Skip to main content
In Cimento this is Microsoft 365 Direct Inject. Cimento writes each simulation straight into the employee’s Inbox through Microsoft Graph, so nothing crosses your mail gateway and there’s nothing to allowlist. Setup takes one admin consent in Microsoft Entra, then an Exchange Online policy that limits Cimento to the people you plan to target.

Before you start

  • A Global Administrator or Privileged Role Administrator, to grant admin consent.
  • An Exchange Administrator or Global Administrator, to create the access policy in Exchange Online PowerShell.
  • A mail-enabled security group containing everyone you plan to send simulations to. Distribution lists and Microsoft 365 groups don’t work for this.
  • The ExchangeOnlineManagement PowerShell module, installed on the computer you’ll run the commands from.

Steps

1

Start setup in Cimento

Go to Admin → Integrations → Phishing, choose Microsoft 365 Direct Inject and click Begin Setup. Your organization can have one email provider active at a time. Read the Before you start step, then click Next.
2

Grant admin consent

In the Grant consent step, click Grant admin consent and sign in to Microsoft as a Global Administrator or Privileged Role Administrator. Select Consent on behalf of your organization, then click Accept. Without that checkbox, the mail permission isn’t granted.
3

Return to the setup guide

Microsoft sends you back to Cimento, which reports the integration as connected. Setup isn’t finished: go back to Admin → Integrations → Phishing and open Microsoft 365 Direct Inject to continue.
4

Limit Cimento to your targets

In the Scope mailboxes step, copy the Application (client) ID. If it’s blank, find it in the Microsoft Entra admin center under Enterprise applications: search for Cimento M365 DMI and copy its Application ID. Then run:
Replace <AppId> with the ID you copied and <GroupAddress> with your security group’s email address.
5

Check the restriction

Test one mailbox inside the group and one outside it:
AccessCheckResult should read Granted for the first and Denied for the second.
6

Name a test mailbox

In the Test mailbox step, enter the address of a mailbox in the group and click Save configuration. Cimento only reads that mailbox’s Inbox folder details, never its messages.
7

Verify

In the Verify step, click Test connection. Policy changes can take up to 30 minutes to reach Microsoft Graph, so if the test fails right after you ran the commands, wait and try again.
Admin consent grants Cimento access to every mailbox in your tenant until the access policy in step 4 is in place. Apply it before you launch a campaign.

Permissions

Cimento never sends mail as your employees, searches their mail or changes their settings. Mailbox permissions explains each call Cimento makes and why the access policy is needed.

Revoke access

  • Remove the application. In the Microsoft Entra admin center, open Enterprise applications, select Cimento M365 DMI, then Properties and Delete.
  • Don’t rely on removing the access policy. Without it, Microsoft lets the application reach every mailbox again.
  • Disconnecting in Cimento stops deliveries, but doesn’t remove the consent or the policy from your tenant.