Skip to main content

Mailbox MFA

TenantCore can guide an operator through Microsoft OATH/TOTP MFA setup for a mailbox and protect the resulting secret through the credential-vault workflow. TenantCore-managed MFA is optional. A mailbox does not need to use TenantCore’s MFA workflow simply to exist or to connect to a sending platform.

What TenantCore manages

TenantCore does not replace Microsoft’s MFA enrollment experience. Instead, TenantCore guides the operator through Microsoft’s Security Info flow and securely handles the OATH/TOTP secret once Microsoft presents it. The flow is:

Why the manual secret is used

Microsoft can display both a QR code and a manual setup option. TenantCore uses the underlying OATH/TOTP secret so it can protect the seed and generate the current six-digit code only when an authorized operator requests it.

After enrollment

Once the setup is confirmed, the mailbox security state can show:
  • MFA status
  • MFA method
  • enrollment state
  • current code when explicitly requested
  • credential-vault synchronization state
The TOTP seed itself should not be exposed back to the normal UI after enrollment.

MFA and sending integrations

MFA setup is not a hard prerequisite for TenantCore sending integrations. When a mailbox is being connected to a sending tool, the operator may:
  • set up TenantCore-managed MFA first
  • continue without TenantCore MFA
  • use an MFA method already managed outside TenantCore
This matters because some operators already have Microsoft MFA configured independently.

Current code generation

TenantCore generates the current TOTP code only when requested. The generated code is short-lived and should not be written to normal logs, Reports, or browser persistence.

Security boundary

A request to reveal an MFA code is authorized against the authenticated TenantCore account and the mailbox resource. Knowing a mailbox email address is not enough to retrieve its security material.