Skip to main content

Connect Microsoft 365 to Cue

Integrate Fountain's Cue AI assistant with Microsoft 365 to search, read, and manage Outlook, Teams, and SharePoint content through user-level permissions.

Cue is Fountain's AI assistant. The Microsoft 365 connector lets Cue read from and act in your Microsoft 365 environment: Outlook mail and calendar, Teams messages, and SharePoint and OneDrive files. One connector covers all of these.

Important: One-time Admin Setup Required

Microsoft 365 requires one-time setup by a Microsoft administrator before individual users can connect. This is a Microsoft requirement, not a Fountain one, the permission Cue uses has to be approved once at the organization level.

Feature Availability

This is currently a limited feature. Please contact your Fountain representative for more information.


Microsoft Administrator Setup

These steps are completed once by your Microsoft Global Administrator, or by a user with the Entra AI Administrator role.

Step 1: Enable Your Organization for Work IQ

Microsoft 365 access runs through Microsoft's Work IQ service. Enabling it requires a Copilot Credits usage-based billing plan in your tenant. This is an organization-level cost, not a per-user license.

Step 2: Approve Org-Wide Access

When someone selects org-wide access on the Microsoft 365 connector card in Cue, a confirmation window explains that your organization's Microsoft admin needs to approve access once, for everyone.

  • If you are the Microsoft admin: select Approve now. You are taken to Microsoft's own screen to review and approve. This happens on Microsoft's side, so nothing else needs to be set up in Fountain first.

  • If you are not the admin: select Copy admin consent link and send it to whoever manages Microsoft 365 at your company. They open it and approve on Microsoft's side. They do not need a Fountain account to do this.

What Org-Wide Access Actually Grants

Approving unlocks the ability for your organization to connect. It does not connect anyone automatically, and it does not give Cue a pooled view of everyone's data. Each person still connects their own account, and Cue only ever sees what that individual person can see.

Step 3: Enable Write Actions

Complete this step only if you want Cue to send and create on your users' behalf.

In the Microsoft 365 admin center, go to AgentsToolsWork IQ MCPPolicyMutations and turn on Allow write actions. Microsoft blocks all write actions by default, so without this step Cue can read but cannot send email, create calendar events, or send Teams messages. Delete is a separate toggle that can be left off.

Understand What You're Approving

When the admin selects Approve now, Microsoft shows its own permissions screen for Fountain Cue, published by OnboardIQ (Fountain's registered company) with a verified publisher badge. It lists four permissions.

What Microsoft shows

What it means in plain terms

Maintain access to data you have given it access to

Lets Cue keep working without making you sign in again every hour

Sign in and read user profile

Confirms who you are when you connect

Ask Work IQ agents on behalf of the user

The actual access to your Microsoft 365 data — mail, calendar, Teams, files — acting as you

Have full access to files you have access to

Lets Cue save a file from a Cue conversation into your OneDrive or SharePoint, and read a file's contents back into a conversation. Like everything else here, it is scoped to your files — it reaches nothing you couldn't already open yourself.

The last permission is worded broadly by Microsoft, so it tends to draw the most attention on the approval screen. It is the standard Microsoft permission for working with files on a person's behalf, and Cue uses it only for the two file actions described below.

What Work IQ Is

Work IQ is Microsoft's own service that provides one secure doorway into all of Microsoft 365. Fountain's connector asks Microsoft for a single permission to use it on your behalf, rather than a separate permission for mail, calendar, Teams, and so on. That is why the list stays short even though Cue can do a lot: Microsoft governs what Cue can actually do through its own admin policy (Step 3), not through a long list of consent items. The files permission sits outside Work IQ because saving and reading file contents goes to Microsoft directly.

"On behalf of the user" is the important part. Cue always acts as the individual signed-in person and can only reach what that person could already open themselves. It is never company-wide access to everyone's mailbox or files.


Connect Your Account

Each user connects their own account.

  1. In Fountain, open Cue in the left navigation and select Skills & Connectors.

  2. In the Connectors (MCP) section, find Microsoft 365 and select Connect.

  3. Sign in through Microsoft and approve.

No individual Microsoft 365 Copilot license is required. Cue can only ever access what your own Microsoft 365 permissions already allow.


What Cue Can Do

Once you are connected, Cue can read the following.

  • Search and read Outlook mail

  • Read your calendar

  • Read Teams chat and channel messages

  • Search SharePoint and OneDrive files

  • Read meeting transcripts

File actions are also available once you are connected, and do not depend on the mutation policy.

  • Save a file from a Cue conversation to your OneDrive or a SharePoint library

  • Read a OneDrive or SharePoint file's contents into a Cue conversation

Saving always creates a file. If the name is already taken, Microsoft saves it under a slightly different name and Cue tells you which name it used — it never overwrites a file you already have.

Write actions become available once your admin has enabled the mutation policy described in Part A, Step 3.

  • Send email from Outlook

  • Create and update calendar events

  • Send Teams messages

Ask Cue in plain language. For example:

  • "What's on my calendar this week?"

  • "Search my email for the offer letter from [name]."

  • "Send [name] a Teams message letting them know the interview is confirmed."


Privacy and Control

  • You only expose what you can already see. Cue acts as you, so it never reaches data your Microsoft 365 account can't. Microsoft's sensitivity labels and compliance policies still apply.

  • You sign in through Microsoft. Fountain never sees your password.

  • Write actions are governed at the organization level. Your admin controls whether Cue can send and create, through the Microsoft admin policy, independent of the connector itself.


Troubleshoot Common Issues

Cue can read my mail and calendar but can't send anything

Your admin has not enabled write actions. Ask them to turn on the mutation policy described in Part A, Step 3. Changes can take up to 24 hours to take effect.

File Saving Is Not Affected

Saving files does not depend on the mutation policy. It is covered by the org-wide approval in Part A, Step 2 instead.

I don't see Microsoft 365 in Cue, or connecting fails

Your admin may not have approved org-wide access yet. See Part A, Step 2. Individual users cannot self-approve.

Did this answer your question?