Integration of Microsoft 365 mail services into ioi

Mise à jour le 18 septembre 2026·

Introduction #

This tutorial details how to configure the integration between Microsoft 365 (Outlook) mail services and the Frappe mail system.

Authentication is managed via the OAuth 2.0 standard.

Prerequisites #

  1. Frappe Version: Ensure that your Frappe instance is updated to at least version 15 (preferably the latest version).
  2. Access to HTTPS Site: You must have access to a Silicon ioi site using the HTTPS protocol.
  3. Microsoft 365 Global Admin Account: A Microsoft 365 account with global administrator privileges is required.

Compatibility #

This methodology was tested and validated with Frappe version 15 as of August 30, 2024.

Step-by-step guide #

Follow the steps detailed on the Frappe forum via this link or refer to the instructions.

→ Also consider the additional configuration points described in the section Additional Configurations.

Azure Admin Portal #

In Azure AD, create an App Registration and configure permissions, secrets, etc.

Attention

Keep in mind that this configuration might impact data security.

Application Registration #

  1. Access the Azure Admin portal:
  1. App registrations.
  1. Create a new registration.

Info

Ignore the redirect URI for now; it will be configured later in this document.

  1. Permissions.

SMTP Standard Mode: Add permissions to the application.

Exemple

Required permissions include:

- Microsoft Graph: IMAP.AccessAsUser.All and SMTP.Send

- Office365 Exchange Online : IMAP.AccessAsApp

Mode MS Graph :

Exemple

After configuring the permissions, select and grant them admin consent.

  1. Enter the Client ID of the application in Silicon ioi.
  1. Create your authentication keys (secrets).

Attention

Save the secret value (not the secret ID). This will not be displayed again after this step, so ensure it is saved for later use. We will use them later on.

  1. Obtain the OpenID configuration endpoint, which will be needed in subsequent steps.

In Silicon ioi #

Attention

Open a private browsing window, Incognito mode, or InPrivate mode.

  1. Create a connected application.
  2. Copy the OpenID configuration value obtained earlier (.7) and use the Fetch OpenID Configuration button to get the endpoint URLs. Then, fill in the Client ID (.5) and secret value (.6).

  1. Connected App Scopes.

SMTP / IMPA Mode: Add the following scopes:

MS Graph Mode: Add the following scopes:

4.Redirect URI

  1. Use the redirect URI value (.4) and return to the M365 app registration to add this URL under authentication.
  1. Connecting the Application in Silicon ioi:

→ In the new Connected app, click Connect to XXXX.

Attention

You must connect using the domain 365 “Admin” user, typically the same user used for configuring Azure Portal.

  1. Create an email account and assign it to the “end user.”

Attention

Close all open browsers, then reopen the page in a private browsing window.\nNext, sign in with the IOI user, using the email address that will be configured here.

Set up the account with the following information:

SMTP-IMAP Mode:

Create a mail domain and then configure the email account.

Email Account Configuration

(SMTP – IMAP Mode)

(MS Graph Mode)

Account creation using only this information.

Exemple

After saving the document, you should see a change in the Incoming and Outgoing section titles, with “(MS Graph)” indicated.

Attention

Use the “Authorize API Access” button after logging into Frappe with the “end user”, the one linked to this account (not the admin). The associated 365 user’s authentication will also be required here.

 

MS Graph Mode :

MS Graph mode has been integrated into Frappe’s standard email module, supporting both sending and receiving emails.

For receiving emails, both the “ALL” and “UNSEEN” modes are supported:

ALL → Imports all emails (up to the Initial Sync Count).

A new entry is created for each account in the doctype ioi Email Pull Request with the last synchronization date (last received email date).

Info

An additional check is present too to prevent any duplicate using the unique email ID.

UNSEEN → Imports only unread emails, marking them as read once imported. If an email is marked unread again, it will be re-imported.

Each received email generates a document in the “Communication” doctype.

Info

Specify the email folder to scan in the “IMAP Folder” table. If the “Append To” field is left empty, only a Communication will be created. You can assign another doctype to create both a Communication and a specific document type.

Additional Configurations #

Adding an Authorized API: SMTP.SendAsApp #

  1. Access Azure Active Directory.
  2. Add a new authorization.
  3. Select APIs used by my organization.
  4. Search for “Office 365 Exchange Online”.
  5. Select Application Permission.
  6. Choose the SMTP.SendAsApp permission.

Disabling “Turn off AUTH SMTP Protocol” #

→ In Microsoft 365 : https://admin.exchange.microsoft.com/#/settings

→ In Frappe :

Error 500: Repeating Redirects Detected Outlook Online Microsoft 365 #

If you encounter a 500 error when connecting to https://outlook.office365.com via your browser :

Astuce

Either watch this video.

Or follow these steps:

  1. Access Azure Active Directory.
  2. Select the administrator user of your application.
  3. Keep only the “Global Administrator” role.
  4. Refresh the page https://outlook.office365.com.

Multi-Address Setup #

You can link multiple email addresses to a single user.

However, only one Microsoft 365 connection instance is allowed per user session.

Info

Therefore, you cannot view the mail stream from two addresses simultaneously due to token cache conflicts.

Attachments #

Attachments are supported for both sending and receiving emails.

For received emails, it is possible to set a maximum acceptable attachment size.

Pages liées

Cette page vous a-t-elle aidé ?