---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure

# Configure the Microsoft Exchange Online integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read

After you've installed the application from the ServiceNow Store, configure
it to connect to your ServiceNow AI Platform instance. This activation activates the search
and delete workflows.

## Before you begin

Role required: sn_si.admin

## Procedure

1. In your ServiceNow AI Platform instance, navigate to Security OperationsIntegrationsIntegration Configurations.
2. Locate the Microsoft Exchange Online tile.
3. Select Configure.  
4. In the Microsoft Exchange Online Configuration dialog that is displayed, select Configure Exchange Online.  
   An example of a completed and validated form follows the table.
   Figure 1. Configure Microsoft Exchange Online

   | Option | Description |
   | Connection Settings tab |   |
   | Tenant | The Microsoft Exchange Online tenant that you want to perform searches on. This text is the unique name that appears after @ for email addresses for your organization. For this example, <kbd class="ph userinput">snowsecops.onmicrosoft.com</kbd> is the tenant (domain). |
   | Certificate Thumbprint | A certificate thumbprint is a hash of a certificate, computed over all certificate data and its signature. Thumbprints are used as unique identifiers for certificates, in applications when making trust decisions, in configuration files, and displayed in interfaces. |
   | OAuth Application ID | The Application (client) ID that was generated for the account that you created in the Microsoft Azure portal. For more information, see [Set up your Microsoft Azure account](https://servicenow-prod.fluidtopics.net/xrfZ7jhb8zBjZmgNX8mJbw "Complete the following setup tasks in your Microsoft Azure portal prior to installing the ServiceNow application for this integration. This account permits access to the Microsoft Exchange Online tenant for email message details."). |
   | OAuth Client Secret | Password (client secret) for the account that you created in the Microsoft Azure portal. For more information, see [Set up your Microsoft Azure account](https://servicenow-prod.fluidtopics.net/xrfZ7jhb8zBjZmgNX8mJbw "Complete the following setup tasks in your Microsoft Azure portal prior to installing the ServiceNow application for this integration. This account permits access to the Microsoft Exchange Online tenant for email message details."). |
   | Additional Settings tab |   |
   | Email Search Window (days) | The email search history range in number of days. The integration searches for email messages that have been sent or received in the Microsoft Exchange Online server for the number of calendar days that you enter. You're required to enter a value between 1-30. 30 days is the default and the maximum number of days you can enter for a search. Entering a low number of days in the search window range improves response time, but you may not capture all matched messages as a result. This global setting is for all searches. Before executing the email search, there are no parameters that permit you to change this value for individual searches. |
   | Maximum Search Duration | Use this option to set the search timeout threshold. If the timeout threshold is reached, the search ends and no results are displayed. You can specify a default value of 90 minutes and a maximum value of 240 minutes. By setting this threshold, you can avoid endless search loops that could cause performance issues on the Microsoft Exchange Online tenant and the ServiceNow instance. |
   | Tagging | Security tag. Default is selected. When enabled, security tags are automatically applied to related security incidents when search and delete capabilities are initiated and successfully completed. The default tag names are displayed, but tag names and colors can be edited. For more information, see [Edit security tags for the Microsoft Exchange Online integration](https://servicenow-prod.fluidtopics.net/6PT~VvN4hN2zOqSQksS7zA "You can edit the names and colors of the security tags in your ServiceNow AI Platform instance for the Microsoft Exchange Online integration. These security tags help you quickly identify when email search either completes or fails. They also identify when requests to delete emails are initiated and when the email items are successfully deleted."). |
   | Recover Deleted Emails | Default is selected. This item only applies to emails that you have deleted using this integration. If you don't want users in your organization to have access to the emails that you've deleted, verify that this check box is cleared. If the check box is cleared, the emails that you delete using the workflow of this integration are permanently deleted and placed in the Purges folder. This folder is a sub folder within the Recoverable Items folder on Microsoft Exchange Online that a user normally can't access. If you want users to recover the emails you delete, select this check box. If this check box is selected, depending on how the user's account is configured in Microsoft Exchange Online, the emails you delete using the workflow of this integration are placed in the Deleted Items folder in the mailbox of the user. If an account is configured so that the user can view the Deleted Items folder in their mailbox, the user can recover the emails you delete from their Microsoft Exchange Online account. For more information, see [Recover deleted items or email in Outlook Web App](https://support.office.com/en-us/article/recover-deleted-items-or-email-in-outlook-web-app-c3d8fc15-eeef-4f1c-81df-e27964b7edd4?ui=en-US&rs=en-US&ad=US). |
   | Search Completion Notification | Select this option to enable notifications when the search is completed. If the Enable check box is selected, you'll receive notifications if any matching emails are found. If the check box is cleared, search completion notifications aren't sent. |
   | Approvals | Request approval to delete emails. Default is cleared. When the check box is cleared, the optional approval process for requesting prior permission before deleting emails from the Microsoft Exchange Online service is disabled. Verify that this check box is cleared if you want to grant your security incident analyst permission to delete emails without requesting prior permission. If enabled, a request is submitted via email to each member of an approval group. From the list, select an approval group from the list. After a request is submitted to an approval group, only one approval is required from the group to complete the request. Any member of the approval group has approval authority. Having a group with more than one person with approval permission ensures that these requests are processed in a timely way. |
   | Failure Notifications | Select the check box to enable failure notifications when the search or delete action fails due to invalid OAuth credentials. If Enabled, failure notifications are sent through email to each member of the failure notifications group when OAuth credentials are invalid. If the check box is cleared, no failure notifications are sent. |
   | Email Result Threshold | If the number of emails being deleted is greater than or equal to the value specified here, the Delete request must be approved before the Delete action is invoked. If the threshold value is set to 1, every Delete request must be approved. From version 10.3 or later, you can specify an email delete threshold for approvals. |
   |-|-|

   {#msx_configure__choicetable_erq_lmy_c2b}
5. Choose one to continue.

   | Option | Description |
   | Save | Save your edits. This action doesn't verify your connection. |
   | On the Connection Settings tab, select Validate. | This action validates your Certificate authentication and OAuth credentials. If your credentials are valid, the Validate button and both indicators are green. |
   |-|-|

   {#msx_configure__choicetable_s2l_b2x_ngb}
If an error message is displayed, or one or more of the indicators to the right of the Validate button are red, verify that the user account credentials you entered are valid. Enter your credentials and select Save again.  
Refer to the following table for more information about the Validate button and the colored icons.{#msx_configure__table_pwz_zdc_sgb__entry__2}

| State of Validate button and indicators | Description |
|-|-|
| Validate button is green and all the small colored indicators are green. | Indicates that the credentials are valid. |
| Validate button is light red with a blue border and one or all the small colored indicators are orange. | The validation is in process. Validation may take a few more moments to complete. |
| Validate button is light red and one or all of the small colored indicators are red. | * Exchange Online certificate-based authentication indicator is red: Indicates that the Exchange Online certificate-based authentication is invalid. * OAuth credentials indicator is red: Indicates that the OAuth credentials are invalid. {#msx_configure__ul_ygp_m4y_q3b} |
[ ]

{#msx_configure__table_pwz_zdc_sgb}
**Previous topic:** [Install Microsoft Exchange Online application](https://servicenow-prod.fluidtopics.net/s6jKx0Dt64gK5dcCr6rLvQ "Before you run the integration on your instance, install the Microsoft Exchange Online application for the integration from the ServiceNow Store.")  
**Next topic:** [Define email search criteria and request a search](https://servicenow-prod.fluidtopics.net/1RzsS82psRGigRxdm6QEKg "As a user with the sn_si.analyst role, set up search criteria and submit an email search request based on incident details on a security incident record.")

*[\>]: and then


