Control

Connect Microsoft 365

One sign-in with the mailbox's account. Two minutes. Nothing to install.

Updated 4 October 2026

Control reads your mailbox through Microsoft 365 with the permissions of one account you choose: the mailbox's own account, or a person's account that has access to the shared mailbox. Control can read exactly what that account can read, and nothing else. There is no application to register and no setting for your administrator to change.

What you need

  • The account that reads the mailbox, and its password or sign-in method (your phone, for example).
  • Any browser, on any device.

The steps

  1. We start the connection during onboarding and give you an address, microsoft.com/devicelogin, and a short code. The code is valid for 15 minutes.
  2. You open the address, enter the code, and sign in with the account above.
  3. Microsoft shows what Control asks for: read your mail, read shared mail you have access to, keep that access, and sign you in. Press Accept.
  4. We confirm on our side that the mailbox can be read and tell you the number of messages in its Inbox. From the next run on, Control reads the mailbox.

If your organisation does not let people accept applications themselves, Microsoft says so at step 3. Your administrator then opens a link we send and presses Accept once; after that, step 2 works for everyone in your organisation.

What Control may do afterwards

Read the connected mailbox, and the shared mailboxes the account can open. Nothing is sent, moved, labelled or deleted: the permissions are read-only, and Control has no code that writes to a mailbox. The access continues without further sign-ins; Microsoft renews it on every use.

When the connection stops

If the account's password changes, the account is disabled, or someone removes Control from your organisation's applications, reading stops at the next run. Nothing else happens: the daily report says the connection no longer works, Työäly is alerted, and reconnecting is the same two minutes.

Removing Control

Tell us, or remove the application yourself: the account's owner under myapps.microsoft.com (Manage your applications), or your administrator under Enterprise applications. Control's records of your messages expire by themselves after 90 days, or earlier on request.

For organisations with their own IT policy

Some organisations forbid applications that act with a person's permissions. For them Control can instead use an application registered in your own tenant, limited to the one mailbox by an Exchange access policy. Your IT does that in about 20 minutes with the instructions we provide; ask us.

Something missing or unclear on this page? Write to hei@tyoaly.fi.