m365_mail kind collects one folder of one Microsoft 365 mailbox, for example a shared mailbox that receives press releases or newsletters. Each mail becomes a Record; attachments are stored with it. The kind comes from the first-party m365-mail plugin. Collect from a source covers what every kind shares.
Prerequisites
- A tenant administrator who can register an application in Microsoft Entra ID and run Exchange Online PowerShell.
- A
credential_keyin Quivr’s configuration, since the instance stores a secret. - The
m365-mailplugin pinned, with outbound HTTPS to Microsoft and to Quivr’s object storage. In the local stack it points at a local fake of Microsoft Graph, so use a real deployment to collect real mail.
Steps
1
Register an application
In the Microsoft Entra admin center, open App registrations, then New registration. Choose a single-tenant application with no redirect URI. Note its Directory (tenant) ID and Application (client) ID.Under Certificates & secrets, add a certificate (recommended) or a client secret, and note its expiry date.
2
Limit it to the monitored mailboxes
Quivr needs the
Mail.Read application permission, which reads every mailbox of the tenant unless you scope it. Scope it with RBAC for Applications in Exchange Online:InScope must be True for a monitored mailbox and False for any other. With this method, do not also grant Mail.Read in Entra ID: grants add up, and a tenant-wide grant cancels the scope. Exchange applies changes within 30 minutes to 2 hours; until then Quivr may report mailbox_access_denied.3
Create the instance
The instance polls every 60 seconds by default and collects mail received from its creation.
What each mail becomes
Search covers the subject and body; attachment text is not extracted. The
connector.m365_mail extension holds the sender, recipients, dates, conversation id and the attachments that were skipped, with why. The Record Key is the mail’s internetMessageId. Read flags do not create Versions, and moving or deleting a mail in the mailbox leaves its Record untouched.
Rotate the secret
Add a new secret or certificate in Entra ID while the old one is valid, deposit it withPUT /v0/connectors/{connector_id}/credential, and delete the old one once health is active again. The next run uses the new secret.
Health codes
All but the last row set the
access_error health state until a later run succeeds. Secrets, tokens, addresses and subjects are never logged.