Skip to content

Office 365 Configuration

Configure Microsoft Office 365 for email delivery using OAuth authentication.

Office 365 (Microsoft 365) can be used for sending emails via Kensium Point-of-Sale. This integration uses OAuth authentication -your password is never stored. Works with Exchange Online as part of Microsoft 365 subscription.

Navigation: Settings → Email → Office 365 (after selecting Office 365 as provider)

Prerequisites

Before configuring Office 365, you need:

  • Active Microsoft 365 subscription with Exchange Online
  • Tenant ID (from Azure AD)
  • Access to Azure AD (Microsoft Entra ID)
  • Ability to register applications
  • Email mailbox in Exchange Online

Office 365 Setup Overview

Why Office 365?

  • Familiar for organizations using Microsoft 365
  • Integrates with Exchange Online
  • OAuth authentication (secure)
  • High sending limits (10,000+ emails/day)
  • Professional support

Setting Up Office 365 OAuth

Step 1: Get Your Tenant ID

  1. Go to Azure Portal
  2. Sign in with Microsoft 365 admin account
  3. Go to Azure Active Directory
  4. Click Properties
  5. Copy Tenant ID (GUID format)
  6. Save for later use

Step 2: Register Application

  1. In Azure Portal, go to App registrations
  2. Click New registration
  3. Fill in:
  4. Name: "Kensium Point-of-Sale"
  5. Account types: Select appropriate type
  6. Redirect URI:
  7. Platform: Web
  8. URI: https://your-pos-url/email/office365/callback
  9. Replace with actual POS URL
  10. Click Register
  11. Copy Application (Client) ID

Step 3: Create Client Secret

  1. Go to Certificates & secrets
  2. Click New client secret
  3. Set expiration (12 months recommended)
  4. Click Add
  5. Copy secret value (shown once)
  6. Save securely

Step 4: Configure Permissions

  1. Go to API permissions
  2. Click Add a permission
  3. Select Microsoft Graph or Office 365 Exchange Online
  4. Add permission: Mail.Send
  5. Click Grant admin consent (admin required)
  6. Permissions should show "Granted"

Step 5: Verify Configuration

You should now have: - Tenant ID - Your organization's ID - Client ID - Application ID - Client Secret - Generated secret - Service Account Email - Email to send from

Configuring in Kensium Point-of-Sale

Step 1: Enter Office 365 Details

  1. Settings → Email → Email Settings
  2. Select Office 365 as provider
  3. Save
  4. Settings → Email → Office 365 Configuration

Step 2: Enter Credentials

  1. Tenant ID
  2. Paste from Azure Portal
  3. Example: 12345678-1234-1234-1234-123456789012

  4. Client ID

  5. Application (Client) ID from registration
  6. Example: 87654321-4321-4321-4321-210987654321

  7. Client Secret

  8. Paste from "Certificates & secrets"
  9. Example: abc123def456ghi789jkl012mnopqrstuv

  10. Default Sender Email

  11. Email address to send from
  12. Example: noreply@company.com
  13. Must have Exchange Online mailbox

  14. Save

Step 3: Authorize Office 365

  1. Click Authorize Office 365 Account
  2. Browser opens Microsoft login screen
  3. Sign in with your Office 365 account
  4. Grant permission request
  5. Browser redirects back to POS
  6. Authorization complete

Test Connection

  1. Click Send Test Email
  2. Enter recipient email
  3. Click Send
  4. Verify email arrives

Using Office 365 with Custom Domain

If using custom domain (not onmicrosoft.com):

Domain Configuration

  1. Ensure domain added to Microsoft 365 tenant
  2. Domain verified in Microsoft 365 admin center
  3. Configure Mail Exchange (MX) records
  4. Ensure sender email address exists in tenant

Exchange Online Mailbox

  • Sender email must have mailbox in Exchange
  • Can be:
  • Shared mailbox (noreply@company.com)
  • Service account mailbox
  • Dedicated POS mailbox
  • Must have Send as/Send on behalf permission

Shared Mailbox Setup

  1. Create shared mailbox (Microsoft 365 admin)
  2. Add POS service account as owner
  3. Grant "Send As" permission
  4. Use shared mailbox email as sender

Troubleshooting Office 365

"Invalid Tenant ID"

Check: - Tenant ID is correct (from Azure AD Properties) - Format is correct (GUID with hyphens) - Tenant exists and is active

Try: - Copy Tenant ID again from Azure Portal - Verify there are no spaces

"Authorization Failed"

Check: - Client ID is correct - Client Secret is correct - Redirect URI matches exactly in Azure - Application is registered properly

Try: - Redo authorization process - Create new application registration - Verify Office 365 account has admin access

"Permission Denied"

Check: - Client has Mail.Send permission - Admin consent granted - Service account has Exchange mailbox - Service account has Send As permission

Try: - Re-authorize - Contact Microsoft 365 admin - Verify shared mailbox permissions

"Emails Not Sending"

Check: - Authorization token is current - Sender email is correct - Email queue shows specific error - Test email works - Service account is active

Try: - Send test email - Reauthorize account - Check token isn't expired

"Quota Exceeded"

Office 365 email sending limits:

  • Standard: 10,000 emails/24 hours
  • Some plans higher
  • Can request increase from Microsoft

Solutions: - Wait for quota reset - Upgrade license/plan - Batch emails during off-peak - Implement rate limiting

Office 365 Monitoring

Check Email Status

In Microsoft 365 admin center:

  1. Go to Health → Message center
  2. Check for Exchange Online notifications
  3. Monitor service health
  4. Review incident history

Monitor Sending Quota

  1. In Power Automate or Exchange logs
  2. Monitor mail flow
  3. Check for throttling warnings
  4. Review delivery reports

Security Considerations

OAuth Benefits

  • ✅ Password never stored
  • ✅ Can revoke access anytime
  • ✅ Limited to specific permissions
  • ✅ Tenant isolation
  • ✅ Compliance-ready

Protecting Credentials

  • ✅ Keep Client Secret confidential
  • ✅ Don't share credentials
  • ✅ Rotate secrets periodically
  • ✅ Use Azure Key Vault (recommended)
  • ✅ Monitor permission changes

Compliance

Office 365 integrates with:

  • Compliance - Retention policies, eDiscovery
  • Auditing - All actions logged
  • Security - Encryption, threat protection
  • Data Loss Prevention - DLP rules apply

Revoking Access

To disconnect Office 365:

  1. Go to Azure Portal → App registrations
  2. Find "Kensium Point-of-Sale" application
  3. Click Delete
  4. Confirm deletion
  5. Also revoke in Enterprise applications if needed

Office 365 Best Practices

  • ✅ Use dedicated service account email
  • ✅ Use OAuth (not password)
  • ✅ Implement shared mailbox for noreply@
  • ✅ Test configuration immediately
  • ✅ Monitor sending quota
  • ✅ Keep credentials secure
  • ✅ Enable MFA on service account (if policy allows)
  • ✅ Review mail flow rules
  • ✅ Set up DLP rules if needed
  • ✅ Document configuration for support

Microsoft 365 Integration

Beyond Email

Other integrations possible:

  • OneDrive - Document storage
  • SharePoint - Team sites
  • Teams - Collaboration
  • Power Automate - Workflow automation

Current scope focuses on email (Mail.Send permission).

Alternatives

  • Gmail: If using Google Workspace
  • SMTP: Use Office 365 via SMTP
  • Custom Server: SMTP to your own server

Office 365 SMTP Alternative

If preferring SMTP over OAuth:

Server: smtp.office365.com Port: 587 Encryption: TLS Username: Your Office 365 email Password: Your Office 365 password

(See SMTP guide for details)