Connect a Microsoft Outlook instance to SSPM to detect posture risks.
| Where Can I Use This? | What Do I Need? |
|
|
- SaaS Security Posture Management license
Or any of the following licenses that include the Data Security license:
|
Previously, you could onboard Microsoft Outlook by supplying
account credentials to SSPM. This enabled SSPM to access the account directly or
through the Okta or Microsoft Azure identity providers. Once connected, SSPM would
use data extraction techniques to scan your Microsoft Outlook instance. In March
2026, we discontinued this earlier connector in favor of a new connector that
accesses Microsoft APIs through a service principal.
This new connector,
described below, leverages the deep integration between Microsoft Outlook and
Microsoft Exchange to scan both of these product instances. A separate connector
for Microsoft Exchange that used data extraction for scans was also discontinued
in March 2026. You now onboard Microsoft Exchange by using this new Microsoft
Outlook connector.
If you already connected SSPM to your Microsoft Outlook
instance using the earlier connector, your established connection will continue
to work. Similarly, if you already connected SSPM to your Microsoft Exchange
instance, that established connection will continue to work. However, if there
is any change to the configuration information that you provided to SSPM (such
as an updated login password), you will need to onboard the Microsoft Outlook
instance again by using the new connector described below. Note that there is no
longer a separate connector for Microsoft Exchange.
For SSPM to detect posture risks in your Microsoft Outlook instance, you must onboard
your Microsoft Outlook instance to SSPM. Through the onboarding process, SSPM
connects to the Microsoft Graph and Office 365 Exchange Online APIs and, through
these APIs, scans your Microsoft Outlook instance at regular intervals.
Microsoft Outlook and Microsoft Exchange share the same
core technology within the Microsoft 365 ecosystem. Because of this deep
integration, onboarding Microsoft Outlook also onboards Microsoft Exchange. SSPM
will scan both Microsoft Outlook and Microsoft Exchange for potential
misconfigurations.
SSPM gets access to your Microsoft Outlook instance through a service principal,
which represents a Microsoft Entra application that you create. You will configure
this application's permissions to enable SSPM to access only the API scopes that
SSPM requires to complete its scans. When you register this application, Microsoft
Entra creates the associated service principle that SSPM will use to connect to the
Microsoft APIs.
The supported Microsoft account plan for SSPM scans is the Microsoft Business Premium
plan.
To access your Microsoft Outlook instance, SSPM requires the following information,
which you will specify during the onboarding process.
| Item | Description |
| Tenant ID | A globally unique identifier (GUID) for your Microsoft Entra
tenant. |
| Client ID | SSPM will access Microsoft APIs through a Microsoft Entra service
principal that represents an application that you create. Microsoft
Entra generates the client ID to uniquely identify the application
and its associated service principal. |
| Client Secret | SSPM will access Microsoft APIs through a Microsoft Entra service
principal that represents an application that you create. Microsoft
Entra generates the client secret, which SSPM uses to authenticate
to the service principal. |
To onboard your Microsoft Outlook instance, you complete the following actions: