🔒 New browser security hardening is live to help defend against AI-driven attacks. Learn more

Enable Shared Mailboxes for Secure Collaboration Gateway

Prev Next

Purpose: Enabling Secure Collaboration Gateway for Shared Mailboxes will allow users to send Secure Mail from a shared mailbox address. To enable the feature, an M365 admin will need to provide consent to eShare’s Outlook API.

  1. Login to Cloud Web Portal with an eShare administrator account. (Your M365 account should have at minimum application administrator role)

  2. Navigate to Manage Organization > Corporate Cloud Providers and turn ON the “Provide consent to eShare for Outlook API” option.

Graphical user interface, application  Description automatically generated

  1. Review the requested permissions for your organization presented by Microsoft and select Accept when ready. Also keep a note of the application (highlighted in the blue box) name you have created in the Entra.

    Note

    Please note that these permissions will be appended to your existing service principal created to connect cloud providers

  1. After accepting the permissions, you should see the option “Get access token” as shown in the screenshot below.  Right click on the “Get access token” and copy the link Graphical user interface, text, application, email  Description automatically generated

  2. Paste the copied link in a new tab. It would look similar to the below link. Remove amp; and click enter. If successful, you should get back to the cloud providers page with Outlook API consent ON. Now refresh the page and Get access token would disappear.

  1. Once the token is acquired, the application you named while connecting to cloud providers page (eSHARE Commercial Prod in this example) will need to be added as an Exchange Administrator

  2. Head over to https://portal.azure.com and open the Azure Active Directory Service

  3. Under the “Manage” category, select “Roles and administrators”

Graphical user interface, text, application, email  Description automatically generated

8 .Find the “Exchange Administrator” role and open the role. When the assignments page opens, select “Add Assignments” at the top of the page, search for your application, select “Add”

  1. With the token acquired and the Exchange Admin role assigned to the application, eShare is now able to query Outlook/Office for members of shared mailboxes. Next, we need to create a SharePoint site specifically for Shared Mailboxes, this is where the trusted shares will live when sending a Secured mail from any shared mailbox.

  2. Go to SharePoint Home, then select “Create site”

Graphical user interface, text, application, email  Description automatically generated

  1. On the create a site page, choose “Team Site”

Graphical user interface, website  Description automatically generated

  1. Call the site name “SharedMailboxes” and select next. You do not need to add any users to the site, then select Finish.

Graphical user interface, application, website  Description automatically generated

Now you will need go back to the eShare admin console to finish setting up SMG for Shared Mailboxes.

  1. Next go to the eShare admin console, then go to the Secure email tab.

  2. Under Secure email, enter the site name of the Shared Mailboxes site under “SP site name”, then select Save.

Graphical user interface, text, application  Description automatically generated

You have now successfully enabled SMG for Shared Mailboxes. Whenever a user sends an email from a shared mailbox, the files will be stored in this SharePoint site in an outbox folder.