Agent skill

CLI Microsoft365

by pnp in pnp/cli-microsoft365-mcp-server

Use CLI for Microsoft 365 to manage Microsoft 365 tenants from the terminal.

MITAuto-check passedDocuments & Office

Install CLI Microsoft365

skills CLI
$ npx skills add pnp/cli-microsoft365-mcp-server --skill cli-microsoft365 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pnp/cli-microsoft365-mcp-server cli-microsoft365 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pnp/cli-microsoft365-mcp-server.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/cli-microsoft365 .claude/skills/cli-microsoft365 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cli-microsoft365
GitHub stars
131
Token cost
~3.5k tokens
SKILL.md length
980 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Use CLI for Microsoft 365 to manage Microsoft 365 tenants from the terminal.

  • Works in 10 steps: Always check login status first with… → Use --output json when you need to… → Use --output text when displaying… → …
  • : running m365 commands
  • SKILL.md covers Prerequisites, Command Syntax, Authentication and Global Options, plus 5 more sections
  • Calls npm and jq; reaches contoso.sharepoint.com and graph.microsoft.com

What it does

CLI Microsoft365 is an agent skill from pnp/cli-microsoft365-mcp-server. Use CLI for Microsoft 365 to manage Microsoft 365 tenants from the terminal. Use when: running m365 commands, managing SharePoint Online, managing Entra ID, managing Teams teams/channels/chats, managing Power Platform, Planner, To Do,Outlook, Viva Engage, querying Microsoft Graph, authenticating to Microsoft 365, scripting Microsoft 365 automation, filtering CLI output with JMESPath.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering Cloud office suites. It works with Microsoft 365, Microsoft SharePoint, Microsoft Entra ID and Power Automate. The repository describes itself as: Manage Microsoft 365 using MCP server. The licence is MIT.

When your agent uses it

  • : running m365 commands
  • Managing SharePoint Online
  • Managing Entra ID
  • Managing Teams teams/channels/chats

Example prompts

  • “/cli-microsoft365”

Requirements

  • Node.js

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Always check login status first with m365 status before running commands
  2. Use --output json when you need to process results programmatically
  3. Use --output text when displaying results to the user for readability
  4. Use --query to filter large result sets server-side instead of post-processing
  5. Use --output none for commands where you don't need to see output (e.g., delete operations)
  6. Use @ file references for complex JSON payloads instead of inline escaping
  7. Prefer named identifiers (e.g., --userName, --title) over GUIDs when both are accepted
  8. Check --help permissions if a command fails with 403 — it shows the required API permissions
  9. Use --debug to troubleshoot failing commands — it shows full HTTP requests/responses
  10. Never hardcode secrets in commands shown to users — use environment variables or prompt

What it can do on your machine

Read from SKILL.md and the folder at commit 6d89707. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • contoso.sharepoint.com
    • graph.microsoft.com

    Also links to:

    • pnp.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

CLI Microsoft365 loads about 3.5k tokens when it runs. Until then it costs about 101 tokens; SKILL.md has 980 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~101
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pnp/cli-microsoft365-mcp-server at commit 6d89707, republished under its MIT licence (© pnp). 980 words, ~3,550 tokens.

Download SKILL.mdSave it as .claude/skills/cli-microsoft365/SKILL.md (or your agent's skills folder).
name
cli-microsoft365
description
Use CLI for Microsoft 365 to manage Microsoft 365 tenants from the terminal. Use when: running m365 commands, managing SharePoint Online, managing Entra ID, managing Teams teams/channels/chats, managing Power Platform, Planner, To Do,Outlook, Viva Engage, querying Microsoft Graph, authenticating to Microsoft 365, scripting Microsoft 365 automation, filtering CLI output with JMESPath.

CLI for Microsoft 365 — Terminal Usage

You are an expert at using CLI for Microsoft 365 (m365) to manage Microsoft 365 tenants from the command line. Follow these instructions when the user asks you to run CLI for Microsoft 365 commands.

Prerequisites

CLI for Microsoft 365 must be installed globally:

sh
npm install -g @pnp/cli-microsoft365

Requires Node.js LTS (18+). Works on Windows, macOS, and Linux with any shell.

Command Syntax

Every command must be prefixed with m365

m365 <command-group> <resource> <action> [options]

start with m365 in terminal to get list of command groups and core commands. Use m365 <command-group> --help to see available resources and actions within a group.

Command Groups (Workloads)
PrefixService
spoSharePoint Online
entraMicrosoft Entra ID (users, groups, apps, enterprise apps, PIM)
teamsMicrosoft Teams
plannerMicrosoft Planner
todoMicrosoft To Do
outlookOutlook (mail, calendar, rooms)
flowPower Automate
paPower Apps
ppPower Platform
vivaViva Engage
purviewMicrosoft Purview
graphMicrosoft Graph extensions & subscriptions
externalMicrosoft Search external connections
speSharePoint Embedded
sppSharePoint Premium
spfxSharePoint Framework project tools
tenantTenant-level reports and service health
onedriveOneDrive reports
fileCross-service file operations via Graph
searchMicrosoft Search
bookingMicrosoft Bookings
exoExchange Online
Core Commands (no workload prefix)
CommandPurpose
m365 loginLog in to Microsoft 365
m365 logoutLog out from Microsoft 365
m365 statusShow login status
m365 setupInteractive setup wizard for CLI configuration and app registration
m365 requestExecute raw HTTP requests against any Microsoft API
m365 searchQuery Microsoft 365 data via Microsoft Search
m365 versionShow CLI version
m365 docsGet docs URL
CLI Management Commands
CommandPurpose
m365 cli config setSet a CLI configuration option
m365 cli config getGet a CLI configuration option
m365 cli config listList all configuration options
m365 cli config resetReset a configuration option
m365 cli doctorDiagnostic information about the environment
m365 connection listList available connections
m365 connection useSwitch to a different connection

Authentication

First-Time Setup

The recommended approach for first-time users:

sh
m365 setup

This wizard creates a Microsoft Entra app registration with the necessary permissions and configures CLI settings.

Login Methods

Device code flow (default, interactive):

sh
m365 login --appId <app-id> --tenant <tenant-id>

Browser-based (most convenient for interactive use):

sh
m365 login --authType browser

Username and password (for automation without MFA):

sh
m365 login --authType password --userName user@contoso.com --password pass@word1

Certificate (app-only, for CI/CD):

sh
m365 login --authType certificate --certificateFile /path/to/cert.pfx --password 'certPassword'

Client secret (app-only, for CI/CD):

sh
m365 login --authType secret --secret topSeCr3t@007

Managed identity (Azure-hosted automation):

sh
m365 login --authType identity
Environment Variables

Instead of passing --appId and --tenant on every login, set:

  • CLIMICROSOFT365_ENTRAAPPID — Application (client) ID
  • CLIMICROSOFT365_TENANT — Directory (tenant) ID
Check Login Status
sh
m365 status
Multiple Connections
sh
m365 connection list
m365 connection use --name "Production"

Global Options

Every command supports these options:

OptionDescription
-o, --output [type]Output format: json (default), text, csv, md, none
--query [jmespath]JMESPath query to filter/transform output
--verboseVerbose logging
--debugDebug logging
-h, --help [section]Help: options, examples, remarks, permissions, response, full
Output Mode Guidelines
  • For scripting/piping: use --output json (default) — returns structured data
  • For human reading: use --output text — returns formatted tables/key-value pairs
  • For spreadsheets: use --output csv
  • For documentation: use --output md
  • For silent/no output: use --output none

When running commands in the terminal for the user, prefer --output json so you can parse and reason about results. When showing results to the user for readability, use --output text.

Filtering with JMESPath

Use --query to filter and transform JSON output:

sh
# Get only titles of all sites
m365 spo site list --query "[*].Title"

# Filter sites by title containing "Project"
m365 spo site list --query "[?contains(Title, 'Project')]"

# Select specific fields
m365 spo site list --query "[*].{Title: Title, Url: Url}"

# Combine filter and projection
m365 spo site list --query "[?contains(Title, 'Project')].{Title: Title, Url: Url}"

# Filter on nested properties
m365 flow environment list --query "[?properties.isDefault]"

JMESPath queries are case-sensitive. Common functions: contains(), starts_with(), ends_with(), length(), sort_by(), reverse().

Common Command Patterns

SharePoint Online
sh
# List all sites
m365 spo site list

# Get a specific site
m365 spo site get --url https://contoso.sharepoint.com/sites/project

# Create a site
m365 spo site add --type CommunicationSite --title "Project Site" --url https://contoso.sharepoint.com/sites/project

# List all lists in a site
m365 spo list list --webUrl https://contoso.sharepoint.com/sites/project

# Get list items
m365 spo listitem list --webUrl https://contoso.sharepoint.com/sites/project --listTitle "Documents"

# Add a list item
m365 spo listitem add --webUrl https://contoso.sharepoint.com/sites/project --listTitle "Tasks" --Title "New Task"

# Upload a file
m365 spo file add --webUrl https://contoso.sharepoint.com/sites/project --folder "Shared Documents" --path ./report.pdf

# Get a file
m365 spo file get --webUrl https://contoso.sharepoint.com/sites/project --url "/sites/project/Shared Documents/report.pdf"

# List files in a folder
m365 spo file list --webUrl https://contoso.sharepoint.com/sites/project --folder "Shared Documents"

# Modern page operations
m365 spo page add --name "NewPage" --webUrl https://contoso.sharepoint.com/sites/project
m365 spo page list --webUrl https://contoso.sharepoint.com/sites/project
m365 spo page set --name "NewPage" --webUrl https://contoso.sharepoint.com/sites/project --publish

# Set the root SharePoint URL for server-relative paths
m365 spo set --url https://contoso.sharepoint.com
Entra ID (Users, Groups, Apps)
sh
# List users
m365 entra user list

# Get a user
m365 entra user get --id user@contoso.com

# Create a user
m365 entra user add --displayName "John Doe" --userName john@contoso.com --password "P@ssw0rd!" --accountEnabled true

# List groups
m365 entra group list

# List M365 groups
m365 entra m365group list

# Get app registrations
m365 entra app list
m365 entra app get --appId <app-id>

# Manage app permissions
m365 entra app permission list --appObjectId <object-id>
m365 entra app permission add --appObjectId <object-id> --applicationPermissions "https://graph.microsoft.com/Sites.Read.All"
Microsoft Teams
sh
# List teams
m365 teams team list

# Get a team
m365 teams team get --id <team-id>

# List channels
m365 teams channel list --teamId <team-id>

# Send a message
m365 teams message send --teamId <team-id> --channelId <channel-id> --message "Hello!"

# List chat conversations
m365 teams chat list

# Send a chat message
m365 teams chat message send --chatId <chat-id> --message "Hi there"

# Create a meeting
m365 teams meeting add --subject "Sprint Review" --startTime "2025-01-15T10:00:00Z" --endTime "2025-01-15T11:00:00Z"
Power Platform
sh
# List Power Apps
m365 pa app list

# List Power Automate flows
m365 flow list --environmentName <env-name>

# List Power Platform environments
m365 pp environment list
Raw API Requests

The request command lets you call any Microsoft API directly:

sh
# GET request to Graph
m365 request --url "https://graph.microsoft.com/v1.0/me"

# Use URL tokens for shorter URLs
m365 request --url "@graph/me"
m365 request --url "@graphbeta/me/profile"
m365 request --url "@spo/_api/web"

# POST with a body
m365 request --url "@graph/me/messages" --method post --body '{"subject":"Test","body":{"content":"Hello"}}'

# Load body from file
m365 request --url "@graph/teams" --method post --body @team-payload.json

# Specify custom headers
m365 request --url "@spo/_api/web/lists" --method post --body @list.json --content-type "application/json;odata=verbose"

URL tokens:

  • @graph → https://graph.microsoft.com/v1.0
  • @graphbeta → https://graph.microsoft.com/beta
  • @spo → Current SharePoint URL (set via m365 spo set)

Important Syntax Rules

Values with spaces → wrap in quotes
sh
m365 spo site add --alias mycoolsite --title "My Cool Site"
Values starting with a dash → use =
sh
m365 planner task get --id=-9rMKQooUjZdxgv1qQVZYABEuw
Empty values → use =
sh
m365 spo contenttype set --description=""
Show full SKILL.md (406 more words)Show less
Complex JSON content → use @ file reference
sh
m365 spo sitescript add --title "Contoso" --content @script.json

The @ prefix works with any option — CLI loads the file contents automatically.

Boolean values

Accepted true values: 1, yes, true, on Accepted false values: 0, no, false, off In PowerShell you can also use $true / $false.

Server-relative SharePoint URLs

After running any spo command or m365 spo set --url https://contoso.sharepoint.com, you can use server-relative URLs:

sh
m365 spo site get --url /sites/contoso

Context Feature

Save frequently used option values so you don't have to type them every time:

sh
# Initialize context in current directory
m365 context init

# Set reusable option values
m365 context option set --name "webUrl" --value "https://contoso.sharepoint.com/sites/project"
m365 context option set --name "listTitle" --value "Tasks"

# Now commands pick up context values automatically
m365 spo listitem list
# Equivalent to: m365 spo listitem list --webUrl "..." --listTitle "Tasks"

Context is stored in .m365rc.json in the working directory. Options explicit in the command override context values.

CLI Configuration

Configure with m365 cli config set --key <key> --value <value>:

KeyDescriptionDefault
outputDefault output formatjson
showHelpOnFailureShow help on command failurefalse
promptEnable interactive promptsfalse
autoOpenLinksInBrowserAuto-open browser linksfalse
copyDeviceCodeToClipboardCopy device code to clipboardfalse
printErrorsAsPlainTextErrors as plain text vs JSONfalse
errorOutputWhere to send errors: stderr or stdoutstderr
helpModeHelp detail level: options or fulloptions

Quick setup for interactive use:

sh
m365 setup --interactive

Quick setup for scripting:

sh
m365 setup --scripting

Getting Help

sh
# List all commands in a workload
m365 help spo

# Get options for a command
m365 spo site list --help

# Get full help with examples
m365 spo site list --help full

# Get only examples
m365 spo site list --help examples

# Check required permissions
m365 spo site list --help permissions

Shell-Specific Notes

PowerShell
  • Escape $ in URLs and JSON: use backtick ` before $

  • Consider setting errorOutput to stdout for easier error handling:

    powershell
      m365 cli config set --key errorOutput --value stdout
  • Use ConvertFrom-Json to parse JSON output:

    powershell
      $sites = m365 spo site list | ConvertFrom-Json
Bash/Zsh
  • Use jq for JSON processing:

    bash
      m365 spo site list | jq '.[].Title'

Best Practices When Running Commands

  1. Always check login status first with m365 status before running commands
  2. Use --output json when you need to process results programmatically
  3. Use --output text when displaying results to the user for readability
  4. Use --query to filter large result sets server-side instead of post-processing
  5. Use --output none for commands where you don't need to see output (e.g., delete operations)
  6. Use @ file references for complex JSON payloads instead of inline escaping
  7. Prefer named identifiers (e.g., --userName, --title) over GUIDs when both are accepted
  8. Check --help permissions if a command fails with 403 — it shows the required API permissions
  9. Use --debug to troubleshoot failing commands — it shows full HTTP requests/responses
  10. Never hardcode secrets in commands shown to users — use environment variables or prompt

Error Handling

  • If a command fails with permission errors, check m365 <command> --help permissions for required scopes
  • If authentication expires, run m365 login --ensure to re-authenticate only if needed
  • Use m365 cli doctor to diagnose environment issues
  • Docs are available at https://pnp.github.io/cli-microsoft365/

© pnp, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/cli-microsoft365 of pnp/cli-microsoft365-mcp-server.

Open the folder on GitHubat commit 6d89707

Compare with similar skills

CLI Microsoft365 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

CLI Microsoft365 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
CLI Microsoft365 this skillpnp/cli-microsoft365-mcp-server131—~3.5kAutomated safety check: PassMIT
Workiqmicrosoft/work-iq1k—~15kAutomated safety check: PassCustom licence
Msgraph Filesautomateyournetwork/netclaw674—~1kAutomated safety check: PassApache-2.0
Msgraph Visioautomateyournetwork/netclaw674—~1kAutomated safety check: PassApache-2.0
Add Workiqmicrosoft/power-platform-skills967—~5.6kAutomated safety check: NotesMIT
Spfx Releasepnp/docker-spfx134—~572Automated safety check: NotesMIT

Similar skills

  • Workiq

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~15k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Msgraph Files

    automateyournetwork/netclaw

    Read OneDrive and SharePoint files via the Microsoft 365 MCP server — list folder contents, fetch item metadata, inspect versions and sharing permissions.

    674 GitHub stars~1k tokensUpdated 2 days ago
    Documents & OfficeAuto-check passed
  • Msgraph Visio

    automateyournetwork/netclaw

    Upload and retrieve Visio (.vsdx) and other diagram files in OneDrive/SharePoint via the Microsoft 365 MCP server.

    674 GitHub stars~1k tokensUpdated 2 days ago
    Documents & OfficeAuto-check passed
  • Add Workiq

    microsoft/power-platform-skills

    Official

    Adds Work IQ (M365 Copilot Search) to a Power Apps code app via the Work IQ Copilot MCP connector (shareda365copilotchatmcp), then wires up a production-ready McpSession wrapper for AI-powered…

    967 GitHub stars~5.6k tokensUpdated yesterday
    Documents & OfficeAuto-check: notes
  • Spfx Release

    pnp/docker-spfx

    Automate SPFx version releases - branch, update files, commit, open PR, then tag after merge

    134 GitHub stars~572 tokensUpdated 3 mo ago
    Documents & OfficeAuto-check: notes
  • Entra Agent User

    github/awesome-copilot

    Official

    Create Agent Users in Microsoft Entra ID from Agent Identities, enabling AI agents to act as digital workers with user identity capabilities in Microsoft 365 and Azure environments.

    40k GitHub starsUsed in 1 repo~2.3k tokens
    Documents & OfficeAuto-check passed

More from pnp/cli-microsoft365-mcp-server

  • CLI Microsoft365 Script

    pnp/cli-microsoft365-mcp-server

    Write PowerShell scripts using CLI for Microsoft 365 commands to automate Microsoft 365 management tasks.

    131 GitHub stars~3.3k tokensUpdated 2 days ago
    Auto-check passed

Questions about CLI Microsoft365

What does CLI Microsoft365 do?

Use CLI for Microsoft 365 to manage Microsoft 365 tenants from the terminal. CLI Microsoft365 is an agent skill from pnp/cli-microsoft365-mcp-server. Use CLI for Microsoft 365 to manage Microsoft 365 tenants from the terminal.

When should I use CLI Microsoft365?

CLI Microsoft365 fits situations like: : running m365 commands; managing SharePoint Online; managing Entra ID; managing Teams teams/channels/chats.

How do I install CLI Microsoft365 in Claude Code?

Run `npx skills add pnp/cli-microsoft365-mcp-server --skill cli-microsoft365 -a claude-code`. Or copy the skill folder (.github/skills/cli-microsoft365 in pnp/cli-microsoft365-mcp-server) into .claude/skills/cli-microsoft365 in your project. Claude Code loads it when a task matches its description.

How do I install CLI Microsoft365 in Codex?

Run `npx skills add pnp/cli-microsoft365-mcp-server --skill cli-microsoft365 -a codex`. Or copy the skill folder (.github/skills/cli-microsoft365 in pnp/cli-microsoft365-mcp-server) into .agents/skills/cli-microsoft365 in your project. Codex loads it when a task matches its description.

Can I use CLI Microsoft365 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pnp/cli-microsoft365-mcp-server --skill cli-microsoft365 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cli-microsoft365, .gemini/skills/cli-microsoft365, .github/skills/cli-microsoft365 and .opencode/skills/cli-microsoft365 in your project.

What does CLI Microsoft365 need to run?

Going by SKILL.md and its folder, CLI Microsoft365 needs the command-line tools its instructions call (npm and jq). Our summary lists: Node.js.

Does CLI Microsoft365 access the network?

SKILL.md names 3 domains. In commands or code: contoso.sharepoint.com and graph.microsoft.com; the agent is likely to contact these when it follows the instructions. As links in the text: pnp.github.io. This is read from the text; nothing was executed.

Is CLI Microsoft365 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does CLI Microsoft365 use?

CLI Microsoft365 is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does CLI Microsoft365 use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to CLI Microsoft365?

Skills that share tags, products or a category with CLI Microsoft365: Workiq (microsoft/work-iq, 1k stars), Msgraph Files (automateyournetwork/netclaw, 674 stars), Msgraph Visio (automateyournetwork/netclaw, 674 stars) and Add Workiq (microsoft/power-platform-skills, 967 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains CLI Microsoft365?

pnp (a GitHub organization) maintains it in pnp/cli-microsoft365-mcp-server, which has 131 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 5, 2026.

Source: pnp/cli-microsoft365-mcp-server on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.