Microsoft Copilot security directory

Office 365 Groups

Published by Microsoft

High risk

Office 365 Groups lets you manage group membership and calendar events in your organization using your Office 365 account. You can perform various actions such as get group roster, add or remove members and create group events.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Can send messages as you: This connector can post messages, emails, or notifications on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.

Available capabilities

This add-on exposes 14 tools or capabilities.

  • Add member to group
  • Create a group event (V2)
  • Create a group event [DEPRECATED]
  • Delete event (V2)
  • List deleted groups
  • List deleted groups by owner
  • List group members
  • List groups
  • List groups that I own and belong to
  • List my owned groups
  • List my owned groups (V2)
  • Remove member from group
  • Restore a deleted group
  • Send an HTTP request [DEPRECATED]
  • Send an HTTP request V2
  • Update a group event

The interactive security report will load automatically.