Setting Up Microsoft 365 Archiving
Microsoft 365 covers email (Outlook and Exchange), team chat (Teams), file collaboration (OneDrive), and calendar - all in one tenant. Comma connects to the whole tenant once and captures across every surface, with admin-consent scopes tiered so you grant only what you need.
How Microsoft 365 capture works
Section titled “How Microsoft 365 capture works”Comma uses the Microsoft Graph API with app-only (application) permissions:
- Email (Outlook, Exchange) - inbound, outbound, CC, BCC, attachments, drafts where retention applies
- Teams - 1:1 chats, group chats, channel messages, reactions, edits, deletes, files, meeting chat
- OneDrive - file create/modify/move/delete, version history, sharing changes, comments
- Calendar - meeting metadata and attendee changes for context
- Direct-source ingestion (no MX rerouting, no journaling proxy)
Channel-message capture follows each monitored user into the Teams they belong to, through a per-team service account.
Permission tiers
Section titled “Permission tiers”Comma supports three Microsoft Graph permission tiers so admins can scope consent:
- Directory access - read users and groups only (lowest scope)
- Contact access - directory plus contacts and calendar
- Full access - directory, contacts, calendar, email bodies, Teams chat, OneDrive content
Pick the lowest tier that covers your retention obligations. You can re-consent at a higher tier later without losing existing capture.
See Microsoft & Google OAuth Permissions for the exact Graph scopes each tier requests and why.
Prerequisites
Section titled “Prerequisites”- Microsoft 365 tenant administrator (Global Admin or Privileged Role Admin)
- Comma team admin access
- About 10 minutes
Setup steps
Section titled “Setup steps”- Sign in to the Comma Compliance dashboard
- Open Integrations in the top navigation
- Under Organizational Integrations, find the Microsoft 365 card and click Connect
- Choose your permission tier (Directory / Contact / Full)
- You’ll be redirected to Microsoft to sign in with your admin account
- Approve the admin consent prompt for the selected scopes
- Microsoft redirects you back to Comma and the installation is confirmed
- Initial sync runs in the background; new messages capture in real time
Verifying capture
Section titled “Verifying capture”After the first sync window (~15 minutes for a typical tenant):
- The integration card lists the connected tenant name and consented scope tier
- A test email sent through the tenant appears in Messages within a few minutes
- Teams chat capture shows under the Teams filter
Removing the integration
Section titled “Removing the integration”- From the Microsoft 365 card in Comma, click Disconnect
- (Optional) Revoke the app in the Microsoft admin portal: Microsoft Entra admin center > Enterprise applications > Comma Compliance > Properties > Delete
- Historical capture remains under your retention policy
What’s next
Section titled “What’s next”- Google Workspace Setup - Mixed M365/Google tenants
- IMAP / Any Email Setup - Cover non-Microsoft mailboxes
- Microsoft & Google OAuth Permissions - Scope-by-scope explainer