What this connection does

The Microsoft 365 connector lets EmDash synchronize the mailboxes you approve for ICES message analysis, Message Trace, and related security workflows. Mailbox access is scoped to the tenant and to the mailbox selection you save; it is not a directory-wide search of unrelated organizations.

Prerequisites

  • The ICES module must be entitled for the tenant.
  • A user with integrations:manage to configure the connection and mailbox scope. integrations:read is enough to view status.
  • A Microsoft 365 Global Administrator (or delegated administrator permitted to grant the requested application consent).
  • Your Microsoft tenant ID (GUID) or verified domain.
  • Permission review with your security team. Typical Graph permissions include Mail.Read, Mail.ReadBasic.All, User.Read.All, MailboxSettings.Read, and Organization.Read.All. SecurityEvents.Read.All supports email-posture checks, while Mail.ReadWrite is needed only for approved mailbox actions such as applying the EmDash category or moving a message to quarantine/release.

Configure Microsoft 365

  1. Open Settings → Integrations and select Microsoft 365.
  2. Enter the Tenant ID or domain for the Exchange Online organization you want to connect.
  3. Select Generate consent link. Have the Microsoft administrator open it, review the Graph permissions, and approve consent for the intended directory.
  4. Return to EmDash and wait for the callback and connection probe to complete. Use Test connection if the page asks for an additional check.
  5. Select Refresh mailbox inventory. Wait for discovery to finish; large tenants may take more than one polling cycle.
  6. Choose the mailbox scope: All approved mailboxes or Selected mailboxes. Search the inventory, select only the addresses your organization authorizes, and save the scope.
  7. Confirm the page shows the expected tenant, mailbox count, and recent sync health. Open Message Trace to verify that new mail is arriving after the first synchronization.

Scope, synchronization, and actions

Mailbox scope is an explicit control. Changing it affects future discovery and synchronization; it does not grant access to another tenant. EmDash uses Microsoft Graph delta synchronization and reports stale, retrying, or reauthorization states when the provider is unavailable. A delayed sync should be retried from the integration page rather than treated as an empty mailbox.

ICES can analyse metadata and, when separately authorized and available, inspect message bodies, attachments, screenshots, or AI-analysis context. Mailbox mutation actions require the relevant permission and integration capability; viewing a message never implies permission to modify it.

Permissions and data boundaries

The Microsoft consent screen is the source of truth for the permissions requested in your environment. Mailbox-scoped access should be used wherever your Microsoft configuration supports it. EmDash keeps provider credentials server-side and does not return access tokens, message bodies, or Graph continuation URLs to the browser.

Troubleshooting

  • Consent succeeded but status is not connected: run Test connection and check that the administrator consented in the same tenant ID you entered.
  • No mailboxes found: refresh inventory, verify the account has Exchange Online mailboxes, and confirm the selected directory.
  • A mailbox is missing: check its discovery status and whether the saved scope is selected-mailbox mode.
  • Message Trace is stale: review the last sync status, retry time, and continuation state; a Graph outage may delay imports without deleting stored rows.
  • A mailbox action is unavailable: the action may require Mail.ReadWrite, a connected integration, a supported provider capability, and an eligible message outcome.
  • Access denied: ask a Tenant Global Admin to grant integrations:manage. See Roles and permissions.

For persistent provider failures, use support and include only the sanitized status and time shown in the portal.