Outlook (Microsoft 365) Connection
Overview
The Outlook (Microsoft 365) connection allows IB-X Agents to connect to Microsoft 365 mailboxes using Microsoft Entra ID application authentication and Microsoft Graph.
Use this connection with workflow activities that need to interact with Microsoft 365 email services.
The connection uses application credentials configured through Microsoft Entra ID and identifies the mailbox that IB-X should access.
Prerequisites
Before creating an Outlook (Microsoft 365) connection:
- Register an application in Microsoft Entra ID.
- Obtain the Client ID of the registered application.
- Obtain the Tenant ID associated with the Microsoft Entra ID tenant.
- Create a Client Secret for the registered application.
- Configure the Microsoft Graph permissions required by the intended email operations.
- Ensure that the application has the required access to the Microsoft 365 environment.
- Identify the Microsoft 365 mailbox that IB-X should access.
The registered application must have the Microsoft Graph permissions required by the email operations performed by the workflow.
Authentication
The Outlook (Microsoft 365) connection uses application credentials configured through Microsoft Entra ID.
IB-X uses the configured Client ID, Tenant ID, and Client Secret to authenticate with Microsoft 365 through Microsoft Graph.
The Email Address identifies the mailbox that IB-X should access using the authenticated application.
Connection Properties
Configure the following properties when creating an Outlook (Microsoft 365) connection.
| Property | Description |
|---|---|
| Name | Unique name used to identify the Outlook connection in IB-X. |
| Description | Optional description of the connection and its intended usage. |
| Client ID (Application ID) | Application (client) identifier of the registered Microsoft Entra ID application. |
| Tenant ID (Directory ID) | Directory (tenant) identifier of the Microsoft Entra ID tenant associated with the application. |
| Email Address | Email address of the Microsoft 365 mailbox that IB-X should access. |
| Client Secret | Client secret configured for the registered Microsoft Entra ID application. |
| Mail Folder | Mail folder that IB-X should use. The default value is Inbox. |
Client ID (Application ID)
Specify the Application (client) ID of the registered Microsoft Entra ID application.
The Client ID identifies the application that IB-X uses when authenticating with Microsoft 365.
You can obtain this value from the registered application's Overview page in Microsoft Entra ID.
Tenant ID (Directory ID)
Specify the Directory (tenant) ID of the Microsoft Entra ID tenant associated with the registered application.
The Tenant ID identifies the Microsoft 365 organization against which the application authenticates.
You can obtain this value from the registered application's Overview page in Microsoft Entra ID.
Email Address
Specify the email address of the Microsoft 365 mailbox that IB-X should access.
For example:
support@example.com
The configured Microsoft Entra ID application must have the required Microsoft Graph permissions to access the specified mailbox.
The Email Address identifies the mailbox that IB-X operates on. Authentication is performed using the configured Microsoft Entra ID application credentials.
Client Secret
Specify the client secret configured for the registered Microsoft Entra ID application.
IB-X uses the Client ID, Tenant ID, and Client Secret when authenticating with Microsoft 365.
The Client Secret is a sensitive credential.
Protect the Client Secret from unauthorized access and manage it according to your organization's credential-management and security policies.
Mail Folder
Specify the mail folder that IB-X should use when accessing the configured mailbox.
The default value is:
Inbox
Change this value when the workflow needs to operate on a different mail folder.
Ensure that the specified folder exists in the configured mailbox and is accessible using the permissions granted to the Microsoft Entra ID application.
Microsoft Graph Permissions
The registered Microsoft Entra ID application must have the Microsoft Graph permissions required by the email operations that IB-X will perform.
The required permissions depend on the workflow activities and operations that use the connection.
Grant only the Microsoft Graph permissions required by the intended IB-X email operations.
Changes to application permissions may require administrator consent within your Microsoft Entra ID environment.
Testing the Connection
After providing the required Outlook connection properties, click Test Connection to verify that IB-X can authenticate with Microsoft 365 and access the configured mailbox using the supplied configuration.
Connection or authentication issues can result from:
- An incorrect Client ID
- An incorrect Tenant ID
- An invalid or expired Client Secret
- An invalid Email Address
- An incorrect or inaccessible Mail Folder
- Missing Microsoft Graph permissions
- Missing administrator consent, where required
- Network connectivity problems
- Microsoft 365 authentication failures
A successful connection test confirms that IB-X can authenticate using the supplied application credentials and configuration. Individual mailbox operations can still depend on the Microsoft Graph permissions granted to the registered application.
Used By
The Outlook (Microsoft 365) connection can be used by IB-X workflow activities that interact with Microsoft 365 email services.
Depending on the workflow activity and configured permissions, operations can include:
- Reading emails
- Processing incoming messages
- Accessing email attachments
- Working with mail folders
- Sending emails
The available operations depend on the workflow activity and Microsoft Graph permissions granted to the configured application.
Security Considerations
When configuring an Outlook (Microsoft 365) connection:
- Protect the Client Secret from unauthorized access.
- Grant only the Microsoft Graph permissions required by the intended workflow operations.
- Ensure that the application has access only to the mailboxes required by your organization's integration.
- Restrict access to connection management based on organizational requirements.
- Rotate Client Secrets according to your organization's security policies.
- Review application permissions periodically and remove permissions that are no longer required.
- Follow your organization's Microsoft Entra ID application-management policies.
Additional Resources
For information about creating, editing, testing, cloning, deleting, and auditing connections, see Connections.