Before you start
- A Global Administrator or Privileged Role Administrator, to grant admin consent.
- An Exchange Administrator or Global Administrator, to create the access policy in Exchange Online PowerShell.
- A mail-enabled security group containing everyone you plan to send simulations to. Distribution lists and Microsoft 365 groups don’t work for this.
- The ExchangeOnlineManagement PowerShell module, installed on the computer you’ll run the commands from.
Steps
1
Start setup in Cimento
Go to Admin → Integrations → Phishing, choose Microsoft 365 Direct Inject and click Begin Setup. Your organization can have one email provider active at a time. Read the Before you start step, then click Next.
2
Grant admin consent
In the Grant consent step, click Grant admin consent and sign in to Microsoft as a Global Administrator or Privileged Role Administrator. Select Consent on behalf of your organization, then click Accept. Without that checkbox, the mail permission isn’t granted.
3
Return to the setup guide
Microsoft sends you back to Cimento, which reports the integration as connected. Setup isn’t finished: go back to Admin → Integrations → Phishing and open Microsoft 365 Direct Inject to continue.
4
Limit Cimento to your targets
In the Scope mailboxes step, copy the Application (client) ID. If it’s blank, find it in the Microsoft Entra admin center under Enterprise applications: search for Cimento M365 DMI and copy its Application ID. Then run:Replace
<AppId> with the ID you copied and <GroupAddress> with your security group’s email address.5
Check the restriction
Test one mailbox inside the group and one outside it:
AccessCheckResult should read Granted for the first and Denied for the second.6
Name a test mailbox
In the Test mailbox step, enter the address of a mailbox in the group and click Save configuration. Cimento only reads that mailbox’s Inbox folder details, never its messages.
7
Verify
In the Verify step, click Test connection. Policy changes can take up to 30 minutes to reach Microsoft Graph, so if the test fails right after you ran the commands, wait and try again.
Permissions
Cimento never sends mail as your employees, searches their mail or changes their settings. Mailbox permissions explains each call Cimento makes and why the access policy is needed.
Revoke access
- Remove the application. In the Microsoft Entra admin center, open Enterprise applications, select Cimento M365 DMI, then Properties and Delete.
- Don’t rely on removing the access policy. Without it, Microsoft lets the application reach every mailbox again.
- Disconnecting in Cimento stops deliveries, but doesn’t remove the consent or the policy from your tenant.