Skip to main content

Quickstart

This guide takes you from a new TenantCore account to your first configured mailbox using the current bring-your-own-tenant workflow. The shortest path is:
You can stop after mailbox creation if that is all you need. MFA, Outlook access, and sending-tool connection are optional workflows.

Step 1 — Connect your Microsoft 365 tenant

Open Tenants in TenantCore and choose the option to connect a Microsoft 365 tenant. TenantCore will open the Microsoft authorization flow. Sign in with an account that is authorized to grant the requested permissions for the tenant. After consent completes, TenantCore returns you to the application, adds the tenant to your account, and loads the data needed for supported operations.

What TenantCore checks

TenantCore checks tenant access, required permissions, and Exchange readiness for the operations you plan to use. Do not manually submit a tenant ID that belongs to some other account or environment. TenantCore operations are always scoped to resources connected to your authenticated TenantCore account.

Step 2 — Add your first domain

Open the connected tenant and choose Add domain. Enter a domain you already own. TenantCore does not register the domain. It adds the domain to the connected Microsoft 365 tenant and creates the corresponding TenantCore resource. Each tenant supports up to 12 domains.

Step 3 — Configure DNS

After the domain is added, choose either Automatic DNS or Manual DNS.

Automatic DNS

Automatic DNS is available on Plus, Complete, and the Plus trial for supported providers. Current direct-provider support includes:
  • Porkbun
  • Cloudflare
  • Namecheap
If your DNS provider is already connected to TenantCore, start Automatic DNS for the domain. TenantCore will continue Automatic DNS setup in the background. The workflow can include:
  1. planning the required Microsoft 365 records
  2. applying supported DNS changes
  3. waiting for DNS propagation
  4. verifying the domain with Microsoft
  5. retrieving DKIM records when Microsoft makes them available
  6. publishing DKIM
  7. enabling DKIM
  8. performing final readiness checks
You do not need to keep the page open while background checks continue.

Manual DNS

If Automatic DNS is unavailable, open the domain’s DNS view and copy the required records to your DNS provider. TenantCore will continue rechecking the domain as records propagate.

Domain readiness

Do not treat the first DNS write as the end of setup. DNS and Microsoft-side changes can take time to propagate. TenantCore tracks the domain’s current state and updates it as the remaining checks complete.

Step 4 — Create your first mailbox

Once the domain is ready enough for mailbox creation, open Mailboxes for the domain and create a mailbox. Each domain supports up to 3 mailboxes. TenantCore creates the mailbox in Microsoft 365 and links it to the correct TenantCore tenant and domain. After creation, the mailbox becomes available for the remaining security, access, sending-limit, and integration workflows.

Step 5 — Review the mailbox credential

Open the mailbox and use the available credential controls when you need the mailbox password. TenantCore protects mailbox credentials through a secure credential vault rather than relying on a temporary password column that disappears after a fixed period. Use the password only where the mailbox authentication flow requires it. Do not store mailbox passwords in spreadsheets or other unprotected operational notes.

Step 6 — Set up MFA if you want TenantCore to manage the code

TenantCore-guided mailbox MFA is optional. If you want to use it, open the mailbox security workflow and choose Set up MFA. TenantCore guides you through Microsoft’s Security Info experience. The flow is designed around Microsoft’s manual authenticator setup:
  1. open Microsoft Security Info
  2. add an Authenticator app
  3. choose the option to use a different authenticator application
  4. select Can’t scan the QR code?
  5. copy the manual OATH/TOTP secret into TenantCore
  6. complete Microsoft verification using the current code
TenantCore protects the MFA seed through its credential-vault architecture and generates a current code only when an authorized operator requests it. You can skip TenantCore-managed MFA if:
  • the mailbox already has MFA configured another way
  • your sending provider does not require this workflow
  • you prefer to manage MFA outside TenantCore
Skipping this step does not prevent the mailbox from being connected to a sending tool.

Step 7 — Configure a sending limit

Open Sending Limits if you want TenantCore to control the mailbox’s daily sending policy. TenantCore tracks mailbox sending usage and enforces the configured daily limit through Microsoft 365. Sending limits are infrastructure controls. They do not guarantee inbox placement or replace good list hygiene. Keep the daily limit configured in your sending tool at or below the limit you intend to enforce through TenantCore.

Step 8 — Enable Outlook access if needed

If you want to open replies or work with the mailbox directly in Outlook, use Open Mailbox. For BYOT tenants, TenantCore can discover suitable licensed Exchange users in the connected tenant. Choose the Microsoft account you want to use as the Outlook sign-in account. TenantCore sets up:
  • Full Access
  • Send As
for the selected mailbox, then opens Outlook. Sign in using the assigned Outlook sign-in account. The sending mailbox remains the mailbox identity; the licensed access account is the Microsoft user used to open it. Microsoft may take up to about 15 minutes to make the delegated mailbox available in Outlook. This delay affects Outlook access only. You can connect the mailbox to a sending tool right away.

Step 9 — Connect a sending tool

Open the mailbox’s sending connection workflow and select a configured integration. For supported providers, TenantCore can manage the connection workflow and track the result. Depending on the provider, you may be asked to:
  • review the mailbox email and password
  • set up MFA first or continue without TenantCore MFA
  • complete a Microsoft OAuth popup
  • authenticate inside the sending tool

If you close the popup

Closing an OAuth or provider popup does not permanently lock the mailbox. If the connection was interrupted, reopen the mailbox connection and try again. Only an active connection attempt in the current browser session should temporarily prevent duplicate clicks.

If the provider is not directly supported

Use the provider’s normal Microsoft 365 connection workflow with the mailbox credentials and MFA method you manage for that mailbox.

Step 10 — Confirm infrastructure status

After setup, use TenantCore rather than manually checking every provider. Useful places to review include:

Dashboard

Use the Dashboard for a current operational summary.

Domains

Check Microsoft verification and MX/SPF/DMARC/DKIM readiness.

Mailboxes

Review mailbox state, sending usage, credential/security state, Outlook access, and sending-tool connection state.

Alerts

Review open alerts, mark them reviewed or resolved, and see alerts that have already been resolved.

Reports

Use Reports for historical operational visibility across your account. Depending on your plan, Reports can include:
  • Overview
  • full Activity Log
  • Infrastructure Report
  • tenant/domain/mailbox drill-downs
  • CSV export
  • executive PDF
  • direct Email PDF
  • scheduled emailed reports
  • Portfolio reporting

Your first setup is complete

A normal first environment now looks like:
From here, repeat the same workflow for additional domains and mailboxes. After your first setup, the most useful next topics are:
  • tenant, domain, and mailbox architecture
  • Automatic DNS and manual DNS
  • mailbox credentials and MFA
  • native Outlook access
  • sending limits
  • sending-tool integrations
  • monitoring and reputation
  • Reports
If you are on Complete and want to automate these workflows programmatically, continue to the API Reference. The public API uses TenantCore resource IDs and can operate only on resources already owned by your TenantCore account.