Jump to:navigation, search
Wiki





































Configuration of OAuth2 authentications

Command in own menu with version: 14.1.0(08.2025)

notempty
This article refers to a Beta version
-
Access: UTM-IP:Port or UTM-URL:Port
Port as configured at Network / Appliance Settings / Webserver
Default-Port: 11115
i.e.: https://utm.ttt-point.de:11115
Default: https://192.168.175.1:11115
Authentication OAuth 2


OAuth 2 UTMuser@firewall.name.fqdn Authentication OAuth 2 Verbindungen für Mailconnector und Mailrelay

OAuth 2 connections can be created and edited in this menu.

Depending on the provider selection the configuration steps will change. The following providers are available:

  • Google Workspace
  • Microsoft 365 (Secret Client Key)
  • Microsoft 365 (Certificate)

Create new connections with the button Add OAuth 2 connection

Google Workspace
Google Workspace
Caption Value Description Add OAuth 2 connection UTMuser@firewall.name.fqdn
Name:     Name of the OAuth 2 connection
Provider: Google Workspace Provider selection
Service account:     The Google Workspace service account is entered
User account: »alice@ttt-point.de The user accounts are selected
Certificate: Google_Workspace-OAuth2_cert The certificate that is uploaded in Azure is selected
Preliminary note Microsoft 365
In order to use Microsoft 365, configured Azure Apps are necessary.


































  • Note

    This article includes descriptions of third-party software and is based on the status at the time this page was created.
    Changes to the user interface on the part of the manufacturer are possible at any time and must be taken into account accordingly in the implementation.
    All information without warranty.

  • In order to use the Mail Connector with Microsoft 365, the following information is required:
    • Application ID
    • Client ID
    • Secret client key
    This guide shows an example of the preparations and setting required in Microsoft Azure
    • Launch Azure Active Directory admin center
    • Note down/Copy Tenant ID from the Azure Active Directory menu
    • Register new app under theApp registration menu under the New registration button
    • Assign a unique name and click the register button
    • In the API permissions menu, click the Add a permission button.
    • Select permission for Office 365 Exchange Online in the APIs my organization uses tab
    • Add IMAP.AccessAsApp permission for Office 365 Exchange Online
    • In the menu API permissions activate the entry Grant admin consent for [...].
    • Create a Client secret in the Certificates & secrets menu
    • Note down Value, will be entered as Secret Client Key when adding an OAuth 2 connection
    • Open menu Enterprise Applications and select app
    • Note down from the app properties Application ID and Object ID.
    • Open Powershell on Windows Client Administrator, import ExchangeOnlineManagement and connect to tenant
    • Select the recipient mailbox in the Exchange admin center and choose Read and manage (Full Access) as delegation.
    • Add member for Mailbox Delegation
    • This completes the configuration in Microsoft Azure.
      The further configuration is done in the UTM in the menu
      Applications Mail Connector  Area Services with button Add Mail Connector Service

    anf in the tab
    OAuth2 with the Add OAuth2 connection button.

    • notempty
      The Microsoft servers may take up to 30 minutes before access works
    Microsoft 365 (Secret client key)
    Microsoft 365 (Secret client key)
    Name:     Name of the OAuth 2 connection
    Provider: Microsoft 365 (Secret client key) Provider selection
    Application ID:     The application ID is entered
    In Microsoft Azure in the App property under Application ID
    Tenant ID:     The tenant's ID is entered
    In Microsoft Azure in the menu Azure Active Directory under Tenant ID
    Secret client key:     The secret client key is entered
    In Microsoft Azure in the menu Certificates & secrets in the tab Client secrets under Value
    Microsoft 365 (certificate)
    Microsoft 365 (certificate)
    Name:     Name of the OAuth 2 connection
    Provider: Microsoft 365 (certificate) Provider selection
    Application ID:     The application ID is entered
    In Microsoft Azure in the App property under Application ID
    Tenant ID:     The tenant's ID is entered
    In Microsoft Azure in the menu Azure Active Directory under Tenant ID
    Certificate: CC-OAuth2-MS365_cert The certificate that is uploaded in Azure is selected