Microsoft 365 admin guide
For IT admins. What CommSync asks Microsoft for, the three ways to approve it, how to check IMAP for a mailbox, Conditional Access, and how to remove CommSync.
A user in your organization wants to connect their Microsoft 365 mailbox to CommSync. CommSync connects with Sign in with Microsoft. The user signs in on the page of Microsoft, and CommSync never sees a password.
Microsoft does not let a user approve IMAP access alone for most apps. So an admin must approve CommSync once for the organization. This page tells you what you approve, how to approve it, and how to take it back.
What CommSync asks for
CommSync asks for delegated permissions only. Each permission acts as the user who signed in, on that user's own mailbox. CommSync asks for no application permissions, so it cannot read a mailbox of a user who did not sign in.
| Resource | Permission | Type | Why CommSync needs it |
|---|---|---|---|
| Office 365 Exchange Online | IMAP.AccessAsUser.All | Delegated | CommSync syncs the mailbox over IMAP: new mail, the Sent folder, and the Spam folder. |
| Microsoft Graph | Mail.Send | Delegated | CommSync sends the mail that the user writes in CommSync. |
| Microsoft Graph | User.Read | Delegated | CommSync reads the primary address of the mailbox. |
| OpenID Connect | openid, profile, email, offline_access | Delegated | CommSync reads who signed in and keeps the mailbox connected. |
IMAP.AccessAsUser.All is the permission that needs your approval. Microsoft
lets a user approve the other permissions alone.
CommSync does not ask for SMTP.Send. It sends through Microsoft Graph, so
the sends work when your tenant turns off SMTP sign-in
(SmtpClientAuthenticationDisabled).
What CommSync does with the mailbox
- It reads the inbox, the Sent folder, and the Spam folder of the mailbox.
- It sends the mail that the user writes in CommSync. Exchange files each send in Sent Items.
- It marks a message as answered after a reply.
- It deletes mail on the server only when the user picks Delete permanently in the Trash view of CommSync.
- It never uses the mail to train AI models.
CommSync encrypts the tokens it gets from Microsoft. AWS Key Management Service protects the key of those tokens. See the Privacy Policy and the Security overview.
Who can approve
One of these Microsoft Entra roles can approve CommSync for the organization:
- Global Administrator
- Cloud Application Administrator
- Application Administrator
Approve CommSync
Use one of these three ways. Each way has the same result: every user in your organization can then connect their own mailbox. Each user still signs in for their own mailbox. Your approval does not connect a mailbox.
1. Open the approval link
When a user needs your approval, CommSync shows them a screen with the
Copy approval link action. The user sends you that link. The user can
also select Send these instructions to someone else. Then CommSync sends
you one email with the link, these steps, and the name of the user who asked.
The link names your tenant, not common, so it approves CommSync for your
organization only.
Open the link
Open the link that the user sent you. Sign in with an admin account of your organization.
Read the permissions
Microsoft shows the permissions of the table above. Make sure that the app is CommSync.
Accept
Click Accept. Microsoft sends you back to CommSync, and a page confirms the approval.
Tell the user
Ask the user to click Try again in CommSync.
If you are the admin and the user, click I am the admin on the approval screen in CommSync. It opens the same link.
2. Approve in the Microsoft Entra admin center
CommSync shows in your tenant after the first user of your organization tries to sign in.
Open the enterprise apps
Sign in to the Microsoft Entra admin center. Open Entra ID, then Enterprise apps. (Some tenants show Identity → Applications → Enterprise applications.)
Find CommSync
Search for CommSync. Open it.
Grant the consent
Under Security, open Permissions. Click Grant admin consent for your organization. Microsoft shows the permissions. Click Accept.
3. Use the admin consent workflow
The admin consent workflow of Microsoft lets a user ask for an app, and lets a reviewer approve the request later. When it is on, the Microsoft sign-in page shows Need admin approval with a request form. CommSync then tells the user that the request is with the IT team.
To turn the workflow on:
Open the consent settings
In the Microsoft Entra admin center, open Enterprise apps, then Consent and permissions, then Admin consent settings.
Turn on requests
Set Users can request admin consent to apps they are unable to consent to to Yes.
Pick the reviewers
Add the users, groups, or roles that review the requests. Click Save.
To review a request, open Enterprise apps, then Admin consent requests. Find CommSync, read the permissions, and approve it.
Check that IMAP is on for a mailbox
CommSync syncs over IMAP. When IMAP is off for a mailbox, the user sees "IMAP is off for this mailbox" in CommSync. Exchange Online can turn IMAP off for one mailbox, or for all new mailboxes.
In the Exchange admin center:
Open the mailbox
Sign in to the Exchange admin center. Open Recipients, then Mailboxes. Select the mailbox.
Open the email apps
Under Email apps, click Manage email apps settings.
Turn on IMAP
Turn on IMAP. Click Save.
In Exchange Online PowerShell:
# Show the IMAP setting of one mailbox
Get-CASMailbox -Identity [email protected] | Format-List ImapEnabled
# Turn IMAP on for that mailbox
Set-CASMailbox -Identity [email protected] -ImapEnabled $trueA change can take some minutes to reach the mailbox. Then ask the user to click Try again.
CommSync does not need SMTP sign-in (SmtpClientAuthDisabled). It sends
through Microsoft Graph.
Conditional Access
A Conditional Access policy can block the sign-in. The user then sees "A
sign-in policy of your organization blocks CommSync". Microsoft reports this
as AADSTS53003 or AADSTS53000.
CommSync keeps the mailbox connected from its own servers. After the first sign-in, the CommSync servers ask Microsoft for a new access token about once an hour. A policy can accept the first sign-in on the user's device, and refuse the token renewal from the servers. The mailbox then shows Action required in CommSync. These conditions often cause this:
- A policy that allows sign-in only from named locations or IP ranges.
- A policy that requires a compliant or joined device.
- A policy that blocks all cloud apps except a list.
To let CommSync work, exclude the CommSync enterprise app from the policy, or add it to the list of allowed apps. Use the What If tool of Conditional Access to test a user and the CommSync app before you change a policy.
Remove CommSync
For one user
The user removes the mailbox in CommSync (Settings → Email accounts → Remove). CommSync deletes its tokens. Microsoft has no endpoint that lets an
app give up its own access, so the user can also remove CommSync on
myapps.microsoft.com.
For the whole organization
Open CommSync
In the Microsoft Entra admin center, open Enterprise apps. Open CommSync.
Stop new sign-ins
Open Properties. Set Enabled for users to sign-in? to No. Click Save. Or delete the app from Properties to remove the consent too.
End the current access
To end the access of a user at once, open that user in Users and click Revoke sessions. That ends every refresh token of the user, for every app.
After this, each connected mailbox shows Action required in CommSync at its next token renewal. CommSync then stops the sync of that mailbox. The conversations that CommSync already synced stay in the CommSync workspace. To ask CommSync to delete that mail, email [email protected].