Observed October 3, 2026 with Claude Code 2.1.273, --permission-mode dontAsk.
My broad --allowedTools rule mcp__claude_ai_* failed to authorize first-party Microsoft 365 tools. Results listed denials for get_me, get_granted_scopes, outlook_email_search and search_people. The connector loaded, but those calls did not reach it. This was my invocation mistake, not proof of a connector outage or an E-Stack-recommended wildcard.
Fix that worked: retain the same session with --resume and explicitly allow exact tool names, e.g. mcp__claude_ai_Microsoft_365__get_me and mcp__claude_ai_Microsoft_365__outlook_email_search, plus read_resource and the necessary draft tools. Sonnet 5.5 medium then searched mail and created/re-read 21 drafts without sending.
Requested change: add first-party MCP discovery/approval example, inspect permission_denials before blaming connector availability, and document safe resume after denials. Never use blanket permission bypass as the default.
Source: https://code.claude.com/docs/en/cli-reference
Acceptance: first-party MCP recipe succeeds under dontAsk with explicit least-scope tool names.
Observed October 3, 2026 with Claude Code 2.1.273, --permission-mode dontAsk.
My broad --allowedTools rule mcp__claude_ai_* failed to authorize first-party Microsoft 365 tools. Results listed denials for get_me, get_granted_scopes, outlook_email_search and search_people. The connector loaded, but those calls did not reach it. This was my invocation mistake, not proof of a connector outage or an E-Stack-recommended wildcard.
Fix that worked: retain the same session with --resume and explicitly allow exact tool names, e.g. mcp__claude_ai_Microsoft_365__get_me and mcp__claude_ai_Microsoft_365__outlook_email_search, plus read_resource and the necessary draft tools. Sonnet 5.5 medium then searched mail and created/re-read 21 drafts without sending.
Requested change: add first-party MCP discovery/approval example, inspect permission_denials before blaming connector availability, and document safe resume after denials. Never use blanket permission bypass as the default.
Source: https://code.claude.com/docs/en/cli-reference
Acceptance: first-party MCP recipe succeeds under dontAsk with explicit least-scope tool names.