> ## Documentation Index
> Fetch the complete documentation index at: https://docs.airmdr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 🔐 M365 Quarantine Emails

> AirMDR requires secure, delegated access to your Microsoft 365 tenant to perform automated quarantined email retrieval. The integration leverages a registered Azure AD App with a certificate-based authentication mechanism.

## ✅ Pre-requisites

Before AirMDR can integrate with your Microsoft 365 tenant to retrieve quarantined emails, the following **technical and organizational prerequisites** must be met:\
\
**Microsoft 365 Tenant Requirements**

| Requirement                       | Description                                                                 |
| :-------------------------------- | :-------------------------------------------------------------------------- |
| Microsoft 365 Tenant              | An active M365 tenant with admin access                                     |
| Microsoft Defender for Office 365 | Plan 1 or Plan 2 licensed (for access to quarantine APIs)                   |
| Global or Security Admin Role     | A user with sufficient privileges to register applications and consent APIs |

**Azure AD App Setup Requirements**

| Requirement                 | Description                                                                                |
| :-------------------------- | :----------------------------------------------------------------------------------------- |
| Access to Azure Portal      | To register an application and manage certificates                                         |
| App Registration Permission | Must be able to create an app in **Azure Active Directory**                                |
| Upload Public Certificate   | You will receive a `.cer` file from AirMDR to upload to your Azure AD application          |
| Grant Admin Consent         | Required to authorize API permissions (e.g., `Mail.Read`, `Security.Read.All`) for the app |

### Onboarding Guide - step by step process to `get_ms365_quarantined_emails`

This guide outlines the process to provide credentials securely, by creating an Azure AD application and uploading a certificate, so AirMDR can access Microsoft 365 quarantine APIs on your behalf. This enables AirMDR security team to audit, review, or act on potentially malicious emails.

<Steps>
  <Step title="Create an App Registration in Azure Portal">
    1. Log in to your [Azure Portal](https://portal.azure.com/) using a user with **Global Admin** or **Application Administrator** permissions.
    2. Navigate to **Microsoft Entra ID** → **App registrations** → **New registration.**

           <img src="https://mintcdn.com/airmdr/wb8NOGyN5Zdemkpe/images/MDE7.png?fit=max&auto=format&n=wb8NOGyN5Zdemkpe&q=85&s=7ad13130c92180ad80c1c2d3c5f56693" alt="MDE7 Pn" width="1424" height="866" data-path="images/MDE7.png" />
    3. Fill out the mandatory details:
       * **Name**: `AirMDR Quarantine Access`
       * **Supported account types**: Select "*Accounts in any organizational directory (Any Microsoft Entra ID tenant - Multitenant)*" option).

             <img src="https://mintcdn.com/airmdr/wb8NOGyN5Zdemkpe/images/MDE3.png?fit=max&auto=format&n=wb8NOGyN5Zdemkpe&q=85&s=4c2565d2535d78e1a84af22dea350797" alt="MDE3 Pn" width="787" height="393" data-path="images/MDE3.png" />
    4. Click **Register**.

    <Tip>
      **Redirect URI (Optional)**: If your app uses authentication, enter a URL (e.g., `https://myapp.com/auth`).
    </Tip>

    <img src="https://mintcdn.com/airmdr/wb8NOGyN5Zdemkpe/images/MDE22.png?fit=max&auto=format&n=wb8NOGyN5Zdemkpe&q=85&s=2d29fdacf6d9d5250edbaaffda85b201" alt="MDE22 Pn" width="2882" height="1180" data-path="images/MDE22.png" />
  </Step>

  <Step title="Upload a Certificate">
    1. After registering the app, navigate to the **Manage** → **Certificates & secrets** section.
    2. Under **Certificates**, click **Upload certificate**.

           <img src="https://mintcdn.com/airmdr/wb8NOGyN5Zdemkpe/images/MDE8.png?fit=max&auto=format&n=wb8NOGyN5Zdemkpe&q=85&s=a997f47f252e394e11489b89b4d0214d" alt="MDE8 Pn" width="2116" height="1014" data-path="images/MDE8.png" />
    3. Select a file and upload the public certificate provided by **AirMDR** (usually a `.cer` file).

           <Note>
             If you do not already have the certificate, please request **AirMDR to generate and provide a new certificate** for you.
           </Note>
    4. Once uploaded, **copy the thumbprint** of the certificate and click on **Add** at the bottom of the page.

           <Check>
             Share the **thumbprint** (**SHA-1 hash**) of the certificate data with AirMDR.
           </Check>

           <img src="https://mintcdn.com/airmdr/wb8NOGyN5Zdemkpe/images/MDE21.png?fit=max&auto=format&n=wb8NOGyN5Zdemkpe&q=85&s=cd39daed583409ed37fe0708eeb63565" alt="MDE21 Pn" width="1162" height="224" data-path="images/MDE21.png" />
  </Step>

  <Step title="Configure API Permissions" stepNumber={3}>
    1. In the application Overview page left navigation pane, select **Manage** dropdown.
    2. Navigate to **API Permissions** and click **+ Add a permission.**

           <img src="https://mintcdn.com/airmdr/-EZh6YrIIs69rcCd/images/MDE17.png?fit=max&auto=format&n=-EZh6YrIIs69rcCd&q=85&s=54e5361be8cf62e7528c23002b967b15" alt="MDE17 Pn" width="1164" height="288" data-path="images/MDE17.png" />
    3. On the **Request API permissions** page, choose **APIs my organization uses** tab.
    4. Search and select **Office 365 Exchange Online** exactly as shown.

           <img src="https://mintcdn.com/airmdr/-EZh6YrIIs69rcCd/images/MDE18.png?fit=max&auto=format&n=-EZh6YrIIs69rcCd&q=85&s=f0e015dac6c7e91a161bb9256c298858" alt="MDE18 Pn" width="1178" height="406" data-path="images/MDE18.png" />
    5. Choose **Application permissions**.

           <img src="https://mintcdn.com/airmdr/-EZh6YrIIs69rcCd/images/MDE11.png?fit=max&auto=format&n=-EZh6YrIIs69rcCd&q=85&s=4f362c52f844093b251162026bd773bf" alt="MDE11 Pn" width="2728" height="648" data-path="images/MDE11.png" />
    6. Search and select the required permissions as shown:

       * **To Manage Exchange as Application** - `Exchange.ManageAsApp`

           <img src="https://mintcdn.com/airmdr/-EZh6YrIIs69rcCd/images/MDE12.png?fit=max&auto=format&n=-EZh6YrIIs69rcCd&q=85&s=068c52974b476c9bc25b8f22b52e2ecd" alt="MDE12 Pn" width="2322" height="332" data-path="images/MDE12.png" />
    7. Choose **Grant admin consent**.

           <img src="https://mintcdn.com/airmdr/-EZh6YrIIs69rcCd/images/MDE19.png?fit=max&auto=format&n=-EZh6YrIIs69rcCd&q=85&s=2ae0aa4a7e5b18c54d6ffb206f1d4f09" alt="MDE19 Pn" width="1174" height="246" data-path="images/MDE19.png" />
    8. Navigate to **Manage** → **Roles and administrators** page, to assign the Exchange Administrator role to the application.
    9. Search and select the **Exchange Administrator** role.

           <img src="https://mintcdn.com/airmdr/-EZh6YrIIs69rcCd/images/MDE14.png?fit=max&auto=format&n=-EZh6YrIIs69rcCd&q=85&s=d8d8841645d0611e52be729a66fe5e14" alt="MDE14 Pn" width="1168" height="450" data-path="images/MDE14.png" />
    10. Choose **Add assignments**, and add the app registration we created.

            <img src="https://mintcdn.com/airmdr/-EZh6YrIIs69rcCd/images/MDE16.png?fit=max&auto=format&n=-EZh6YrIIs69rcCd&q=85&s=62216a2b08f3b8504c8171d9a8e6894f" alt="MDE16 Pn" width="1152" height="358" data-path="images/MDE16.png" />
    11. In the search bar enter the application name "**For example**: `AirMDR Quarantine Access`" given earlier.
    12. Click on **Add** at the bottom of the page.
    13. Navigate to \*\*Entra ID \*\*→\*\*Manage \*\* →\*\*App registrations \*\* →**All Applications**
    14. Search and select the application name.
    15. In the **Overview** page copy all the required essentials (Application (client) ID, Directory (tenant) ID).

            <img src="https://mintcdn.com/airmdr/wb8NOGyN5Zdemkpe/images/MDE20.png?fit=max&auto=format&n=wb8NOGyN5Zdemkpe&q=85&s=e7cb481b3fe8d9d9a9e8ddd2d0a69896" alt="MDE20 Pn" width="1166" height="474" data-path="images/MDE20.png" />
  </Step>

  <Step title="Create a Client Secret (For Authentication)">
    1. In the left navigation pane, select **Manage** dropdown.
    2. Click **Certificates & secrets**.
    3. Click **+ New client secret**.

           <img src="https://mintcdn.com/airmdr/wb8NOGyN5Zdemkpe/images/MDE6.png?fit=max&auto=format&n=wb8NOGyN5Zdemkpe&q=85&s=c3d8732152f5e9b62265b292bcf1a6e1" alt="MDE6 Pn" width="874" height="300" data-path="images/MDE6.png" />
    4. Enter a description (e.g., `MySecretKey`) and set expiration.
    5. Click **Add**.

    <Warning>
      Copy and secure the **Secret ID** and **Value** (**Client Secret**) immediately – (It won’t be shown again!)
    </Warning>
  </Step>
</Steps>

## 📤 **Information to Provide to AirMDR**

1. Go to [**Azure Portal**](https://portal.azure.com/) → **Entra ID.**
2. Click **App registrations** and select your **registered app.**
3. Under the **Overview** section, locate the **Application (client) ID** and **Tenant ID (Directory ID).**
4. Click the **Copy** icon **📋** next to the Client ID, and the Tenant ID respectively.

<Check>
  Securely share the **Client (Application) ID, Tenant ID, Client Secret Value,** **Secret ID, Certificate Thumbprint,** and the **Tenant Domain** (**Organization**) to AirMDR.
</Check>

| Field                                     | Description                                                                                 |
| :---------------------------------------- | :------------------------------------------------------------------------------------------ |
| **Client (Application) ID and Tenant ID** | Found under the **Overview** section of the registered Azure AD app                         |
| **Certificate Thumbprint**                | Found in the **Certificates & Secrets** tab after uploading the certificate                 |
| **Tenant Domain** (**Organization**)      | Usually in the form `<yourcompany>.onmicrosoft.com` (e.g., `foundationcap.onmicrosoft.com`) |
| **Client Secret Value **and**Secret ID**  | **Client Secret Value **and**Secret ID**  securely saved earlier for Authentication         |

> **Example:**\
> For a customer like FCAP, the domain was `foundationcap.onmicrosoft.com`. The `.onmicrosoft.com` suffix is common across tenants.

<Check>
  If you need assistance during this process, contact [AirMDR](mailto:support@airmdr.com) support.
</Check>

## 💼 AirMDR Internal Requirements

Once credentials are received:

* AirMDR will create a **connection in the Connection Manager** using:
  * `Provider type: Microsoft`
  * The credentials listed above
* Access is used **only for retrieving quarantined emails** via Microsoft Graph or Defender APIs

## 🔁 Future Automation

Once AirMDR agents are deployed to the customer's remote infrastructure:

* The current **Powersheller instance** used to perform these operations can be deprecated.
* The onboarding steps (like certificate auth and quarantine sync) will be handled **directly by remote agents**.

<Info>
  This ensures full automation, scalability, and centralized control without requiring manual setup steps on an ongoing basis.
</Info>

## 🛑 Security & Access Best Practices

* ✅ Certificate-based auth ensures **non-password-based secure access**
* ✅ Permissions are **application-only** and limited to read quarantine info
