Setup

Connecting Microsoft 365.

Microsoft won't let a regular user approve an outside app, so connecting a mailbox needs an administrator once — about two minutes, and it covers everyone. This page is written to be forwarded to them.

IronVail CRM sends sequences and campaigns from your team's real mailboxes rather than from a shared marketing domain, so replies land in the rep's inbox like any other email. That requires a connection to Microsoft 365, and Microsoft requires an administrator to approve that connection for your tenant.

What you're approving

Four delegated permissions. The fourth is the one people ask about, so it's worth reading first.

User.Read

Sign the user in, and read their name and email address.

offline_access

Stay connected, so the user isn't forced to re-authenticate every day.

Mail.Send

Send email as that user, from their own mailbox.

Mail.ReadBasic

Read message headers only — who sent it, the subject line, and when. This does not include message bodies or attachments, and there is no scope requested that would allow reading them.

IronVail cannot read the contents of your users' email. That isn't a policy commitment, it's a structural one:Mail.ReadBasicreturns headers and nothing else. It's how the product notices that a prospect replied — so it can stop the sequence before the next message goes out — without knowing what they said.

Why approval is needed at all

None of the four permissions normally requires an administrator. The trigger is your tenant's consent policy. Microsoft's default for modern tenants is to allow user consent only for apps from verified publishers, and our publisher registration is still in progress — so the consent screen may say “unverified”. That word refers to paperwork we haven't finished, not to anything detected about the app. Many tenants also disable user consent outright, in which case an administrator would be required regardless.

Option 1 — a direct link

Your IronVail contact can send you a consent URL with your domain and our client ID filled in. Open it on your own device, sign in with an administrator account, review the permissions, and click Accept. That grants consent tenant-wide, once, for every user.

You need one of: Global Administrator, Privileged Role Administrator, or Cloud Application Administrator. With a lesser role the approve button is typically greyed out rather than explained.

Option 2 — the admin center

More clicks, no URL to construct, and it always works:

  1. 1. Go to entra.microsoft.com and sign in as an administrator.
  2. 2. Applications Enterprise applications.
  3. 3. Search for IronVailCRM. It appears once one of your users has attempted to sign in — if it isn't there, have them try connecting again first.
  4. 4. Open it → Security Permissions.
  5. 5. Click Grant admin consent for [your organization], review, and Accept.

Confirming it worked

The user retries Settings → Connections → Connect Microsoft 365 in IronVail. The consent screen either doesn't appear or shows a plain Accept without the administrator warning, and the mailbox shows as connected. In the portal, the four permissions above will now be listed as granted for the organization.

Revoking

The same Enterprise applications entry is where you remove access. Revoking consent, or an individual user disconnecting their mailbox in IronVail, cuts off access immediately. Removing a user from an IronVail workspace also removes their mailbox connection.

Questions from a security review

Reasonable ones, and we'd rather answer them up front. Our security page covers isolation, encryption, and the limits we don't hide, and the privacy policy names every subprocessor. A filled-in security questionnaire (SIG-Lite / CAIQ shape, with our known gaps marked as gaps) is ready to send — ask your IronVail contact.