
Connect Outlook to Aithon
Connect your Microsoft 365 mailbox for read-only intelligence, for sending outreach, or both, with delegated access you can verify in Microsoft Entra.
Last updated
Aithon connects to your Microsoft 365 mailbox through the Microsoft Graph API with delegated access: you sign in to Microsoft yourself and Aithon never sees your password. Each user connects their own mailbox, and you can connect more than one.
A mailbox can be connected for two purposes, chosen with two checkboxes when you connect. Intelligence reads your email so Aithon can surface stakeholder signals, commitments and deal health; it is read-only. Outreach lets Aithon draft and send emails from your account as part of outreach sequences, and reads delivery and bounce notifications to protect your deliverability. You can tick one or both, and the permissions Microsoft asks you to approve follow your choice.
Prerequisites
- A Microsoft 365 work account with an Exchange Online mailbox.
- An active Aithon account.
- Nothing from your IT administrator, unless your tenant requires admin consent for new applications. See the section for administrators below.
Step 1: Open Integrations
Open the menu under your name at the bottom of the left sidebar and choose Integrations.
Step 2: Connect Outlook
Find Outlook in the list and click Connect. A short dialog asks what this mailbox is for: Intelligence, Outreach, or both. If you plan to run cold outreach, a dedicated sending mailbox is recommended; mixing outreach and inbox intelligence on one mailbox mixes bounce traffic into your insights.
Step 3: Sign in and approve
You are sent to Microsoft's sign-in page. Sign in with your work account and approve the permissions listed on the consent screen. You are then returned to Aithon, where the Outlook card shows the mailbox as connected.
What Aithon asks for
All permissions are Microsoft Graph delegated permissions, granted for your own mailbox only.
| Permission | When it is requested | What it allows |
|---|---|---|
openid, profile, email, offline_access | Always | Sign-in, and a refresh token so you are not asked to sign in again |
User.Read | Always | Your own basic profile, to know whose mailbox this is |
Mail.Read | Intelligence | Read-only access to your mail |
Mail.ReadWrite, Mail.Send | Outreach only | Create drafts and send email from your account |
Aithon never asks for Teams or online-meeting permissions, calendar, files, SharePoint or contacts, other users' mailboxes, directory-wide reads, or any application-level (app-only) permission. An Intelligence-only connection is strictly read-only.
What is read, and what is not
For an Intelligence mailbox, Aithon reads your mail, leaving out junk, deleted items and drafts. Email becomes evidence on the accounts and deals it relates to: Deal Intelligence summaries with citations, the engagement timeline on each account, and reply handling for outreach. For an Outreach-only mailbox, Aithon reads delivery and bounce notifications and message metadata; message bodies are not ingested.
Only one mailbox per user can be the Intelligence mailbox. If you connect a second Outlook mailbox for intelligence, Aithon keeps the first and connects the new one for outreach only, and tells you so.
For IT administrators
The integration is user-initiated and delegated. No administrator connects mailboxes on behalf of other users. Two optional controls are available in the Microsoft Entra admin center (formerly Azure AD):
- Tenant-wide consent, so individual users are not prompted: Enterprise applications, then the Aithon application, then Permissions, then Grant admin consent. This does not widen the permission set, it only suppresses the per-user prompt.
- Restricting who can connect, through app assignment or a Conditional Access policy on the Aithon application.
To verify what was granted, open the same Permissions page and confirm the consented delegated Graph permissions match the table above. Per-user grants are visible under each user's sign-in and consent records.
Changing or revoking access
To change a mailbox from one purpose to another, Microsoft requires disconnecting and reconnecting; Aithon walks you through it. To revoke, disconnect the mailbox from the Integrations page, or revoke the Aithon application from the Entra admin center. A mailbox that is the sending mailbox of an active campaign cannot be disconnected until it is removed from that campaign.
Organization admins can exclude email from AI processing entirely in Aithon's privacy controls.
Need help?
For assistance, contact support@aithon.ai.
Related guides
Connect Gmail to Aithon
Connect your Google Workspace mailbox for read-only intelligence, for sending outreach, or both.
Read guide →Connect Google Calendar and Google Meet to Aithon
Calendar gives Aithon the meeting itself, Meet gives it the transcript. Connect both and every customer meeting becomes evidence on its deal.
Read guide →Connect Gong to Aithon
Bring call transcripts and participants into Aithon, where they become the richest evidence behind deal intelligence.
Read guide →Connect Slack to Aithon
Bring customer channel conversations into Aithon as evidence on the deals they belong to.
Read guide →