Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Problem

As of October 2022, Microsoft will completely deprecate basic authentication for mailbox access. Customers using one of these services MUST upgrade their version of GlobalCapture if any workflows import email from one of these sources. Customers will need to be on GlobalCapture 2.4.113 or greater to continue use of these services in conjunction with GlobalCapture.

Solution

Customers will need to upgrade to gain access to the supporting technology required to properly authenticate to Microsoft’s services. Once upgraded:

...

Note

To reiterate, you will need:

  • Client ID

  • Tenant ID

  • Client Secret

Note, you can only access the Client Secret value at the time of creation. You will not be able to access the value in the future without previously documenting it yourself.

Import Node Configuration

Customers implementing oAuth2 will need to ensure they are using the option for Exchange email import. The server address will resemble:

...

Info

The mail engine has changed in 2.4.113 to allow for oAuth2, which has also changed inbox import behavior. Now, Office365 emails that would have been moved to the deleted folder will instead be permanently deleted from your email inbox. To keep a record of these emails, it is recommended to create a second email address for GlobalCapture to import from and copy forward the emails to that address. The 1st email account should contain the originals, while the 2nd email account should contain copies which the workflow will delete.

Microsoft Resources

If you are looking to control access to specific mailboxes, speak to your admin about application specific policies. This article can also provide some context on access control.

The mailbox-level permission needed is Mail.ReadWrite, it needs to be set for each mailbox that GlobalCapture is going to import from. This is separate from the API level access mentioned above. If you want to limit the permissions to a subset of mailboxes, you follow the directions in the Microsoft article to create a new ApplicationAccessPolicy, with only Mail.ReadWrite permissions to the desired mailboxes. These specific steps cannot be performed by Square 9 support. If you run into issues please contact Microsoft support or your Azure / Office 365 admin.

Filter by label (Content by label)
showLabelsfalse
max5
spacescom.atlassian.confluence.content.render.xhtml.model.resource.identifiers.SpaceResourceIdentifier@4acc8e4
sortmodified
showSpacefalse
reversetrue
typepage
cqllabel = "kb-troubleshooting-article" and type = "page" and space = "S9SKB"
labelskb-troubleshooting-article