Temporary access for MailDesk setup (Microsoft 365)
The few, time-limited accesses your admin grants so MIT can set up MailDesk + Microsoft 365 for you remotely — with exact steps and official Microsoft links.
When you order the MailDesk setup service and use Microsoft 365, our team performs the entire technical setup remotely. This page lists the few, time-limited accesses your administrator grants — with the exact steps. It takes about 5–10 minutes on your side; no meeting is required.
What we need (least privilege)
| Access | Scope | Time limit |
|---|---|---|
Temporary Microsoft 365 account mit-setup@your-domain | Role Application Administrator (+ Exchange Administrator only if shared mailboxes are connected); MFA enabled. No Microsoft 365 licence required. | Until acceptance (max 5 business days), then you delete it. |
Odoo administrator account mit-setup | Access-rights group Administration / Settings. | Until acceptance. |
| One-time Grant admin consent | A single click by a Global Administrator (we send a ready link). | One-time. |
| Only if we install the module: Odoo.sh collaborator, or SSH (self-hosted) | Deploy the MailDesk modules and restart Odoo. | Until acceptance. |
Not requested: your employees' passwords, permanent admin rights, or application permissions (tenant-wide mailbox access). MailDesk uses delegated Mail.ReadWrite only.
Step 1 — Temporary Microsoft 365 account
- Create the user
mit-setup@your-domainin the Microsoft Entra admin center — how to create a user. - Assign the role Application Administrator (and, only if you connect shared mailboxes such as info@ / support@, also Exchange Administrator) — how to assign a role.
- Enable MFA for the account — require MFA via Conditional Access (or per-user MFA).
- Send us the sign-in details over a secure channel.
Step 2 — Odoo administrator account
- In Odoo: Settings → Users → New, e-mail
mit-setup@your-domain. - Set the access-rights group Administration: Settings.
- Send us the login or an invitation link.
Step 3 — Grant admin consent (one click)
After we register the MailDesk application in your tenant, we send your Global Administrator a ready-made link. One click on “Accept” authorises the app tenant-wide — no navigation, no meeting — about admin consent.
Connecting the mailboxes
We initiate every mailbox connection ourselves from the MailDesk admin area. For each personal mailbox there is one ~2-minute Microsoft sign-in (the standard login your team knows from Outlook), completed by the mailbox owner — the password is entered only on Microsoft's own page and is never seen or stored by us or by Odoo. If you prefer, you can provide temporary credentials and we complete the sign-ins for you.
After acceptance
You receive a full handover report (what was set up, where and how). You then delete the temporary mit-setup accounts (part of the handover protocol). We delete all access data within 14 days; the OAuth tokens remain exclusively in your Odoo.