Browse
On this page

The Microsoft Entra ID page at a glance

One page holds the whole Microsoft connection: the app registrations created in your own Microsoft tenant, the mailboxes your help desk and billing send from, and the advanced cards you only open when something is wrong.

  1. What this connection is for

    Integrations, then Microsoft Entra ID. The line under the title names the work this connection does: client tenant Microsoft 365 sync, the help desk mailbox, and CyberSentry ingest.

  2. MSP Runtime App

    The app registration that reads and manages your own Microsoft tenant. Its row shows the App (client) ID, which permission set it is on with an Up to date or Update available badge, and how many days its secret has left.

  3. Client Access App

    The narrower app your clients grant consent to, with the same three facts plus Consented client tenants, the count of client tenants already on it.

  4. Clients still on the old app

    An amber note counting client tenants that are still syncing through the retired shared app. They keep working, and each one moves across when that client re-consents.

  5. Tenant, and the last two checks

    Which Microsoft tenant is connected, when a token was last minted and tested, and when the permissions were last checked. The tenant shows its directory id when it has no display name.

Mail Connections: the mailboxes your portal sends from

  1. Mailbox to connect

    Type the mailbox you want to connect, for example [email protected], then press Authorize a Mailbox. Leave the field blank to connect whichever mailbox you sign in as. The note between the two says what happens on Microsoft's own sign-in screen next.

  2. Help Desk, Billing and Training

    The three mail functions. Each one shows Ready or Held, the mailbox it currently uses, a picker to point it at any authorized mailbox, and a switch to turn that function's mail on or off. Held means no mailbox is connected yet, and that function's mail waits.

  3. Authorized mailboxes

    Every mailbox authorized here, with Connected, Pending or Error, and via the account that signed in to authorize it when that account is not the mailbox itself. Send test email sends a real message from that mailbox, which is the only proof that sending works.

The advanced tail, closed until you need it

  1. Sync health

    The scheduled background jobs this integration owns, with their last run, next run and recent failures. Open it when a client's Microsoft data looks stale.

  2. Legacy credentials

    The Client ID, Client Secret and Tenant ID of the retired shared app. This card only appears while those values still exist, and it goes away once every client has moved to your own Client Access app.

  3. Connection Test

    Test legacy credentials checks those retired values alone. The check for your own apps is Test Graph connection, in the menu on the Microsoft apps card at the top of the page.

  4. Danger Zone

    Disable Microsoft Integration stops sync and mail while keeping every credential. Start Over forgets this portal's record of your app registrations so setup shows again, and asks you to type START OVER first. Neither one deletes anything in your Microsoft tenant.

  5. What we access & why

    Every Microsoft Graph permission the two apps request, grouped by app, each with a plain sentence about what it is for.

Why it works this way

A connected page is a quiet page. Before anything is connected this page opens with Connect Microsoft as Admin instead, and after that sign-in it offers Run Azure App Creation, which creates the MSP Runtime, Client Access and Mail Auth registrations in your own Microsoft tenant in one pass.

Client tenants are not granted here. Once the apps exist, each Microsoft client's own Overview page carries a Link & Consent banner, and a Global Administrator on that client's tenant approves it there.

The menu on the Microsoft apps card holds Test Graph connection, Rotate Credentials and Generate PowerShell script. Update Graph Permissions joins them only when a newer permission set is available, which is why it is absent while both apps read Up to date.

Full Access and Send As are two different Microsoft permissions. Full Access lets the portal read a mailbox, and that is all the Authorize step can prove. Sending needs Send As or Send on Behalf, granted separately, which is why a mailbox can read Connected and still not send.

To connect a shared mailbox such as helpdesk@ or billing@, sign in with a real account that has been granted Full Access to it. In the Microsoft 365 admin center go to Recipients, then Mailboxes, open that mailbox, and add the signing-in account under Manage mailbox delegation. The classic Exchange admin center calls the same screen Mailbox delegation. Grant Send As or Send on Behalf there as well if that mailbox has to send, and give Microsoft a few minutes to apply a new grant before you retry Authorize.

Mailbox sign-in is not portal sign-in. This connection is the Microsoft data plane, and the page's own line under the title says sign-in only falls back through it.

Other ways to do this

Settings, Email, Mailbox & Sending

The same Help Desk, Billing and Training map, read-only, with a link back to this page.

When you only want to check which mailbox a function is using and do not intend to change anything.

Questions this page answers

How do I set up Microsoft 365 / Microsoft Entra ID?

Open the Microsoft Entra ID card. App creation (the MSP Runtime, Client Access, and Mail Auth apps) and mailbox delegation both live on that one page - connect as an admin, then run app creation; the Mail Connections card right below lets you authorize mailboxes for Help Desk / Billing / Training once the apps exist. Each client tenant's M365 access is then granted per client from their Overview page.

How do I connect a mailbox on this page?

Type the address you want to connect, for example [email protected] or [email protected], into the mailbox field and click Authorize a Mailbox. Microsoft's sign-in screen opens next: sign in with that exact account to connect it directly, or sign in with a different account that has delegate access to it (see "How do I grant delegate access") to connect a shared mailbox that has no interactive sign-in of its own. Leave the field blank to connect whichever mailbox you sign in as. Once connected, assign the mailbox to a function, Help Desk, Billing, or Training, in the list below.

How do I grant delegate access to a shared mailbox (e.g. helpdesk@ or billing@) in Microsoft 365?

Shared mailboxes like helpdesk@ or billing@ usually can't sign in interactively, so a real user account signs in on their behalf and needs permission first. In the Microsoft 365 admin center, go to Recipients > Mailboxes, open the shared mailbox, and under "Manage mailbox delegation" add the signing-in account with Full Access, required, it lets the portal read the mailbox. If you also want the portal to send from it, separately grant Send As or Send on Behalf, a different permission from Full Access. In the classic Exchange admin center this is Recipients > Mailboxes > (the mailbox) > Mailbox delegation. Grants can take a few minutes to apply before the portal's Authorize step will succeed.

Was this helpful?

Last validated 2026-09-18