# Connect email capture to Microsoft 365

Point an email capture job at a Microsoft 365 mailbox with modern (OAuth2) authentication — the Entra app registration it needs, the four values that go into Content Central, and how to switch an old IMAP or POP3 job over.

Product: content-central · Versions: 7.x · Audience: system-administrator · Time: 45 minutes (most of it in Microsoft Entra) · Last verified: 2026-09-05

Canonical: https://help.ademero.com/content-central/capture/connect-email-capture-to-microsoft-365

**At the end of this guide, a capture job reads a Microsoft 365 mailbox using modern (OAuth2) authentication — the setup Microsoft requires now that plain username-and-password mail access is gone — and attachments arriving in that mailbox become documents automatically.**

The work splits in two: your Microsoft administrator creates an **app registration** (steps 1–2), then Content Central gets its four values (steps 3–4).

## Step 1: Register an application in Microsoft Entra

In the Microsoft Entra admin center, create an **App registration** for Content Central's mailbox access. Content Central uses the app-only ("client credentials") sign-in style, which means:

- **No redirect URI is needed** — leave that blank.
- The registration needs **application permissions** (not delegated) for reading mail — and mail *modify* rights if you'll turn on delete-after-capture below.
- An administrator must **grant admin consent** to those permissions — without consent, the connection test fails no matter what you type.

Then create a **client secret** for the registration and copy its value immediately (Microsoft shows it once).

Collect three values: the **Directory (tenant) ID**, the **Application (client) ID**, and the **client secret**.

> **IMPORTANT:** The client secret has an expiration date you choose at creation. Calendar it — when it expires, email capture stops with login failures, and the fix is a new secret pasted into the job.

## Step 2: Pick the mailbox

Decide which mailbox the job reads — a dedicated address like `capture@yourcompany.com` works best. Content Central reads that mailbox's **Inbox** (folder selection isn't configurable), so keep the mailbox single-purpose.

## Step 3: Create (or open) the email capture job

Capture jobs live in the **Catalog Manager** application on the Content Central server:

1. Open **Catalog Manager**, select the catalog, click **Modify...**, and go to the **Capture** tab.

2. Click **Add...** for a new job — or **Edit...** to convert an existing IMAP/POP3 job.

3. On the **General** tab: name the job, pick the **Document Type**, and set **Capture Source** to **Email**.

## Step 4: Enter the Microsoft 365 connection

On the **Details** tab, under **E-mail Server Settings**:

1. Set **Server Type:** to **OAuth2**. (On an existing IMAP or POP3 job, this is the whole conversion — the hostname/port/password fields disappear and the OAuth2 fields appear; everything else about the job is untouched.)

2. Set **Provider:** to **Azure**, then fill the four fields:
   
   | Field | Value |
   |---|---|
   | **Directory Id:** | The Directory (tenant) ID from step 1 |
   | **Application Id:** | The Application (client) ID from step 1 |
   | **Client Secret:** | The secret value from step 1 |
   | **Username:** | The mailbox address from step 2 |

3. Decide **Delete message after capturing:**
   - **Unchecked** — the job captures **unread** messages and leaves them in place (already-read mail is ignored).
   - **Checked** — every processed message is deleted. The dialog makes you confirm: "I understand all messages will be deleted."

4. Click **Test Server Settings**.

**What you should see:** "Test Succeeded." with a message count. "Could not login" means the IDs/secret/consent from step 1 need rechecking; "Could not connect" points at the server-side network.

*[Screenshot: The Capture Job Details dialog with Server Type OAuth2 and the Azure fields filled, after a successful Test Server Settings]*

## Step 5 (optional): Capture email details as field values

The **E-mail Field Settings** section maps message metadata — **From address**, **Subject**, **Date/Time**, **Body**, and more — onto the document type's fields. Two checkboxes change what gets captured: the email **message itself** instead of attachments, or the email **and** its attachments together.

Click **OK** and save the catalog.

## Step 6: Prove it

Send a test email with a PDF attached to the mailbox, as **unread** mail (don't open it first if delete-after-capture is off).

**Success check:** within a couple of minutes the attachment appears as a document in the Coding Queue or catalog. Remember the capture rule: one document can't span multiple emails.

## If capture stops working later

The usual culprits, in order: the **client secret expired** (step 1's calendar note), the mailbox password-style settings were "cleaned up" in Entra, or admin consent was removed. Re-run **Test Server Settings** — it tells you which side is failing. Then see [Capture documents sent to email](/content-central/capture/capture-documents-sent-to-email) for the day-to-day mailbox behaviors.

## What's next

- [Capture documents sent to email](https://help.ademero.com/content-central/capture/capture-documents-sent-to-email)
- [How documents get into Content Central](https://help.ademero.com/content-central/capture/how-documents-get-into-content-central)
