Skip to content

Connecting Outlook and Microsoft 365 without moving mail

Part 04 of 7

On this page

Connect a Microsoft 365 or Outlook.com account to another email app and your mail stays where it is. Every message keeps the folder it’s in. What a second app writes into an Outlook mailbox is a category, a tag that sits on top of the message. That one word decides most of what follows.

  • A message in an Outlook mailbox has one parent folder. Microsoft’s developer documentation records it as a single value. That’s why filing in Outlook is a move, and why you want an app that sorts your mail to stay out of your folders.
  • A category is the part that adds. Microsoft says you can put one or more of them on a message, and that they’re yours alone to see.
  • Which of the two Microsoft account systems you have decides the rest of this page. They’re separate systems, and one of them has an administrator standing in front of it.
  • Out of the box, letting an app reach your own mailbox is your call. Microsoft says so in its own admin documentation, and gives your administrator three ways to change it.
  • Microsoft’s blue verified badge tells you who published an application, not what it does with your mail. Microsoft’s own FAQ says so plainly, and the program that covers handling is voluntary.

A folder holds one copy of a message

In an Outlook mailbox a message sits in one folder. Microsoft’s developer documentation for a mail message lists the property as parentFolderId, described as “The unique identifier for the message’s parent mailFolder” (Microsoft Graph, checked September 6, 2026). One identifier, one parent. The same page says what moving does. “Move the message to a folder. This creates a new copy of the message in the destination folder” (same page, checked September 6, 2026).

That’s the reason for whatever unease you arrived with. In a folder system, filing means moving. Anything that sorts your mail by putting it somewhere is competing for the slot your own filing uses. The client folders you’ve kept since 2014 are exactly what software with an opinion could undo.

So the object to watch here is the category.

Microsoft describes categories plainly. “Categories let you easily tag, label and group messages in Outlook on the web and new Outlook”, and the instructions have you “assign one or more categories to your messages” (Microsoft Support, checked September 6, 2026). One or more. A category sits on top of a message and leaves it where it is, and your folder tree carries on exactly as before.

There’s a second sentence on that page that matters more to a firm than it looks. “Other people won’t see the categories you assign” (same page, checked September 6, 2026). A category is a note on your copy of a message. The client whose email got tagged sees their own thread, the same as always. Sorting that happens in your mailbox stays in your mailbox. A reply is the thing that leaves the building, and that’s worth holding separately in your head.

Archiving is the one place a real move happens, and Microsoft is clear about what that means. The Archive button will “move one or more messages to your Archive folder without deleting them”. Archived items “remain easy to find from the search box or by navigating to your Archive folder”. And “Using the Archive button to move messages to the Archive folder doesn’t reduce your mailbox size” (Microsoft Support, checked September 6, 2026). Putting mail away in Outlook leaves it in a named folder, still in the mailbox, still searchable, still counted. If you’ve come across from the other provider, where that word means something structurally different, the Gmail part of this series has that half of it.

That leaves you a rule you can apply to any product’s claims before you know a thing about the product. Everything a connected app does inside an Outlook mailbox is one of two things. It’s a category, which is added and can be taken off. Or it’s a move between folders, which shows up in your own folder list the moment it happens. Ask a vendor which of the two its sorting is, and the answer carries the whole of the risk.

Which of the two Microsoft accounts you have

The word Outlook names an app, a website and a mailbox. Underneath it, Microsoft runs two separate account systems.

Microsoft’s own account of the split is short. A Microsoft account is a personal one, made by the person using it, for products like Outlook.com and OneDrive. A work or school account is “created in your organization by an administrator” and goes with Microsoft 365 for business (Microsoft Support, checked September 6, 2026).

Your address usually tells you which you have. An address at your firm’s own domain, inside a Microsoft 365 subscription somebody pays for every month, is a work account. That holds whether or not anybody’s ever called it that, and whether or not the person who set it up still works with you. An address at outlook.com is a personal one.

One case is worth knowing before you meet it, and that’s when both exist. Microsoft documents the screen. “If you see a screen asking, ‘Which account do you want to use?’ when you sign in, it means that you have two accounts with Microsoft which use the same email address” (Microsoft Support, checked September 6, 2026). The same page states plainly that “Personal Microsoft accounts and Microsoft 365 work or school accounts cannot be merged, but they can be used side by side” (same page, checked September 6, 2026). If that screen appears while you’re connecting something, you’re choosing which mailbox the app points at. They’re two different mailboxes. It’s a five-second decision with a long tail when it goes the wrong way.

The two types also differ in what they can do. Microsoft notes that “All delegated permissions are valid for work or school accounts, but not all are valid for personal Microsoft accounts” (Microsoft Graph, checked September 6, 2026). In practice a product may handle one type and leave the other, or handle one of them less completely. That’s a fair thing to establish before a demo rather than during onboarding.

And if your firm runs an Exchange server of its own in its own building, rather than paying Microsoft for the hosted service, this page is about the hosted case. Enough is different that the right move is a question to whoever looks after that server. Ask it before anything is scheduled.

What the sign-in screen is actually asking

The sign-in happens on Microsoft’s page. What comes back to the app is a set of named permissions, and Microsoft’s names for them read almost as English.

Mail.Read “Allows the app to read email in user mailboxes”. Mail.ReadWrite “Allows the app to create, read, update and delete email in user mailboxes. Does not include permission to send mail”. Mail.Send “Allows the app to send mail as users in the organization” (Microsoft Graph, checked September 6, 2026).

Notice the sentence Microsoft appended to the middle one. Reading, filing, marking and deleting are one permission. Sending is a separate permission, asked for by name. So if what you want to know is whether an application can write to your clients, the answer is on that screen, before you agree to anything.

Then there’s a distinction with no equivalent on the Google side. For a firm holding client correspondence, it’s the most useful thing on this page.

Microsoft Graph has two kinds of access. Delegated permissions “let the application act on behalf of a signed-in user”, and Microsoft draws the boundary in the very next sentence: “the application can’t access anything the signed-in user couldn’t access” (Microsoft Graph, checked September 6, 2026). Application permissions are the other kind. Microsoft calls them “highly privileged because they allow applications to access and modify resources without requiring a signed-in user”, and adds that “Only Privileged Role Administrator and Global Administrator can consent to application permissions” (same page, checked September 6, 2026).

The difference to you is the size of the thing you’re granting. Under delegated access an application reaches your mailbox and stops where you stop. Your own reach is its reach. Under application access it reaches the organization with nobody signed in at all. That’s the right shape for a backup system, and a lot more than something you read your mail in needs. So the question to put to any supplier connecting to Microsoft 365 is which of the two it uses, and the answer you want is delegated. It belongs beside the retention and subprocessor questions in questions to ask any AI tool about your data.

One thing the screen leaves out, because Microsoft closed it off. Microsoft turned off password-based connections to Exchange Online. “Basic authentication is now disabled in all tenants”, and “no one (you or Microsoft support) can re-enable Basic authentication in your tenant” (Microsoft Learn, checked September 6, 2026). Basic authentication, in Microsoft’s own description, “simply means the application sends a username and password with every request, and those credentials are also often stored or saved on the device” (same page, checked September 6, 2026). Everything reaching a Microsoft 365 mailbox now works another way, and that’s Microsoft’s doing rather than any vendor’s restraint. What replaced it, and what it does and does not protect you from, is why Point never needs your email password.

What it takes to end it later

What you granted is filed inside the account itself, and Microsoft publishes the page for reviewing it. The account holds the record, and the application that asked for it holds nothing. For a work or school account the list sits in the My Apps portal, where you can “review and revoke permissions or clear saved account credentials” (Microsoft Support, checked September 6, 2026).

Then there’s the sentence nobody quotes, and it’s the one to know on the day you grant rather than the day you want it gone. “You can’t revoke these permissions because the administrator consented to them, and they’re often required for your organization’s policy” (same page, checked September 6, 2026). Where an administrator approved an application on the organization’s behalf, ending it is their action. In a seven-person firm whose owner is also the administrator, that’s a distinction without a difference. Where the console belongs to an IT contractor who visits on Thursdays, it’s the difference between an afternoon and a support ticket.

Microsoft adds a fair warning alongside it. “Removing permissions or accounts may break some app functionality” (same page, checked September 6, 2026). Which is unremarkable, and it reads as description rather than discouragement.

What ending access reaches is the same wherever you do it. Revoking stops what happens next. Material a company is already holding, and how long it holds it, live in your agreement with the supplier rather than in any console. Working through those terms clause by clause is what keeping client data out of model training is for. And where the credentials themselves live while a connection is running is where your email credentials are kept.

The setting your administrator already chose

Start with the common case, because it’s also the good one. Microsoft’s default is permissive for precisely the thing you’re trying to do. “By default, all users are allowed to consent to applications for permissions that don’t require administrator consent” (Microsoft Entra, checked September 6, 2026). The example Microsoft reaches for is yours, that “by default, a user can consent to allow an app to access their mailbox but can’t consent to allow an app unfettered access to read and write to all files in your organization” (same page, checked September 6, 2026).

So in a firm where nobody has changed anything, connecting your own mailbox is yours to decide. You already hold the permission you need.

Administrators can change it, and Microsoft encourages them to: “we recommend that you allow user consent only for applications that have been published by a verified publisher” (same page, checked September 6, 2026). There are three settings. One allows consent to any application for permissions that don’t require admin consent. A narrower one covers only verified publishers, and only permissions the administrator has classified as low impact. The third switches user consent off entirely (same page, checked September 6, 2026).

If you land on a policy that stops you, Microsoft’s arrangement is more convenient than Google’s. There’s a request path built into the screen you’re already looking at. In Microsoft’s words: “When a user tries to access an application but is unable to provide consent, they can send a request for admin approval. The request is sent via email to admins who are designated as reviewers. A reviewer takes action on the request, and the user is notified of the action” (Microsoft Entra, checked September 6, 2026).

Two things about that request are worth carrying. It exists only where somebody switched it on. So a refusal with no request button beside it means the workflow is off, and you did everything right. And requests expire, on a number of days the administrator sets (same page, checked September 6, 2026). A request that goes unanswered lapses quietly. That’s why one sent on a Thursday and forgotten is worth raising in person the following week.

Who your administrator actually is, and why that’s worth establishing before you book the afternoon instead of during it, is the same argument on both providers, and the Gmail part makes it. On a personal Microsoft account there’s no administrator, and this section passes you by.

What Microsoft’s blue badge does not cover

You may see a blue badge on the consent screen. Here’s Microsoft’s description of it. “When an app has a verified publisher, this means that the organization that publishes the app has been verified as authentic by Microsoft” (Microsoft Entra, checked September 6, 2026). Since November 2020, under a risk-based policy, “users can’t consent to most newly registered multitenant apps that aren’t publisher verified”. Where the policy applies, “a warning appears on the consent screen” telling the person that the application “was created by an unverified publisher” (same page, checked September 6, 2026).

That’s worth having, and Microsoft is unusually direct about where it stops. From its own FAQ: “The blue verified badge doesn’t imply or indicate quality criteria you might look for in an app. For example, you might want to know whether the app or its publisher have specific certifications, comply with industry standards, or adhere to best practices. Publisher verification doesn’t give you this information” (same page, checked September 6, 2026).

The badge answers who. It doesn’t answer how. A separate Microsoft program answers how. Microsoft 365 Certification puts an application through “a yearly independent audit that includes penetration testing and reviews of data handling, privacy, and security practices”. The controls are “based on widely recognized industry standards such as SOC 2, PCI DSS, and ISO 27001” (Microsoft Learn, checked September 6, 2026). Beside it sits Publisher Attestation, which Microsoft describes as vendors completing “a self-assessment of their app or agent’s security, data handling, and compliance practices” (same page, checked September 6, 2026).

Here’s the comparison that matters if you’re weighing the two mailboxes rather than two products, and it does not flatter Microsoft. On the Google side, an application that reads the content of your messages holds a class of permission that carries a required annual assessment by an outside assessor, and the Gmail part sets out what that does and does not prove. On the Microsoft side the equivalent audit exists, it’s thorough, and it’s optional. Certification is something a vendor chooses to buy. Publisher verification, which most will hold, establishes identity and stops there.

All of which is a reason to look closely, and your firm’s mail can stay where it is. The floor under this whole category sits lower on the Microsoft side, so more of the weight lands on what you ask a supplier and get back in writing. Two questions do most of the work. Does the application hold Microsoft 365 Certification? And where it does not, what independent assessment does it have instead?

Four Outlook specifics nobody mentions

Some of your mail may already have left the mailbox. A Microsoft 365 mailbox can have a second one attached to it, the In-Place or Online Archive. Mail moves across on a schedule somebody else set. “An administrator enables your archive mailbox and also sets the policies that control when emails will be moved to archive and how long they will be saved there for you” (Microsoft Support, checked September 6, 2026). Where a firm has one, older mail sits in the mailbox next door, and a new app connects to the first one. That changes the answer to how far back a new client can read. It’s the question the first part of this series argues is much cheaper to ask now than in month two.

The word Other is about to mean two things. Microsoft classifies incoming mail with a property carried on the message itself, and its two possible values are focused and other. The Focused Inbox view is what reads from it (Microsoft Graph, checked September 6, 2026). A connected client writing categories of its own may well use the same word for its third group. The two mean unrelated things. Microsoft’s is a guess about what’s bulk. The other program’s is a verdict about what can wait past today. Same word, two authors, and conflating them costs somebody an afternoon in the first week.

A rule you built may belong to a computer rather than to the mailbox. Some Outlook rules run at the server, and they apply to everything reading the account. Others run inside one installed copy of Outlook, and only while that copy is open. Stop opening that machine every morning and those rules stop firing. From the outside that looks exactly like new software breaking something. How to switch to an AI email client carries Microsoft’s own wording on this, and the audit worth running before you connect anything.

An address nobody signs in to connects a different way. The accounts@ or info@ that several people work out of is usually a Microsoft 365 shared mailbox, and by Microsoft’s design it has no sign-in of its own. Access to it arrives as a permission sitting on your own account instead. That’s a different arrangement with a different answer. The same switching guide works through it properly, along with distribution lists and mailboxes somebody reads on your behalf.

Point on an account Microsoft already holds

Point signs in to the Microsoft 365 account you already run, on Microsoft’s own page, and reads that mailbox where it sits. You keep your address. Microsoft goes on taking delivery and holding the mail, and the subscription you pay them is the subscription you were paying. There’s no export and no import. From your correspondents’ side, it’s an ordinary week.

Point asks the account for four things. The mail in that mailbox. Permission to file and mark it. Permission to send when you send. And the calendar, because finding a meeting slot takes one. What Point can see, and what it cannot is the reach in full. It’s the page to read if that list is the part giving you pause.

What Point works out goes back into the mailbox as three ordinary Outlook categories. They’re Now, Later and Other, one of them on each triaged message. So the sorting reads from Outlook itself, with Point closed and nothing new installed. File a thread away from inside Point and the mailbox files it as well, which in Outlook means the Archive folder. Your contacts arrive with the connection, duplicates merged. The reason that turns out to matter more than it sounds is a later part of this series.

How much Point handles by itself is set per kind of work rather than once for everything. There are three positions. Point stays out of it. Point prepares something for your approval. Or Point does that sort of work itself. Connect today and every kind of work starts in the middle one. Whatever does get done is written down afterward in ordinary language, and any one of those entries can be taken back. The autonomy dial is where each position stops, the activity log behind every action is that written record, and everything Point does is the full inventory.

The limits are Microsoft-shaped, and they belong in the same breath as the rest. An address with no individual sign-in behind it cannot be connected by anybody. A consent policy is the administrator’s to change and nobody else’s. A domain somebody else owns stays a decision made somewhere upstream of every product on the market. Those three are settled before a product is chosen. The certification question two sections up is the one that varies between suppliers. That’s exactly why it’s worth putting to Point in writing along with everyone else.

The category you did not put there

Here’s what all of this comes to, seen from the only place that counts.

It’s a morning in your own Outlook. Your folder tree sits exactly as you left it on Friday. On three or four messages there’s a small colored tag with one word on it that you didn’t put there. Everything stayed where it was. Your client saw an ordinary thread. Two account systems, a consent screen, a permission bounded by your own reach, an administrator’s policy and a badge about a publisher, and the entire visible result is one word on a message, in vocabulary the mailbox already had.

That’s the point at which the subject changes. Everything on this page has described an application reading a mailbox. That tag is the first thing traveling the other way, and the other way is where the care goes. What else gets written. What happens when you act in Outlook instead of the new app. Whether the two are still agreeing with each other by Friday.

That’s the next part, and it’s the one worth being fussy about.

Ready for a calmer inbox?

Join the private beta

We're onboarding a few teams at a time. Leave your email, confirm it once, and we'll send an invitation the moment a place opens.

By joining you agree to our privacy policy.

Private beta

What you're joining

It runs on the mail you have

Point sits on top of Gmail or Outlook. Your address, your history and your contacts stay exactly as they are, so there is nothing to migrate.

You set how much Point does

Out of the box everything waits for your review, replies included. You hand over only what you trust, one kind of work at a time.

Join the private beta

We're onboarding a few teams at a time. Leave your email, confirm it once, and we'll send an invitation the moment a place opens.

By joining you agree to our privacy policy.