Skip to main content

Microsoft 365: Connecting Your Mailboxes to Captured Knowledge

For IT administrators: connect Exchange Online mailboxes to Captured Knowledge with Exchange RBAC for Applications — access limited to the mailboxes you choose, no tenant-wide admin consent.

N
Written by Nick Laffey

Microsoft 365: Connecting Your Mailboxes to Captured Knowledge

As of: 29 September 2026

Time required: approximately 20 minutes, plus up to 2 hours for Microsoft to apply the permissions

Who this article is for: IT administrators of organisations that use Exchange Online (Microsoft 365) and are connecting their mailboxes to Captured Knowledge (CK).

Expected results: Captured Knowledge can read and work with exactly the mailboxes you release — and no others. No tenant-wide admin consent is needed, and you can verify the restriction yourself.

Captured Knowledge connects to your Exchange Online mailboxes through Microsoft Graph. You grant our application permissions in Exchange Online only for the mailboxes you put into one group ("RBAC for Applications", the method Microsoft recommends).

Overview:

  1. Register Captured Knowledge in your tenant — without any permissions.

  2. Choose the central mailbox — and optionally further mailboxes Captured Knowledge should read.

  3. Create a group — it determines which mailboxes Captured Knowledge may access.

  4. Assign permissions in Exchange Online — limited to those mailboxes.

  5. Grant "Send As" (if Captured Knowledge should reply with staff members' sender addresses).

  6. Verify the setup.

  7. Send us the details.

Prerequisites:

  • An account with the Exchange Administrator and Application Administrator (or Cloud Application Administrator) roles — or a Global Administrator.

  • PowerShell with the modules Microsoft.Graph.Applications and ExchangeOnlineManagement (version 3 or later):

Install-Module Microsoft.Graph.Applications, ExchangeOnlineManagement -Scope CurrentUser

  • Microsoft applies permission changes only after 30 minutes to 2 hours.

Please run the Microsoft Graph commands (recognisable by Mg in the name, e.g. Connect-MgGraph) and the Exchange Online commands (all others) in two separate PowerShell windows; the two modules occasionally interfere with each other's sign-in in the same session.

Step 1: Register Captured Knowledge in your tenant

Our application ("Captured Knowledge Email Connector", application ID fd947736-20c0-45be-ab8b-f1c871926061) is created in your tenant as an enterprise application. No permissions are granted.

Connect-MgGraph -Scopes "Application.ReadWrite.All"
$SP = New-MgServicePrincipal -AppId "fd947736-20c0-45be-ab8b-f1c871926061"
$SP.Id                       # object ID – needed in step 4
(Get-MgContext).TenantId     # your tenant ID – please send it to us (step 7)

The first time, Connect-MgGraph may ask for consent for the Microsoft application "Microsoft Graph Command Line Tools" — that is Microsoft's PowerShell tool, not Captured Knowledge.

If the second command reports that the application already exists (for example because consent was granted earlier), get the object ID like this instead — and please read the note "Earlier admin consent" at the end of this article:

$SP = Get-MgServicePrincipal -Filter "appId eq 'fd947736-20c0-45be-ab8b-f1c871926061'"
$SP.Id                       # object ID – needed in step 4

⚠️ Please do not grant admin consent — neither through a consent link nor with the button for granting admin consent ("Grant admin consent") in the Microsoft Entra admin center. A permission granted there applies to all mailboxes in your organisation and cancels the restriction from step 4. It is correct that the enterprise application's "Permissions" page stays empty: Microsoft Entra does not show permissions granted in Exchange Online there.

Step 2: Choose the central mailbox

Captured Knowledge needs a central mailbox that receives the emails to be processed — usually a shared mailbox (no licence, no password) your team already uses. Captured Knowledge also sends replies from this mailbox and creates its working folders in it. Below, [email protected] stands for this mailbox.

Optionally, Captured Knowledge can read further mailboxes, such as individual staff members' personal mailboxes ([email protected]). Captured Knowledge reads and tags these mailboxes and transfers relevant emails into the central mailbox. By default the original then goes to the mailbox owner's Deleted Items; on request it stays where it is, tagged, instead. Captured Knowledge sends no email from these mailboxes and creates no folders in them.

Public folders are not supported through Microsoft Graph. Please use a shared mailbox instead.

Step 3: Create a group

The group determines which mailboxes Captured Knowledge may access. Sign in to Exchange Online and create a mail-enabled security group:

Connect-ExchangeOnline -UserPrincipalName [email protected]# The central mailbox only:
New-DistributionGroup -Name "CK_Connector_Mailboxes" -Alias "ck-connector-mailboxes" -Type Security -Members "[email protected]"# Or: the central mailbox and further mailboxes Captured Knowledge should read:
New-DistributionGroup -Name "CK_Connector_Mailboxes" -Alias "ck-connector-mailboxes" -Type Security `
    -Members "[email protected]","[email protected]"

Note: only direct members of the group count; nested groups are not considered. A plain Microsoft Entra security group (not mail-enabled) does not work.

Step 4: Assign permissions in Exchange Online

First create two scopes (management scopes): all mailboxes in the group, and the central mailbox only. Then register our application in Exchange Online (with the object ID from step 1) and assign the roles to those scopes.

$Gruppe = Get-DistributionGroup -Identity "CK_Connector_Mailboxes"
New-ManagementScope -Name "CK Postfaecher" -RecipientRestrictionFilter "MemberOfGroup -eq '$($Gruppe.DistinguishedName)'"
New-ManagementScope -Name "CK Versand" -RecipientRestrictionFilter "EmailAddresses -eq 'smtp:[email protected]'"# Check: "CK Postfaecher" must list exactly the group's mailboxes, "CK Versand" exactly the central mailbox
foreach ($Name in "CK Postfaecher", "CK Versand") {
    $Scope = Get-ManagementScope -Identity $Name
    Get-Recipient -RecipientPreviewFilter $Scope.RecipientFilter | Format-Table Name, PrimarySmtpAddress
}New-ServicePrincipal -AppId "fd947736-20c0-45be-ab8b-f1c871926061" -ObjectId "<object ID from step 1>" -DisplayName "Captured Knowledge"# Read, move and tag emails – in all mailboxes of the group
New-ManagementRoleAssignment -App "fd947736-20c0-45be-ab8b-f1c871926061" -Role "Application Mail.ReadWrite" -CustomResourceScope "CK Postfaecher"
# Send emails – from the central mailbox only
New-ManagementRoleAssignment -App "fd947736-20c0-45be-ab8b-f1c871926061" -Role "Application Mail.Send" -CustomResourceScope "CK Versand"

Only if Captured Knowledge reads further mailboxes (step 2), additionally:

# Transfer emails from further mailboxes into the central mailbox
New-ManagementRoleAssignment -App "fd947736-20c0-45be-ab8b-f1c871926061" -Role "Application MailboxItem.ImportExport" -CustomResourceScope "CK Postfaecher"

Background: this role lets Captured Knowledge transfer an email from a staff member's mailbox into the central mailbox so your team can work on it there. Like all roles here, it applies only to the mailboxes in the group.

Step 5: Grant "Send As" (optional)

Captured Knowledge sends replies from the central mailbox. If the responsible staff member's sender address should appear (for example [email protected]), the central mailbox needs the "Send As" permission for that address. Run this once per sender address:

Add-RecipientPermission -Identity "[email protected]" -Trustee "[email protected]" -AccessRights SendAs -Confirm:$false

The mailbox [email protected] does not need to be a member of the group from step 3 for this. If Captured Knowledge only sends with the central mailbox's address, skip this step.

Step 6: Verify the setup

Check the central mailbox, a further mailbox from step 2 (if any) and a mailbox Captured Knowledge must not reach — replace the three addresses with your own:

foreach ($Postfach in "[email protected]", "[email protected]", "[email protected]") {
    "--- $Postfach"
    Test-ServicePrincipalAuthorization -Identity "fd947736-20c0-45be-ab8b-f1c871926061" -Resource $Postfach |
        Format-Table RoleName, AllowedResourceScope, InScope
}

Expected result:

  • Central mailbox: every role shows InScope = True.

  • Further mailbox: Application Mail.Send shows False as expected, the other roles True.

  • Any other mailbox: all roles show False — Captured Knowledge has no access there.

Note: this check shows the configuration immediately. Microsoft applies it only after 30 minutes to 2 hours.

Step 7: Send us the details

  • Your tenant ID (from step 1, or under "Overview" in the Microsoft Entra admin center)

  • The email address of the central mailbox

  • (Optional) The email addresses of the further mailboxes Captured Knowledge should read — please inform each mailbox owner beforehand; we provide an information sheet for this

  • (Optional) The sender addresses for which you granted "Send As" in step 5

We do not need any passwords or secret keys.

Notes

Adding or removing a mailbox later: add it to the group or remove it from the group. The change takes effect after 30 minutes to 2 hours.

Add-DistributionGroupMember -Identity "CK_Connector_Mailboxes" -Member "[email protected]" -BypassSecurityGroupManagerCheck
Remove-DistributionGroupMember -Identity "CK_Connector_Mailboxes" -Member "[email protected]" -BypassSecurityGroupManagerCheck -Confirm:$false

If it is the first further mailbox besides the central mailbox, also assign the role Application MailboxItem.ImportExport (step 4, last command) — otherwise Captured Knowledge cannot take over emails from that mailbox.

Earlier admin consent: if admin consent was granted for our application earlier (for example through a consent link), it still applies to all mailboxes — permissions from Microsoft Entra and from Exchange Online add up. So remove all application permissions granted to our application in Microsoft Entra (Microsoft Graph and Exchange Web Services) — but only after we have confirmed that your connection runs through Microsoft Graph, and no earlier than 2 hours after step 4. While we still read your mailboxes through Exchange Web Services, removing them would interrupt the connection.

Connect-MgGraph -Scopes "Application.ReadWrite.All", "AppRoleAssignment.ReadWrite.All"
$SP = Get-MgServicePrincipal -Filter "appId eq 'fd947736-20c0-45be-ab8b-f1c871926061'"
Get-MgServicePrincipalAppRoleAssignment -ServicePrincipalId $SP.Id |
    ForEach-Object { Remove-MgServicePrincipalAppRoleAssignment -ServicePrincipalId $SP.Id -AppRoleAssignmentId $_.Id }

An application access policy set up earlier for our application only restricts permissions from Microsoft Entra, so it no longer has any effect; you can remove it with Remove-ApplicationAccessPolicy.

Removing access completely: delete the enterprise application "Captured Knowledge Email Connector" (in the Microsoft Entra admin center or with Remove-MgServicePrincipal -ServicePrincipalId (Get-MgServicePrincipal -Filter "appId eq 'fd947736-20c0-45be-ab8b-f1c871926061'").Id). Exchange Online removes the related role assignments automatically. The scopes and the group remain; if you no longer need them:

Remove-ManagementScope -Identity "CK Postfaecher" -Confirm:$false
Remove-ManagementScope -Identity "CK Versand" -Confirm:$false
Remove-DistributionGroup -Identity "CK_Connector_Mailboxes" -BypassSecurityGroupManagerCheck -Confirm:$false

IP address: Captured Knowledge accesses Microsoft 365 from the Frankfurt data centre (Google Cloud, europe-west3) through the fixed IP address 34.185.226.196. No firewall rule is needed; the address matters only if you restrict application access to certain IP addresses with Conditional Access.

Troubleshooting:

Message

Cause

New-ServicePrincipal cannot find the object

The object ID was taken from "App registrations" instead of "Enterprise applications" — use the object ID printed in step 1

Role not found

Role name misspelled — the correct name is e.g. Application MailboxItem.ImportExport, without the .All of the Microsoft Graph permission of the same name

A scope lists no mailbox in the check (step 4)

Typo in the filter or the address

InScope = False for a mailbox Captured Knowledge should read

The mailbox is not a direct member of the group, or the group is not mail-enabled

InScope = True, but Captured Knowledge still reports "access denied"

Microsoft has not applied the change yet (up to 2 hours)

Captured Knowledge reports that it may not send "as" an address

"Send As" is missing for that address (step 5)

If you have questions or need help with the setup, write to us at [email protected].

Related Articles

Did this answer your question?