Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | Microsoft 365 MCP ServerWatchlist candidate | Atlassian Remote MCPMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | Community implementation Softeria · Publisher source ↗ | First-party MCP Atlassian · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Aug 24, 2026 Package: Aug 24, 2026 | Repo: Not documented Package: Not documented |
| Popularity evidence | ||
| GitHub stars | 958 GitHub stars · checked 2026-09-08 | Not documented |
| Package downloads / 30 days | 173,619 package downloads / 30 days · checked 2026-09-08 | No reliable download data |
| External adoption evidence |
| Not documented |
| Client coverage | ||
| Client coverage details | Not documented | Claude Code✓ Streamable HTTP Claude Desktop✓ Streamable HTTP Codex✓ Streamable HTTP VS Code✓ Streamable HTTP Cursor✓ Streamable HTTP OpenCode✓ Streamable HTTP |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | The documented options include Device Code Flow for local stdio, OAuth Authorization Code Flow for HTTP, a caller-supplied MS365_MCP_OAUTH_TOKEN, and a custom Microsoft Entra application for organization or production deployment. Use a dedicated identity, restrict consented Graph scopes, remove the MCP entry and local credentials when access is no longer needed, and revoke Microsoft authorization or tokens through the applicable account or Entra controls. | OAuth 2.1 browser authorization is the default and recommended method. Admin-enabled, scoped personal API tokens support headless use and are required for Jira Service Management and Bitbucket Cloud tools; Compass tools require OAuth. |
| Cost | The MIT-licensed npm package has no separate package purchase price documented. Access still depends on the Microsoft account, service access, licenses, tenant permissions, and admin consent required by the chosen workload; self-hosted HTTP deployments can also incur normal hosting, container, and secret-management costs. | The core connection has no separately stated MCP fee. Users need applicable Atlassian Cloud products and an AI client. Beta tools are currently free; Atlassian says some may later be billed in Rovo credits with notice, and Teamwork Graph calls are expected to consume credits at general availability. |
| Permissions | The MCP can read and write Microsoft Graph resources including email, calendar, OneDrive files, SharePoint Sites and Lists, Teams/chats/meetings, contacts, users, OneNote, Planner, To Do, and Excel. Organization-mode SharePoint can request broad Sites.Read.All, Sites.ReadWrite.All, and Sites.Manage.All scopes; use --allowed-scopes, --enabled-tools, --read-only, and Sites.Selected where the documented operation supports them. | Tools are grouped by product and read, write, or search intent. Organization admins grant or revoke permission groups, and calls also honor the connected user's Jira, Confluence, Jira Service Management, Bitbucket, Compass, project, space, IP-allowlist, and OAuth or API-token scopes. |
| Data handling | The local MCP handles Microsoft Graph request and response data. Documented local MSAL token caching is encrypted, while the headless fallback still depends on directory access controls. The HTTP deployment documents stateless per-request bearer-token Graph requests. Structured audit logging is enabled for Graph-reaching tool calls and can include principals, tool names, outcomes, resource identifiers, and recipient counts or domains; response bodies are not recorded by that structured log, and separate operational logging can record tool parameters. Token and PII redaction is documented as configurable rather than an absolute data-boundary guarantee. | The Atlassian-hosted server retrieves and returns authorized Atlassian Cloud content to the external MCP client. Teamwork Graph tools can aggregate relationships across Atlassian products and connected third-party apps and may use AI processing. Traffic uses HTTPS/TLS, and Atlassian records tool-use events in the organization audit log. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | This broad Microsoft Graph MCP can expose sensitive business email, files, SharePoint content, Teams/chats/meetings, contacts, and tenant information, and it includes material write and delete operations. Destructive-operation confirmation is documented as off by default; default organization-mode SharePoint permissions can be broad, and HTTP Dynamic Client Registration is enabled by default unless disabled. Use read-only mode, presets/tool filtering, allowed scopes, Sites.Selected when applicable, dedicated identities, and explicit review before enabling writes or tenant-wide discovery. GHSA-9w34-3f56-vwmh affected versions through 0.136.0; reviewed version 0.146.1 is above the documented 0.137.0 fixed version. This patched advisory is not a general security certification. | The integration can read and modify enterprise work and knowledge across several Atlassian products. Approve client domains, use least privilege, restrict permission groups and token scopes, retain write confirmation, review audit logs, and evaluate the external AI client's data policy. This review does not claim MCP100 execution testing. |
| Evidence date | ||
| Editorial review | 2026-08-24T12:00:00.000Z | 2026-09-05 |
| Candidate evidence | 2026-08-24T12:00:00.000Z | 2026-09-05T00:00:00.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →