Allow the Mobile Locker MCP server in Microsoft 365 Copilot
Private beta. The Mobile Locker MCP server is in private beta. Only a team that Mobile Locker has invited can connect. Email support@mobilelocker.com before you allow it for your users. Mobile Locker will send the server address when your team is in the beta.
Use this article if you are an IT administrator and you want Microsoft 365 Copilot users to look up Mobile Locker. Field users cannot add this server themselves.
Bring-your-own MCP in Microsoft 365 is a Microsoft preview. Mobile Locker has not completed a click-through of this product against our server. Follow Microsoft's current admin page if a label on your screen differs from this article.
Read Security of the Mobile Locker MCP server before you approve the server.
Who allows it
A Microsoft 365 administrator reviews the server in the Microsoft 365 admin center. Approval needs permission to grant tenant-wide consent. A field user cannot add the server.
What to allow
https://app.mobilelocker.comfor the Global region. Most teams use this host.https://eu.mobilelocker.comwhen the team uses the EU instance.- The team host your users already sign in on, when that host is different
- Sign-in paths under
/oauth/and/.well-known/oauth- - The MCP server address Mobile Locker sends for your beta
Most teams that connect also use Single Sign-On in Mobile Locker. Allow the hosts in Allow these hosts, including WorkOS and your identity provider. You do not set up a second SSO connection for this server.
Approve the server
- Sign in to the Microsoft 365 admin center.
- Open Agents, then Tools, then Requests.
- Open the Mobile Locker request. Confirm the server address matches the address Mobile Locker sent you.
- Approve the request.
Tenant-wide consent lets the organization use the server. It does not sign people in. Each person still approves with their own Mobile Locker account.
What each person does
After you approve the server, each person opens Copilot and connects with their own Mobile Locker account. When the email domain has an SSO connection, sign-in follows How SSO works.