Last modified by Sabrina V. on 2026/07/21 12:39

Show last authors
1 {{aagon.priorisierung}}
2 160
3 {{/aagon.priorisierung}}
4
5 {{aagon.floatingbox/}}
6
7 With the change to the Microsoft 365 sign-in method, users can no longer sign in using standard authentication as they did before. As of October 1, 2022, Microsoft has disabled traditional authentication using an username and password and replaced it with OAuth2. All applications running on the Microsoft 365 Server (e.g., email traffic) must now be registered in Microsoft Azure Active Directory. If the app ID is not registered, email traffic can no longer pass through the Microsoft Server. Read here to find out what requirements you must meet to set up OAuth2 on the ACMP Server.
8
9 {{aagon.warnungsbox}}
10 OAuth2 can only be used starting with Server 2012 R2, since [[kein TLS 1.2>>https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/enable-support-tls-environment?tabs=azure-monitor]] is not supported in earlier versions.
11 {{/aagon.warnungsbox}}
12
13 {{aagon.infobox}}
14 When IMAP mailboxes are moved, you must ensure that the UID in the database is also reset. If the last UID that ACMP retrieved is higher than that of the new mailbox, ACMP will not retrieve any emails as long as the last UID in the mailbox is lower. Please contact Support if you have any questions about how to reset the UID.
15 This also affects the case where a mailbox has been moved from a local Server to Online Exchange!
16 {{/aagon.infobox}}
17
18 = Requirements for OAuth2 =
19
20 To use OAuth2, the following prerequisites must be met:
21
22 - You must register an app (Application/Client ID) in the enterprise application (Microsoft Entra ID). For more information on what you need to consider, see the section [[Register a company application in Microsoft Entra ID>>doc:ACMP.610.Unternehmensanwendung registrieren in der Microsoft Entra ID.WebHome]].
23
24 - The following permissions must be specified for the app:
25
26 * IMAP.AccessAsUser.All
27 * POP.AccessAsUser.All
28 * SMTP.Send
29 * offline_access
30
31 Then proceed as follows:
32
33 (((
34 To continue working on the settings, you must now go to the Microsoft 365 Admin Center ([[https:~~/~~/admin.microsoft.com/Adminportal/Home>>url:https://admin.microsoft.com/Adminportal/Home]]) and sign in there. All permissions must be enabled for the mailbox you want to access.
35
36 {{figure}}
37 [[image:64_Einstellungen_ACMP Server_Postfach aktivieren11.png||data-xwiki-image-style-alignment="center"]]
38
39 {{figureCaption}}
40 Microsoft 365 Admin Center
41 {{/figureCaption}}
42 {{/figure}}
43
44 There, in the left-hand navigation under //Users//, you'll find the menu item //Active Users//. Select the user to whom the changes should apply. Open the account settings, go to the //Email// tab, and click //Email Apps// > //Manage Email Apps//.
45
46 Select the apps in which the user can access Microsoft 365 emails. At this point, you must select all the checkboxes to grant access.
47
48 {{aagon.warnungsbox}}
49 Please note that the “Authenticated SMTP” setting is important and must also be activated. This setting is not always enabled by default!
50 {{/aagon.warnungsbox}}
51
52 {{figure}}
53 [[image:64_Einstellungen_ACMP Server_E-Mail-Apps verwalten12.png||data-xwiki-image-style-alignment="center"]]
54
55 {{figureCaption}}
56 Manage Email App settings
57 {{/figureCaption}}
58 {{/figure}}
59
60 = Configuring Settings in ACMP =
61
62 After you have made the relevant changes on the selected Microsoft pages, you must also customize additional settings in the ACMP settings. To do this, navigate to //System //> //Settings //> //ACMP Server //> //E-Mail Service//.
63
64 {{aagon.infobox}}
65 Starting with ACMP version 6.5, the option to choose an authentication mode is no longer available. Authentication occurs automatically via the OAuth configuration.
66 {{/aagon.infobox}}
67
68 Enter all the dates as shown in the following figure:
69
70 {{figure}}
71 [[image:68_Einstellungen_Server Information_1002.png||alt="68_Einstellungen_ACMP Server_Server Informationen für ACMP.png" data-xwiki-image-style-alignment="center"]]
72
73 {{figureCaption}}
74 Server information for ACMP
75 {{/figureCaption}}
76 {{/figure}}
77
78 {{aagon.infobox}}
79 You do not need to enable the two “Accept untrusted certificates” checkboxes under “Receive/Send Emails.”
80 {{/aagon.infobox}}
81
82 When requesting the token, it is crucial that the email address and the user match so that the process works smoothly. The token is requested under the //OAuth configuration// section
83
84 To request the token, you must have selected “OAuth” under the //password encryption// setting. When requesting the token, you must enter the Application/Client ID and set the account type to “Microsoft Azure AD (organizations only).” At this point, you must insert the ID that you previously saved or copied. The username used here is taken from the Server information (sender).
85
86 {{figure}}
87 [[image:66_Einstellungen_Neues Autorisierungstoken anfordern_496.png||alt="64_Einstellungen_ACMP Server_Neues Autorisierungstoken anfordern.png" data-xwiki-image-style-alignment="center"]]
88
89 {{figureCaption}}
90 Request a new authorization token
91 {{/figureCaption}}
92 {{/figure}}
93
94 Make sure the token is created using the same email address that will be used to retrieve it. You used this email address in the email service settings. If a browser window does not open when creating the token, allowing you to select the Helpdesk user or email address, this is because Single Sign-On (SSO) is activated, which causes the token to be retrieved for the current Windows user. To resolve this issue, you must use a local Windows user who cannot execute SSO, or log in to Windows using the “Helpdeskuser”/email address that should also retrieve emails.
95
96 {{figure}}
97 [[image:64_Einstellungen_ACMP Server_Anmeldung im Konto.png||data-xwiki-image-style-alignment="center" height="560" width="480"]]
98
99 {{figureCaption}}
100 Log in to your account
101 {{/figureCaption}}
102 {{/figure}}
103
104 {{aagon.infobox}}
105 Another option is to start the ACMP Console as a local user.
106 {{/aagon.infobox}}
107
108 == Changes to the AAD or Exchange settings ==
109
110 If you need to change settings in Azure Active Directory or the Online Exchange mailbox—such as two-factor authentication - it may take several minutes for the change to synchronize across all servers in AAD. In this case, you should wait a moment before retrieving a new token from ACMP.
111
112 == Two-Factor Authentication ==
113
114 If you have activated two-factor authentication, you must disable it in order to retrieve emails using ACMP.
115
116 == Shared Mailboxes ==
117
118 Currently, shared mailboxes can only be used if the mailbox has an Outlook/Exchange license (e.g., “Microsoft 365 E3”) and a password. Only then can the token be retrieved and emails be accessed.
119 )))
© Aagon GmbH 2026
Besuchen Sie unsere aagon-Community