Cookies

We use analytics to see how the site is used so we can improve it.

Skip to content
Renada

The setting that empties a shared mailbox the moment you authorise it

A step by step guide for MSP admins connecting an Office 365 shared mailbox to HaloPSA without losing existing emails or getting stuck in ticket loops

10 December 2024 10 min watch Connor Fagan

The short version

A walkthrough of connecting an Office 365 shared mailbox to HaloPSA, from creating the Azure app registration through to setting redirect URIs and authorising the connection. Covers the permissions you actually need, the settings that stop ticket loops, and a warning about what happens to existing mail in the inbox.

What you'll take away

  • Authorising the mailbox pulls every email out of it

    HaloPSA processes and deletes every message in the inbox the moment you authorise the connection, so make sure the shared mailbox is empty first.

  • Two redirect URIs, not one

    The app registration needs your HaloPSA URL appended with azure/auth and account/azure response, both added under Web platform in Azure.

  • No admin consent required

    Unlike some Azure integrations, this app registration does not need admin consent granted for the permissions to work.

  • Shared mailboxes have no licence, so someone else has to vouch for them

    You authorise the connection using a licensed 365 account that has read, manage and send as permissions on the shared mailbox.

  • Set a 24 month reminder for the client secret

    Client secrets expire. Put a note in your diary to refresh it before that date or the mailbox connection stops working.

  • Dynamic email exclusions stop help desk loops

    Excluding the help desk address itself from new ticket notifications prevents HaloPSA emailing itself into an endless ticket cycle.

Key insights from the episode

  1. Remove the default User.Read permission from the app registration since the shared mailbox setup does not need it.

  2. Add the delegated Microsoft Graph permissions email, offline_access, openid, profile, Mail.Read, Mail.ReadWrite.Shared, Mail.Send and Mail.Send.Shared.

  3. Shared mailbox provisioning times can run long, so send a test outbound email from the mailbox before configuring HaloPSA.

  4. In Microsoft 365 admin centre give a licensed user read and manage plus send as permissions on the shared mailbox before authorising in HaloPSA.

  5. Setting the new ticket type to Incident controls what ticket type is created from inbound mail to that mailbox.

  6. Turn off ticket acknowledgment emails on the mailbox setup page if you do not want automatic replies sent from that inbox.

  7. In Configuration, Email, turn off allow the web application to handle sending of emails and handle acknowledgment emails at the bottom of the page.

  8. Overriding the default site and user controls what HaloPSA does with mail from addresses it cannot match to an existing contact.

Questions people actually ask

How do I connect a shared Office 365 mailbox to HaloPSA?

Go to Configuration, Email, Mailbox Setup in HaloPSA and create a new mailbox using the Office 365 Azure option, then supply the shared mailbox address, Azure tenant ID, application ID and client secret from an Azure app registration. You then add two redirect URIs in Azure and authorise the connection using a licensed 365 account with permissions on the shared mailbox.

Why does my HaloPSA shared mailbox lose all its existing emails?

Authorising the mailbox connection in HaloPSA causes it to process every email currently sitting in the inbox into a ticket and then delete it. Empty the shared mailbox before you authorise it in HaloPSA to avoid losing mail or flooding your helpdesk with historic tickets.

What Azure permissions does HaloPSA need for a shared mailbox?

You need the delegated Microsoft Graph permissions email, offline_access, openid, profile, Mail.Read, Mail.ReadWrite.Shared, Mail.Send and Mail.Send.Shared. Admin consent is not required for these to work.

Why can't I authorise a shared mailbox directly in HaloPSA?

A shared mailbox has no licence of its own, so it cannot authenticate. You authorise the connection using a licensed 365 account that has been given read, manage and send as permissions on the shared mailbox in the Microsoft 365 admin centre.

How do I stop HaloPSA creating duplicate tickets from a shared mailbox?

Add a dynamic email exclusion for the mailbox address itself under Configuration, Email. This stops the address being emailed on new tickets or added to email lists, which is what causes a helpdesk address to email itself into a repeating ticket loop.

What redirect URIs does HaloPSA need in the Azure app registration?

Add your HaloPSA URL appended with azure/auth as one Web redirect URI, and account/azure response as the second. Both need adding under the app registration's Web platform in Azure before authorisation will work.

How long does a HaloPSA Azure app registration client secret last?

You choose the expiry when creating it, and the video sets it to 24 months. Put a reminder in your diary to refresh the secret before it expires, otherwise the mailbox connection in HaloPSA stops working.

Full transcript

1,999 words

Read full transcript

Hello, let's get this rock and rolling. I have just done a video on how to set up a licensed mailbox and I'm now going to do a video on how to set up a shared mailbox.

So we need access to a few things before we start this video. You obviously need access to HaloPSA and you need to be an admin so you can access configuration. You're going to need access to portal.azure.com to create an app registration and you're also going to need access to admin.microsoft.com so you can create a shared mailbox and set up the permissions correctly.

I'm going to get that loaded very quickly now. Admin.microsoft.com. Just going to sign in and then let's get this started.

So in HaloPSA go to configuration, go to email and then go to mailbox setup. And in the top right go ahead and click new. I'm going to call this YouTube shared. Oh, if I could type YouTube shared mailbox. And then I'm going to select Office 365 Azure.

You're then going to see you need a few things. You need the shared mailbox with the FQDN, which is fully qualified domain name, the Azure tenant ID, the application ID and the secret value. All of the app registration we're going to make on Azure right now. So go ahead and navigate to portal.azure.com.

And if you don't know how to do this you basically go to here and click on Azure Active Directory. If you don't see it, type in Azure Active Directory. Azure Active Directory, click on this and then click on app registrations on the left hand side.

We're going to go ahead and make a new one. We're going to call this YouTube HaloPSA shared mailbox. And we're just going to go ahead and click register in the bottom left. My little face is just about covered that up but go ahead and click register. We will add the redirect URIs in a few minutes.

Then we need to go to API permissions and we need to remove user.read as we don't require it. Yes, remove. And then we're going to add some permissions so click on add permissions. These are Microsoft Graph, so the big one at the top, and these are delegated permissions.

This time we need email, offline access, openid and profile. And then click in the box and type in mail.read and we're going to need mail.readwrite.shared. And then type in mail.send.

Mail dot send. And then we need mail.send.shared and then click add permissions.

There we go. And we do not need to grant admin consent because it is not required.

Then we need to go to certificates and secrets on the left hand side and click a new client secret. And I'm going to call this YouTube HaloPSA shared mailbox.

Now this expires in, I'm going to select 24 months. Please make a note in your diary to go and refresh the secret. If not, it will expire and your mailbox will stop working.

Then go ahead and click add. What we can then do is basically grab this value, which is the middle one, copy it to clipboard and then paste that into the Azure application secret in HaloPSA.

We can then click overview in the top left and grab the application client ID, paste that into the application ID here. Then we need to grab the tenant ID, which is the bottom one, and paste that into the Azure tenant ID at the top.

Then we need to jump into 365 admin, which is the fourth tab over here, and go to teams and groups and then shared mailbox.

Now I'm going to be using the HaloPSA shared mailbox that I've already created. Just bear in mind if you're doing this, I've been seeing quite long provision times for shared mailboxes. So what I recommend doing after you've made it, before testing Halo, is just jump in the mailbox and check if you can send outbound mails from that mailbox. I've been seeing like post-on provision times recently which is not what I'm used to, but just a quick side note.

Um, once you've made this, there's something else you need to do and it's important that you do it in here. So you need to make sure you have the top two permissions set. And obviously you can see here I have my email address which is kind of renada.co.uk. I need to make sure you have send as permissions as well.

Now because we're using a shared mailbox it doesn't have a licence. We need to basically authorise that with a licensed 365 account and in this instance I'm going to make sure it's me that is authorised in the mailbox. So I need to have these permissions.

You don't need any other permissions in here. The app will work correctly from this but this is just to basically get a provision into HaloPSA. And then you need to basically grab the primary fully qualified domain name at the top and paste that into the shared mailbox name in Halo and then go ahead and click save.

What you can do as a quick side note is you can edit the settings down below. So ticket type for new tickets, I'm just going to say incident. This basically means when an email comes into that mailbox and it gets processed into Halo, what ticket does it make? So I'm going to select incident.

And I'm just going to turn off ticket acknowledgment emails for now and because I don't want any emails that are in that inbox to be sent welcome emails. And just a note on that one by the way, when you enable this and authorise it it will pull every single email out of that mailbox. So please make sure that the inbox is empty. And there is a setting coming maybe after this video is out in a week or two where you can tell it to leave the mail in there but for now it will process every single email in that inbox and create a ticket in Halo and then delete it from the inbox. And just make sure your inbox is empty before you authorise this.

And overriding the default site and user, this basically means if the email address isn't found in your Halo what should it do with it? And there's a few ways you can handle this but this is basically saying if it's not set it will put them in unknown. Unknown. What some customers do is make them in their own tenants so they know to go and check it but again you could do not set and leave that as unknown and then go ahead and click save.

We've not quite finished though yet. We need to add in two redirection URIs. And what we need to do is just grab our Halo URL which is at the top. So mine is dot halopsa.com. If you do have a CNAME in place so you have vanity URLs then you will need to grab them instead of mine. And so that could be you know portal.yourbusinessname.com.

So go ahead and grab that and then jump back to portal.azure.com. On the right hand side on the overview page you will see add redirect URI. And we're going to basically click add a platform in the top left and we're then going to go ahead and click web.

We're going to need to add two in here. So copy this in here. And I did this in the last video as well. I'm going to show you where abouts I find these and I will put the link to this guide in the description as well. It kind of goes through this all in a bit more of a detailed approach but essentially you'll notice here that you need two redirection URIs.

So the first one is your URL appended with /azure/auth.

Oh long page. /azure/auth. And I'm going to select both of these down below. And then I'm going to add another one which will then pop up here. I'm going to copy that.

And this is /account/azure/response.

And again you can check that by going to that guide. And see here account is your response. I'm just going to paste that in there because my spelling can be sometimes slightly dubious. And then basically just click save in the bottom left.

It's going to cycle that page. Make sure that it is still there. Yep, they've both been saved.

And then we're about finished. So back into HaloPSA we need to authorise the application. You need to make sure you authorise it with the account that has the read and manage and send as permissions on that shared mailbox.

Consent on behalf and click accept.

And there you go, that is the mailbox set up. This side, email settings you need to make sure you've got turned on. Just go back to the configuration email root page and scroll all the way to the bottom.

What you'll want to make sure you do is select this box here: show the mailbox name instead of the email address. Um, that's just so it looks prettier essentially. And you can override that by the way by changing the name here if you want the name to be different, you can rename that there.

And you also at the very bottom again need to ensure you turn off these two settings: allow the web application to handle the sending of emails and allow the web application to handle the creation of acknowledgment emails.

Couple more things we need to do, or what I like to do, is add a dynamic email exclusion. So these email addresses will not be emailed new ticket emails or added to email lists. This can stop you getting in ticket loops where it's kind of emailing the same help desk, creating a ticket and then getting stuck in a cycle.

So just go ahead and click dynamic email exclusions. And you'll see here that um I've already added it but you just need to click new and type in that email address in that box and then click save.

And then finally, if you want to, back in email you can override the outgoing email default. You can select what mailbox you want to use as your primary. Just to note, any emails that come in from a mailbox you will by default reply from the email address. So if you have a sales ad you will reply from sales ad, but you can override this for new emails or um service items. If you're sending out bulk stuff like welcome emails and stuff it will use this mailbox unless overriding of course.

And that is essentially that. That is how to set up a shared mailbox in Office 365 and in HaloPSA. Hope that helps you. Any questions, let me know. Have a good day. Bye.

The Renada team is amazing.
Ashton Solutions Google Logo

Our Core Services

Offering support to enable sustainable success for your organisation.

Consultation Harness the transformative potential of an agnostic advice tailored to your unique business needs. From PSA implementation to ongoing support, our exceptional consultation services pave the way for extraordinary success. Find out more
Virtual Admin Let us handle the technical heavy lifting. Our expert team builds solutions, creates powerful reports and dashboards, and develops automated integrations - giving you more time to focus on what matters most: your clients. Find out more
Product Onboarding We understand that the first steps in adopting a new product can be daunting, we are here to guide you through every stage of the process with precision and clarity. From initial setup to advanced features, maximise the value of your product from day one. Find out more
Virtual Chief Technology Officer (vCTO) Benefit from a remote and adaptable technology expert to seamlessly combine strategic guidance and effective leadership to propel your business to new heights and empower your organisation’s technology ability. Find out more
Where to next? Get the cutting-edge tools to support your MSP business. Contact us today to receive a bespoke quote tailored to your specific needs.