Exchange Server (On-Premises): Connecting Your Mailboxes to Captured Knowledge
As of: 29 September 2026
Time required: approximately 30 minutes
Who this article is for: IT administrators of organisations running their own Exchange Server (Subscription Edition, 2019 or 2016) who are connecting their mailboxes to Captured Knowledge (CK). Exchange Online (Microsoft 365) has its own guide.
Expected results: Captured Knowledge accesses exactly the mailboxes you put into one group, through Exchange Web Services (EWS) with a dedicated service user — following the principle of least privilege.
The steps below can be done either in the Exchange Admin Center (EAC) or in the Exchange Management Shell. We give the commands for reference. Please note that they must be run in the Exchange Management Shell — a regular PowerShell session does not have the required Exchange cmdlets.
Overview:
Choose the target mailbox: an existing mailbox becomes the central point of the integration with Captured Knowledge.
Create a dedicated service user: a user created only for our application.
Assign
ApplicationImpersonation: the service user may act as the target mailboxes.Assign "Send As": the target mailbox may send email with other users' addresses.
Find the EWS URL: the external URL of Exchange Web Services.
Firewall: if needed, allow access from our IP address.
Adjust the EWS throttling policy (optional): connection limits for the service user.
Verify the configuration.
Send us the details: over a secure channel.
Step 1: Choose the target mailbox
The integration needs a mailbox that serves as the central collection point for emails Captured Knowledge should process. Usually this is an existing mailbox (for example a shared or functional mailbox) your team already uses for this purpose. Please decide together with your team which mailbox to use.
Below, [email protected] stands for this mailbox's email address.
If you wish, Captured Knowledge can also read further mailboxes, such as individual staff members' personal mailboxes — see steps 3 and 9.
Step 2: Create a dedicated service user
The integration needs its own service user with an Exchange mailbox. This ensures the access is used only for its intended purpose and is clearly traceable.
Run the following command in the Exchange Management Shell. Replace captknowledge and yourdomain.com with the values for your environment.
$password = Read-Host -AsSecureString "Please enter a secure password for the new service user 'captknowledge'"New-Mailbox -Name "captknowledge" `
-UserPrincipalName "[email protected]" `
-Password $password `
-DisplayName "Captured Knowledge Service User"
New-Mailbox creates both the AD user and an Exchange mailbox in one step. The mailbox is not actively used — but Exchange requires a mailbox for the service user so that the ApplicationImpersonation role can be used.
Recommended hardening of the service user: since this user is intended only for programmatic EWS access, we recommend disabling unneeded access protocols and hiding the account from the address book:
Set-CASMailbox -Identity "captknowledge" -OWAEnabled $false -ActiveSyncEnabled $false -PopEnabled $false -ImapEnabled $false Set-Mailbox -Identity "captknowledge" -HiddenFromAddressListsEnabled $true
Step 3: Assign ApplicationImpersonation through a group
For our service to access the intended mailboxes, the new service user needs the ApplicationImpersonation role. It lets the service user act on behalf of another mailbox without knowing its password.
We control access through a security group, so you can manage access simply by adding mailboxes to or removing them from the group.
Note: the scope covers only direct members of the group. Nested groups are not supported — every mailbox must be added as a direct member.
If your organisation wants Captured Knowledge to read further mailboxes as well (for example individual staff members' personal mailboxes), add them as further direct members of the same group — no extra credentials or configuration are needed. Captured Knowledge reads and tags such mailboxes and transfers relevant emails into the target mailbox; by default the original then goes to the mailbox owner's Deleted Items (on request it stays where it is, tagged, instead). Captured Knowledge sends no email from these mailboxes (the "Send As" permission in step 4 is independent and only relevant for addresses Captured Knowledge should send as).
Create the group and assign the permission: run the following commands in the Exchange Management Shell on your Exchange Server. Replace CK_Integration_Mailboxes with your preferred group name, [email protected] with the target mailbox from step 1 and captknowledge with the service user from step 2.
# Create the security group New-DistributionGroup -Name "CK_Integration_Mailboxes" -Type Security# Add the mailbox to the group Add-DistributionGroupMember -Identity "CK_Integration_Mailboxes" -Member "[email protected]"# Resolve the group's distinguished name $DG = Get-DistributionGroup -Identity "CK_Integration_Mailboxes"# Assign the "ApplicationImpersonation" permission New-ManagementScope -Name "CapturedKnowledgeScope" ` -RecipientRestrictionFilter "MemberOfGroup -eq '$($DG.DistinguishedName)'" New-ManagementRoleAssignment -Name "CapturedKnowledgeImpersonation" ` -Role "ApplicationImpersonation" ` -User "[email protected]" ` -CustomRecipientWriteScope "CapturedKnowledgeScope"
Step 4: Grant "Send As"
Captured Knowledge processes emails through the target mailbox (step 1) but sends replies with the sender address of the responsible user (for example a case handler). For this, the target mailbox needs the "Send As" permission for those users' mailboxes.
Background: the ApplicationImpersonation permission lets the service user access the target mailbox. Sending an email from there with a different sender address (another user) additionally requires "Send As".
Run the following command in the Exchange Management Shell for each mailbox that should receive this permission:
Get-Mailbox -Identity "[email protected]" | Add-ADPermission -User "[email protected]" -AccessRights ExtendedRight -ExtendedRights "Send As"
Note: replace [email protected] with the address of the user's mailbox and [email protected] with the target mailbox from step 1. Add-ADPermission -Identity does not accept an email address, so the mailbox is passed in with Get-Mailbox.
Step 5: Find the EWS URL
Our application needs the external EWS URL of your Exchange Server. It is usually https://mail.yourdomain.com/EWS/Exchange.asmx. You can check the exact URL in the Exchange Management Shell:
Get-WebServicesVirtualDirectory | Select-Object InternalUrl, ExternalUrl
Please make sure the ExternalUrl is reachable from outside your network and has a valid SSL certificate. Our application uses this URL directly (without Autodiscover).
Step 6: Firewall configuration
If your Exchange environment is behind a firewall, access to the EWS endpoint (HTTPS, port 443) must be allowed for our IP address. Our service connects from the Frankfurt data centre (Google Cloud, europe-west3) exclusively through the fixed IP address:
34.185.226.196
Please set up a firewall rule that allows incoming connections from this IP address to your Exchange Server's EWS endpoint. Some geolocation services wrongly place Google Cloud addresses in Frankfurt in the USA, so country-based blocking (geo-blocking) can block the connection.
Step 7: Adjust the EWS throttling policy (optional)
By default Exchange limits the number of concurrent EWS connections and requests per user. For a service user that polls mailboxes regularly, the default throttling policy can cause occasional connection problems. We recommend a dedicated policy for the service user:
New-ThrottlingPolicy -Name "CK_ServicePolicy" -EWSMaxConcurrency 50 Set-Mailbox -Identity "captknowledge" -ThrottlingPolicy "CK_ServicePolicy"
Step 8: Verify the configuration
You can check that impersonation is set up correctly with these commands:
# Check that the role assignment was created correctly Get-ManagementRoleAssignment -RoleAssignee "[email protected]" -Role "ApplicationImpersonation"# Check that the scope resolves the right mailboxes $scope = Get-ManagementScope -Identity "CapturedKnowledgeScope" Get-Recipient -RecipientPreviewFilter $scope.RecipientFilter | ft Name,PrimarySmtpAddress,RecipientType
Step 9: Send us the details
Once the configuration is complete, we need the following details to activate the integration. Please send them over an agreed, secure channel (for example encrypted email or a secure text-sharing service):
Service user name: preferably in UPN format (for example
[email protected]), alternatively in DOMAIN format (for exampleYOURDOMAIN\captknowledge)Service user password
External EWS server address (for example
https://mail.yourdomain.com/EWS/Exchange.asmx)Email address of the target mailbox (from step 1)
Email addresses of all further mailboxes Captured Knowledge should read (members of the group from step 3) — please inform each mailbox owner beforehand; we provide an information sheet for this
A list of the mailboxes for which "Send As" was granted
If you have questions or need help with the setup, write to us at [email protected].
Related Articles