{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-guides/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition"]},"type":"markdown"},"seo":{"title":"Exchange Online Email Security Configuration Guide","siteUrl":"https://docs.synqly.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This guide walks you through creating the configuration needed to access Exchange Online ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://learn.microsoft.com/en-us/graph/api/resources/exchangemessagetrace?view=graph-rest-1.0"},"children":["message traces"]}," using the Exchange Online Email Security integration."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"1-create-an-application","__idx":0},"children":["1. Create an application"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://portal.azure.com"},"children":["Azure portal"]},", navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["App registrations"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+ New registration"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Configure a name for the registration, for example \"Exchange Online Integration\"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Configure ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Supported account types"]}," as needed for your tenant."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Register"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["On the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Overview"]}," page for your new app registration, note down the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Application (client) ID"]}," and the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Directory (tenant) ID"]},". You will need these values later."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"2-configure-permissions-for-the-application","__idx":1},"children":["2. Configure permissions for the application"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Within the app registration you created in the previous step, navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Manage → API permissions"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+ Add a permission"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Request API permissions"]}," dialog, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Microsoft Graph → Application permissions"]},". Locate the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["ExchangeMessageTrace.Read.All"]}," permission, check the box next to it, then select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add permissions"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Grant admin consent for {your tenant name}"]},". Follow the dialog that appears to finish granting admin consent."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Configured permissions"]}," table, find ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Microsoft Graph → ExchangeMessageTrace.Read"]},". Verify that the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Type"]}," column reads ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Application"]},", and that the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Status"]}," column reads ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["✅ Granted for {your tenant name}"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"3-create-an-application-client-secret","__idx":2},"children":["3. Create an application client secret"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Within the app registration you created in the previous step, navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Manage → Certificates & secrets"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Navigate to the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client secrets"]}," tab."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+ New client secret"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add a client secret"]}," dialog that appears, enter a description and expiration appropriate for your tenant, then select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Find your new secret in the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client secrets"]}," table. Note down the secret value from the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Value"]}," column. Store this in a safe place."]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The secret value will not be shown again after you leave this page. Make sure you record it in a secure location."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"4-configure-the-integration","__idx":3},"children":["4. Configure the integration"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Create your integration by supplying the following configuration values:"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client ID"]},": use the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Application (client) ID"]}," gathered in step 1."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Tenant ID"]},": use the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Directory (tenant) ID"]}," gathered in step 1."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client Secret"]},": use the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client secrets → Value"]}," gathered in step 3."]}]},"headings":[{"value":"1. Create an application","id":"1-create-an-application","depth":2},{"value":"2. Configure permissions for the application","id":"2-configure-permissions-for-the-application","depth":2},{"value":"3. Create an application client secret","id":"3-create-an-application-client-secret","depth":2},{"value":"4. Configure the integration","id":"4-configure-the-integration","depth":2}],"frontmatter":{"slug":"guides/provider-configuration/exchange-online-setup","seo":{"title":"Exchange Online Email Security Configuration Guide"}},"lastModified":"2026-07-10T19:05:17.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/guides/provider-configuration/exchange-online-setup","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}