Cookies

We use analytics to see how the site is used so we can improve it.

Skip to content
Renada

Empty that mailbox before you authorise it in HaloPSA

A step by step walkthrough for MSPs connecting a licensed Office 365 mailbox to HaloPSA, from app registration through to outgoing email defaults

10 December 2024 10 min watch Connor Fagan

The short version

This tutorial walks through connecting a licensed Office 365 mailbox to HaloPSA, covering the Azure app registration, API permissions, client secret, redirect URIs and authorisation flow. It also flags the setup steps that stop ticket loops and prevent a flood of tickets from an inbox full of old email.

What you'll take away

  • Four delegated permissions plus three mail scopes

    The Azure app registration needs email, offline access, openid and profile, then mail.read, mail.readwrite and mail.send. None of them require admin consent.

  • An empty inbox is not optional

    Authorising the application processes every email already sitting in that mailbox and turns each one into a ticket.

  • Client secrets expire, mailboxes fail silently

    A 730 day secret means diarising a renewal roughly two years out or the mailbox simply stops working.

  • Two redirect URIs, not one

    HaloPSA needs both the Azure auth and account Azure response URLs added under the web platform in the app registration, copied from the HaloPSA API integration page rather than typed from memory.

  • Vanity URLs break the redirect if you slip

    If you have a CNAME set up but log in via the default halopsa.com address, certain integrations start breaking, so the redirect URI has to match whichever domain you actually authenticate against.

  • Turn off acknowledgment emails during first setup

    Switching acknowledgment emails off while a backlog processes, then turning them back on, avoids sending a flood of thank you replies for old email.

Key insights from the episode

  1. Add a dynamic email exclusion for your own helpdesk address to stop a ticket loop when staff email the mailbox themselves.

  2. Untick both web application options for sending emails and handling acknowledgment emails once the Azure app is authorised, so Azure handles delivery instead.

  3. Set the outgoing email default under Configuration, Email so system generated emails, like service catalogue items, have a defined sending mailbox.

  4. A ticket always replies from the mailbox the original email arrived on, unless you override that in outgoing email settings.

  5. Grab the application ID and tenant ID from the Azure app registration Overview page, not from certificates and secrets.

  6. Choose not set for the new user location setting if you want unmatched senders to land on the default site as an unknown user.

  7. Remove the default user.read permission from the app registration since a mailbox connection does not need it.

Questions people actually ask

How do I connect a licensed Office 365 mailbox to HaloPSA?

Go to Configuration, Email, Mailbox Setup in HaloPSA and create a new mailbox using Office 365 Azure as the type. You then register an application in portal.azure.com, add the required Microsoft Graph permissions and a client secret, and paste the application ID, tenant ID and secret back into the HaloPSA mailbox record.

What Azure permissions does HaloPSA need for a mailbox?

Under delegated permissions for Microsoft Graph you need email, offline access, openid and profile, plus mail.read, mail.readwrite and mail.send. None of these require admin consent in Azure.

Why did HaloPSA create tickets from every old email in my mailbox?

Authorising the Azure application processes the entire existing inbox and turns each message into a ticket. Empty the mailbox before you click authorise, or you will get a large unwanted backlog of tickets.

What redirect URIs does HaloPSA need in the Azure app registration?

You need the Azure auth URL and the account Azure response URL, both added as a web platform in the app registration. Copy these from the HaloPSA API integration page in HaloPSA rather than guessing them, since a mismatched vanity URL can break the integration.

How long does a HaloPSA mailbox client secret last?

In this walkthrough the secret was set to expire after 730 days. Whatever expiry you choose, put a reminder in your diary near that date, because an expired secret means a failing mailbox in HaloPSA.

How do I stop a ticket loop when someone emails my own helpdesk?

Add a dynamic email exclusion in Configuration, Email for that address. Excluded addresses will not be emailed new tickets or added to email lists, which stops the loop.

Should I turn on acknowledgment emails immediately when setting up a HaloPSA mailbox?

No, leave acknowledgment emails off while any backlog of existing mail processes into tickets, then switch the setting back on. Turning it on too early sends thank you emails for old messages that should never have generated a reply.

Full transcript

1,785 words

Read full transcript

Hello, good day, how are we doing? I am going to do a short video hopefully on how to set up a mailbox in Microsoft 365 into HaloPSA. I will do a second video which will be the shared mailbox. For today I'm just going to do a static licensed mailbox and show you how to set that up within HaloPSA.

So a few things before we get started. You're obviously going to require admin access to HaloPSA. You're also going to require access to portal.azure.com, which has just been renamed or there's an additional page now which is Entra ID. And I think that should be it. So let's get started.

So in Halo, go to configuration, go to email, and then go to mailbox setup. What we're going to do is we're going to click new in the top right. I'm actually going to give this a name. So I'm just going to call this YouTube mailbox. Okay.

Then what we're going to do is select Office 365 Azure. And you'll see here that we need an application ID, a tenant ID, and an application secret. This is a Microsoft 365 app registration.

So this is where we need to spin into portal.azure.com. Once we're here, what we need to do is basically click new registration and give this a name. I'm going to call this HaloPSA YouTube mailbox.

And we're just going to click register. We will fill out the redirect URI later, but for now we're just going to move past it and we're going to click register.

Then we're going to go to API permissions on the left-hand side. I'm just going to remove this user.read as we don't need it. And then we're going to add some permissions.

We're going to select Microsoft Graph in the top right and then select delegated permissions. We're going to need these four here, which is email, offline access, openid, and profile. And then we're going to need a few more for the mailbox. So we're going to do mail.read, mail.readwrite, and we're going to do mail.send.

So we couldn't see that before. And then we're going to do app permissions. And as you see, none of these require admin consent. So that is all we need to do to set that up.

Next, we need to go into certificates and secrets and create a new client secret. And we're going to give this a name again: HaloPSA YouTube video mail secret. That is a mouthful. Expires, I'm going to select 730 days. This doesn't really matter when you set this, just bear in mind it will expire. So you'll have to refresh that client secret. If you do select two years, I would put a note in your diary for 720 days time to make sure you come in here and refresh the secret. Else you will have a failing mailbox.

And we're just going to click add. What we can then do is basically grab the value from here and copy this directly into the Halo secret box, which is down here.

They need to grab our tenant ID and our application ID. So overview, we need our application client ID, which is this top one here, which is the application ID. And then we need the tenant ID here, which is the tenant ID here.

And then we can go ahead and do a few more settings down below. The first option here is saying when an email comes in, what ticket do you want it to make? So I'm just going to select incident because that is the most common ticket type we use.

And I'm going to say send acknowledgment emails: yes. This basically means if someone emails this inbox and it gets processed, do they get a thank you for logging your ticket email?

And I'm just going to basically click save. If the user isn't found in your Halo environment, you can tell them to be created in a set location. I'm just going to do not set, which will basically mean the default site and user is unknown, unknown. And I'm going to go ahead and click save.

Now I mentioned earlier we need to go ahead and do our redirect URI. So we're going to do add redirect URI. We're just going to click add a platform here and then we're going to do web in the top right-hand side.

We then need redirect URIs. Now the best way to know what these are is if you go into Halo, it's going to open another page very quickly. Go down to Integrations and find HaloPSA API.

You will find your authorisation server, which is here. So I'm going to grab that. I'm going to copy that into here. So we need two for this one. I'm just going to pull the guide up very quickly so you know where I'm getting this information from.

I will also link this guide in the comment section below. So just going to type in Azure mail and then we're going to find Azure mail here. So the two we're looking for is Azure auth and also the account Azure response. Now the reason I say get that URL is just so you know you're definitely using the right one.

There was this like caveat with this one. If you do have any vanity URLs, but you do log in with your dot halopsa.com one, it will start breaking certain integrations. So just make sure if you do have a CNAME setup that you are setting that up correctly as the redirection URI points back to that. You can add in your dot halopsa.com as a tertiary one as well, but for now we're just going to make sure that we have these. So we need Azure slash auth. So if we go to here, we get rid of the auth and just do Azure forward slash auth. I'm just going to select both of these boxes down here and click configure.

And we're going to go and add one more in here. We're going to type in the same URL again. And this time we're going to do account Azure response and paste that over here.

Then we're going to go ahead and click save. And that is, if I just refresh that, should hopefully be saved: yes, Azure auth, Azure auth, and account Azure response.

What I need to do is go back to Halo. Sorry, too many tabs open here. Let me get rid of this one. And we need to authorise our application. So what this is saying for this mailbox is we need to log in with the account that we want to use to basically have the emails coming in and going out with.

Now there's a slight caveat here, and that is it will process every single email in your inbox and create a ticket for it. So before you go ahead and authorise this application, please make sure that mailbox is empty. If not, you're going to have a field day. And I do recommend as well, initially just turning off the new acknowledgment emails when you're obviously setting this up for the first time. Let your emails processing come in, in case you do have any backlog, and then turn this setting on.

But essentially all you need to do is click authorise Azure application. And it's even a pop-up. Now this mailbox is the user that you sign in, we will have their inbox processed by HaloPSA.

I'm just going to sign in with my email address for now. Consent and accept. And there we go, that's the mailbox setup.

There is a few additional steps that I like to do. So I'm just going to grab my Renada email address and I'm just going to go back to the email page. That's configuration, email. And I'm going to add a dynamic email exclusion.

These email addresses will not be emailed new tickets or added to email lists. This basically means you won't get yourself in a ticket loop where if someone happens, if you happen to email your own helpdesk, you can keep generating tickets. So I'm just going to add in a dynamic email exclusion. I'm going to click new in the top right and I'm just going to paste in that email address here.

I want to go back to this email page and scroll down. And you also want to make sure that you untick both of these boxes: allow the web application to handle the sending of emails and allow the web application to handle the creation of acknowledgment emails. Untick both of those.

And then there's one final step. What you'll need to do is go into Halo. Hold on a second, I've just realised that I've set up my email and that's turned on. That could be bad, okay.

And let's just go back here. And then you want to set up the outgoing email defaults. So click on this. Then you can select the mailbox that you want to use as your primary outgoing mailbox.

Now the way Halo works is if a ticket or an email comes in on a certain mailbox and you reply, it will always reply on that mailbox unless you override that. This is for when you create outgoing email by default from the system, such as service catalogue items, or you just do a send an email button.

And that is how to set up a licensed mailbox in Microsoft 365 into HaloPSA. I've been Connor, have a lovely day, and I'll catch you all soon. Bye.

You know your shit! You've gotten me to a point in my setup with HaloPSA that multiple other consultants promised, but never delivered on. You delivered!
Leet Services LLC Google Logo

Our Core Services

Offering support to enable sustainable success for your organisation.

Consultation Harness the transformative potential of an agnostic advice tailored to your unique business needs. From PSA implementation to ongoing support, our exceptional consultation services pave the way for extraordinary success. Find out more
Virtual Admin Let us handle the technical heavy lifting. Our expert team builds solutions, creates powerful reports and dashboards, and develops automated integrations - giving you more time to focus on what matters most: your clients. Find out more
Product Onboarding We understand that the first steps in adopting a new product can be daunting, we are here to guide you through every stage of the process with precision and clarity. From initial setup to advanced features, maximise the value of your product from day one. Find out more
Virtual Chief Technology Officer (vCTO) Benefit from a remote and adaptable technology expert to seamlessly combine strategic guidance and effective leadership to propel your business to new heights and empower your organisation’s technology ability. Find out more
Where to next? Get the cutting-edge tools to support your MSP business. Contact us today to receive a bespoke quote tailored to your specific needs.