This procedure enables the Message Trace API for an Microsoft 365 installation, which helps Expel investigate phishing submissions.
This procedure varies depending on which option you selected while connecting your Microsoft 365 installation to Workbench:
-
If you chose Option 1: Enable Microsoft 365 integration during installation, use Option 1 below.
-
If you chose Option 2: Create Custom Azure Application during installation, use Option 2 below.
For more information, see the Microsoft 365 Direct setup for Workbench. If you need help, contact your engagement manager.
Option 1: If you choose to enable Microsoft 365 integration
New installation
-
Navigate to Azure AD roles and administrators, scroll down and select these roles:
-
Global reader
-
Security reader
-
-
Click Add assignments.
-
Search for the Expel Microsoft 365 integration enterprise app and select it.
-
Click Add.
Existing installation
-
Open the Expel Microsoft 365 Integration > API Permissions tab and select Grant admin consent.
-
Consent to the new API permissions.
-
Navigate to Azure AD roles and administrators, scroll down and select these roles:
-
Click Add assignments.
-
Search for the Expel Microsoft 365 integration enterprise app and select it.
-
Click Add.
Option 2: If you choose to create custom Azure application
New and existing installations
-
Follow all previous API permission steps for Option 2: Create Custom Azure Application in the Microsoft 365 Direct setup for Workbench.
-
Navigate to the custom Azure application and click API Permissions.
-
On the APIs my organization uses tab, click Add a permission.
-
Search for and select Microsoft 365 Exchange Online.
-
Select Application permissions and search for ReportingWebService in the Select permissions search field.
-
Select the ReportingWebService.Read.All permission, then click Add permissions.
-
Select Grant admin consent for Expel, and then click Yes.
-
Confirm that consent is granted for the added permission.
-
Navigate to Azure AD roles and administrators, scroll down and select these roles:
-
Global reader
-
Security reader
-
-
Click Add assignments.
-
Search for the custom Azure app registration and select it.
-
Click Add.
Tip
This article was accurate at the time of writing, but changes happen. If you find the instructions are outdated, leave a description in the comment field below and let us know!
Office365, O365, messagetrace, MessageTrace
Comments
0 comments
Please sign in to leave a comment.