For IT admins
Approve Inbox Search for your organisation
Someone in your organisation wants to use Inbox Search, an Outlook add-in that finds emails by meaning as well as by keyword. Your organisation only lets admins approve apps that read mail, so Microsoft told them to ask you. This page explains what Inbox Search asks for, and how to approve it once for everyone.
Approve it for everyone
This opens Microsoft's own approval window. Sign in with an account that can grant consent for your whole organisation, such as a Global Administrator or Privileged Role Administrator. Microsoft lists the permissions described below; press Accept. You come back to this site when it's done.
Approving does not install anything. Each person still adds Inbox Search in Outlook, or you can deploy it to everyone from the Microsoft 365 admin center under Settings › Integrated apps.
What it asks for
Mail.Read (delegated) |
Microsoft shows it as Read your mail. Inbox Search reads the user's mail to build a search index on their device. Read-only: it cannot send, delete, move or change anything. |
|---|---|
User.Read (delegated) |
Sign-in: the user's own basic profile, so Inbox Search knows which mailbox it is indexing. |
openid, profile |
Sign-in: who the user is. |
offline_access |
Keeps the user signed in, so Outlook doesn't ask them again every hour. |
- Delegated only. It acts as the signed-in user, in their own mailbox. There are no application permissions and no access to anyone else's mailbox.
- It cannot send, delete or change email.
Mail.Readis read-only, and Inbox Search asks for nothing broader. - No calendar, contacts, files or directory access.
Where the email data goes
- Email content stays on the user's device. The search index and the AI model run inside the add-in in Outlook. Emails are never sent to Inbox Search's servers or to any AI service.
- Our server receives the user's email address and a pseudonymous ID, usage counts (searches run, results opened, emails indexed), the add-in version and Outlook platform, and diagnostics such as errors, with email addresses and file paths removed. For the free plan's daily allowance and for subscriptions, it also receives the user's Microsoft account ID. Never email content, subjects, folder names or search queries.
- Full details are in the Privacy Policy.
Details for your records
| App name | Inbox Search |
|---|---|
| Application (client) ID | e5594d8d-6e77-4091-8e66-dcb2a4bdd5cc |
| Publisher | Henry Stassart, verified by Microsoft (blue badge on Microsoft's approval window) |
| Listing | Inbox Search on Microsoft Marketplace |
| Works in | Classic and new Outlook for Windows, Outlook on the web, Outlook for Mac |
Prefer the Entra admin center?
You can grant the same approval there:
- Open the Microsoft Entra admin center.
- Go to Enterprise applications and search for Inbox Search (or the client ID above).
- Open Permissions and choose Grant admin consent.
If Inbox Search isn't listed there, use the Approve for my organisation button above, which adds it.
Changing your mind
To withdraw the approval, open Inbox Search under Enterprise applications in the Entra admin center and delete it, or review its permissions there. Users then lose access until it is approved again.
Questions
Email hello@inboxsearch.app. For how the add-in works day to day, see Support.