Microsoft 365 integration: Configuration guide
Table of Contents
To set up the Microsoft 365 Integration, you will need:
- Microsoft 365 admin credentials for your organization.
- A Paradox user role with permission to access the Connected Apps section of the Integration Center.
- If you choose the Custom App configuration, you will need your Azure Application (Client) ID, Directory (Tenant) ID, and Client Secret Value.
Complete the below configuration steps to set up a Microsoft 365 integration with Paradox.
Configure a Microsoft 365 integration
- Select All Apps in the top left corner of the header and then select Integrations.
- On the Integration Center page, open the Connected Apps section.
- Select Connect Microsoft 365 on the tile.
If an integration is already connected, select the three-dotted menu on the tile and Tenant Connection Details. In the modal, select + Add New Tenant to connect another one.
Step #1: Select integration approach
- Select the method your organization prefers for calendar management:
- Service Account: Uses a dedicated Microsoft 365 account to manage calendars across your organization. Best for centralized control.
- Azure Admin Account: Grants organization-wide permissions via your Azure admin. Best for enterprises that require admin-level control without a specific service account.
- Select Continue.
Step #2: Select app management method
- Choose how the Paradox application is registered in your Azure environment:
- Use Default App (Recommended): A quick setup using the pre-configured Paradox application. No additional Azure configuration is required.
- Custom App: Uses your organization's registered Azure application, requiring you to provide the Application ID, Tenant ID, and Client Secret.
- Select Continue.
Step #3: Select functionality selections
- Enable the features this tenant connection will support. You must select at least one feature.
-
Microsoft O365 National Clouds: Select the Microsoft O365 environment that matches your organization’s setup:
- Microsoft O365 Global Cloud: The standard environment for most commercial businesses worldwide.
- Microsoft O365 Government GCC High: For U.S. government contractors and agencies.
- Send Calendar Invites (Service Accounts Only): Enable this to send interview invites to candidates and interviewers from the service account's email address.
-
Read Calendar Availability: Enable this to allow the service account to check free/busy times for scheduling.
- Default to Calendar Timezone Sync: Enable (or disable) this to sync Paradox timezone with O365 Working Hours timezone each time the calendar is accessed. This is automatically enabled by default. Learn more about employee/user timezones.
- Enable Microsoft Teams Meetings: Enable this to automatically create Teams meeting links for every scheduled virtual interview.
-
Enable recording and transcription: Allows recording and transcription for the meeting.
- Note: Your Microsoft Teams Admin must also enable recording and transcription in your Teams tenant-level policies.
- Set attendees as co-organizers: Sets attendees as co-organizers.
- Lobby Bypass Settings: Select who is admitted directly into the meeting without waiting in the lobby. Options include Organizer, Organization, Organization and Federated, Everyone, Invited, and Organization Excluding Guests.
-
Microsoft O365 National Clouds: Select the Microsoft O365 environment that matches your organization’s setup:
- Select Continue.
Step #4: Configure app permissions and credentials (custom app only)
This step is only required if you selected Custom App in Step 2. If you chose the Default App, skip to Step 5.
When using a Custom App, you will need to copy information between the Paradox setup wizard and your organization's Azure Portal.
Part A: Configure app permissions
- Review the list of required Microsoft Graph API permissions displayed in Paradox. This list is based on the functionality you selected in Step 3.
- Navigate to your organization's Azure Portal App registrations and add the required permissions.
- A Microsoft 365 Admin must grant admin consent for these permissions in Azure.
- Warning: Missing any required permission will cause the integration to fail.
- Copy the specific Paradox Redirect URI shown in the setup wizard and paste it into the app's settings in your Azure Portal.
-
Service Account Setup:
https://olivia.paradox.ai/user/outlook-oauth2(or the EU version) -
Azure Admin Setup:
https://paradox.ai/azure-admin-consent(or the EU version)
-
Service Account Setup:
- Once your Azure configuration is complete, select Continue.
Part B: Enter your managed app credentials in Paradox
- Enter the following credentials from your registered Azure application:
- Application ID: The unique ID number for your app.
- Secret Value: The app's secret password (ensure you use the value, not the ID).
- Directory (Tenant) ID: Your organization's unique Azure tenant identifier.
- Secret Value Date Expiration: Select a future date.
- Select Continue.
Step #5: Tenant identification (azure admin only)
This step is only required if you selected Azure Admin Account in Step 1.
- In the Tenant ID field, enter your organization's Tenant ID in GUID format.
- Select Continue.
Step #6: Notify recipients
- Select up to 5 individuals who should receive proactive alerts about integration issues, such as outages or expiring credentials.
- Note: All selected users must have Full Access to Connected Apps in Paradox.
- Select Continue.
Step #7: Establish connection
- Select Sign in with Microsoft. This initiates the necessary authentication flow:
- Service Account: The OAuth flow opens a window/tab for the service account user to sign in and grant consent.
- Azure Admin: An admin consent URL opens a window/tab for the Azure Admin to grant consent to the application permissions.
- On the Microsoft page, select Accept.
- If successful, the Sign In Successful! message displays. Select Continue.
If the authentication is unsuccessful, the Authentication Unsuccessful message displays and notifies the user of the reason for error.
Step #8: Review the tenant overview
- Review all the tenant connection details. Adjust any settings as needed.
- Select Complete Setup.
Step #9: Configure calendar invites
After completing the tenant setup, a separate window will appear to configure how interview invitations are sent. This setting applies to all connected tenants.
- Select one of the following options:
- Send Calendar Invites from Service Account Email: Only visible if a Service Account tenant is connected and configured to send invites.
- Send Calendar Invites from a Different Email: Use this option to connect a dedicated email address by signing in with Outlook.
- Send Calendar Invites from Paradox Email: Invitations are sent from a default Paradox sender and requires no additional setup.
- If you select one of the first two options, you will be prompted to address DNS records to ensure email deliverability:
- Generate DNS Records: Displays the required CNAME and TXT records that must be added to your organization's DNS host. These records are vital for email authentication (e.g., SPF and DKIM) to prevent invitations from being flagged as spam.
- Generate DNS Records Later: Allows you to defer the DNS record setup and proceed with the integration connection.
Your Microsoft 365 integration is now connected and ready to use. You can manage tenants and settings from the Microsoft 365 tile in Connected Apps.
Permissions
Users will need full access to the Connected Apps permission (under the Integration Center parent permission) in order to set up the Microsoft 365 integration.