Overview
The new Microsoft Mailbox Connector runs inside your own Azure tenant. The connector is installed in your Azure tenant, allowing Valimail Enforce to scan email header information in order to provide advanced reporting within the platform.
What's new compared with the Classic Microsoft 365 connector:
Multiple tenants per Valimail account. Connect every Microsoft 365 tenant you operate, each covering all of its inbound domains.
Faster mailbox scans.
Data stays in Azure, where it's also available to Microsoft Defender, Microsoft Sentinel, and other tools you run there.
Before you begin
Requirement | Details |
Microsoft 365 / Entra ID | A Global Administrator (or Privileged Role Administrator) to grant tenant-wide admin consent |
Azure subscription | An active subscription in the same tenant to host the connector. |
Azure tenant name | The domain part of the account you sign in to Azure with, e.g., valimail.com or valimail.onmicrosoft.com |
Valimail | A Valimail admin user (Owner type); available on Enforce. |
Budget approval | Sign-off from whoever owns your Azure spend (see cost callout above) |
Connect a Microsoft 365 tenant
In Valimail, go to Account Settings → Integrations and click Connect on the Microsoft 365 card.
Enter your Azure tenant name (for example, valimail.onmicrosoft.com). The connector is installed in this tenant.
Click CONNECT. You're redirected to Microsoft.
Sign in as a Global Administrator and review the requested permissions. Click Accept to grant admin consent.
You're returned to Valimail. The tenant appears in the connections list once consent is accepted and the connector is active.
(Optional) Add more tenants: open Microsoft 365 → Manage and click Add tenant, then repeat steps 2–5.
Manage connections: the Manage page lists each tenant with its latest activity. Click a tenant to see mailboxes scanned, who created it, and when. To remove a tenant, choose Delete.
Upgrading from Classic: tenants still on the Classic connector show a yellow warning icon. You can Add tenant and then delete the Classic connection.
Permissions, security and data residency
Admin consent: the connector is registered as an enterprise application in your Entra ID tenant. You can review or remove it any time under Entra ID → Enterprise applications.
Tenant scope: one Azure tenant can cover many inbound domains, so protection is per tenant, not per domain.
Troubleshooting and FAQ
Issue | What to do |
Microsoft error AADSTS700016 ("application was not found in the directory") | The tenant name doesn't match the account you signed in with, or consent wasn't granted. Check the tenant name and sign in as a Global Admin of that tenant. |
Tenant not listed after setup | Consent wasn't completed. Reconnect and click Accept on the Microsoft consent screen. |
"Tenant not found" in Valimail | Use the domain from your Azure sign-in (e.g. valimail.onmicrosoft.com), not a mailbox address. |
Latest activity is blank | New connections can take [X hours] to complete the first scan. |
Unexpected Azure charges | Review the connector's resource group in Azure Cost Management and set a budget alert. |
Do I have to move off Classic?
Not right away. Classic stays available; the new connector is required for multi-tenant support and upcoming reporting features.
Can I disconnect?
Yes, delete the tenant in Valimail and remove the Helios Connector from Azure → Entra ID → Enterprise Applications




