Skip to main content

Microsoft 365 Mailbox Connector

Overview

The new Microsoft Mailbox Connector runs inside your own Azure tenant. The connector is installed in your Azure tenant, allowing Valimail Enforce to scan email header information in order to provide advanced reporting within the platform.

What's new compared with the Classic Microsoft 365 connector:

  • Multiple tenants per Valimail account. Connect every Microsoft 365 tenant you operate, each covering all of its inbound domains.

  • Faster mailbox scans.

  • Data stays in Azure, where it's also available to Microsoft Defender, Microsoft Sentinel, and other tools you run there.

Before you begin

Requirement

Details

Microsoft 365 / Entra ID

A Global Administrator (or Privileged Role Administrator) to grant tenant-wide admin consent

Azure subscription

An active subscription in the same tenant to host the connector.

Azure tenant name

The domain part of the account you sign in to Azure with, e.g., valimail.com or valimail.onmicrosoft.com

Valimail

A Valimail admin user (Owner type); available on Enforce.

Budget approval

Sign-off from whoever owns your Azure spend (see cost callout above)

Connect a Microsoft 365 tenant

  1. In Valimail, go to Account Settings → Integrations and click Connect on the Microsoft 365 card.

  2. Enter your Azure tenant name (for example, valimail.onmicrosoft.com). The connector is installed in this tenant.

  3. Click CONNECT. You're redirected to Microsoft.

  4. Sign in as a Global Administrator and review the requested permissions. Click Accept to grant admin consent.

  5. You're returned to Valimail. The tenant appears in the connections list once consent is accepted and the connector is active.

(Optional) Add more tenants: open Microsoft 365 → Manage and click Add tenant, then repeat steps 2–5.

Manage connections: the Manage page lists each tenant with its latest activity. Click a tenant to see mailboxes scanned, who created it, and when. To remove a tenant, choose Delete.

Upgrading from Classic: tenants still on the Classic connector show a yellow warning icon. You can Add tenant and then delete the Classic connection.

Permissions, security and data residency

  • Admin consent: the connector is registered as an enterprise application in your Entra ID tenant. You can review or remove it any time under Entra ID → Enterprise applications.

  • Tenant scope: one Azure tenant can cover many inbound domains, so protection is per tenant, not per domain.

Troubleshooting and FAQ

Issue

What to do

Microsoft error AADSTS700016 ("application was not found in the directory")

The tenant name doesn't match the account you signed in with, or consent wasn't granted. Check the tenant name and sign in as a Global Admin of that tenant.

Tenant not listed after setup

Consent wasn't completed. Reconnect and click Accept on the Microsoft consent screen.

"Tenant not found" in Valimail

Use the domain from your Azure sign-in (e.g. valimail.onmicrosoft.com), not a mailbox address.

Latest activity is blank

New connections can take [X hours] to complete the first scan.

Unexpected Azure charges

Review the connector's resource group in Azure Cost Management and set a budget alert.

Do I have to move off Classic?

Not right away. Classic stays available; the new connector is required for multi-tenant support and upcoming reporting features.

Can I disconnect?

Yes, delete the tenant in Valimail and remove the Helios Connector from Azure → Entra ID → Enterprise Applications

Did this answer your question?