This procedure enables the Message Trace API for an Microsoft 365 installation, which helps Expel investigate phishing submissions.

This procedure varies depending on which option you selected while connecting your Microsoft 365 installation to Workbench:

  • If you chose Option 1: Enable Microsoft 365 integration during installation, go to Option 1.

  • If you chose Option 2: Create Custom Azure Application during installation, go to Option 2.

For more information, see the Microsoft 365 Direct setup for Workbench. If you need help, contact support.

Option 1: If You Choose to Enable Microsoft 365 Integration

New Installation

  1. Navigate to Roles and administrators, scroll down and select these roles:

    • Global reader

    • Security reader

    mceclip0.png
  2. Select Add assignments.

    mceclip0.png
  3. Search for the Expel Microsoft 365 integration enterprise app and select it.

    mceclip2.png
  4. Select Add.

    Add_assignments_click_add.jpg

Existing Installation

  1. Navigate to Expel Microsoft 365 Integration > API Permissions, and then select Grant admin consent.

  2. Consent to the new API permissions.

  3. Navigate to Roles and administrators, scroll down and select these roles:

    • Global reader

    • Security reader

    mceclip0.png
  4. Select Add assignments.

    mceclip0.png
  5. Search for the Expel Microsoft 365 integration enterprise app and select it.

    mceclip2.png
  6. Select Add.

    Add_assignments_click_add.jpg

Option 2: If You Choose to Create Custom Azure Application

New and Existing Installations

  1. Follow all previous API permission steps for Step 2: Option 2 in Microsoft 365 Direct setup for Workbench.

  2. Navigate to the custom application and select API Permissions.

  3. On the APIs my organization uses tab, select Add a permission.

  4. Search for and select Microsoft 365 Exchange Online.

    Office365_Message_Trace_API_Permissions.png
  5. Select Application permissions, and then, in the Select permissions search field, search for ReportingWebService.

    Request_API_permissions_Add.jpg
  6. Select the ReportingWebService.Read.All permission, and then select Add permissions.

  7. Select Grant admin consent for Expel, and then select Yes.

    Grant_admin_consent.jpg
  8. Confirm that consent is granted for the added permission.

    Grant_admin_consent_confirm.jpg
  9. Navigate to Roles and administrators, and then select the following roles:

    • Global reader

    • Security reader

    mceclip0.png
  10. Select Add assignments.

    mceclip0.png
  11. Search for the custom app registration and select it.

    Add_assignments_Option2.jpg
  12. Select Add.

Microsoft 365, M365, messagetrace, MessageTrace