Connect via your organization's own MS Entra app
IT Admin instructions for connecting Microsoft 365 emails
Last updated
Was this helpful?
IT Admin instructions for connecting Microsoft 365 emails
Use this setup when your team wants its own Microsoft Entra ID app registration. This gives your security team direct control over consent, mailbox scope, and revocation. If you are fine using Tally's shared multi-tenant app, use Connect Emails.
Before you start:
A logged-in Tally user must open Settings → Email and start the setup.
You can generate a secure setup link for your IT or Microsoft admin. They do not need a Tally account.
The setup link expires 3 days after creation.
Certificate creation and upload are required for this flow.
Start the setup in Tally
Go to Settings → Email.
Open Custom Microsoft app registration.
Click Set up custom app.
If your IT or Microsoft admin does not have a Tally account, generate the secure setup link and send it to them.
Copy the link when it appears. It is shown once and expires 3 days after creation.

Once in the setup wizard, follow the guide below to configure your app and Tally's access.


Create the app registration
Create the Microsoft Entra ID app registration that Tally will use.


Grant API permissions
Grant only the permissions required by the integration.
Scope mailbox access with RBAC
Grant Tally read access only to the mailboxes you want it to monitor by using Exchange Online RBAC for Applications.



Provide credentials to Tally

Create your certificate, upload it, then validate
Create a certificate in your app registration.
Upload the certificate to Tally.
Run validation to confirm the setup works.


Once validation succeeds, you should see this:

Once connected, select the mailbox you want Tally to monitor. Tally only has access to the mailboxes you configure.

Last updated
Was this helpful?
Was this helpful?
