Critical-risk tools in SharePoint Online MCP Server
13 of the 56 tools in SharePoint Online MCP Server are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
batchDeleteListItemsDestructiveDelete multiple items from a SharePoint list using a single batch request
-
deleteListDestructiveDelete a SharePoint list or document library
-
deleteListContentTypeDestructiveDelete a content type from a SharePoint list
-
deleteListFieldDestructiveDelete a field (column) from a SharePoint list
-
deleteListItemDestructiveDelete an item from a SharePoint list
-
deleteListViewDestructiveDelete a view from a SharePoint list
-
deleteModernPageDestructiveDelete a modern page from SharePoint
-
deleteNavigationLinkDestructiveDelete a navigation link from a SharePoint site (global or quick navigation)
-
deleteSiteContentTypeDestructiveDelete a content type from a SharePoint site
-
deleteSubsiteDestructiveDelete a SharePoint subsite
-
removeAllViewFieldsDestructiveRemove all fields from a SharePoint list view
-
removeGroupMemberDestructiveRemove a user from a SharePoint group
-
removeViewFieldDestructiveRemove a field from a SharePoint list view
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.