As part of its Secure Future Initiative, Microsoft is deprecating legacy features that will impact the Salesforce Outlook integration in the coming months. Microsoft is moving to Nested App Authentication (NAA).
This article outlines steps that Microsoft 365 (M365) admins must take to keep Salesforce admins' users able to access the Salesforce Outlook integration as this feature is updated in 2024 and 2025. Salesforce admins will not have the required permissions or access to make these changes - M365 admins must execute these steps before Exchange Online tokens are turned off in the tenant. Failure to do so could prevent users from accessing the Salesforce Outlook integration.
This article explains the two key migration milestones M365 admins need to track, the recommended Admin Consent Flow that simplifies the migration for end users, and the banner message users will see during this transition.
Microsoft refers to this change as Nested App Authentication, or NAA. Refer to the official Microsoft documentation, available here, for more information, including timelines based on which update channel(s) your organization is using. While we encourage customers to implement these changes immediately, any questions about the exact timing of the milestones below should be directed to your M365 admin.
When reviewing Microsoft's documentation, there are two key milestones to be mindful of:
We strongly suggest that M365 admins use the Admin Consent Flow, which automates the scope authorization process for all users in an account's tenant so individual users don't have to manually authorize the integration after Microsoft rolls out these changes. M365 admins can use this link to initiate the Admin Consent Flow. This link must be used by an M365 admin.
All users are notified of these changes by a banner message that reads: "Upcoming Microsoft changes might block access to this application. To avoid losing access to your Outlook add-in, notify your Salesforce admin about this message."
002723592

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.