Outlook
Connect a Microsoft Outlook or Microsoft 365 mailbox so Sift can reply to email-based conversations, such as Custom Form submissions that captured an email address. Sift sends from your mailbox, and when the customer answers, their reply threads back into the same action in your inbox.
At a glance
| Outbound: email replies from your connected mailbox | ✅ |
| Inbound: customer replies thread back into the same action | ✅ real time |
| Sign in with a Microsoft account (OAuth) | ✅ |
| Connect with app credentials (no user sign-in) | ✅ recommended for shared mailboxes |
| Shared or service mailboxes | ✅ via app credentials |
| Per-inbox email signature | ✅ |
| New actions from arbitrary inbound email | ❌ only replies on conversations Sift started |
| Send-as aliases | ❌ mail goes out from the connected mailbox address |
Choose a connection method
Outlook lives under Settings → Integrations → Microsoft Outlook. There are two ways to connect, and you can mix them across mailboxes:
- Add account (OAuth): sign in with a Microsoft work account. Fastest to set up. The connection is tied to that person's account, so it stops working if the account is disabled or the grant is revoked.
- Connect with app credentials: your Microsoft administrator registers an application in your own Microsoft Entra tenant and pastes its credentials into Sift. Nothing is tied to a person, which makes this the right choice for shared support mailboxes like
support@yourcompany.com.

Set it up: OAuth sign-in
- Go to Settings → Integrations → Microsoft Outlook and click Add account.
- Sign in with the Microsoft account that owns the mailbox and accept the requested permissions (read and write mail, send mail).
- Back in Sift, click Connect inbox on the account row. Sift starts watching the inbox for replies.
Set it up: app credentials
Your Microsoft administrator does steps 1 through 5 in the Microsoft Entra admin center; anyone with admin access to Sift does step 6.
- Register an application. Go to App registrations → New registration. Choose "Accounts in this organizational directory only" (single tenant). No redirect URI is needed.
- Copy the IDs. From the app's Overview page, note the Application (client) ID and the Directory (tenant) ID.
- Add application permissions. Under API permissions → Add a permission → Microsoft Graph → Application permissions, add
Mail.ReadWriteandMail.Send. These must be Application permissions, not Delegated. - Grant admin consent. On the same API permissions page, click Grant admin consent for [your organization]. Without this, the connection test in Sift fails.
- Create a client secret. Under Certificates & secrets → New client secret, create a secret and copy its Value immediately (it is shown only once). Secrets expire after at most 24 months; see Rotating the client secret below.
- Connect in Sift. In Settings → Integrations → Microsoft Outlook, click Connect with app credentials and enter the tenant ID, client ID, client secret, and the mailbox address. Use the account's primary address (its user principal name), not an alias. Sift validates the credentials, checks the permissions, probes the mailbox, and connects the inbox in one step.

Limit the app to your support mailbox (recommended)
By default, application permissions let the registered app read and send mail in every mailbox in your organization. Sift only ever touches the mailbox you connect, but we recommend enforcing that on the Microsoft side too. In Exchange Online PowerShell, scope the app to the support mailbox:
# Replace with your app's client ID and the mailbox Sift uses
New-ApplicationAccessPolicy -AppId "<client-id>" `
-PolicyScopeGroupId "support@yourcompany.com" `
-AccessRight RestrictAccess `
-Description "Restrict Sift to the support mailbox"
# Verify
Test-ApplicationAccessPolicy -AppId "<client-id>" -Identity "support@yourcompany.com"Microsoft is replacing application access policies with role-based access control for applications; both work today. If your organization already uses RBAC for Applications, create a management scope for the mailbox and assign the app the Application Mail.ReadWrite and Application Mail.Send roles against that scope instead.
Rotating the client secret
Client secrets expire (24 months at most, and many organizations require shorter). When the secret expires or is rotated, the account row in Sift shows that the credentials are invalid. Create a new secret in the Entra admin center, then click Update secret on the account row in Sift and paste the new value. Everything else stays connected.
What you can do
Reply by email from any action whose conversation captured an email address: your reply is sent from the connected mailbox, and the customer receives a normal email. Follow the thread: when they answer, their reply appears on the same action in real time. Set a signature per inbox under the account row. Pause an inbox with its toggle without disconnecting it.
Tips
- App credentials suit shared mailboxes; OAuth suits a quick start with a personal work account. You can switch a mailbox from OAuth to app credentials later by connecting the same address with app credentials.
- The mailbox address must be the account's primary address. If Sift reports it cannot access the mailbox, check for a typo, an alias, or an application access policy that excludes the app.
- Sift never creates new actions from ordinary inbound email. Only replies on conversations Sift is already tracking are ingested.