Skip to content

Azure App Configuration

Follow these steps to set up an app in Azure Active Directory. You need the app when an SMTP server sends mail through an Office 365 mailbox, or when a POP3 or IMAP server reads one.

The steps below outline the setup for a typical Office 365 subscription.

The steps may vary with the level of subscription and administrative privileges, and they do not cover Azure permissions in full.

Once you have created the app, you will have noted three values: the Azure Tenant Id, the Azure Application (Client) Id and the Client Secret. You enter them when you set up an Office 365 SMTP server or an Office 365 POP3 server.

Azure Active Directory Login

  1. Sign in to Azure Active Directory as a user with admin rights, that is, rights to create an app in Azure Active Directory.The Azure portal's left-hand service list, with Azure Active Directory between Virtual networks and Monitor
  2. Click App registrations.
    The Manage section of the Azure Active Directory menu: Users, Groups, External Identities, Roles and administrators, Administrative units, Delegated admin partners, Enterprise applications, Devices, and App registrations highlighted at the foot

Create An App Registration

  1. Click New registration at the top.The New registration button on the App registrations toolbarEnter a name for the app, such as Realisable IMan, and click Register. Azure opens the new app registration.
  2. Click Authentication and add a new redirect URI, https://authorisation.realisable.co.uk/OAuthCallback.The app registration's Authentication page. Under Platform configurations a Web platform is expanded, and its Redirect URIs list holds a single entry, https://authorisation.realisable.co.uk/OAuthCallback, ticked as validThen click Save.
  3. Click Certificates & secrets, then Client secrets, then New client secret.
  4. Enter a description and select an expiry, then click Add. With a short expiry, you will need to re-authenticate often.The Add a client secret panel open over the Certificates and secrets page, with a Description of Realisable IMan and Expires set to 24 months
  5. Copy the client secret and keep a note of it. Azure shows it only once, and if you do not copy the value you will need to create a new secret.The Client secrets tab after the secret is created, listing one row: Description Realisable IMan, an expiry date, a truncated Value with a copy button, and a Secret ID. A callout marks the Value column as the client secret
  6. Click API permissions.The API permissions entry in the app registration's Manage menu
  7. Click Add a permission.The Add a permission button on the API permissions page
  8. Click Delegated permissions.The question "What type of permissions does your application require?" with the Delegated permissions tile selected, described as your application needing to access the API as the signed-in user
  9. Click Microsoft Graph.The Microsoft Graph tile under Commonly used Microsoft APIs
  10. Search for offline_access and tick its check box.The Select permissions search filtered on "offline", showing the OpenId permissions group with offline_access ticked and Admin consent required reading No
  11. Repeat the step above to add the following permissions. The configured permissions grid listing five Microsoft Graph entries, each Delegated and needing no admin consent: offline_access, openid, POP.AccessAsUser, SMTP.Send and User.Read
    • openid
    • User.Read
    • SMTP.Send
      • This allows users to send email.
    • POP.AccessAsUser.All
      • Required only when IMan needs access to a POP3 mailbox.
    • IMAP.AccessAsUser.All
      • Required only when IMan needs access to an IMAP mailbox.
  12. Click Overview.The Overview entry at the top of the app registration menu
  13. Note the Directory (tenant) ID and Application (client) ID values.The app registration Overview page's Essentials block, with the Application (client) ID, Object ID and Directory (tenant) ID redacted. Callouts mark the Directory (tenant) ID and the Application (client) ID as the two values IMan needs