Connecting Microsoft 365 and Outlook
Scout reads Outlook and Exchange mail the same way it reads Gmail: read-only, one mailbox at a time, with the thread kept as proof behind every point it raises. This article covers the three paths — your own mailbox, the extra step when your company requires an administrator to approve Scout, and connecting a named shared mailbox so its work belongs to a team instead of a person.
Path 1: connect your own mailbox
- Open Connections from your avatar menu.
- Find the Microsoft card under Communication. It reads "Outlook and Exchange messages, folders, participants, threads, and attachment details — read-only."
- Choose Connect.
- Sign in at Microsoft with your work or school account. Personal Microsoft accounts are refused — Scout is built for the company mailbox.
- Read the permission list. Scout asks to sign you in, read your basic profile, read your mail, and keep the connection alive so it does not have to ask again. There is no send permission and no permission to change a message.
- Accept. Microsoft returns you to Scout, the card shows CONNECTED, and your mailbox appears under Manage access as a PERSONAL MAILBOX.
Scout reads your Inbox and Sent Items: participants, timestamps, subjects, message text, the thread each message belongs to, and the details of attachments — not their contents.
Path 2: when your tenant needs an administrator's consent
Many Microsoft 365 tenants are configured so an ordinary user cannot grant an application access on their own. If yours is one of them, Microsoft stops the sign-in above with a message saying an administrator must approve the app first. Nothing is broken; it is one extra step and it is done once for the whole company.
- An Owner or Admin of the Scout workspace starts the administrator-consent flow from the Microsoft card.
- Scout sends the browser to Microsoft's administrator-consent page for your tenant.
- A tenant administrator — a Global Administrator, or someone with rights to grant application consent — signs in and grants the consent for the organization.
- Microsoft returns to Scout, which records the consent and resumes the connect that was interrupted, at the step where it stopped. The person who started it lands back where they were.
The consent request has a short life and is tied to the browser that started it. If it is abandoned it expires on its own; nothing half-connected is left behind. Scout keeps a dated record of the attempt — started, returned, denied or invalid — so an administrator can see what happened.
Path 3: connect a named shared mailbox
A shared mailbox — orders@, art@, service@ — has no single owner to consent, and work that arrives there should belong to a team, not to whoever happens to read it. Scout connects these differently, and deliberately narrowly: it uses a separate application identity that holds no tenant-wide mail permission at all, and your Exchange administrator grants that identity access to one named mailbox at a time.
Two people are involved: an Owner or Admin of the Scout workspace, and an Exchange Administrator or Global Administrator of your Microsoft tenant. They are often the same person.
Step A — authorize the tenant
- On the Microsoft card, choose Add shared mailbox.
- Scout shows Authorize a Microsoft shared mailbox tenant. It states the boundary you are agreeing to: the dedicated Scout application must have no tenant-wide Microsoft Graph application permissions, and Exchange Application RBAC must grant only Application Mail.Read and Application MailboxSettings.Read, through one explicit mailbox scope.
- Enter your Microsoft tenant ID.
- Tick the confirmation: "I confirm the workload app has zero Microsoft Graph application-role grants; its only Exchange application roles are Application Mail.Read and Application MailboxSettings.Read, both under one explicit mailbox scope."
- Choose Verify tenant administrator and sign in at Microsoft. Scout asks for identity only at this step — it reads no mail here. If the account signing in is not an Exchange or Global Administrator, Scout refuses and says so.
Step B — name the mailbox, and the mailbox that must be denied
- Scout shows Configure a Microsoft shared mailbox with three fields.
- Approved shared mailbox — the address you want Scout to read. It must already be explicitly allowed by Exchange Application RBAC.
- Known unrelated mailbox — an address that exists in your tenant and must stay unreadable to Scout. This is the isolation proof. Scout tries both: it must be able to read the first and must be refused on the second. If it can read the second, the configuration is rejected — that is the check that stops tenant-wide access being accepted by accident.
- Owning team — pick the Scout team that should own the work from this mailbox, for example Sales or Production.
- Choose Verify and connect. Scout runs both probes, and only then creates the connection.
Screenshot: a shared mailbox listed beside personal mailboxes under Manage access.
The shared mailbox then shows as SHARED MAILBOX, owned by the team you chose. Work from it routes inside that team, and there is no personal-mail review to clear, because no employee's private mail is involved.
Reconnecting a shared mailbox repeats this configuration rather than a browser sign-in — a shared mailbox never goes back through Microsoft consent.
Good to know
- Microsoft offers no way for an application to revoke its own access. When you disconnect a Microsoft source, Scout destroys its stored authorization and records that it did — but the Microsoft consent and the Exchange rules stay until a tenant administrator removes them. Scout says this on the connection page.
- If the authorization stops working, the card shows SYNC FAILED or RE-AUTHORIZE and an Owner or Admin reconnects it; see The connection detail page.
- Losing access to one mailbox degrades only that mailbox. The rest of the connection keeps reading.
- Scout reads Inbox and Sent Items only. Other folders are not read.
- If Gmail and Microsoft 365 are both connected and both see a message, Scout reconciles them into one item rather than two.
- Scout never sends from Outlook. It prepares a draft for you to copy; you send it.