Office 365 Configuration¶
Configure Microsoft Office 365 for email delivery using OAuth authentication.
Office 365 (Microsoft 365) can be used for sending emails via Kensium Point-of-Sale. This integration uses OAuth authentication -your password is never stored. Works with Exchange Online as part of Microsoft 365 subscription.
Navigation: Settings → Email → Office 365 (after selecting Office 365 as provider)
Prerequisites¶
Before configuring Office 365, you need:
- Active Microsoft 365 subscription with Exchange Online
- Tenant ID (from Azure AD)
- Access to Azure AD (Microsoft Entra ID)
- Ability to register applications
- Email mailbox in Exchange Online
Office 365 Setup Overview¶
Why Office 365?¶
- Familiar for organizations using Microsoft 365
- Integrates with Exchange Online
- OAuth authentication (secure)
- High sending limits (10,000+ emails/day)
- Professional support
Setting Up Office 365 OAuth¶
Step 1: Get Your Tenant ID¶
- Go to Azure Portal
- Sign in with Microsoft 365 admin account
- Go to Azure Active Directory
- Click Properties
- Copy Tenant ID (GUID format)
- Save for later use
Step 2: Register Application¶
- In Azure Portal, go to App registrations
- Click New registration
- Fill in:
- Name: "Kensium Point-of-Sale"
- Account types: Select appropriate type
- Redirect URI:
- Platform: Web
- URI:
https://your-pos-url/email/office365/callback - Replace with actual POS URL
- Click Register
- Copy Application (Client) ID
Step 3: Create Client Secret¶
- Go to Certificates & secrets
- Click New client secret
- Set expiration (12 months recommended)
- Click Add
- Copy secret value (shown once)
- Save securely
Step 4: Configure Permissions¶
- Go to API permissions
- Click Add a permission
- Select Microsoft Graph or Office 365 Exchange Online
- Add permission:
Mail.Send - Click Grant admin consent (admin required)
- Permissions should show "Granted"
Step 5: Verify Configuration¶
You should now have: - Tenant ID - Your organization's ID - Client ID - Application ID - Client Secret - Generated secret - Service Account Email - Email to send from
Configuring in Kensium Point-of-Sale¶
Step 1: Enter Office 365 Details¶
- Settings → Email → Email Settings
- Select Office 365 as provider
- Save
- Settings → Email → Office 365 Configuration
Step 2: Enter Credentials¶
- Tenant ID
- Paste from Azure Portal
-
Example:
12345678-1234-1234-1234-123456789012 -
Client ID
- Application (Client) ID from registration
-
Example:
87654321-4321-4321-4321-210987654321 -
Client Secret
- Paste from "Certificates & secrets"
-
Example:
abc123def456ghi789jkl012mnopqrstuv -
Default Sender Email
- Email address to send from
- Example:
noreply@company.com -
Must have Exchange Online mailbox
-
Save
Step 3: Authorize Office 365¶
- Click Authorize Office 365 Account
- Browser opens Microsoft login screen
- Sign in with your Office 365 account
- Grant permission request
- Browser redirects back to POS
- Authorization complete
Test Connection¶
- Click Send Test Email
- Enter recipient email
- Click Send
- Verify email arrives
Using Office 365 with Custom Domain¶
If using custom domain (not onmicrosoft.com):
Domain Configuration¶
- Ensure domain added to Microsoft 365 tenant
- Domain verified in Microsoft 365 admin center
- Configure Mail Exchange (MX) records
- Ensure sender email address exists in tenant
Exchange Online Mailbox¶
- Sender email must have mailbox in Exchange
- Can be:
- Shared mailbox (noreply@company.com)
- Service account mailbox
- Dedicated POS mailbox
- Must have Send as/Send on behalf permission
Shared Mailbox Setup¶
- Create shared mailbox (Microsoft 365 admin)
- Add POS service account as owner
- Grant "Send As" permission
- Use shared mailbox email as sender
Troubleshooting Office 365¶
"Invalid Tenant ID"¶
Check: - Tenant ID is correct (from Azure AD Properties) - Format is correct (GUID with hyphens) - Tenant exists and is active
Try: - Copy Tenant ID again from Azure Portal - Verify there are no spaces
"Authorization Failed"¶
Check: - Client ID is correct - Client Secret is correct - Redirect URI matches exactly in Azure - Application is registered properly
Try: - Redo authorization process - Create new application registration - Verify Office 365 account has admin access
"Permission Denied"¶
Check:
- Client has Mail.Send permission
- Admin consent granted
- Service account has Exchange mailbox
- Service account has Send As permission
Try: - Re-authorize - Contact Microsoft 365 admin - Verify shared mailbox permissions
"Emails Not Sending"¶
Check: - Authorization token is current - Sender email is correct - Email queue shows specific error - Test email works - Service account is active
Try: - Send test email - Reauthorize account - Check token isn't expired
"Quota Exceeded"¶
Office 365 email sending limits:
- Standard: 10,000 emails/24 hours
- Some plans higher
- Can request increase from Microsoft
Solutions: - Wait for quota reset - Upgrade license/plan - Batch emails during off-peak - Implement rate limiting
Office 365 Monitoring¶
Check Email Status¶
In Microsoft 365 admin center:
- Go to Health → Message center
- Check for Exchange Online notifications
- Monitor service health
- Review incident history
Monitor Sending Quota¶
- In Power Automate or Exchange logs
- Monitor mail flow
- Check for throttling warnings
- Review delivery reports
Security Considerations¶
OAuth Benefits¶
- ✅ Password never stored
- ✅ Can revoke access anytime
- ✅ Limited to specific permissions
- ✅ Tenant isolation
- ✅ Compliance-ready
Protecting Credentials¶
- ✅ Keep Client Secret confidential
- ✅ Don't share credentials
- ✅ Rotate secrets periodically
- ✅ Use Azure Key Vault (recommended)
- ✅ Monitor permission changes
Compliance¶
Office 365 integrates with:
- Compliance - Retention policies, eDiscovery
- Auditing - All actions logged
- Security - Encryption, threat protection
- Data Loss Prevention - DLP rules apply
Revoking Access¶
To disconnect Office 365:
- Go to Azure Portal → App registrations
- Find "Kensium Point-of-Sale" application
- Click Delete
- Confirm deletion
- Also revoke in Enterprise applications if needed
Office 365 Best Practices¶
- ✅ Use dedicated service account email
- ✅ Use OAuth (not password)
- ✅ Implement shared mailbox for noreply@
- ✅ Test configuration immediately
- ✅ Monitor sending quota
- ✅ Keep credentials secure
- ✅ Enable MFA on service account (if policy allows)
- ✅ Review mail flow rules
- ✅ Set up DLP rules if needed
- ✅ Document configuration for support
Microsoft 365 Integration¶
Beyond Email¶
Other integrations possible:
- OneDrive - Document storage
- SharePoint - Team sites
- Teams - Collaboration
- Power Automate - Workflow automation
Current scope focuses on email (Mail.Send permission).
Alternatives¶
- Gmail: If using Google Workspace
- SMTP: Use Office 365 via SMTP
- Custom Server: SMTP to your own server
Office 365 SMTP Alternative¶
If preferring SMTP over OAuth:
Server: smtp.office365.com
Port: 587
Encryption: TLS
Username: Your Office 365 email
Password: Your Office 365 password
(See SMTP guide for details)