Enable SCG Support for Shared Mailboxes
Purpose: Enabling SCG for Shared Mailboxes will allow users to send Secure Mail from a shared mailbox address. To enable the feature, an M365 admin will need to provide consent to eShare’s Outlook API.
- Login to Cloud Web Portal with an eShare administrator account. (Your M365 account should have at minimum application administrator role).
- Navigate to Manage Organization > Corporate Cloud Providers and turn ON the “Provide consent to eShare for Outlook API” option.
- Review the requested permissions for your organization presented by Microsoft and select Accept when ready.
- Verify eShare’s Service principal is present in Azure Enterprise Applications. Once verified, select the option “Get access token” as shown in the screenshot below.
- Once the token is acquired, the application “e-Share EXO Reader” in your enterprise applications listing in Azure AD. This app will need to be added as an Exchange Administrator
- Head over to https://portal.azure.com and open the Azure Active Directory Service
- Under the “Manage” category, select “Roles and administrators”
- Find the “Exchange Administrator” role and open the role. When the assignments page opens, select “Add Assignments” at the top of the page, search for “e-Share”, select the “e-Share EXO Reader” app, select “Add”
- With the token acquired and the Exchange Admin role assigned to the application, eShare is now able to query Outlook/Office for members of shared mailboxes.
Next, we need to create a SharePoint site specifically for Shared Mailboxes, this is where the trusted shares will live when sending a Secured mail from any shared mailbox. - Go to SharePoint Home, then select “Create site”
- On the create a site page, choose “Team Site”
- Call the site name “SharedMailboxes” and select next. You do not need to add any users to the site, then select Finish.
Now you will need go back to the eShare admin console to finish setting up SMG for Shared Mailboxes. - Next go to the eShare admin console, then go to the Secure email tab.
- Under Secure email, enter the site name of the Shared Mailboxes site under “SP site name”, then select Save.
You have now successfully enabled SMG for Shared Mailboxes. Whenever a user sends an email from a shared mailbox, the files will be stored in this SharePoint site in an outbox folder.