API Access
Summary
Customers using Microsoft 365 or Google Workspace as their email infrastructure can enable domain and directory access, message remediation, setup and maintenance (M365 only), and delegated access APIs in INKY. These features allow administrators to efficiently manage their INKY account by adding new domains and directly removing one or multiple messages from a user’s mailbox.
For Microsoft 365 users, the setup and maintenance feature enables administrators to perform tenant configuration changes directly through the INKY dashboard. Delegated access grants policy administrators and super administrators enhanced permissions to manage the tenant. Super administrators, in particular, can access more sensitive content, such as email details.
Granting API access requires a Microsoft 365 Global Admin or a Google Super Admin account. INKY will not remove any messages automatically; only an authorized administrator can invoke the remediation actions.
Domain and Directory Access
To enable this feature, sign in to your INKY Dashboard and navigate to Settings > API Access.
Microsoft 365
Select the Grant Domain and Directory Access button under the Microsoft Graph API Access tab.
Your browser will redirect you to Microsoft to sign in and grant the necessary permissions. If this step is completed successfully you’ll see “Access Granted” under Domain and Directory Access as shown below.
Google Workspace
Navigate to the Google Workspace - Domain Wide Delegation Console.
Select Add New and enter the following information:
Client ID: 102036946623295318758
Scopes: https://www.googleapis.com/auth/admin.directory.user.readonly, https://www.googleapis.com/auth/admin.directory.domain.readonly
Select Authorize
Navigate to Settings > API Access > Google API Access in your INKY Dashboard
Select the Verify Domain and Directory Access button. To verify this, you’ll need to be logged into INKY as the Google Admin.
Administrators can now add domains to their INKY Dashboard under Settings > Routing. For more information, please see this article.
Remediation
To enable this feature, sign in to your INKY Dashboard and navigate to Settings > API Access.
Microsoft 365
Select the Grant Remediation Access button under the Microsoft Graph API Access tab.
Your browser will redirect you to Microsoft to sign in and grant the necessary permissions. If this step is completed successfully you’ll see “Access Granted” under Remediation Access as shown below.
Google Workspace
Navigate to the Google Workspace - Domain Wide Delegation Console.
Select Add New and enter the following information:
Client ID: 116106903419769312436
Select Authorize
Navigate to Settings > API Access > Google API Access in your INKY Dashboard
Select the Verify Remediation Access option
Administrators can remediate messages from the observations tab and within a custom dashboard under visualizations. For more information, please see the “Routing | Add-a-Domain” article linked below.
Setup & Maintenance Access (M365 only)
INKY requires Global Admin access to your O365 tenant for setup and maintenance. This allows INKY to run PowerShell commands on your behalf to perform discoveries, modify Exchange mail flow rules, and to install/uninstall the service for you.
Delegated Access to Tenant (M365 & Google)
When Delegated Tenant Access is enabled, parent and ancestor organization administrators will be authorized to access sensitive mail content within your tenant and perform tenant operations (uninstall and update). Note that reading mail content applies only to administrators who can remediate mail (Policy Admin, Super Admin), and tenant operations can only be performed by Super Admins.
Related Articles