Microsoft 365
32 min
there are three routes to authorize ashby with microsoft 365 application wide admin consent docid eaaljgrtew uoxtk8i7 individual consent docid eaaljgrtew uoxtk8i7 hybrid setup docid 1s6nwgsw6i4jaqafrryqo (configure some access application wide for easier scheduling, while relying on individual microsoft authorization for more sensitive workflows) this article explains each route, how to sync users and rooms, and how email sync, microsoft teams, and group calendars work once the integration is in place application wide admin consent this is the fastest route to get the integration in place for all users ashby automatically syncs all users of a microsoft domain once you give application wide consent you must be an organization admin in ashby and an admin in your organization's microsoft tenant to configure application wide admin consent this method allows an admin of both ashby and an organization's microsoft tenant to authorize all permissions that ashby requires for everyone in their organization a user from your microsoft organization with the permission to administer applications logs in to ashby and heads to the integrations page microsoft 365 is in the platform section of the integrations marketplace the microsoft 365 tile in integrations click microsoft 365 click enable microsoft 365 click connect to microsoft 365 confirm the account and review the permissions requested click accept to allow ashby access once you accept, you see a message confirming that ashby has enabled the integration admins can also opt to disable the user sync and opt to not automatically enable synced users by unchecking the following checkboxes in the general settings section of the microsoft integration sync microsoft users? when unchecked, the automatic user sync is stopped, so microsoft users in your tenant will not be synced to ashby automatically enable synced users? will stop enabling synced users so they will need to sign into ashby before they can be scheduled or configured the general settings within the microsoft 365 tile individual consent if you'd prefer users to give consent on an individual basis, each user can manage ashby's access from their microsoft 365 settings (within personal settings https //app ashbyhq com/settings/personal info ) the user needs to give the same permissions as listed above for application wide admin consent a user can click connect with microsoft 365 to connect their account the scopes and status on the microsoft 365 settings page users can also individually disable email sync in the email settings section of their personal settings https //app ashbyhq com/settings/email if users have the email sync option enabled, they can also opt to include personal email aliases in the sync if they respond to a candidate using one of their personal aliases in their email client, ashby still detects and syncs it all aliases listed under aliases to include in email sync are set not to sync by default, and the user needs to opt in to enable the sync for that alias setting up email syncing as part of the individual consent route if you have taken the application wide admin consent route, users still see to send and receive emails and appointments in ashby, connect your microsoft account when navigating to the microsoft 365 settings https //app ashbyhq com/settings/microsoft 365 page within personal settings they do not need to complete this additional step if they are not organizing interviews with teams or group calendars the connect with microsoft 365 button they can review the list of scopes in the status section of this page to confirm what is functional and currently syncing the list of scopes in the status section of microsoft 365 settings users who are organizing meetings for interviews using teams, or those looking to schedule interviews to group calendars, need to go through the additional authorization processes within microsoft 365 settings https //app ashbyhq com/settings/microsoft 365 to use these features this applies even if you took the application wide admin consent route to set up the integration authorizing microsoft 365 room and user sync a user with the user read all permission in microsoft can enable user syncing in the additional authorization section of the microsoft 365 integration settings in the integrations marketplace https //app ashbyhq com/admin/integrations/marketplace you have the following options for syncing users and rooms as part of your integration setup authorize microsoft 365 user sync sync users to ashby from your microsoft tenant authorize microsoft 365 room and user sync sync your users, or users and rooms, from your microsoft tenant to ashby the additional authorization section of the microsoft 365 tile if you enable the authorize microsoft 365 room and user sync option, you need to determine a delegated room sync user the user you select from the dropdown must have the following permissions in your tenant user read all — for user sync and room sync place read all — for room discovery calendars readwrite shared — for shared and room calendar access (the delegated user must be a delegate of the room calendars in microsoft 365 for calendar subscription to work) ashby inherits whatever visibility the delegated sync user has in the tenant for those rooms ashby only syncs the rooms that the delegated user has access to in microsoft if you see only free/busy information, that is the information microsoft returns for the delegated user's access level if you do not want to sync users into ashby but do want to sync rooms, ensure that the sync microsoft users? checkbox is unchecked in the general settings section of the integration tile the general settings section where you can adjust the user sync and enablement settings hybrid setup for more on configuring a hybrid setup for microsoft 365, check out microsoft 365 hybrid setup docid 1s6nwgsw6i4jaqafrryqo email sync if you enable email syncing as part of your microsoft 365 configuration, synced emails to and from the candidate appear in the feed section of the candidate's profile email attachments attachments included in an email also appear on the synced email on the candidate's feed in ashby to save an email attachment from an inbound email to the other files section of the candidate's profile, click the file icon on the attachment the option to save an email attachment as a file on the candidate profile is not available for outbound emails click the file icon to the right of the attachment name to add it to the other files section of the candidate profile a popover opens with the following options description file category (more on this at candidate files and file categories) ashby prefills this with 'from email on x date', but you can amend it privacy (if you have permission to view private fields) once you save the file, the privacy set is separate from the email privacy settings changing the email privacy later does not impact who can access the file saved to the candidate profile deleting the email from the candidate's feed does not remove the saved file from the candidate profile automatically microsoft teams for more information on scheduling via ashby, check out scheduling & interviews an introduction docid\ xw 3irivonbho uf37lbh when scheduling an interview, ashby can also automatically schedule a meeting in teams if you have the microsoft 365 integration in place and if you set microsoft teams as the interview's location setting a location for an interview to teams the organizer of the teams meeting needs to have set up individual oauth within microsoft 365 settings (in personal settings https //app ashbyhq com/settings/personal info ) to use this, even if you took the application wide admin consent route group calendars as part of the microsoft 365 integration, you can add a group calendar for scheduling interviews if you'd like to set up a group calendar as part of your integration, reach out to your customer success manager (csm) or support\@ashbyhq com mailto\ support\@ashbyhq com creating the group calendar to get started, create a microsoft 365 group and add the people who will be scheduling to that group as members the group comes with a calendar that everyone in the group has write access to newly created microsoft 365 groups may take up to 24 hours to fully propagate configuring a group calendar important group requirements it must be public it must be a group (not a distribution list or shared mailbox) teams capabilities should be enabled it must be mail enabled (not a security group) make sure hide this group from the global address list is unchecked these requirements are critical for the calendar to sync correctly with ashby authorizing and adding the group calendar in ashby anyone who is scheduling on that calendar needs to go through the individual microsoft 365 authorization in their personal settings https //app ashbyhq com/settings/personal info the user adding the calendar must be an organization admin in ashby and also be a member or owner of the group for workspaces with more than 100 groups, reach out to support\@ashbyhq com mailto\ support\@ashbyhq com for assistance adding a specific group calendar if you don't see the group calendar listed ashby asks you to supply the group object id, which appears either in the url when you navigate to the group or, if you have access to your domain within azure, in the group object id section to add the group calendar, head to the microsoft 365 integration settings in integrations https //app ashbyhq com/admin/integrations/marketplace you then see the option + add calendar the calendar you add becomes the default calendar when scheduling interviews adding a group calendar in ashby additional considerations to schedule interviews onto this calendar, users need to authorize with individual oauth the organizer of the meeting is the group name, and interviewers are attendees therefore, name the group something that can be externally facing, as it shows on candidate invites when you authorize a new calendar, users should reauthenticate in their personal settings email aliases microsoft 365 email alias sharing in ashby uses personal settings > email sharing https //app ashbyhq com/settings/email sharing a user can share their email address with specific ashby users from this page personal microsoft 365 aliases do not appear in admin > organizational settings > shared email aliases https //app ashbyhq com/admin/organizational settings/shared email aliases and cannot be used as the organization wide no reply address the steps below explain how to enable microsoft 365 alias sending for the personal settings email sharing workflow ashby supports sending emails from user aliases to successfully send an email from an alias, a microsoft admin needs to enable the turn on from sending aliases option in the exchange online admin center https //admin exchange microsoft com/ log in and navigate to settings > mail flow > general , then check the turn on from sending aliases checkbox if this setting is not enabled, emails still send but fall back to the user's primary email address the mail flow settings in microsoft the turn on sending from aliases checkbox unlike google, microsoft does not allow different from names on an alias for example, if an email from your primary email has the from name of julie meadows, most email clients show messages from your alias with the same from name in this example, julie meadows shows as the from name for emails sent from the alias email address as well to set up a company specific no reply email address, see email domain setup docid\ rkqq453zhhg4vmishy9q2 this is the supported route for a company specific no reply address with microsoft 365, and it is available on enterprise plans known limitations currently, there are a few options that the integration does not support email signatures ashby cannot sync email signatures over from microsoft 365 calendar syncing and scheduling if you are the interview organizer and on the panel interviewing, you see two events on your calendar if a group calendar is not in place faqs what access level do i need to authenticate this application? the person who grants access to the application by clicking connect to microsoft 365 must be someone who can manage azure application registrations and grant application permissions to the graph api can my team set up a custom application instead of using the ashby integration? review microsoft custom applications (gcc high) docid\ wlpeo48evoa15qd5ty q6 for guidance on setting up an azure application and pointing it to ashby can i set up both google workspace and microsoft 365 integrations in my ashby account? ashby currently supports deep integration with either google workspace or microsoft 365, but not both simultaneously for more information, check out does ashby support integrating with both google and microsoft at the same time? docid 92txkuc2vvmorzxeptmkj i've set up the google workspace integration — can i use microsoft teams for interviewing? ashby currently supports deep integration with either google workspace or microsoft 365, but not both simultaneously can i reschedule or change the date and time of an interview via the event on my outlook calendar? we support a two way syncing option, so if you move an interview event on your outlook calendar to a new date and/or time, ashby syncs and reflects the changes in most cases, we recommend rescheduling in ashby (for example, if you're amending the interview type or interviewers on the panel) you need to move the calendar event on the account's shared interview calendar (the calendar determined in the communication tab of your interview) if you did not schedule it via the direct booking option for an interview scheduled via a direct booking link, you can move the calendar invite on the shared calendar, or the meeting organizer can move the interview on their personal calendar if they don't have access to the shared calendar ashby then syncs these changes back and sends out new calendar invites you do not need to resend the calendar invites if you reschedule the interview via outlook, ashby adds an event to the candidate's feed showing that rescheduling happened outside of ashby a note showing that an interview was rescheduled externally how are users pulled into ashby? ashby can sync users over via the following routes if you have user sync enabled as part of your google workspace or microsoft 365 integration settings if you migrate data via the greenhouse, workday, or lever api migration options, ashby pulls user accounts over as part of the migration if you configure a user sync via system for cross domain identity management (scim) if a user signs in for the first time using the native `sign in with microsoft` button, ashby can create their user account even when microsoft 365 user sync is disabled the user must sign in with an email address that matches an organization domain configured for the corresponding sign in method new accounts created this way start as limited access users once directory sync (scim) is enabled, ashby does not create users through native microsoft sign in users must be provisioned through directory sync (scim) if you have users synced over via an api migration or by enabling user sync as part of the google workspace or microsoft 365 integration and then set up scim, the scim sync deactivates any user accounts that ashby initially added but that are not in your scim directory to reactivate any users that ashby deactivated when it shouldn't have, add them back to your scim directory if you've enabled the user sync option as part of your google workspace or microsoft 365 integration (and do not have scim configured), ashby automatically provisions and deactivates users based on their status in your workspace or tenant if you added users via an api migration from greenhouse, workday, or lever, you can deactivate any users who do not need access manually if you are not planning to configure scim you can read more about deactivating users at how do i provision new users in my ashby account manually? docid\ jgh sn34vmmt0v5cezha8 will synced users receive a welcome email? no once you add a user, they can sign in at the ashby sign in page https //app ashbyhq com/signin i send a large volume of no reply emails each day — can i still use a branded email address? this is possible if you configure an email domain within ashby if you are sending more than 1,000 no reply or automated emails a day, or are looking to set up a company specific no reply and are using microsoft 365, check out our email domain setup docid\ rkqq453zhhg4vmishy9q2 guide what permissions are necessary on the ashby side for a user set as the delegated room sync user in microsoft 365 integration settings? the user needs to be an active ashby user for them to be an option to delegate room access as such, they need to be enabled for sign in you can set this user up as a limited access user in ashby, and they don't need to authenticate in ashby where are meeting rooms pulled from in microsoft 365? in microsoft 365, meeting rooms appear on the rooms & equipment page within the microsoft 365 admin center i have some non gregorian calendar events on my calendar and they aren't syncing over, why? ashby does not support recurring calendar events that include the "rscale" property in their recurrence rules (rrules), and does not sync these events over during calendar syncs the "rscale" property specifies non gregorian calendars ashby still syncs all events on the user's calendar without the "rscale" property