> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cimento.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect Microsoft 365

> Place phishing simulations directly in Outlook inboxes with Microsoft 365 Direct Inject, step by step: admin consent, mailbox scoping and a connection test.

In Cimento this is **Microsoft 365 Direct Inject**. Cimento writes each simulation straight into the employee's Inbox through Microsoft Graph, so nothing crosses your mail gateway and there's nothing to allowlist. Setup takes one admin consent in Microsoft Entra, then an Exchange Online policy that limits Cimento to the people you plan to target.

## Before you start

* A Global Administrator or Privileged Role Administrator, to grant admin consent.
* An Exchange Administrator or Global Administrator, to create the access policy in Exchange Online PowerShell.
* A mail-enabled security group containing everyone you plan to send simulations to. Distribution lists and Microsoft 365 groups don't work for this.
* The ExchangeOnlineManagement PowerShell module, installed on the computer you'll run the commands from.

## Steps

<Steps>
  <Step title="Start setup in Cimento">
    Go to **Admin → Integrations → Phishing**, choose **Microsoft 365 Direct Inject** and click **Begin Setup**. Your organization can have one email provider active at a time. Read the **Before you start** step, then click **Next**.
  </Step>

  <Step title="Grant admin consent">
    In the **Grant consent** step, click **Grant admin consent** and sign in to Microsoft as a Global Administrator or Privileged Role Administrator. Select **Consent on behalf of your organization**, then click **Accept**. Without that checkbox, the mail permission isn't granted.
  </Step>

  <Step title="Return to the setup guide">
    Microsoft sends you back to Cimento, which reports the integration as connected. Setup isn't finished: go back to **Admin → Integrations → Phishing** and open **Microsoft 365 Direct Inject** to continue.
  </Step>

  <Step title="Limit Cimento to your targets">
    In the **Scope mailboxes** step, copy the **Application (client) ID**. If it's blank, find it in the Microsoft Entra admin center under **Enterprise applications**: search for **Cimento M365 DMI** and copy its **Application ID**. Then run:

    ```powershell theme={null}
    Connect-ExchangeOnline
    New-ApplicationAccessPolicy -AppId <AppId> -PolicyScopeGroupId <GroupAddress> -AccessRight RestrictAccess -Description "Cimento simulation targets"
    ```

    Replace `<AppId>` with the ID you copied and `<GroupAddress>` with your security group's email address.
  </Step>

  <Step title="Check the restriction">
    Test one mailbox inside the group and one outside it:

    ```powershell theme={null}
    Test-ApplicationAccessPolicy -Identity <MailboxInTheGroup> -AppId <AppId>
    Test-ApplicationAccessPolicy -Identity <MailboxOutsideTheGroup> -AppId <AppId>
    ```

    `AccessCheckResult` should read `Granted` for the first and `Denied` for the second.
  </Step>

  <Step title="Name a test mailbox">
    In the **Test mailbox** step, enter the address of a mailbox in the group and click **Save configuration**. Cimento only reads that mailbox's Inbox folder details, never its messages.
  </Step>

  <Step title="Verify">
    In the **Verify** step, click **Test connection**. Policy changes can take up to 30 minutes to reach Microsoft Graph, so if the test fails right after you ran the commands, wait and try again.
  </Step>
</Steps>

<Warning>
  Admin consent grants Cimento access to every mailbox in your tenant until the access policy in step 4 is in place. Apply it before you launch a campaign.
</Warning>

## Permissions

| Permission | Type | What Cimento uses it for |
| - | - | - |
| `Mail.ReadWrite` | Application | Places simulations and follow-up messages in the Inbox, checks whether a simulation was read, and runs the connection test. |
| `openid` | Delegated | Used once during consent, to learn your tenant ID. |

Cimento never sends mail as your employees, searches their mail or changes their settings. [Mailbox permissions](/phishing/mailbox-permissions#microsoft-365) explains each call Cimento makes and why the access policy is needed.

## Revoke access

* **Remove the application.** In the Microsoft Entra admin center, open **Enterprise applications**, select **Cimento M365 DMI**, then **Properties** and **Delete**.
* **Don't rely on removing the access policy.** Without it, Microsoft lets the application reach every mailbox again.
* **Disconnecting in Cimento** stops deliveries, but doesn't remove the consent or the policy from your tenant.
