# get-drive-delta

Track changes in a driveItem and its children over time. Your app begins by calling delta without any parameters. The service starts enumerating the drive's hierarchy, returning pages of items and either an @odata.nextLink or an @odata.deltaLink, as described below. Your app should continue calling with the @odata.nextLink until you no longer see an @odata.nextLink returned, or you see a response with an empty set of changes. After you have finished receiving all the changes, you may apply them to your local state. To check for changes in the future, call delta again with the @odata.deltaLink from the previous response. Deleted items are returned with the deleted facet. Items with this property set should be removed from your local state. 💡 TIP: Tracks changes to a driveItem and its children over time. Returns a collection of driveItems that have been created, modified, or deleted. Use get-drive-root-item first to get the root driveItem-id, then pass it here. Supports $select and delta tokens for incremental sync via @odata.deltaLink.

Agent View of the PolicyLayer registry record for `get-drive-delta`. HTML page: https://policylayer.com/tools/jo3zik-ms-365-mcp-server/get-drive-delta

## Facts

- Tool: `get-drive-delta`
- Server: Ms 365 (`@jo3zik/ms-365-mcp-server`) — https://policylayer.com/tools/jo3zik-ms-365-mcp-server.md
- Install: `npx -y @jo3zik/ms-365-mcp-server`
- Homepage: https://www.npmjs.com/package/@jo3zik/ms-365-mcp-server
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 12 (2 required)
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `top` | number | no | Page size (Graph $top). Start small (e.g. 5–15) so responses fit the model context; raise only if needed. Use $select to return fewer fields per item. For more |
| `skip` | number | no | Items to skip for pagination. Not supported with $search. |
| `count` | boolean | no | Set true to enable advanced query mode (ConsistencyLevel: eventual). Required for complex $filter on flag/flagStatus or contains(). |
| `expand` | array | no | Navigation properties to inline, e.g. attachments on a message or event. Only navigation properties can be expanded: expanding a non-navigation property such as |
| `filter` | string | no | OData filter expression. Add $count=true for advanced filters (flag/flagStatus, contains()). Cannot combine with $search. |
| `search` | string | no | KQL search query — wrap value in double quotes. Cannot combine with $filter. |
| `select` | string | no | Comma-separated fields to return, e.g. id,subject,from,receivedDateTime |
| `driveId` | string | yes | Value for the 'driveId' path segment. Pass it under the name 'driveId', not as 'id'. Use the 'id' field of the drive object as returned by Microsoft Graph. |
| `orderby` | string | no | Sort expression, e.g. receivedDateTime desc |
| `driveItemId` | string | yes | Value for the 'driveItemId' path segment. Pass it under the name 'driveItemId', not as 'id'. Use the 'id' field of the drive item object as returned by Microsof |
| `fetchAllPages` | boolean | no | Follow @odata.nextLink and merge up to 100 pages into one response. Can return enormous payloads—only when the user explicitly needs a full export. Prefer a sma |
| `includeHeaders` | boolean | no | Include response headers (including ETag) in the response metadata |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get-drive-delta",
    "arguments": {
      "driveId": "<driveId>",
      "driveItemId": "<driveItemId>"
    }
  }
}
```

## Why get-drive-delta is rated Low

Even though get-drive-delta only reads data, uncontrolled read access leaks sensitive information and racks up API costs: an agent caught in a retry loop can make thousands of calls a minute without anyone noticing.

Risk signals: High parameter count (13 properties) · Admin/system-level operation

## Use case

AI agents call get-drive-delta to retrieve information from Ms 365 without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Ms 365:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "get-drive-delta": {}
  }
}
```

## Other tools on Ms 365 (193)

- `cancel-calendar-event` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/cancel-calendar-event.md
- `clear-excel-range` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/clear-excel-range.md
- `delete-calendar` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-calendar.md
- `delete-calendar-event` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-calendar-event.md
- `delete-contact-folder` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-contact-folder.md
- `delete-drive-item-permission` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-drive-item-permission.md
- `delete-excel-range` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-excel-range.md
- `delete-excel-table-row` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-excel-table-row.md
- `delete-focused-inbox-override` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-focused-inbox-override.md
- `delete-mail-attachment` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-mail-attachment.md
- `delete-mail-folder` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-mail-folder.md
- `delete-mail-message` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-mail-message.md
- `delete-mail-rule` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-mail-rule.md
- `delete-my-calendar-permission` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-my-calendar-permission.md
- `delete-onedrive-file` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-onedrive-file.md
- `delete-onenote-page` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-onenote-page.md
- `delete-outlook-contact` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-outlook-contact.md
- `delete-planner-bucket` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-planner-bucket.md
- `delete-planner-task-message` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-planner-task-message.md
- `delete-specific-calendar-event` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-specific-calendar-event.md
- `delete-subscription` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-subscription.md
- `delete-todo-linked-resource` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-todo-linked-resource.md
- `delete-todo-task` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-todo-task.md
- `delete-todo-task-list` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/delete-todo-task-list.md
- `graph-batch` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/graph-batch.md
- `logout` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/logout.md
- `remove-account` — Destructive — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/remove-account.md
- `parse-teams-url` — Execute — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/parse-teams-url.md
- `tentatively-accept-calendar-event` — Execute — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/tentatively-accept-calendar-event.md
- `dismiss-calendar-event-reminder` — Read — https://policylayer.com/tools/jo3zik-ms-365-mcp-server/dismiss-calendar-event-reminder.md
- …and 163 more: https://policylayer.com/tools/jo3zik-ms-365-mcp-server.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=jo3zik-ms-365-mcp-server · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/jo3zik-ms-365-mcp-server
