Requests stay in the inboxes your team uses
Nexcade uses Microsoft Graph to read quote requests and attachments, organise the work, and send and receive supplier or customer messages within the agreed workflow. Your project lead and IT team agree which shared inboxes or user mailboxes are included.
This guide explains the access model and setup responsibilities. Your Nexcade project lead supplies the detailed configuration instructions for your Microsoft 365 environment.
Access is limited to the agreed mailboxes
Your IT team registers an application in Microsoft Entra ID, Microsoft's identity service. This gives Nexcade a dedicated application identity for the connection, separate from an employee's personal sign-in.
Exchange Online application role-based access control, or RBAC, assigns the mail permissions to a defined group of mailboxes. Your administrators manage which mailboxes are in scope. Mailboxes outside that scope must remain inaccessible to the application.
Microsoft treats Exchange RBAC permissions and Entra application permissions as additive. A scoped RBAC assignment does not cancel a broad mail permission granted in Entra. Any equivalent unscoped Entra mail grants must be removed for the RBAC restriction to be effective.
Your IT team sets up the connection
Agree the mailbox list
Choose the inboxes and work Nexcade will handle. Identify the Microsoft 365 administrator who will configure access.
Create the application identity
Register a single-tenant application in Entra ID and create its credentials. Your administrators retain control of the registration.
Set the permissions and mailbox scope
Assign the mail roles needed for the agreed workflow through Exchange RBAC. Check for broad Entra mail grants that would allow access beyond that scope.
Test and hand over securely
Confirm access to an allowed mailbox and denial for a mailbox outside the scope. Share the tenant ID, application ID and credential through the agreed secure channel.
The setup needs permission to register applications and administer Exchange Online. Your IT team should also record the credential expiry date and agree how it will be rotated. Keep credential values out of ordinary email, chat and shared documents.
Check both allowed and denied access
Before the workflow starts, verify that the application can perform the agreed actions in an included mailbox. Then verify that the same application cannot access an excluded mailbox. Allow for Microsoft's permission changes to take effect before drawing a conclusion from a test.
Review the application grants as well as the Exchange scope. An Exchange permission test on its own does not establish that separate Entra grants are absent. Repeat the access checks when the mailbox list or permission configuration changes.
Mail permissions and operator approvals do different jobs
Microsoft permissions determine which mailboxes and actions the application can access. Nexcade's review gates determine when work is released. Permission to send email does not remove the operator approval steps agreed for your deployment.
Your Microsoft 365 administrators can change or revoke the connection's permissions and credentials. Coordinate changes with your Nexcade project lead so the affected workflow can be paused or reconfigured.
The email connection is separate from TMS and rate-source access. See how Nexcade works with CargoWise or request a demo around your team's workflow.