Before you begin
- Confirm mailbox import is provisioned for your tenant and that the Client, API, and Workflow Engine versions support it. If Mailbox importer or Mail imported is missing, check availability and permissions first.
- Have the Microsoft 365 tenant ID, application ID, intended mailbox address, and folder ready. The application needs permission to read the message body and attachments without a signed-in user.
- Prepare the destination document types and standalone keyword types. Record the document type IDs and confirm the keyword names to select for each destination. The mapping dropdowns show keyword names with IDs.
- Confirm the importer service account has Document Creation and the required keyword rights on every destination type, including attachments and rule-specific destinations. This account is established for your tenant; you do not choose it in the mailbox form.
- Use a dedicated test mailbox or folder for your first import. Decide the earliest received time to include before saving the configuration.
Grant access in Nobly Insight
Open Admin settings → Access → Permissions and grant the appropriate tier to your user groups. You need Manage permissions to change grants; see Managing permissions.
For example, give an Import monitoring group View, an Import configuration group Manage, and a Mailbox credentials group Admin. These are example group names you can adapt.
The secret remains write-only even with Admin. All three tiers can see the keyword type catalogue used by the mapping dropdowns; separate document keyword access is not required to see these names. Importer permissions do not grant access to archived documents or their keyword values. The service account’s document rights and each reader’s document rights are separate from these settings permissions.
Prepare the Microsoft 365 application
You need access to register applications and arrange the required Microsoft 365 permission grants. If someone else manages your Microsoft 365 tenant, give them the mailbox list and the access requirements below.Register the application
- In the Microsoft Entra admin center, open Entra ID → App registrations → New registration.
- Give the application a recognizable name, such as Nobly Insight mailbox import. For a customer-specific registration, choose accounts in that organizational directory only. The importer does not need a redirect URI or interactive sign-in.
- After registration, copy Directory (tenant) ID and Application (client) ID from Overview. These go into the correspondingly named fields in Nobly Insight. They are not the application’s object ID.
Grant mail access and restrict the mailboxes
The required capability is application-only Mail.Read. Basic mail permissions omit content needed for archiving. The importer does not need mail write or send access. Choose the access model with the person responsible for Exchange Online:Create the application secret
- In the app registration, open Certificates & secrets → Client secrets → New client secret.
- Set a description and expiration that follows your organization’s credential policy. Record the expiry and who will rotate it.
- Choose Add and securely retain the secret Value for entry into Nobly Insight. The Secret ID will not work. Microsoft shows the value only when it is created; see Add application credentials.
Create the mailbox configuration
Open your profile menu, choose Admin settings, then Mailbox importer → Mailboxes. Select Add mailbox. Keep Enable scheduled import off while configuring it.
Existing messages in the watched folder received on or after your start time are eligible. This is not limited to unread messages or messages arriving after you enable the configuration. Take particular care when choosing a historical start date.
For your first setup,
inbox works regardless of the mailbox’s display language. For a custom folder, obtain its Graph folder ID from the person managing Microsoft 365; the importer does not offer a folder picker or recursively watch subfolders. Microsoft documents folder IDs and well-known names.
After the first save, tenant, mailbox, folder, and start time are locked. Create a new configuration to change the source. The name, application ID, archive policies, mappings, interval, size limit, comment, and enabled state can be changed. Recovery guidance explains what happens to previously imported messages.
Choose the initial archive policy
For a first whole-message archive, set Default archive policy → Archive format to Whole email (.eml) and enter your destination Document type ID. The example below uses10.
Under Mail keyword mappings, open each dropdown and search by keyword name or ID. Select the keyword assigned as standalone on your destination type; the selected name and ID remain visible. Use Do not map for an optional parameter only if the document type allows it. For separate mail and attachment documents, or rules that choose different destinations, complete Archive rules and keyword mappings before enabling the mailbox.
Save the secret, then enable intake
1
Save settings while disabled
Select Save settings. Saving the configuration makes its Application secret section available; it does not fetch mail.
2
Enter the application secret
With
mailbox-importer.admin, paste the secret value into New client secret and choose Save secret. The field clears and the mailbox reports Secret: Configured. You cannot read the stored value back.3
Prepare the postprocessing workflow
If you need automatic postprocessing, configure and publish the Mail imported workflow before enabling intake. Scope it to the EML or HTML mail document type.
4
Enable and save
With Manage or Admin, check Enable scheduled import and choose Save settings again. The mailbox card should show Enabled. The checkbox is unavailable until the configuration and secret have been saved.
5
Verify a representative message
Send a message to the watched folder and follow the acceptance checklist. A successful settings save alone does not verify Microsoft 365 access or document creation.

A saved, enabled whole-email configuration. The disabled source fields are locked after creation; the secret field is empty after saving. All addresses and identifiers are fictional.
Where to read next
Archive rules and keyword mappings
Choose EML or HTML with separate attachments, route messages by rule, and map mail metadata into each document type.
Managing permissions
Grant View, Manage, and Admin to the groups responsible for the integration.
