> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tenantcore.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Native Outlook Access

> Understand how TenantCore provides Outlook access to sending mailboxes through a licensed Mailbox Access Account.

# Native Outlook Access

TenantCore can provide native Outlook access to a TenantCore-created mailbox without requiring a separate Microsoft licence for every sending mailbox.

The model uses Microsoft mailbox delegation.

## Sending mailbox vs. Mailbox Access Account

These are two different identities.

### Sending mailbox

The sending mailbox is the address used for outbound sending and replies.

Example:

```text theme={null}
alex@sending-domain.com
```

### Mailbox Access Account

The **Mailbox Access Account** is a normal licensed Exchange Online user in the Microsoft 365 tenant.

That licensed user is granted delegated access to one or more TenantCore-created mailboxes.

For BYOT tenants, the operator selects an eligible existing licensed user.

## Permissions TenantCore applies

TenantCore grants:

* **Full Access**
* **Send As**

Full Access allows the licensed account to open and manage the delegated mailbox.

Send As allows the operator to send from Outlook as the sending mailbox rather than as the Mailbox Access Account.

## Normal workflow

```text theme={null}
Open Mailbox
    ↓
Choose licensed Exchange user
    ↓
TenantCore grants Full Access + Send As
    ↓
TenantCore verifies permissions
    ↓
Open Outlook
    ↓
Sign in using the Mailbox Access Account
```

The operator signs in with the licensed access account, not with a separate licence assigned to every shared mailbox.

## Delegation propagation

Microsoft permission changes are not always instantaneous.

After TenantCore applies Full Access or Send As, Microsoft may need time to propagate the change.

TenantCore tracks delegation state so the UI can distinguish between:

* assigning
* ready
* failed
* needs repair

## Repair and reapply

If permissions drift or Microsoft does not complete the expected delegation state, TenantCore can reapply and verify the permissions.

For BYOT tenants, changing the Mailbox Access Account should grant and verify the new account before removing the previous delegation.

## Security model

The Mailbox Access Account does not need administrative roles simply to access delegated mailboxes.

TenantCore should limit its Outlook-access workflow to mailboxes already registered to the authenticated TenantCore account.

The customer continues using their normal Microsoft identity for the licensed access account.

## Outlook URL behavior

TenantCore can use an Outlook on the web deep link for a convenient one-click experience.

The underlying security model is Microsoft delegation, not the URL itself.

If Microsoft's deep-link format changes, the same mailbox can still be opened through Microsoft's normal shared-mailbox workflow without changing the permission model.
