# forward-calendar-event

This action allows the organizer or attendee of a meeting event to forward the meeting request to a new recipient. If the meeting event is forwarded from an attendee's Microsoft 365 mailbox to another recipient, this action also sends a message to notify the organizer of the forwarding, and adds the recipient to the organizer's copy of the meeting event. This convenience is not available when forwarding from an Outlook.com account. 💡 TIP: Forwards a meeting invitation to additional recipients. Body: { ToRecipients: [{ emailAddress: { address, name } }], Comment (optional) }. If the forwarder is an attendee (not organizer), the organizer is also notified and the new recipient is added to the organizer's attendee list.

Agent View of the PolicyLayer registry record for `forward-calendar-event`. HTML page: https://policylayer.com/tools/jo3zik-ms-365-mcp-server/forward-calendar-event

## Facts

- Tool: `forward-calendar-event`
- Server: Ms 365 (`@jo3zik/ms-365-mcp-server`) — https://policylayer.com/tools/jo3zik-ms-365-mcp-server.md
- Install: `npx -y @jo3zik/ms-365-mcp-server`
- Homepage: https://www.npmjs.com/package/@jo3zik/ms-365-mcp-server
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 5 (2 required)
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `body` | object | yes |  |
| `confirm` | boolean | no | For destructive operations when the confirm gate is enabled (MS365_MCP_REQUIRE_CONFIRM=true; off by default). Set to true only after the user has explicitly app |
| `eventId` | string | yes | Value for the 'eventId' path segment. Pass it under the name 'eventId', not as 'id'. Use the 'id' field of the event object as returned by Microsoft Graph. |
| `includeHeaders` | boolean | no | Include response headers (including ETag) in the response metadata |
| `excludeResponse` | boolean | no | Exclude the full response body and only return success or failure indication |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "forward-calendar-event",
    "arguments": {
      "body": {},
      "eventId": "<eventId>"
    }
  }
}
```

## Why forward-calendar-event is rated Low

Even though forward-calendar-event only reads data, uncontrolled read access leaks sensitive information and racks up API costs: an agent caught in a retry loop can make thousands of calls a minute without anyone noticing.

Risk signals: Accepts raw HTML/template content (body) · High parameter count (10 properties)

## Use case

AI agents call forward-calendar-event to retrieve information from Ms 365 without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Ms 365:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "forward-calendar-event": {}
  }
}
```

## Other tools on Ms 365 (193)

- `cancel-calendar-event` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/cancel-calendar-event.md
- `clear-excel-range` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/clear-excel-range.md
- `delete-calendar` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-calendar.md
- `delete-calendar-event` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-calendar-event.md
- `delete-contact-folder` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-contact-folder.md
- `delete-drive-item-permission` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-drive-item-permission.md
- `delete-excel-range` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-excel-range.md
- `delete-excel-table-row` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-excel-table-row.md
- `delete-focused-inbox-override` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-focused-inbox-override.md
- `delete-mail-attachment` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-mail-attachment.md
- `delete-mail-folder` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-mail-folder.md
- `delete-mail-message` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-mail-message.md
- `delete-mail-rule` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-mail-rule.md
- `delete-my-calendar-permission` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-my-calendar-permission.md
- `delete-onedrive-file` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-onedrive-file.md
- `delete-onenote-page` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-onenote-page.md
- `delete-outlook-contact` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-outlook-contact.md
- `delete-planner-bucket` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-planner-bucket.md
- `delete-planner-task-message` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-planner-task-message.md
- `delete-specific-calendar-event` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-specific-calendar-event.md
- `delete-subscription` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-subscription.md
- `delete-todo-linked-resource` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-todo-linked-resource.md
- `delete-todo-task` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-todo-task.md
- `delete-todo-task-list` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-todo-task-list.md
- `graph-batch` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/graph-batch.md
- `logout` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/logout.md
- `remove-account` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/remove-account.md
- `parse-teams-url` — Execute — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/parse-teams-url.md
- `tentatively-accept-calendar-event` — Execute — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/tentatively-accept-calendar-event.md
- `dismiss-calendar-event-reminder` — Read — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/dismiss-calendar-event-reminder.md
- …and 163 more: https://policylayer.com/tools/jo3zik-ms-365-mcp-server.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=jo3zik-ms-365-mcp-server · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/jo3zik-ms-365-mcp-server
