๐Ÿ”‘

Single Sign-On & Permissions

MailBroom for Business ย ยทย  Last updated: 8 July 2026 ย ยทย  AIERT Ltd

โœ… Microsoft Publisher Verified
๐Ÿ”‘
OAuth 2.0 / OpenID Connect
๐Ÿข
Microsoft Entra ID only
โš™๏ธ
Zero SSO setup required
โœ…
Publisher Verified ยท AIERT Ltd
๐Ÿ”‘

Protocol

MailBroom for Business uses OpenID Connect and OAuth 2.0 (the Authorization Code flow) against the Microsoft identity platform's v2.0 endpoint, via Microsoft Entra ID. It does not support SAML, and does not support any identity provider other than Microsoft Entra ID โ€” this is a Microsoft 365-only product.

๐Ÿข

Publisher

MailBroom for Business is published by AIERT Ltd (Companies House No. 16587000) and is a Microsoft Publisher Verified application (MPN ID 7106038) โ€” the sign-in consent screen shows AIERT Ltd's verified badge.

โš™๏ธ

Configuration required

None. There's no SAML metadata to exchange, no certificate to upload, and no SSO setup screen in the app. Sign-in uses Microsoft's own native OAuth flow โ€” a user clicks "Sign in with Microsoft" and authenticates exactly as they would for Outlook or Teams. The only thing that can require IT action once is a one-time admin consent grant, described below.

๐Ÿ›ก๏ธ

Permissions requested

ScopeTypeWhy it's needed
openid, email, profileStandard OpenID Connect scopesConfirms who's signing in โ€” your name, email, and that you have a valid Microsoft account. Included automatically with every Microsoft sign-in.
offline_accessDelegated ยท Microsoft GraphLets MailBroom refresh its own access token quietly in the background, so you're not prompted to sign in again every hour during a long cleanup session.
Mail.ReadWriteDelegated ยท Microsoft GraphThe core permission Smart Sweep, Storage Cleanup, and Power Search all depend on โ€” reading mailbox contents to rank senders and size, and performing the bulk delete/move actions you choose.
Mail.SendDelegated ยท Microsoft GraphUsed for exactly one feature: notifying your organisation's admin by email the moment a seat-limit is reached, sent on the signed-in admin's own behalf. Not used anywhere else.
โœ…

One-time admin consent

Some Microsoft 365 tenants are configured to require an administrator to approve a new application's permissions before any user in that tenant can sign in to it. If your tenant is configured this way, the first person to sign in will see a message asking an admin to grant consent โ€” any Global Administrator or Cloud Application Administrator can do this in one click from that same screen, and it only needs doing once per organisation.

๐Ÿงช

Testing before you commit

IT Directors evaluating MailBroom for Business can request a free 30-day trial โ€” a time-limited login with full feature access, no card required, no company-wide licence purchase needed to test it against your own tenant.

Request a trial โ†’
๐Ÿšฆ

Troubleshooting

  • โœ“"Need admin approval" on sign-in โ€” your tenant requires admin consent for new apps. Any Global Administrator or Cloud Application Administrator can approve this once, from the same screen.
  • โœ“Access revoked or lost โ€” you or your IT admin can revoke MailBroom's Graph access at any time from your organisation's Microsoft Entra ID enterprise applications list, independent of anything in MailBroom itself.
  • โœ“Personal email accounts (Gmail, Outlook.com, etc.) cannot use company licensing โ€” access is scoped to verified business email domains only.
โœ‰๏ธ

Engineering & support contact

For SSO onboarding, integration questions, or anything gallery/marketplace-review related, contact AIERT Ltd directly.

Email AIERT Ltd at support@aiert.co.uk โ€” this is our named engineering and support contact for SSO onboarding and integration queries.