Skip to main content

Mailbox Credentials & Security

TenantCore-created mailboxes may need credentials for Microsoft sign-in, sending-platform setup, Outlook-related workflows, or troubleshooting. TenantCore keeps those credentials available through a secure server-side credential vault rather than treating plaintext passwords or MFA secrets as ordinary application data.

How credential protection works

At a high level:
The browser does not connect directly to the underlying credential store. TenantCore checks the signed-in account and mailbox ownership before a protected value can be retrieved or changed.

What TenantCore stores

TenantCore keeps the non-sensitive information needed to manage the credential workflow, such as:
  • mailbox identity
  • credential synchronization state
  • credential update timestamp
  • MFA status
  • MFA method
  • MFA enrollment timestamp
The password or MFA seed is not treated as normal profile or reporting data.

Password reveal and copy

When an authorized operator requests a mailbox password, TenantCore retrieves it securely and displays it temporarily. Use reveal/copy only when you need the credential for a supported workflow. Avoid moving mailbox credentials into spreadsheets, tickets, chat messages, or other unprotected systems.

Password reset

TenantCore can reset the mailbox password in Microsoft 365 and synchronize the new credential with its protected credential store. If Microsoft accepts the password change but secure credential synchronization does not complete, TenantCore surfaces the problem rather than silently reporting the workflow as fully healthy.

MFA material

TenantCore-managed OATH/TOTP MFA follows the same security model. The MFA seed is protected as a secret. TenantCore generates the current short-lived code only when an authorized operator requests it.

What TenantCore does not put in normal logs or Reports

Sensitive security values are kept out of normal logs, Reports, and operational event details. That includes:
  • plaintext mailbox passwords
  • OATH/TOTP seeds
  • current MFA codes
  • recovery secrets
TenantCore can record that a security action occurred without recording the secret itself. For example:
  • password reset completed
  • password revealed
  • credential synchronization failed
  • MFA setup initiated
  • MFA enrollment confirmed

API behavior

The Complete API is intentionally more restrictive than the interactive security UI. The API can support actions such as:
  • password reset
  • credential synchronization status
  • MFA status
It does not provide unrestricted password or MFA-secret retrieval simply because a caller has an API key. The public API is designed for infrastructure automation, not general secret extraction.