Cookies

We use analytics to see how the site is used so we can improve it.

Skip to content
Renada

Setting up instant email processing in HaloPSA with webhooks

A walkthrough for MSPs on replacing HaloPSA's mailbox scan with webhook based email processing, plus a warning about the app permissions you create along the way

7 January 2025 16 min watch Connor Fagan

The short version

HaloPSA can now pull emails in and send them out instantly using webhooks instead of the old mailbox scan that ran every couple of minutes. This tutorial walks through enabling the beta settings, registering an app in Entra, setting the right Microsoft Graph permissions, and creating the mailbox subscription, plus a warning about how wide those permissions actually reach.

What you'll take away

  • Three tickboxes in advanced settings

    Scroll to the email section of advanced settings and enable the outgoing and incoming service beta options, ideally out of hours.

  • Webhooks replace mailbox scan

    The old method scanned the mailbox every couple of minutes. Selecting use web hooks on the mailbox setup makes processing instant instead.

  • You need an app registration in Entra

    Create a new app registration named for the purpose, then copy the application ID, tenant ID and a client secret into HaloPSA's mailbox setup.

  • Only two permissions required now

    Mail.ReadWrite and Mail.Send as application permissions, plus offline access as a delegated permission, is all Microsoft Graph needs.

  • New mailboxes do not backfill

    Instant processing only picks up mail arriving after setup. Anything already sitting in the inbox has to be pulled in manually with the import emails option.

  • HaloPSA can quietly read every mailbox in your tenant

    Application permissions mean the app registration can process any inbox in the tenant, not just the one you configured, unless you lock it down with an application access policy scoped to specific mailboxes.

Key insights from the episode

  1. Turn on outgoing service beta and incoming service beta in advanced settings, under the email section, out of hours.

  2. Disable an existing mailbox in email and mailbox setup before creating a new one configured to use web hooks.

  3. When creating the Entra app registration you no longer need a redirect URI.

  4. Application permissions required are Mail.ReadWrite and Mail.Send, plus offline access set as delegated, not application.

  5. Grant admin consent for the permissions in Entra before creating the subscription in HaloPSA.

  6. Turn off acknowledgement emails the first time you set up a mailbox in case a misconfiguration starts processing the wrong inbox.

  7. A new webhook mailbox only processes mail arriving after setup, so use import emails to bring in anything already sitting in the inbox.

  8. Application permissions let the app registration read and write any mailbox in the tenant, so restrict it with an application access policy scoped to the specific UPN.

Questions people actually ask

How do I enable instant email processing in HaloPSA?

Go to advanced settings, scroll to the email section, and tick the outgoing service beta and incoming service beta options. Then set up a mailbox under email and mailbox setup using the web hooks option instead of mailbox scan.

What permissions does HaloPSA need in Azure for instant email processing?

You need Mail.ReadWrite and Mail.Send as Microsoft Graph application permissions, plus offline access added as a delegated permission. Admin consent must be granted for these before HaloPSA can create the subscription.

Does HaloPSA instant email processing pull in old emails already in the inbox?

No, a newly configured webhook mailbox only processes emails arriving after setup, it does not scan back through existing inbox content. Use the import emails option to manually select older emails and turn them into tickets.

Is HaloPSA instant email processing safe to enable during working hours?

It should not break anything according to testing, but enabling it changes how inbound and outbound mail is handled immediately. It is safer to do it out of hours or on a weekend when the desk is not expecting live email traffic.

Can the HaloPSA app registration access mailboxes other than the one I set up?

Yes, because the permissions granted are application permissions rather than scoped to one mailbox, the app registration can read and write to any mailbox in the tenant. Set up an application access policy restricting the app ID to specific UPNs to prevent this.

Why would I disable the old HaloPSA mailbox before setting up instant processing?

The old mailbox scan method and the new webhook method are different setups, so the recommended approach is to disable the existing mailbox first and create a fresh one configured to use web hooks. This avoids running both methods against the same inbox.

Does instant email processing in HaloPSA actually make the service desk more efficient?

Not necessarily. The speaker found that near instant replies encouraged shorter, less detailed messages and staff subconsciously waiting for replies instead of moving on, which increased the number of emails needed to resolve a ticket.

Full transcript

3,397 words

Read full transcript

Connor: Processing email instantly, it's almost here. I'm going to be honest, as of today it's not fully here, but you know we're going to do it anyway. So with that being said, we're currently on, if you're on the stable version of Halo, instant email processing is in beta. But today is the 25th of March and that's going to change over the next week or two depending on the region you're in. Then you'll become to the new stable version of Halo which I believe is 2.43. Don't hold me to that.

And then instant email processing I believe should be off beta. And we've been using it for a couple of months now. It's been rocky, but I think everything's ironed out. So let's discuss how we can enable instant email processing. It is 10 times easier. It is B, 10 times better because we can see a log of it now, and um, oh yeah, it's instant. So let's do this, let's jump over to Halo.

Here we are, Halo. And let's get into this. So you want to start by going to advanced settings and you want to scroll all the way down this page until you find, um, oh let me just, uh, be me a second please. Let me just delete that, uh, until we find um email. And what yours should look like is probably something like this. So these three boxes won't be ticked.

Okay, um, I would now, if you're feeling brave enough, um, tick them all. But don't do it during your working day. Um, I don't think it'll break anything, but that's me thinking and we know how dangerous that is. Uh, please do this out of hours. Or you know, actually just do it out of hours. Or on a weekend or at a point when your desk isn't working or expecting inbound and outbound emails. I don't think enabling it will break anything, but um, thinking is dangerous as we've just established.

So um, I would now click every in here. Now you can click use the outgoing service beta at any point in your time, um, and it will work pretty much instantly. Um, and you will instantly have outgoing emails. Now I've had no problems with this at all. I don't think nope, at all. Um, the outgoing service beta, or the instant outbound has been working flawlessly for me and the incomings had a few issues, but I believe they've all been ironed out now.

But you're currently see that time sensitive processing is currently using the NHP server so you know it runs every two minutes. When we click use the incoming service beta we can then move to the webhook version of email which will mean we can then pull emails in via webhook instantly. So how do we do that? Well, what I recommend doing is going to email and mailbox setup. And if you have one in here I would disable it. So just click on the mailbox and click disable, and then make a new one. Once you're at that stage, click in the middle here or click new in the top right hand corner and type in a mailbox alias.

I'm going to make this. I'm not keep it as it is. I'm going to call this um, alerts. That's what I'm going to set up today. I'm then going to click Office 365 hyphen Azure. And I'm going to select use webhooks. So mailbox scan was the old method. It scanned it every few minutes. Now we're using webhooks, which basically means it's going to be instant. Then what we can do is we can go to portal.azure.com, click on Microsoft Entra and click app registrations on the left hand side.

If you've already got an application that's fine, um, we can just leave it there for now, um, and I like to do this with a bit resiliency. So we're going to click on new app registration. And I'm going to give this a name of HaloPSA instant email processing. What a day to be alive. And then we're going to click register. I don't think we need a redirect URI at all anymore, um, so we'll just click register and we'll do this together.

Then I'm going to copy the application ID from the top and spin back over here and pop that in the Azure application ID box. I'm then going to go to the um, tenant ID, which is the bottom one. So directory tenant ID, copy that and post that into the Azure tenant ID uh box. Then I need an Azure application secret. So to do that I'm going to go over to certificates and secrets. I'm going to click a new one, give this a name. I'm going to do the same thing: HaloPSA instant email processing. And I'm going to go press add.

And what you want to copy is the value from this, um. I don't think you can see the value, but if for whatever reason I leak it I'm going to delete this after this video. So you unfortunately can't process my dev alert tickets. I know it's a sad day. Um, then we need to add in the email address that we want to pull the emails, you know, in from and send from. Um, again be really careful with this. If you type in your own like a silly sausage you will start processing your own emails inbound and outbound.

And I'm just going to go over here and copy my UPN. So this is by the way a shared mailbox as we can see over here, shared mailbox. Um, and I'm just going to actually, um, actually don't think it matters at all, um, yeah, so there's no I don't think you require any permissions anymore for this. I'm going to remove these. This is a dev environment, but I don't think we need the senders and receivers anymore at all.

Okay, I guess, I guess wants to remain on here forever. Come on Alex, it's time to go mate. Oh okay, there's clearly some little UI bug with this. Three hours later, Connor still deleting people. There we go. So I don't think we need any permissions on here. Again, if you are using this in production and there is permissions on there, don't just go ahead and delete them willy-nilly. But if you only had them in here because of the old method then you can probably safely delete them.

Um, again save this for a later period in time. So I going to copy that UPN, m is alerts at TRN cn.microsoft.com. This is a dev instance. And then the final piece of this little puzzle is to make the API permissions that we require. And again, they're so much easier now. So go back over to um, Azure AD, Entra, sorry, go back over to Entra, click on API permissions. And you can remove user.read. We don't require that in here.

The two or three we do require, the first two when we click add permission and then Microsoft Graph, are going to be application permissions. And what we need, if we look over here, is mail.read write. So we can go over here. I'll close that screen. We need mail.read write, this one here. We need mail.send, this one here. Now it also says offline access, but I'm pretty sure that's a delegated permission, pretty sure it's not an application permission, so just ignore that for now and click add permission.

And we're going to add another permission and I'm going to add delegated for offline access, add permission. Then what I'm going to do is I'm going to grant the admin consent for these, and I think that is it done. So mail.readwrite, mail.send, both application permissions. Offline access being delegated. We can go back over here. We can select what ticket type we want to make for these, and again I always advise the first time you're set up any mailbox just turn off the acknowledgement emails for now now, because if you do make a mistake and it does start processing them into your desk, at least you're not going to be spamming your customers saying thank you for logging your ticket.

So unselect that and go ahead and press save everything out should be fine. I'll let you in your own time read through what they are. Then what we can simply do is click create subscription. Now, if there have been any issues, this subscription won't create. However, there's that few pieces of the puzzle. Now this should be fairly straightforward and you'll see it makes a subscription. This does update, so don't panic you've not got to go in here every three days and update this. This will continue to change over the course of forever really.

Um, one thing to note though, if this is a new mailbox, um, the way this works now is it literally pulls them in and outbound as they're coming in and outbound of the mailbox. It doesn't go back through a mailbox and pull them all in. So if you do have mail in the inbox that you want to get into your desk as tickets, you'll have to click import emails, select the emails in the inbox that you want to create tickets for, and then go through this process manually.

But with that being said, what we can now do is go to service desk, click new. I'm going to click send an email. If you don't have this button enabled, just make a ticket. I'm going to email from the mailbox I've just set up as instant processing. I'm going to email it to myself, so Connor at Renada. And I'm going to put hello this is from YouTube. It's obviously not from YouTube, but this is a YouTube one.

What I'm going to do is grab this email over here. And there we go, hello, this is from YouTube. How fast was that? I'm then going to click reply and go wow, that was super fast. And click send. And then going to sit in all of my tickets. We're currently at 28. I'm going to refresh. I'm going to refresh anyone got a stopwatch? Anyone got a stopwatch? Come on, we've got this, doing this real time for you all. Watch it not working. I broke something. I have to re-record this again. Classic Connor. How instant is it going to be? There we go, look at that.

And there we go, wow, that was super fast. And it's still 10:39. So there you go, my name isn't Jeff, it's Connor. But that is it. It's a good day in the Halo world as we now have instant inbound and outbound email.

Um, there's a few things though you must remember to be conscious of. Um, the first thing is, actually, is actually a win. We now have the inbound and the outbound log on the mailbox, so we can literally see what's coming in and what's going out. Again, I ran a test before this video, um, but this is fantastic. So we can now see, did the email actually send from this mailbox from within Halo? Yes, it can. This shouldn't be revolutionary, but it is for us.

All right. Um, so we can see the log. We can say yep, it delivered. We can see, you know, how many attempts it had, um, and if it broke or not. We can also go down to uh, advanced settings, scroll all the way down to the bottom when this page wants to load and click on the backend service monitoring. And we can then see the outbound and inbound log for all mailboxes or webhooks or whatever you want.

Um, so this is also really epic now. This is just, you know, this has been here for a while, the event service. But um, it's, it's just, it shouldn't be this revolutionary for resing some of the things we do in Halo. But it is. Um, and the final thing is um, we have to really be conscious of what we've just done here. So we've basically set up um, an app registration inside of Office 365 or Azure or Entra, whatever you want to call it, um, and we've made them application permissions.

Um, what that means is I could type in any email address of my tenant in here and this will process their inbox, both inbound and outbound. Um, Halo's guide, which I'll put in the description, actually touches on this, which is fantastic. Um, and the suggestion is you can see in my address bar is to limit the application permissions to a single or multiple mailboxes. Um, again I will link this down below as well.

Um, this isn't really a concern of mine. If if one of my staff want to process my mailbox inbound and outbound, I have bigger problems at hand, such as how quickly do I need to sack them. I'm joking, I wouldn't do that. I love Robbie too much. But um, again, security conscious, you can set up um, an application access policy to say um, from this app ID. So uh, overview, so from this application ID, only allow that to interface or process emails from this UPN address. Um, which again just, you know, restricts that application down. Because if not, this application can read and write to any mailbox in your environment.

Um, again, I'll document this below, but there it is. This video is 12 minutes long. I've rambled as always. Um, this is inbound and outbound processing. Um, hopefully in the next couple of weeks, so post the 25th of March, the verbage should change from saying incoming service beta to just incoming service. Um, and there we go.

Um, I'm pleased I could do this video. Um, I'm pleased it's finally out. If you do have any problems with this, please do let me know. Um, but I think it is pretty, pretty straightforward now. And um, yeah, it's a bit of a game changer. I will just add one thing at the end. So if you have made it this far, um, I really do appreciate you. Please do like, subscribe, comment, all that YouTube crap. Um, but there is something I want to touch on, and that's um, behavioural changes I've witnessed since doing this.

So, as you're probably aware, the old method was, you know, maximum it would take is two minutes. Um, on average it would take a minute for an email to come in and then an email to go out. So again, you could be in the worst situations be waiting four minutes from the email coming in and you sending out, which is quite a long time really.

However, we've kind of adopted or I don't know, self-material way of working with Halo is I will send an email and I will move on to the next thing, um, and I'll come back once they reply, which could be four minutes at best or two minutes at best. But again, typically because of a delay, you know, every twenty, half an hour, whatever your replies are. Um, with this new processing though, what I've discovered is, is my behaviour has changed a lot, and the way I work with tickets now, and and there's two things that I've really noticed in the way we work is firstly, our responses, because they can be instant, you know, we can almost converse over a ticket now. Um, our details gotten really bad, um, you know, we'll type something like can you give that a quick test for me? And then wait for the response to come back. Um, and the detail has not always been as robust as it once was because we know we can conversationally fix the problem.

We might not ask can you tell us these three things. It might be is it this? No, is it this? No. Um, another problem I found, but touching on that is I'm now waiting for replies, um, subconsciously waiting for replies. So you know, I might, if someone emails in and I'm hot off the press and email back straight away, I'll kind of sit and wait for their response to come back in. Um, it's actually made us less efficient. Instant email processing, honestly, um, and it has reduced the quality of our responses.

Um, it's something we're addressing personally, of course. And again, it's going to have to be a training thing or definitely keep an eye on it. Um, one of the things that I would probably look at doing is writing a report to see um, up until this day, how many emails has it taken us to, you know, um, fix a problem, and then do the process in a month? Because what I think is going to happen when everyone knows this is, I think your email outbound is going to go up quite a bit, and which isn't a positive thing, right? It means taking more time typically to resolve a problem. Um, again, it's just an observation. I'm not saying this will be the same for everyone.

It certainly is for us, and you know, we try and be super quick and try and get out super fast and help as much as we can. But it's actually had the, you know, as I mentioned, the reverse effect. So um, yeah, just an interesting one for you to think about really, and something to keep an eye on. Um, but yeah, that's that's it. That is instant email processing. If you made it this far, I really do appreciate you. Um, thank you so much for the support over the past year. It's been absolutely phenomenal. Our growth on YouTube and socials has been huge, as well as the business. So again, I owe that all to you watching this video right now. You really do motivate me to get these out.

I've been Connor Fagan. We are Renada Solutions. I hope you have a fantastic day and I hope this changes your life. See you all soon, bye-bye.

Working with Renada on our HaloPSA setup has been an absolute blast. Right from the get-go, they felt more like friends than just another service provider. They took our initial concept and turned it into a fully operational PSA system in less than a month.
Wendego Google Logo

Our Core Services

Offering support to enable sustainable success for your organisation.

Consultation Harness the transformative potential of an agnostic advice tailored to your unique business needs. From PSA implementation to ongoing support, our exceptional consultation services pave the way for extraordinary success. Find out more
Virtual Admin Let us handle the technical heavy lifting. Our expert team builds solutions, creates powerful reports and dashboards, and develops automated integrations - giving you more time to focus on what matters most: your clients. Find out more
Product Onboarding We understand that the first steps in adopting a new product can be daunting, we are here to guide you through every stage of the process with precision and clarity. From initial setup to advanced features, maximise the value of your product from day one. Find out more
Virtual Chief Technology Officer (vCTO) Benefit from a remote and adaptable technology expert to seamlessly combine strategic guidance and effective leadership to propel your business to new heights and empower your organisation’s technology ability. Find out more
Where to next? Get the cutting-edge tools to support your MSP business. Contact us today to receive a bespoke quote tailored to your specific needs.