Critical-risk tools in Ms 365
27 of the 194 tools in Ms 365 are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
cancel-calendar-eventDestructiveThis action allows the organizer of a meeting to send a cancellation message and cancel the event. The action moves the event to the Deleted Items folder. The organizer can als...
-
clear-excel-rangeDestructiveClear an Excel range. 💡 TIP: Clear cell contents and/or formatting on the given range. Body: { applyTo: 'All' | 'Formats' | 'Contents' }. 'Contents' wipes values but keeps for...
-
delete-calendarDestructiveDelete a calendar other than the default calendar. 💡 TIP: Deletes a calendar and all its events. The default calendar cannot be deleted. This action cannot be undone.
-
delete-calendar-eventDestructiveRemoves the specified event from the containing calendar. If the event is a meeting, deleting the event on the organizer's calendar sends a cancellation message to the meeting ...
-
delete-contact-folderDestructiveDelete contactFolder other than the default contactFolder. 💡 TIP: Deletes a contact folder. The default 'Contacts' folder cannot be deleted — Graph returns an error. The folde...
-
delete-drive-item-permissionDestructiveDelete a drive item permission. 💡 TIP: Removes a specific permission from a file or folder. Only permissions that are not inherited can be deleted. Use list-drive-item-permiss...
-
delete-excel-rangeDestructiveDelete an Excel range. 💡 TIP: Delete cells at the given range, shifting remaining content. Body: { shift: 'Up' } or { shift: 'Left' }. Use 'Up' to delete entire rows.
-
delete-excel-table-rowDestructiveDelete an Excel table row. 💡 TIP: Delete a single row from a formal Excel table by zero-based row index.
-
delete-focused-inbox-overrideDestructiveDelete an override specified by its ID. 💡 TIP: Deletes a Focused Inbox override. Future messages from that sender revert to the Outlook ML classifier's default behavior. Use l...
-
delete-mail-attachmentDestructiveDelete a mail attachment.
-
delete-mail-folderDestructiveDelete the specified mailFolder. The folder can be a mailSearchFolder. You can specify a mail folder by its folder ID, or by its well-known folder name, if one exists. 💡 TIP: ...
-
delete-mail-messageDestructiveDelete an Outlook email message by its message ID. This is a soft delete that moves the message to Deleted Items. 💡 TIP: Soft delete — moves to Deleted Items. To permanently d...
-
delete-mail-ruleDestructiveDelete the specified messageRule object. 💡 TIP: Deletes a message rule permanently. Use the Inbox folder ID (get it from list-mail-folders) for inbox rules.
-
delete-my-calendar-permissionDestructiveDelete my calendar permission. 💡 TIP: Revokes a calendar share or delegate access. Get the permission id via list-my-calendar-permissions. Permissions where isRemovable=false ...
-
delete-onedrive-fileDestructiveDelete a OneDrive file.
-
delete-onenote-pageDestructiveDelete a OneNote page. 💡 TIP: Deletes a OneNote page permanently. This cannot be undone.
-
delete-outlook-contactDestructiveDelete a contact.
-
delete-planner-bucketDestructiveDelete plannerBucket. 💡 TIP: CRITICAL: Requires If-Match header with ETag from get-planner-bucket (use includeHeaders=true).
-
delete-planner-task-messageDestructive[beta] Delete a plannerTaskChatMessage object. 💡 TIP: Deletes a message from a Planner task's chat. No request body; If-Match is optional if you want conditional deletion; ret...
-
delete-specific-calendar-eventDestructiveDelete a specific calendar event. 💡 TIP: Deleting a seriesMaster deletes ALL occurrences. To cancel a single occurrence, use the specific instance ID.
-
delete-subscriptionDestructiveDelete a subscription. For the list of resources that support subscribing to change notifications, see the table in the Permissions section. 💡 TIP: Deletes a webhook subscript...
-
delete-todo-linked-resourceDestructiveDelete a linkedResource object. 💡 TIP: Removes a linked resource from a To Do task.
-
delete-todo-taskDestructiveDelete a todoTask object.
-
delete-todo-task-listDestructiveDeletes a todoTaskList object. 💡 TIP: Deletes a Microsoft To Do task list. Built-in lists (Flagged emails, the default Tasks list) cannot be deleted — the API returns an error...
-
graph-batchDestructiveCombine up to 20 Graph requests into a single HTTP call. Body: { requests: [{ id: '1', method: 'GET'|'POST'|'PATCH'|'DELETE', url: '/me/messages?$top=5', headers?: {...}, body?:...
-
logoutDestructiveLog out from Microsoft account
-
remove-accountDestructiveRemove a Microsoft account from the cache. Accepts email address (e.g. user@outlook.com) or account ID. Use list-accounts to discover available accounts.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.