Skip to main content

Personal mailbox or RBAC application access: choosing how to connect Microsoft 365

The two ways Kolleno can connect to a Microsoft 365 mailbox, what each one needs, what breaks each one, and how to pick between them.

Kolleno connects to Microsoft 365 in two ways. Both appear on the same screen when you connect a mailbox, and both talk to Microsoft the same way underneath. The difference is who Kolleno authenticates as: you, or itself.

The short answer

Pick Personal mailbox if the mailbox belongs to one person, that person can sign in to Microsoft, and they are happy for mail to go out from their own address.

Pick (Role-Based Access Control (RBAC) application access if the mailbox is shared, for example ar@yourcompany.com or finance@yourcompany.com, if nobody signs in to it, or if the connection needs to outlive whoever set it up.

If you are choosing for a team inbox, RBAC is almost always the right answer.


Personal mailbox

You click Sign in with Microsoft and authenticate with your own Microsoft 365 account. Kolleno receives a token that acts on your behalf. Whichever account you sign in with is the mailbox that gets connected, so mail goes out from that address and replies are read from it.

Who sets it up: whoever owns the mailbox, on their own, in about a minute. No IT involvement in most organizations.

If your organization blocks user consent: Microsoft will show a "Need admin approval" message instead of connecting. Use Copy admin approval link under the Personal mailbox card and send it to whoever administers your Microsoft 365 tenant. They approve once, then you sign in normally.

What it needs: an account that can sign in interactively. That rules out shared mailboxes, which have sign-in blocked by design.

What ends it:

  • The person leaves and their account is disabled or deleted

  • The mailbox is converted to a shared mailbox, which blocks sign-in

  • An admin revokes Kolleno's approval or signs all sessions out

When any of those happen, Kolleno flags the mailbox as needing attention. The fix is for the same person to sign in again.


Role-Based Access Control (RBAC) application access

Nobody signs in. Kolleno authenticates as an application using a certificate, and your IT admin grants it access to named mailboxes using a Microsoft feature called Exchange RBAC for Applications. Access belongs to the mailbox, not to a person.

Who sets it up: a Microsoft 365 admin, in two parts.

  1. They approve Kolleno once for the organization. Either they click Connect mailbox while signed in to Kolleno, or you send them the Copy admin approval link from the RBAC card and they open it themselves.

  2. The same admin runs a short PowerShell sequence to scope access to the specific mailbox. It takes about five minutes and is covered step by step in the IT setup article linked at the bottom of this page.

Once that is done, you enter the mailbox address in Kolleno. Kolleno checks the mailbox before saving anything, so if the scoping is not in place yet you get a clear error rather than a connection that silently does nothing.

What it needs: someone with the Exchange Administrator or Global Administrator role, once per organization, plus one short command per mailbox after that.

What ends it: IT removing the role assignment or the mailbox scope. Kolleno notices on its next send or check and flags the mailbox as needing attention.


Side by side

Personal mailbox

RBAC application access

Who signs in

The mailbox owner

Nobody

Suits

Individual inboxes

Shared and IT-managed inboxes

Needs an admin

Only if user consent is blocked

Yes, always

Setup time

About a minute

About five minutes, once per organization

Works with shared mailboxes

No

Yes

Survives the person leaving

No

Yes

What Kolleno can reach

The mailbox of the account that signed in

Only the mailboxes IT has scoped, and this is provable

Multiple mailboxes

One sign-in each

Reuses the same approval, one command per mailbox


The two "Copy admin approval link" buttons are different links

Both cards have a Copy admin approval link option and they are not interchangeable. Kolleno uses a separate Microsoft app registration for each path, so each link asks your admin to approve a different thing.

Copy the link from the card for the path you actually want. If the wrong one is approved, the approval succeeds and the connection still fails, which is a confusing place to end up.


What happens when the person who connected it leaves

This is usually the deciding factor. A personal connection is tied to a Microsoft account, so when that account is disabled the connection stops and the mail stops with it. Somebody has to notice, and then somebody with access to the mailbox has to reconnect it.

An RBAC connection has no account behind it. Staff can come and go and the connection is unaffected. Only an IT admin deliberately removing the scope will stop it.


Converting a personal mailbox into a shared mailbox

A mailbox often starts as one person's and later becomes a shared inbox. Worth knowing before you do it: converting to a shared mailbox blocks interactive sign-in, so an existing personal connection stops working and cannot be set up again.

Set up RBAC access for that address either before or straight after the conversion. The email address does not change, so nothing else in Kolleno needs updating, and the RBAC scope keeps matching.


Checking which method a mailbox is using

Go to Settings, then Email profiles, and open the profile. A mailbox connected with RBAC shows a Connection type of "Shared mailbox | RBAC application access", along with the Microsoft tenant it belongs to and the date it was connected.

Company admins can see every organization that has approved Kolleno under the cog icon, then Microsoft tenants. Access can be revoked from there, which disconnects every mailbox under that organization at once.


For your IT admin

The PowerShell setup for the RBAC path, with the scoping commands and how to verify them: For IT admins: giving Kolleno access to one shared mailbox (Microsoft 365).

That article is written to be forwarded as-is. It needs nothing from Kolleno beyond the mailbox address.


Limitations

Please note that if you have high volumes of emails sent and received, Microsoft will have API limitations that will be a blocker. In that case, we recommend setting up Custom DNS.

Did this answer your question?