail.

  • SSO not working: For enterprise deployments, Microsoft Entra ID can be used to secure MCP access with Single Sign-On, though other identity providers like Okta or Google Workspace can also be configured for enterprise SSO.

Security best practices

If you're rolling this out across a team rather than just your own account, here's what your IT admin will need to handle. When deploying agents that act across business systems, follow these practices to govern access at the team level:

  • Least privilege access: Grant each administrator exactly the permission they need to do their job. Use Microsoft Entra ID's role-based access control to enforce granular permissions.

  • Conditional Access policies: Require compliant devices and multifactor authentication when admins activate roles. Implement Privileged Identity Management (PIM) for just-in-time activation determined by security gates such as MFA and approval workflows.

  • Credential management: Restrict user consent so users cannot grant arbitrary apps access. Require admin consent beyond a small set of low-risk scopes, and audit existing OAuth grants quarterly for over-broad access.

  • Data encryption: Composio encrypts all sensitive data such as tokens, keys, and configuration at rest and in transit. For zero data retention requirements, Composio offers a ZDR add-on that stops retention of request and response payloads.

Maintaining your Teams integration

Composio maintains and updates all toolkit integrations automatically, so your agents always work with the latest Microsoft API versions. When Microsoft deprecates an endpoint or changes OAuth scopes, Composio handles the migration without breaking your agent workflows.

You can programmatically update your MCP server configuration using the Composio API.

For teams using Composio's meta tools, agents can search the catalog, inspect schemas, and authenticate users without loading every possible tool into context. This keeps your Teams integration efficient even as you add more apps to your workflow.

Create a free Composio account and follow the steps above to connect Teams to Claude Code or Cursor. The free tier includes 100,000 tool calls per month with no credit card required.

FAQs

What is the difference between Teams MCP and the Microsoft Graph API?

The Microsoft Graph API is the underlying REST API that provides access to Teams data. Our Teams MCP server wraps the Graph API in the Model Context Protocol, providing structured tool schemas and managed authentication that AI clients can consume natively without you writing custom OAuth code.

Does Composio store my Teams messages or credentials?

Composio encrypts all sensitive data at rest and in transit. With the Zero Data Retention (ZDR) add-on, Composio does not retain your request and response payloads. Audit logs contain metadata only, with retention windows you configure.

Can I use Teams MCP with frameworks other than Claude?

Yes. Composio provides framework-specific integrations for OpenAI Agents SDK, Vercel AI SDK, Mastra AI, Pydantic AI, AutoGen, and LlamaIndex.

How much does the Teams MCP server cost?

Composio offers a generous free tier with 100,000 tool calls per month, unlimited connections, and no credit card required. The Pro plan starts at $29/month for pay-as-you-scale usage. Enterprise plans with custom pricing include SSO, SCIM, and dedicated support. Check the pricing page for current rates.

What happens if Microsoft changes their API?

Composio automatically updates toolkit integrations to handle API deprecations and version changes. Your agent continues working without code changes on your end, unlike self-hosted solutions where you must manually update OAuth scopes and endpoint URLs.

Key terms

Model Context Protocol (MCP): An open protocol that enables AI applications to connect with external data sources and tools through a standardized client-server model.

OAuth 2.0: An authorization framework that enables applications to obtain limited access to user accounts on HTTP services like Microsoft Graph without exposing passwords.

On-Behalf-Of (OBO) Flow: An OAuth 2.0 flow where a middle-tier service exchanges a token received from a client for a new token to access downstream APIs like Microsoft Graph.

Microsoft Entra ID: Microsoft's cloud-based identity and access management service (formerly Azure Active Directory) that handles authentication for Teams and Microsoft 365.

Tool Router: The Composio meta tool that inspects incoming requests and routes them to the appropriate toolkit based on the user's authenticated connections, eliminating conditional logic in agent code.

Zero Data Retention (ZDR): A Composio add-on that prevents the platform from retaining request and response payloads, ensuring sensitive data passes through without storage.

Get started

Your agents can
do more

Connect your agents to 1,500+ apps. Start for free, no credit card needed.

Are you an AI agent? See setup options

Share