🔐 Microsoft 365 Setup
🔐

This guide walks you through creating a Microsoft Entra ID (Azure AD) app registration for Mail Pro.

You only need this if your mail is hosted at Microsoft 365. For Google Workspace see Google Workspace Setup; for any other host see IMAP/SMTP Setup.

Step 1: Create App Registration

  1. Go to Azure Portal → App Registrations
  2. Click New registration
  3. Configure:
    • Name: Odoo Mail Pro (or your preference)
    • Supported account types: Accounts in this organizational directory only
    • Redirect URI: Web → copy the Callback URL from Odoo (Settings → Mail Pro, the arrow on step 1). The URL format is https://your-odoo-domain.com/microsoft_oauth/callback
  4. Click Register

Step 2: Note Application IDs

After registration, copy these values (you'll need them in Odoo):

  • Application (client) ID
  • Directory (tenant) ID

Step 3: Create Client Secret

  1. Go to Certificates & secrets
  2. Click New client secret
  3. Add description: Odoo
  4. Select expiration (recommend 24 months)
  5. Click Add
  6. Copy the Value immediately (it won't be shown again)

Azure shows two columns here: Value and Secret ID. Odoo needs the Value. The Secret ID is a different string and is never used.

Step 4: Configure API Permissions

  1. Go to API permissions
  2. Click Add a permission
  3. Select Microsoft Graph
  4. Select Delegated permissions
  5. Add these permissions:

    Required (personal mailbox):

    • Mail.ReadWrite - Create drafts, read emails
    • Mail.Send - Send emails
    • offline_access - Refresh tokens
    • User.Read - User profile

    Required for shared mailboxes:

    • Mail.ReadWrite.Shared - Create drafts in shared mailbox
    • Mail.Send.Shared - Send from shared mailbox
  6. Click Grant admin consent (requires Azure admin)

Step 5: Configure in Odoo

  1. Go to Settings → Mail Pro and press the arrow on step 1, Email Provider
  2. Create the provider row and set Provider to Microsoft 365
  3. Enter the three values under the same names Azure gives them:
    • Application (client) ID
    • Client Secret Value (the Value from Step 3, not the Secret ID)
    • Directory (tenant) ID
  4. Save
  5. Click Test Credentials. Azure answers whether these three are the ones it issued. Nothing is sent and no mailbox is read.
  6. Click Sign In Myself. This walks the real consent screen, which is the only check that also covers the Callback URL, the permissions from Step 4 and whether your tenant lets users consent at all.

Next Steps

Configuration is complete. Proceed to User Setup to connect Microsoft accounts.