Symptom
- Understanding what the Email Configuration tab represents and how mailbox access is defined for an organization.
- Understanding the available Mailbox Access Type picklist values and where the current status can be found.
- Whether Shared or Delegated Mailbox access is supported.
- Which Microsoft Exchange On-Premises versions are supported.
Environment
- SAP Sales Cloud version 2
- SAP Service Cloud version 2
- SAP Sales and Service Cloud Version 2
Resolution
1. Does the tab name EMAIL CONFIGURATION refer to integration login mechanisms?
Yes. When a new organization is created, an administrator specifies the type of mailbox access to be used for all users in that organization. Once configured, all users in the organization can only use the defined access type to access their mailboxes. These details are available in the Email Configuration tab.
2. The Mailbox Access Type picklist shows all statuses - what do the values mean, and where can the status value be found?
Available mailbox access types:
Exchange On-Prem:
- Microsoft Exchange basic authorization (EWS API) - End User logon
- Microsoft Exchange basic authorization (EWS API) - Impersonated logon
Microsoft Office 365:
- Microsoft 365 OAuth (EWS API) - End User logon
- Microsoft 365 OAuth (EWS API) - Impersonated logon
- Microsoft 365 OAuth (EWS API) - App-only logon
Google/Gmail:
- Google Direct Logon
- Google Service Account
Universal access type:
- Any
Description:
- Microsoft Exchange basic authorization (EWS API) - End User logon: The typical scenario where end users enter their Exchange login credentials to activate the Sync engine.
- Microsoft Exchange basic authorization (EWS API) - Impersonated logon: Used to mass-authorize users with MS Exchange mail accounts via an impersonating service account. Before setting this access type, the Exchange EWS URL and a configured Impersonated Account login and password are required. See [Exchange EWS URL] for more information.
- Microsoft 365 OAuth (EWS API) - End User logon: Used to authorize SAP Sales Cloud Add-in end users with Office 365 mail accounts over Office 365 OAuth. In the latest product updates, this is the default option for bulk O365 user authorization using a service account. See [this article] for more information.
- Microsoft 365 OAuth (EWS API) - App-only logon: Used to mass-authorize SAP Sales Cloud Add-in end users with Office 365 mail accounts via app-only access with the EWS API. This access type requires a mail server and SAP Sales Cloud Add-in Admin account credentials.
- Microsoft 365 OAuth (EWS API) - Impersonated logon: Used to mass-authorize SAP Sales Cloud Add-in end users with Office 365 mail accounts via an impersonating account. This access type requires a mail server and SAP Sales Cloud Add-in Admin account credentials.
- Google Direct Logon: Used to authorize SAP Sales Cloud Add-in/Extension end users with Gmail / Google Workspace accounts over Gmail OAuth. Each user authorizes access individually. See [this article] for more information.
- Google Service Account: Used to mass-authorize SAP Sales Cloud Add-in/Extension end users with Gmail / Google Workspace accounts.
- Any: The organization supports any type of mailbox access.
Additional details:
- Shared/Delegated Mailbox access is not officially supported in the product. Support cannot be provided for such configurations.
- The product is compatible with all versions of Exchange On-Premises that are officially supported by Microsoft and have the latest updates applied.
Keywords
Groupware settings, Outlook integration, Email Configuration, Mailbox Access Type, Exchange On-Premises, EWS API, OAuth, Office 365, O365, Google Service Account, Gmail, Shared mailbox, Delegated mailbox, impersonated logon, end user logon, app-only logon, V2, Version 2, CEC-CRM-GW , KBA , CEC-CRM-GW , Groupware for SAP Sales/Service Cloud , How To
SAP Knowledge Base Article - Public