🔐
This guide walks you through creating a Microsoft Entra ID (Azure AD) app registration for Mail Pro.
You only need this if your mail is hosted at Microsoft 365. For Google Workspace see Google Workspace Setup; for any other host see IMAP/SMTP Setup.
Step 1: Create App Registration
- Go to Azure Portal → App Registrations
- Click New registration
- Configure:
- Name:
Odoo Mail Pro(or your preference) - Supported account types: Accounts in this organizational directory only
- Redirect URI: Web → copy the Callback URL from Odoo (Settings → Mail Pro, the arrow on step 1). The URL format is
https://your-odoo-domain.com/microsoft_oauth/callback
- Name:
- Click Register
Step 2: Note Application IDs
After registration, copy these values (you'll need them in Odoo):
- Application (client) ID
- Directory (tenant) ID
Step 3: Create Client Secret
- Go to Certificates & secrets
- Click New client secret
- Add description:
Odoo - Select expiration (recommend 24 months)
- Click Add
- Copy the Value immediately (it won't be shown again)
Azure shows two columns here: Value and Secret ID. Odoo needs the Value. The Secret ID is a different string and is never used.
Step 4: Configure API Permissions
- Go to API permissions
- Click Add a permission
- Select Microsoft Graph
- Select Delegated permissions
-
Add these permissions:
Required (personal mailbox):
Mail.ReadWrite- Create drafts, read emailsMail.Send- Send emailsoffline_access- Refresh tokensUser.Read- User profile
Required for shared mailboxes:
Mail.ReadWrite.Shared- Create drafts in shared mailboxMail.Send.Shared- Send from shared mailbox
-
Click Grant admin consent (requires Azure admin)
Step 5: Configure in Odoo
- Go to Settings → Mail Pro and press the arrow on step 1, Email Provider
- Create the provider row and set Provider to Microsoft 365
- Enter the three values under the same names Azure gives them:
- Application (client) ID
- Client Secret Value (the Value from Step 3, not the Secret ID)
- Directory (tenant) ID
- Save
- Click Test Credentials. Azure answers whether these three are the ones it issued. Nothing is sent and no mailbox is read.
- Click Sign In Myself. This walks the real consent screen, which is the only check that also covers the Callback URL, the permissions from Step 4 and whether your tenant lets users consent at all.
Next Steps
Configuration is complete. Proceed to User Setup to connect Microsoft accounts.