This article is for Microsoft 365 administrators and Cirrus Insight admins setting up an admin-managed connection, also called a service account. A service account lets Cirrus Insight sync email and calendar data for many users from a single app registration in Microsoft Entra ID, so each user does not have to sign in and grant consent individually.
If your users connect their own mailboxes instead, see How do I use Manage Connections?
Cirrus Insight reads and writes mailbox data through Microsoft Graph. For an admin-managed connection, Microsoft requires an app registration in your Entra tenant. The app registration gives Cirrus Insight three things:
You control which Cirrus Insight features can run by choosing which permissions to grant, and you can optionally limit which mailboxes the service account can reach. See Restricting which mailboxes the service account can reach at the end of this article.
Still using an Exchange (EWS) service account? Microsoft is retiring Exchange Web Services for Exchange Online. Blocking began October 1, 2026 and EWS will be fully removed on April 1, 2027. Create the app registration below and switch your service account to Microsoft 365 before then. On-premises Exchange Server is not affected.
You will need:
⚠️ Copy the Value, not the Secret ID. Pasting the Secret ID into Cirrus Insight instead of the secret Value is the most common cause of a failed connection.
Client secrets expire, with a maximum lifetime of 24 months. When this secret expires, every user synced through the service account stops syncing at once and the service account shows as Disconnected in Cirrus Insight. Record the expiry date somewhere your team will see it, and set a reminder before it lapses.
To rotate the secret, create a new client secret in Entra, open the existing service account in Cirrus Insight, paste the new Value into the Client Secret field, and Save. Users resume syncing on the next cycle.
Cirrus Insight supports client secrets only; certificate credentials are not supported.
All permissions must be Application permissions. Delegated permissions have no effect for a service account.
| Cirrus Insight feature | Permissions to add |
|---|---|
| Email Sync | Mail.ReadWrite |
| Calendar Sync | Calendars.ReadWrite, MailboxSettings.Read |
| Calendar Scheduling | Calendars.ReadWrite, MailboxSettings.Read |
| Email Blasts | Mail.Send (plus Mail.ReadWrite) |
| Email Blast Sync to Salesforce, or email alias matching | User.Read.All |
Combine rows for the features you use. For example, Email Sync + Calendar Sync needs Mail.ReadWrite, Calendars.ReadWrite, and MailboxSettings.Read.
What each permission does:
Mail.ReadWrite: read messages and folders, apply the "Filed with CI" category to synced emails, and create drafts for Email Blasts.Calendars.ReadWrite: read calendars and events, create and update events for Salesforce → Outlook sync and Calendar Scheduling bookings, and apply the "Filed with CI" category to synced events.MailboxSettings.Read: read each user's mailbox time zone so event times are correct.Mail.Send: send Email Blasts on the user's behalf.User.Read.All: read directory profile attributes (display name and email aliases) so Cirrus Insight can match aliases to the primary address and match sent Email Blasts to Salesforce records. This permission does not grant access to mailbox content.Do not add Mail.Read alongside Mail.ReadWrite, or Calendars.Read alongside Calendars.ReadWrite. The ReadWrite permission already includes everything Read allows.
Not available through a service account: Task Sync (Cirrus Insight To Do) requires an individual user connection.
If your security policy does not allow write access to mailboxes or calendars, Cirrus Insight can run Email Sync and one-way Calendar Sync (Outlook → Salesforce) with read-only permissions.
| Feature | Read-only permissions | What you give up |
|---|---|---|
| Email Sync | Mail.Read |
The "Filed with CI" category on synced emails |
| Calendar Sync (Outlook → Salesforce only) | Calendars.Read, MailboxSettings.Read |
The "Filed with CI" category on synced events, and Salesforce → Outlook sync |
Before enabling sync with read-only permissions, make these changes in Cirrus Insight:
Calendar Scheduling and Email Blasts are not available with read-only permissions, since both need to create items in the mailbox.
contoso.com). Users whose domain is not on this list are not picked up by the service account, and no error is shown.The service account now appears in the Service Accounts list with a status of Connected. Connected means Cirrus Insight was able to sign in with your Client Id, Secret, and Tenant. It does not confirm that permissions were granted.
Run Test signs in with your app registration and reads one day of calendar events from the mailbox in the Test Account field. It confirms your Client Id, Secret, and Tenant are correct and that a Calendars permission has been granted.
Run Test does not check Mail permissions, other mailboxes, or your Domain List.
"Test failed" is expected, and not a problem, when:
"Test failed" is a real problem when:
If you have checked all of the above and the test still fails, contact Cirrus Insight Support and include the email address the admin who set up the service account uses to sign in to Cirrus Insight.
The permissions you grant in Entra ID apply to every mailbox in your tenant. If you want to limit the service account to specific mailboxes (for example, only your sales team), your Exchange Online administrator can do this using Role Based Access Control (RBAC) for Applications in Exchange Online.
Cirrus Insight fully supports RBAC-scoped service accounts. Setup happens entirely on the Microsoft side, so it is not covered in this article. Microsoft's guide is here: Role Based Access Control for Applications in Exchange Online.
⚠️ Remove scoped permissions from Entra ID. For any permission your admin scopes in Exchange, remove that same permission from the app registration in Entra ID. If a permission is granted in both places, the tenant-wide Entra grant takes priority and the Exchange scope has no effect.
A few things to share with your Exchange admin:
Application Mail.ReadWrite and Application Calendars.ReadWrite).User.Read.All cannot be scoped this way. It is a directory permission, not a mailbox permission, and it only exposes profile attributes, not mailbox content.Your service account is connected. To start syncing, enable Email Sync or Calendar Sync for your users. See Sync Administration with a Service Account for how to manage users under a service account.