Skip to main content
The m365_mail kind collects one folder of one Microsoft 365 mailbox, for example a shared mailbox that receives press releases or newsletters. Each mail becomes a Record; attachments are stored with it. The kind comes from the first-party m365-mail plugin. Collect from a source covers what every kind shares.

Prerequisites

  • A tenant administrator who can register an application in Microsoft Entra ID and run Exchange Online PowerShell.
  • A credential_key in Quivr’s configuration, since the instance stores a secret.
  • The m365-mail plugin pinned, with outbound HTTPS to Microsoft and to Quivr’s object storage. In the local stack it points at a local fake of Microsoft Graph, so use a real deployment to collect real mail.

Steps

1

Register an application

In the Microsoft Entra admin center, open App registrations, then New registration. Choose a single-tenant application with no redirect URI. Note its Directory (tenant) ID and Application (client) ID.Under Certificates & secrets, add a certificate (recommended) or a client secret, and note its expiry date.
2

Limit it to the monitored mailboxes

Quivr needs the Mail.Read application permission, which reads every mailbox of the tenant unless you scope it. Scope it with RBAC for Applications in Exchange Online:
InScope must be True for a monitored mailbox and False for any other. With this method, do not also grant Mail.Read in Entra ID: grants add up, and a tenant-wide grant cancels the scope. Exchange applies changes within 30 minutes to 2 hours; until then Quivr may report mailbox_access_denied.
3

Create the instance

The instance polls every 60 seconds by default and collects mail received from its creation.

What each mail becomes

Search covers the subject and body; attachment text is not extracted. The connector.m365_mail extension holds the sender, recipients, dates, conversation id and the attachments that were skipped, with why. The Record Key is the mail’s internetMessageId. Read flags do not create Versions, and moving or deleting a mail in the mailbox leaves its Record untouched.

Rotate the secret

Add a new secret or certificate in Entra ID while the old one is valid, deposit it with PUT /v0/connectors/{connector_id}/credential, and delete the old one once health is active again. The next run uses the new secret.

Health codes

All but the last row set the access_error health state until a later run succeeds. Secrets, tokens, addresses and subjects are never logged.