Outlook, threaded onto every case in the firm.
Connect any Microsoft 365 mailbox over Microsoft Graph. Two-way delta sync pulls every client thread onto the case timeline within about a minute. Every reply you compose inside ImmiIQ leaves through your own Outlook and lands in Sent Items with the correct References and In-Reply-To headers. No shared inbox, no rules mess, no hunting for who replied to whom last week.
Skills assessment came back positive. Ready to lodge the 190 nomination?
1 attachmentGreat news. Filing the NSW nomination this week and I will send the payment link tonight.
Sent via your OutlookWhat the Microsoft 365 integration actually does.
Every capability listed below is live in production today. Nothing here is a roadmap promise or a marketing stub.
Two-way delta sync
Graph delta queries fetch only what changed since the last sync token. Client replies land on the case timeline whether typed inside ImmiIQ or straight into Outlook.
Send-through-Graph
Outbound composed in ImmiIQ leaves through Microsoft Graph and lands in your Sent Items with correct threading headers. Clients see your real firm address in the From line.
Alt-email chips per client
Attach personal, work and secondary addresses to one client record. Every reply from any of those addresses still threads onto the same person, not a duplicate card.
90-day historic backfill
The moment a mailbox is connected the integration pulls the last 90 days of relevant messages so the case timeline is already populated on day one. No blank state.
How it works.
Three stages. Connect, configure and then everything else runs itself. Tenant admins can pre-approve the ImmiIQ app registration so users only see one consent screen.
Connect
Sign in with your Microsoft 365 account under Settings then Integrations. Microsoft shows the exact Graph scopes ImmiIQ has asked for. Approve and the connection is live. Global admins can grant tenant-wide consent so end users skip the individual prompt.
Configure
Pick which client records the mailbox routes to. Alt-email chips let a single client have several Outlook and personal addresses. Set the default From identity so replies leave under the right agent even when the case is co-managed.
Automate
Graph change-notification subscriptions push new mail to ImmiIQ within seconds. Replies thread onto the client card. Compose inside the case and the send routes back through Graph so it lands in your own Sent Items. Subscriptions renew every three days automatically.
In the app
One consent screen. One tenant. Every user's mailbox.
The Microsoft 365 tile sits in the Integrations marketplace inside the app. Each user connects their own mailbox so nothing is co-mingled across the team.
Security posture
Sealed with your organisation's key. Not ours.
Access and refresh tokens are sealed with AES-256-GCM using a per-organisation key derived from AUTH_SECRET via HKDF. Microsoft rotates refresh tokens on every exchange and the sealed row is updated in place. Plaintext tokens never touch the database and never appear in logs. Every connect and disconnect is written to the tenant audit log with the actor, timestamp and IP. Mailboxes are scoped per user so one agent's Outlook never becomes shared infrastructure for the whole firm. Tenant isolation is enforced at the row level: Microsoft 365 data for one organisation cannot be queried, indexed or searched from another organisation under any code path. Revoking the connection tears down the Graph change-notification subscription, deletes the sealed row and stops all outbound routing through that account within seconds. Provider-sent messages still hit the org suppression list before send so a previously bounced address cannot be re-hit through a connected mailbox.
Frequently asked.
Does the Microsoft 365 integration work with Exchange Online and hybrid tenants?
The integration targets Microsoft 365 tenants and Exchange Online mailboxes over Microsoft Graph. Hybrid tenants work as long as the mailbox itself lives on Exchange Online. Pure on-prem Exchange without a Microsoft 365 identity is not currently supported.
Which Microsoft Graph scopes does ImmiIQ ask for?
We request Mail.ReadWrite and Mail.Send, plus offline_access so the refresh cycle keeps working without a fresh consent every hour. Tenant admins can pre-approve the ImmiIQ app registration for the whole tenant. That means users only see one prompt at connect time and admins keep the option to revoke the whole grant from Entra ID whenever they want.
How quickly do inbound replies show up on the client timeline?
Within about a minute. The integration uses Microsoft Graph change-notification subscriptions that renew automatically every three days, so new mail is pushed to ImmiIQ within seconds of hitting your mailbox rather than being polled.
Do sends through Microsoft 365 count against my ImmiIQ email quota?
No. Anything sent through your connected Microsoft 365 mailbox leaves via your own account and never touches the ImmiIQ shared sending quota. Only the fallback path, used when no mailbox is connected for that agent, counts against the monthly limit.
How are Microsoft 365 OAuth tokens stored and what happens on disconnect?
Access and refresh tokens are sealed with AES-256-GCM using a per-organisation key derived from AUTH_SECRET via HKDF. Microsoft rotates refresh tokens on every exchange and we persist the new one. Disconnecting a mailbox tears down the Graph subscription and deletes the sealed row immediately. Every connect and disconnect is written to the tenant audit log.
Related integrations.
Connect Microsoft 365 in-app in under a minute.
Start a trial, connect your Outlook mailbox and see the last 90 days of client conversation on the timeline immediately.