Mailbox Credentials & Security
TenantCore-created mailboxes may need credentials for Microsoft sign-in, sending-platform setup, Outlook-related workflows, or troubleshooting. TenantCore keeps those credentials available through a secure server-side credential vault rather than treating plaintext passwords or MFA secrets as ordinary application data.How credential protection works
At a high level:What TenantCore stores
TenantCore keeps the non-sensitive information needed to manage the credential workflow, such as:- mailbox identity
- credential synchronization state
- credential update timestamp
- MFA status
- MFA method
- MFA enrollment timestamp
Password reveal and copy
When an authorized operator requests a mailbox password, TenantCore retrieves it securely and displays it temporarily. Use reveal/copy only when you need the credential for a supported workflow. Avoid moving mailbox credentials into spreadsheets, tickets, chat messages, or other unprotected systems.Password reset
TenantCore can reset the mailbox password in Microsoft 365 and synchronize the new credential with its protected credential store. If Microsoft accepts the password change but secure credential synchronization does not complete, TenantCore surfaces the problem rather than silently reporting the workflow as fully healthy.MFA material
TenantCore-managed OATH/TOTP MFA follows the same security model. The MFA seed is protected as a secret. TenantCore generates the current short-lived code only when an authorized operator requests it.What TenantCore does not put in normal logs or Reports
Sensitive security values are kept out of normal logs, Reports, and operational event details. That includes:- plaintext mailbox passwords
- OATH/TOTP seeds
- current MFA codes
- recovery secrets
- password reset completed
- password revealed
- credential synchronization failed
- MFA setup initiated
- MFA enrollment confirmed
API behavior
The Complete API is intentionally more restrictive than the interactive security UI. The API can support actions such as:- password reset
- credential synchronization status
- MFA status