> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tenantcore.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage Mailbox Credentials

> Reveal, copy, and reset mailbox passwords using TenantCore's protected credential workflow.

# Manage Mailbox Credentials

TenantCore protects mailbox passwords through a secure credential vault.

Passwords are not intended to live permanently in tables, logs, browser storage, or operational spreadsheets.

## Reveal a password

When an authorized workflow needs the current mailbox password:

1. open the mailbox
2. open its credential/security controls
3. choose the password reveal/copy action
4. use the credential for the intended workflow
5. close the reveal state when finished

TenantCore confirms that the mailbox belongs to your account before the protected credential is retrieved.

## Reset a password

Use password reset when:

* a provider connection needs a fresh credential
* you suspect the password is compromised
* Microsoft requires a rotation
* operational policy requires a change

The reset workflow updates Microsoft 365 and synchronizes the new value with TenantCore's protected credential store.

## Credential synchronization state

A password reset is fully healthy only when both the Microsoft password change and secure credential synchronization complete successfully.

If Microsoft accepts the new password but credential synchronization fails, TenantCore surfaces that state so the mismatch is not hidden.

## Security practices

Do not:

* save mailbox passwords in spreadsheets
* send them through unprotected chat
* paste them into support tickets
* store them in browser notes

Use the TenantCore credential workflow when you need the current value.

## Public API

The Complete API supports password reset for owned TenantCore mailbox resources.

It does not provide unrestricted password or MFA-secret extraction simply because a caller has an API key.
