When you click Connect Outlook / Office 365, Microsoft asks you to sign in and approve IntelliDesk. If something in your Microsoft 365 setup blocks that, you land back on the Settings page with a red message explaining what went wrong. This article covers each message and what to do about it.
Always use Connect Outlook / Office 365 for Outlook, Hotmail and Microsoft 365 mailboxes. Microsoft no longer allows password sign-in over IMAP, so the IMAP/SMTP form won't work for them.
Sign in as the mailbox, not as yourself
IntelliDesk reads the inbox of the account you sign in with. To connect support@yourcompany.com, sign in to Microsoft as support@yourcompany.com. If you sign in with your own work account, IntelliDesk connects your inbox instead. After connecting, check the address shown next to the Connected badge on the card.
"Your IT admin needs to approve IntelliDesk"
Your organisation doesn't let people approve apps that read mail; an administrator has to do it once for the whole Microsoft 365 tenant.
- On the error message, click Copy admin consent URL (the message stays on screen for 30 seconds).
- Send the link to your Microsoft 365 administrator. They open it, sign in with an admin account and approve IntelliDesk.
- Once they've approved it, click Connect Outlook / Office 365 again.
If the message has already gone, the admin consent link is:
https://login.microsoftonline.com/organizations/adminconsent?client_id=39477c74-008c-420f-bc91-c2c841869a98
"Blocked by your organization's Conditional Access policy"
Your IT team has a policy that blocks apps they haven't approved. Ask them to allow IntelliDesk, then try again.
"User not assigned to IntelliDesk"
Your Microsoft 365 tenant only lets people use apps they've been assigned to. Ask IT to assign the mailbox's account to IntelliDesk (or allow all users), then try again.
"Wrong Microsoft account" or "External account blocked"
- Wrong Microsoft account: the account you signed in with doesn't belong to the Microsoft 365 tenant that hosts the mailbox. Sign in with a work account from that tenant.
- External account blocked: the tenant doesn't allow guest or personal Microsoft accounts. Use a work account that belongs to the tenant.
Tip: if Microsoft signs you in automatically with the wrong account, try again in a private browser window.
"Microsoft sign-in cancelled"
The Microsoft window was closed, or Cancel was clicked, before finishing. Click Connect Outlook / Office 365 again when you're ready.
"Missing refresh token"
Microsoft didn't give IntelliDesk permission to stay connected. Try again and accept all the permissions on Microsoft's approval screen.
"Security check failed", "Signed out during Microsoft connect" or "Microsoft sign-in failed"
These are usually one-off problems. Sign in to IntelliDesk again if needed, make sure the right workspace is selected, and retry.
When it was working and then stopped
If the mailbox connected fine but the card now shows Error, read the Email account error box. A message saying the mailbox rejected the sign-in, or mentioning Microsoft authentication expired or a missing refresh token, means Microsoft has ended IntelliDesk's access. This happens when the account's password is reset, access is revoked, or an admin changes policies. Click Disconnect, then Connect Outlook / Office 365 again. See Reconnecting a mailbox that shows Error for how to catch up on email that arrived in the meantime.
If the card still shows Connected with a Sync is retrying notice instead, Microsoft didn't answer a check. IntelliDesk retries automatically and only moves the mailbox to Error after 5 failed checks in a row.
When to contact support
Contact IntelliDesk support if you see Microsoft integration not configured, Workspace not found, Failed to save the Microsoft connection, or if Microsoft rejected the authorization keeps coming back after a retry. Tell us the desk name and the exact message.
Related: Connecting a mailbox: Gmail, Outlook, and IMAP · Reconnecting a mailbox that shows Error