HomeArticle

Elon Musk has stepped into Copilot's home turf, Grok Bot takes over Microsoft accounts, and it keeps working while you sleep.

新智元2026-09-08 10:38
Grok Bot can do your job for you now.

Grok Bot can now go to work on your behalf.

On September 1, Grok Bot quietly officially announced a piece of news that blew up the tech circle:

Grok Bot can now directly connect to your Microsoft account to perform reading, writing and execution actions. Through brand-new plugins, your AI assistant can directly connect to Outlook, Calendar and OneDrive.

A few hours later, Elon Musk reposted the announcement with only one line: Grok Bot has been upgraded.

There was no launch event, no demo video. But behind this post lies real, tangible changes:

Grok Bot, an AI employee that never clocks off, has officially obtained access to your email, calendar and cloud drive. It can send emails, reschedule meetings for you, and upload files to OneDrive.

The comment section quickly became lively.

Statements like "Copilot is panicking" and "Microsoft opened the door for Elon Musk" quickly went viral.

But if you check xAI's official documentation, you will find one fact: as early as May this year, the Outlook and OneDrive connectors had already appeared in Grok's documents.

That means Grok has been able to read and write Microsoft accounts for more than three months.

So what exactly is new in this update?

The answer lies in the word "Bot": the permissions have never changed, what has changed is the holder of the access key.

Three Plugins

What Exactly Can They Operate

First break down "reading, writing, executing" down to the action level, to see what the new plugins can actually do.

The Outlook email plugin has the most complete capabilities.

Searching for emails, reading the body and attachments are basic operations; it can also draft, send, reply to all with one click, and forward emails; it can even do organizing work like moving emails to other folders for you.

Files generated by Grok can also be directly added to drafts as attachments.

Among the permissions applied for in the background, the two most critical ones are Mail.ReadWrite and Mail.Send, plus offline_access, which means you don't need to log in repeatedly after authorizing once.

The calendar is a separate connector with separate authorization.

It can check events by date, find free time slots for multiple people, create and modify meetings with attendees and recurring rules, and even click accept, reject or tentative for you.

OneDrive's capabilities are more limited.

The official documentation lists three functions: browsing folders, reading documents, and uploading content generated by Grok. If you want to full-text search files in OneDrive, you need to connect an additional SharePoint connector.

Moreover, it is only open to Grok Business and Enterprise users, and personal accounts are not included in the official connection process.

So to be more precise: emails can be received, sent and organized, calendars can be created, modified and responded to, and cloud drives can be viewed and uploaded to.

Email and calendar give you a full key, while the cloud drive only gives you half of it.

Permissions Have Been Available Since May

This Time the Key Holder Is Grok Bot

Since the connectors were ready back in May, why did Elon Musk officially announce them only now?

In May, these connectors served the traditional chat scenarios.

When you ask a question in grok.com like "What did that email from the supplier last week say", it calls Outlook and reads the result to you.

After the conversation ends, the permissions stay unused.

On August 11, Grok Bot entered early testing, and its form is completely different.

It does not reside in a chat box, but in a permanent cloud computer, with its own browser, file system and terminal. It can log in to websites, save sessions, run tasks in parallel, and even keep running after you close your laptop.

This update is equivalent to making the batch of connectors from May into plugins on this cloud computer.

So the same set of permissions is used in a completely different way.

In the past you would say "Help me check my emails", but now it can read all your emails overnight by itself, judge which ones need to be replied to, finish the drafts and save them in the draft box, waiting for your confirmation in the morning.

The executor is no longer a chat box waiting for you to ask questions, but an employee that never clocks off.

Microsoft and Google

Different Openness Logics

In this wave of changes, Microsoft's role is the most subtle.

What Grok Bot accesses is exactly the core Microsoft 365 scenario of Copilot.

Just six days ago, Grok 4.6 was announced to be launched on Microsoft Foundry, hosted and sold by Azure.

Some people connected these two events and joked that Microsoft gave Elon Musk the green light.

But these two lines are completely independent technically.

Foundry is a place for enterprises to buy models, which has nothing to do with individual users.

The Outlook plugin follows the standard authorization process that Microsoft opens to all third parties, just like when you authorize any app to log in. The key is handed over by you clicking "Agree" yourself, not by Microsoft on your behalf.

Microsoft is not helping Grok to besiege its own products. This is just the price of platform openness: if you open your door to others, someone will always walk into your core territory.

In contrast, Google is much more cautious.

The Google Account help page clearly states that login will be blocked under the following circumstances:

The browser is "controlled by automated software instead of a real person", or "embedded in other applications". The browser running in Grok Bot's cloud computer exactly falls into this category.

Some users encountered a blocking prompt when trying to log in to Google in Grok Bot.

But this does not mean that Google has blocked Grok.

xAI's official documentation still lists the OAuth connectors for Gmail, Google Drive and Google Calendar.

Google blocks "Bots logging in like real people in a cloud browser", but allows "users to officially authorize via OAuth".

The two giants take two different paths:

Microsoft lets you open the door through standard authorization, while Google always checks whether a real person is knocking on the door.

Competition for Agents

Expands to Your Microsoft Account

Grok Bot is not the only one squeezing into these three entry points.

Microsoft's own Copilot already resides in Outlook, and the company also launched Autopilot "Scout" at the Build conference, which can stay in Outlook to monitor emails all the time, having the home advantage.

Anthropic's Microsoft 365 connector supports the full suite of functions, and can read SharePoint, OneDrive, Outlook and Teams.

But actions like sending emails, modifying calendars, and writing files require separate authorization from the tenant administrator, and only work accounts are supported, so personal @outlook.com mailboxes cannot connect.

The open-source OpenClaw takes the community route.

There are a large number of Microsoft Graph skills on ClawHub, the official Outlook skill has been downloaded more than 6,600 times, and the microsoft365 skill covering OneDrive has also got thousands of downloads. The trade-off is that users need to register applications on Azure by themselves and manage tokens on their own.

All three parties are trying to embed their agents into your Microsoft account.

The difference of Grok Bot this time is that it combines "permanent cloud computer" and "first-party plugins" together.

Elon Musk posted another update that day: "Grok Bot runs 24/7 on its own cloud computer, so whether your laptop is on or off doesn't affect it at all."

You don't need to configure Azure yourself, or keep your computer turned on. Just authorize once, and the Bot will run on the cloud on its own.

Although the boundary of delegated permissions is limited to personal accounts, your account contains all real work communications. Sending an email by mistake or deleting an important meeting will lead to real, tangible losses.

Fortunately, xAI has set approval points in the product.

In the official demo, a Bot called Inbox Manager finishes running in the middle of the night, and leaves you a message in the morning: "Inbox cleared, 5 drafts are waiting for your review."

Another Bot called Sales Outbound can better illustrate this point.

You give it a task: filter potential customers from Google Sheet, conduct online research, supplement information from Hex, Sumble and Salesforce, and draft emails and LinkedIn outreach sequences in your tone.

It runs all night and returns a list: 52 customer accounts, 3 similar customer groups, 4 people who have been contacted recently are automatically skipped, 36 drafts are queued, 0 emails have been sent.

You take a look and reply: "The first 10 drafts look good, send them out, and run this task once a week from now on." Then it sends the emails out, and saves this task as a weekly routine.

The final decision-making power always stays in your hands.

For ordinary people, when entering the agent era, four issues are more important than model benchmark scores:

Whether it asks for my confirmation before sending anything, whether I can check what it has done, whether I can revoke the permission with one click if I want to take back the key, and whether the mistakes it makes such as wrong sending or deletion can be recovered.

Email, calendar and cloud drive are the three most fundamental entry points for knowledge work.

Whoever gets the authorization first will occupy the default position in the workflow first.

And the "onboarding procedure" of the AI employee is hidden in that authorization button you click casually.

Before clicking, make sure you know exactly what you are handing over. The hype is all around, but you need to stay sober about this point.

References:

https://x.com/elonmusk/status/2094577304647164374

https://docs.x.ai/grok/connectors/outlook

https://x.com/bot/status/2094543253811183943

This article is from the WeChat official account "Xinzhiyuan", written by ASI Revelation, edited by Yuan Yu, and published with authorization from 36Kr.