Microsoft Graph Mail Single User
Microsoft Graph grants Cortex XSOAR authorized access to a user's Microsoft Outlook mail data in a personal account or organization account.
Email · Microsoft Graph Mail
Details
| ID | Microsoft Graph Mail Single User |
|---|---|
| Provider | Microsoft |
| Category | |
| From Version | 5.0.0 |
| Docker Image | demisto/crypto:1.0.0.10120494 |
| Supported Modules | Agentix Cloud Runtime Security XSIAM EDR Cortex Cloud |
README
Microsoft Graph grants Cortex XSOAR authorized access to a user’s Microsoft Outlook mail data in a personal account or organization account.
This integration was integrated and tested with version 1.0 of Microsoft Graph Mail Single User
Note: This integration operates against a single user mailbox — the one specified in the Email address to associate for this integration. configuration parameter. Because it uses delegated permissions, it cannot access other users’ mailboxes. For multi-mailbox or cross-tenant access, use the Microsoft Graph Mail (multi-tenant) integration.
Fetch Incidents
The integration imports email messages from the destination folder in the target mailbox as incidents. If the message contains any attachments, they are uploaded to the War Room as files. If the attachment is an email (item attachment), Cortex XSOAR fetches information about the attached email and downloads all of its attachments (if there are any) as files. To use Fetch incidents, configure a new instance and select the Fetches incidents option in the instance settings.
OData Usage
The OData parameter can be used to create different queries for the msgraph-mail-list-emails and msgraph-mail-get-email commands. Please see OData Docs for detailed information.
Examples:
!msgraph-mail-list-emails odata="$select=from"
!msgraph-mail-list-emails odata="$filter=from/emailAddress/address eq 'azure-noreply@microsoft.com'"
!msgraph-mail-list-emails odata="$filter=sentDateTime gt 2020-03-25T09:35:23Z and sentDateTime lt 2020-03-25T12:04:47Z"
Note:
The query parameter $filter is not supported when using the search parameter.
Authentication
For more details about the authentication used in this integration, see Microsoft Integrations - Authentication.
Note - The credentials (created by the Cortex XSOAR application) are valid for a single instance only.
Note - When authenticating with the Cortex application, sign in with the same user you want to integrate with. Since this user must grant consent for the app’s permissions, they must be an administrator. To let a non-admin user use the app instead, after an admin has consented to the application once, go to the Azure Portal > Enterprise applications, find the app, and set Assignment required? to No. This way, other users can obtain the Cortex application credentials without needing to sign in or consent themselves. Alternatively, you can use a Self-Deployed Application.
Email Attachments Limitations
- The maximum attachment size to be sent in an email can be 150-MB. large-attachments
- The larger the attachment, the longer it would take for a command that supports adding attachments to run.
- Requires the permission of Mail.ReadWrite (Application) - to send attachments > 3mb
- When sending mails with large attachments, it could take up to 5 minutes for the mail to actually be sent.
Required Permissions
The following permissions are required for all commands:
- Mail.ReadWrite - Delegated
- Mail.Send - Delegated
- User.Read - Delegated
- MailboxSettings.ReadWrite - Delegated
The following permissions are required for Shared Mailbox:
- Mail.Read.Shared
- Mail.ReadBasic.Shared
- Mail.ReadWrite.Shared
- Mail.Send.Shared
Configure Microsoft Graph Mail Single User in Cortex
| Parameter | Description | Required |
|---|---|---|
| ID or Client ID | False | |
| Token or Tenant ID | False | |
| Key or Client Secret | False | |
| ID or Client ID - see Detailed Instructions (?) | False | |
| Token or Tenant ID - see Detailed Instructions (?) | False | |
| Key or Client Secret - see Detailed Instructions (?) | False | |
| Certificate Thumbprint (optional for self-deployed Azure app) | False | |
| Private Key | False | |
| Certificate Thumbprint (optional for self-deployed Azure app) | Used for certificate authentication. As appears in the “Certificates & secrets” page of the app. | False |
| Private Key | Used for certificate authentication. The private key of the registered certificate. | False |
| Authorization code (required for self-deployed Azure app) | False | |
| Application redirect URI (required for self-deployed Azure app) | False | |
| Use Azure Managed Identities | Relevant only if the integration is running on Azure VM. If selected, authenticates based on the value provided for the Azure Managed Identities Client ID field. If no value is provided for the Azure Managed Identities Client ID field, authenticates based on the System Assigned Managed Identity. For additional information, see the Help tab. | False |
| Azure Managed Identities Client ID | The Managed Identities client ID for authentication - relevant only if the integration is running on Azure VM. | False |
| Fetch incidents | False | |
| Email address from which to fetch incidents (e.g., “example@demisto.com”) | During authentication, ensure you are logged in to this email address. | True |
| Name of the folder from which to fetch incidents (supports Folder ID and sub-folders e.g., Inbox/Phishing) | True | |
| First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days) | False | |
| Maximum number of emails to pull per fetch | False | |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False | |
| Use a self-deployed Azure application | Select this checkbox if you are using a self-deployed Azure application. | False |
| Incident type | False | |
| Display full email body | If not active, only a preview of the email will be fetched. | False |
| Fetch emails in HTML format | Select this checkbox to retrieve the body of an email in HTML format. If this checkbox is not selected, a psuedo-text representation of HTML emails will be returned and some functionality in other packs (e.g., email previews in the Email Communication pack) may not provide their full capabilities. | False |
| Mark fetched emails as read | Relevant only if fetch incidents is active. | False |
| Incidents Fetch Interval | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
msgraph-mail-create-draft
Creates a draft message in the specified user’s mailbox.
Base Command
msgraph-mail-create-draft
Input
| Argument Name | Description | Required |
|---|---|---|
| to | A comma-separated list of email addresses for the ‘to’ field. | Optional |
| cc | A comma-separated list of email addresses for the ‘cc’ field. | Optional |
| bcc | A comma-separated list of email addresses for the ‘bcc’ field. | Optional |
| subject | The subject for the draft. | Required |
| body | The contents (body) of the draft. | Optional |
| body_type | The body type of the email. Can be: “text”, or “HTML”. Possible values are: text, HTML. Default is text. | Optional |
| flag | The flag value that indicates the status of the draft. Possible values are: notFlagged, complete, flagged. Default is notFlagged. | Optional |
| importance | The importance of the draft. Possible values are: Low, Normal, High. Default is Low. | Optional |
| headers | A comma-separated list of additional headers in the format, headerName:headerValue. For example, “headerName1:headerValue1,headerName2:headerValue2”. | Optional |
| attach_ids | A comma-separated list of War Room entry IDs that contain files, which are used to attach files to the draft. For example, attachIDs=15@8,19@8. | Optional |
| attach_names | A comma-separated list of names of attachments to be displayed in the draft. Must be the same number of elements as attachIDs. | Optional |
| attach_cids | A comma-separated list of CIDs to embed attachments within the actual email. | Optional |
| ran_once_flag | Flag for rate limit retry. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| MicrosoftGraph.Draft.Cc | String | The CC recipients of the draft email. |
| MicrosoftGraph.Draft.IsRead | String | The “Is read” status of the draft email. |
| MicrosoftGraph.Draft.Bcc | String | The BCC recipients of the draft email. |
| MicrosoftGraph.Draft.Body | String | The body of the draft email. |
| MicrosoftGraph.Draft.MessageID | String | The message ID of the draft email. |
| MicrosoftGraph.Draft.SentTime | Date | The sent time of the draft email. |
| MicrosoftGraph.Draft.Headers | String | The headers of the draft email. |
| MicrosoftGraph.Draft.From | String | The user that sent the draft email. |
| MicrosoftGraph.Draft.Subject | String | The subject of the draft email. |
| MicrosoftGraph.Draft.ReceivedTime | String | The received time of the draft email. |
| MicrosoftGraph.Draft.Importance | String | The importance status of the draft email. |
| MicrosoftGraph.Draft.CreatedTime | String | The created time of the draft email. |
| MicrosoftGraph.Draft.Sender | String | The sender of the draft email. |
| MicrosoftGraph.Draft.ModifiedTime | Date | The modified time of the draft email. |
| MicrosoftGraph.Draft.IsDraft | Boolean | Whether it is a draft email. |
| MicrosoftGraph.Draft.ID | String | The ID of the draft email. |
| MicrosoftGraph.Draft.To | String | The ‘to’ recipients of the draft email. |
| MicrosoftGraph.Draft.BodyType | Unknown | The body type of the draft email. |
| MicrosoftGraph.Draft.ConversationID | String | The conversation ID of the draft email. |
reply-mail
Replies to an email using Graph Mail Single User.
Required Permissions
The following permissions are required for this command:
- Mail.Send (Application)
- Mail.ReadWrite (Application) - to send attachments > 3mb
Base Command
reply-mail
Input
| Argument Name | Description | Required |
|---|---|---|
| to | A comma-separated list of email addresses for the ‘to’ field. | Required |
| body | The contents (body) of the email to be sent. | Optional |
| subject | Subject for the email to be sent. | Required |
| inReplyTo | ID of the item to reply to. | Required |
| attachIDs | A comma-separated list of War Room entry IDs that contain files, and are used to attach files to the outgoing email. For example: attachIDs=15@8,19@8. | Optional |
| cc | A comma-separated list of email addresses for the ‘cc’ field. | Optional |
| bcc | A comma-separated list of email addresses for the ‘bcc’ field. | Optional |
| htmlBody | HTML formatted content (body) of the email to be sent. This argument overrides the “body” argument. | Optional |
| attachNames | A comma-separated list of names of attachments to send. Should be the same number of elements as attachIDs. | Optional |
| attachCIDs | A comma-separated list of CIDs to embed attachments within the email itself. | Optional |
| ran_once_flag | Flag for rate limit retry. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| MicrosoftGraph.SentMail.body | String | The body of the email. |
| MicrosoftGraph.SentMail.bodyPreview | String | The body preview of the email. |
| MicrosoftGraph.SentMail.subject | String | The subject of the email. |
| MicrosoftGraph.SentMail.toRecipients | String | The ‘To’ recipients of the email. |
| MicrosoftGraph.SentMail.ccRecipients | String | The CC recipients of the email. |
| MicrosoftGraph.SentMail.bccRecipients | String | The BCC recipients of the email. |
| MicrosoftGraph.SentMail.ID | String | The immutable ID of the message. |
send-mail
Sends an email using Microsoft Graph.
Required Permissions
The following permissions are required for this command:
- Mail.Send (Application)
- Mail.ReadWrite (Application) - to send attachments > 3mb
Base Command
send-mail
Input
| Argument Name | Description | Required |
|---|---|---|
| to | A comma-separated list of email addresses for the ‘to’ field. | Optional |
| cc | A comma-separated list of email addresses for the ‘cc’ field. | Optional |
| bcc | A comma-separated list of email addresses for the ‘bcc’ field. | Optional |
| subject | The subject of the email. | Required |
| body | The contents (body) of the email. | Optional |
| body_type | The body type of the email. Can be: “text”, or “HTML”. Possible values are: text, HTML. | Optional |
| renderBody | Indicates whether to render the email body. Possible values are: true, false. | Optional |
| flag | The flag value that indicates the status for the email. Possible values are: notFlagged, complete, flagged. Default is notFlagged. | Optional |
| importance | The importance of the email. Possible values are: Low, Normal, High. Default is Low. | Optional |
| headers | A comma-separated list of additional headers in the format: headerName:headerValue. For example: “headerName1:headerValue1,headerName2:headerValue2”. | Optional |
| attach_ids | A comma-separated list of War Room entry IDs that contain files, which are used to attach files for the email to send. For example, attachIDs=15@8,19@8. | Optional |
| attach_names | A comma-separated list of names of attachments to display in the email to send. Must be the same number of elements as attachIDs. | Optional |
| attach_cids | A comma-separated list of CIDs to embed attachments within the actual email. | Optional |
| attachIDs | A comma-separated list of War Room entry IDs that contain files, which are used to attach files for the email to send. For example, attachIDs=15@8,19@8. | Optional |
| attachNames | A comma-separated list of names of attachments to display in the email to send. Must be the same number of elements as attachIDs. | Optional |
| attachCIDs | A comma-separated list of CIDs to embed attachments within the actual email. | Optional |
| replyTo | Email addresses that need to be used to reply to the message. Supports comma-separated values. | Optional |
| ran_once_flag | Flag for rate limit retry. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| MicrosoftGraph.Email.internetMessageHeaders | String | The email headers. |
| MicrosoftGraph.Email.body | String | The body of the email. |
| MicrosoftGraph.Email.bodyPreview | String | The body preview of the email. |
| MicrosoftGraph.Email.subject | String | The subject of the email. |
| MicrosoftGraph.Email.flag | String | The flag status of the email. |
| MicrosoftGraph.Email.importance | String | The importance status of the email. |
| MicrosoftGraph.Email.toRecipients | String | The ‘to’ recipients of the email. |
| MicrosoftGraph.Email.ccRecipients | String | The CC recipients of the email. |
| MicrosoftGraph.Email.bccRecipients | String | The BCC recipients of the email. |
| MicrosoftGraph.Email.replyTo | String | The replyTo recipients of the email. |
msgraph-mail-reply-to
The replies to the recipients of a message.
Base Command
msgraph-mail-reply-to
Input
| Argument Name | Description | Required |
|---|---|---|
| message_id | The ID of the message. | Required |
| comment | The comment of the replied message. | Required |
| to | A comma-separated list of email addresses for the ‘to’ field. | Required |
| attach_ids | A comma-separated list of War Room entry IDs that contain files, which are used to attach files for the email to send. For example, attachIDs=15@8,19@8. | Optional |
| attach_names | A comma-separated list of names of attachments to display in the email to send. Must be the same number of elements as attach_ids. | Optional |
| attach_cids | A comma-separated list of CIDs to embed attachments within the actual email. | Optional |
| ran_once_flag | Flag for rate limit retry. | Optional |
Context Output
There is no context output for this command.
Command Example
msgraph-mail-send-draft
Sends a draft email using Microsoft Graph.
Base Command
msgraph-mail-send-draft
Input
| Argument Name | Description | Required |
|---|---|---|
| draft_id | The ID of the draft email. | Required |
| ran_once_flag | Flag for rate limit retry. | Optional |
Context Output
There is no context output for this command.
msgraph-mail-test
Tests connectivity of the email.
Base Command
msgraph-mail-test
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
There is no context output for this command.
msgraph-mail-auth-reset
Run this command if for some reason you need to rerun the authentication process.
Base Command
msgraph-mail-auth-reset
Input
There are no input arguments for this command.
Context Output
There is no context output for this command.
msgraph-mail-list-emails
Gets the properties of returned emails. Typically shows partial results, use the “page_size” and “pages_to_pull” arguments to get all results. This command lists emails only from the mailbox specified in the integration configuration.
Base Command
msgraph-mail-list-emails
Input
| Argument Name | Description | Required |
|---|---|---|
| folder_id | A comma-separated list of folder IDs, in the format: (mail_box,child_mail_box,child_mail_box). | Optional |
| odata | An OData query. See OData Usage for OData usage examples. | Optional |
| search | The term for which to search. This argument cannot contain reserved characters such as !, $, #, @, etc. For further information, see https://tools.ietf.org/html/rfc3986#section-2.2. | Optional |
| page_size | The maximum number of emails to fetch in one request. Default is 20. | Optional |
| pages_to_pull | The number of pages of emails to return (maximum is 10 emails per page). Default is 1. | Optional |
| ran_once_flag | Flag for rate limit retry. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| MSGraphMail.ID | String | The ID of the email. |
| MSGraphMail.Created | Date | The time the email was created. |
| MSGraphMail.LastModifiedTime | Date | The time the email was last modified. |
| MSGraphMail.ReceivedTime | Date | The time the email was received. |
| MSGraphMail.SendTime | Date | The time the email was sent. |
| MSGraphMail.Categories | String | Categories of the email. |
| MSGraphMail.HasAttachments | Boolean | Whether the email has attachments. |
| MSGraphMail.Subject | String | The subject of the email. |
| MSGraphMail.IsDraft | Boolean | Whether the email is a draft. |
| MSGraphMail.Body | String | The content (body) of the email. |
| MSGraphMail.Sender.Name | String | The name of the sender. |
| MSGraphMail.Sender.Address | String | The email address of the sender. |
| MSGraphMail.From.Name | String | The name of the user in the ‘from’ field of the email. |
| MSGraphMail.From.Address | String | The email address of the user in the ‘from’ field of the email. |
| MSGraphMail.CCRecipients.Name | String | The names of the CC recipients. |
| MSGraphMail.CCRecipients.Address | String | The email address of the user in the ‘cc’ field of the email. |
| MSGraphMail.BCCRecipients.Name | String | The names of the users in the ‘bcc’ field of the email. |
| MSGraphMail.BCCRecipients.Address | String | The email address of the user in the ‘bcc’ field of the email. |
| MSGraphMail.ReplyTo.Name | String | The name in the ‘replyTo’ field of the email. |
| MSGraphMail.ReplyTo.Address | String | The email address in the ‘replyTo’ field of the email. |
| MSGraphMail.UserID | String | The ID of the user. |
| MSGraphMail.ConversationID | String | The ID of the conversation. |
| MSGraphMail.InternetMessageID | String | Internet Message ID of the message. |
| MSGraphMail.Recipients.Name | String | The name of the user in the ‘toRecipients’ field of the email. |
| MSGraphMail.Recipients.Address | String | The email address of the user in the ‘toRecipients’ field of the email. |
| MSGraphMail.NextPage | String | A token to pass to the next list command to retrieve additional results. |
Command Example
!msgraph-mail-list-emails folder_id=Inbox page_size=20
msgraph-mail-list-attachments
Lists all attachments of an email.
Base Command
msgraph-mail-list-attachments
Input
| Argument Name | Description | Required |
|---|---|---|
| message_id | The email message id. | Required |
| folder_id | The id of the folder. | Optional |
| ran_once_flag | Flag for rate limit retry. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| MSGraphMailAttachment.ID | String | The email ID. |
| MSGraphMailAttachment.Attachment.ID | String | The ID of the attachment. |
| MSGraphMailAttachment.Attachment.Name | String | The name of the attachment. |
| MSGraphMailAttachment.Attachment.Type | String | The attachment type. |
| MSGraphMailAttachment.UserID | String | The ID of the user. |
msgraph-mail-get-attachment
Gets an attachment from the email.
Base Command
msgraph-mail-get-attachment
Input
| Argument Name | Description | Required |
|---|---|---|
| message_id | The unique ID of the mail. You cannot use the ‘MessageID’ key in the form ‘<message-id>’. | Required |
| folder_id | A comma-separated list of folder IDs, in the format: (mail_box,child_mail_box,child_mail_box). | Optional |
| attachment_id | The ID of the attachment. In case not supplied, the command will return all the attachments. | Optional |
| ran_once_flag | Flag for rate limit retry. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| File.Size | Number | The size of the file. |
| File.SHA1 | String | The SHA1 hash of the file. |
| File.SHA256 | String | The SHA256 hash of the file. |
| File.Name | String | The name of the file. |
| File.SSDeep | String | The SSDeep hash of the file. |
| File.EntryID | String | The entry ID of the file. |
| File.Info | String | File information. |
| File.Type | String | The file type. |
| File.MD5 | String | The MD5 hash of the file. |
| File.Extension | String | The file extension. |
msgraph-mail-get-email-as-eml
Retrieves an email message by message ID and uploads the content as an EML file.
Base Command
msgraph-mail-get-email-as-eml
Input
| Argument Name | Description | Required |
|---|---|---|
| message_id | The unique ID of the email. You cannot use the ‘MessageID’ key in the form ‘<message-id>’. | Required |
| ran_once_flag | Flag for rate limit retry. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| File.Size | String | The size of the file. |
| File.SHA1 | String | The SHA1 hash of the file. |
| File.SHA256 | String | The SHA256 hash of the file. |
| File.SHA512 | String | The SHA512 hash of the file. |
| File.Name | String | The name of the file. |
| File.SSDeep | String | The SSDeep hash of the file. |
| File.EntryID | String | The EntryID of the file. |
| File.Info | String | Information about the file. |
| File.Type | String | The file type. |
| File.MD5 | String | The MD5 hash of the file. |
| File.Extension | String | The extension of the file. |
msgraph-update-email-status
Update the status of an email to read / unread.
Base Command
msgraph-update-email-status
Input
| Argument Name | Description | Required |
|---|---|---|
| message_ids | Unique ID of the emails to update. You cannot use the ‘MessageID’ key in the form ‘<message-id>’. Can be a list of comma-separated values. | Required |
| folder_id | The folder ID. | Optional |
| status | Status to set the email to. Possible values are: Read, Unread. | Required |
Context Output
There is no context output for this command.
msgraph-mail-generate-login-url
Generate the login url used for Authorization code flow.
Base Command
msgraph-mail-generate-login-url
Input
There are no input arguments for this command.
Context Output
There is no context output for this command.
Command Example
msgraph-mail-generate-login-url
Human Readable Output
Authorization instructions
- Click on the login URL to sign in and grant Cortex XSOAR permissions for your Azure Service Management.
You will be automatically redirected to a link with the following structure:
REDIRECT_URI?code=AUTH_CODE&session_state=SESSION_STATE- Copy the
AUTH_CODE(without thecode=prefix, and thesession_stateparameter)
and paste it in your instance configuration under the Authorization code parameter.
msgraph-mail-create-folder
Creates a new folder under the specified folder (parent).
Base Command
msgraph-mail-create-folder
Input
| Argument Name | Description | Required |
|---|---|---|
| new_folder_name | display name of new folder. | Required |
| parent_folder_id | The ID of the parent folder under which to create a new folder. | Optional |
| ran_once_flag | Flag for rate limit retry. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| MSGraphMail.Folders.ChildFolderCount | number | The number of child folders. |
| MSGraphMail.Folders.DisplayName | string | The folder display name. |
| MSGraphMail.Folders.ID | string | The Folder ID. |
| MSGraphMail.Folders.ParentFolderID | string | The parent folder ID. |
| MSGraphMail.Folders.TotalItemCount | number | The total number of email messages in the folder. |
| MSGraphMail.Folders.UnreadItemCount | number | The number of unread email messages in the folder. |
msgraph-mail-move-email
Move a message to another folder. This operation creates a new copy of the message in the destination folder and deletes the original message. As a result, the message ID changes.
Base Command
msgraph-mail-move-email
Input
| Argument Name | Description | Required |
|---|---|---|
| message_id | The unique ID of the mail. You cannot use the the ‘MessageID’ key in the form ‘<message-id>’. | Required |
| destination_folder_id | The ID of the destination folder. | Required |
| ran_once_flag | Flag for rate limit retry. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| MSGraphMail.MovedEmails.DestinationFolderID | string | The folder where the email message was moved. |
| MSGraphMail.MovedEmails.ID | string | The new ID of the moved email message. |
| MSGraphMail.MovedEmails.UserID | unknown | The user ID. |
msgraph-mail-list-folders
Returns the mail folder list directly under the root folder.
Base Command
msgraph-mail-list-folders
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum number of mail folder lists to return. Default is 20. | Optional |
| ran_once_flag | Flag for rate limit retry. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| MSGraphMail.Folders.ChildFolderCount | number | Number of child folders. |
| MSGraphMail.Folders.DisplayName | string | Folder display name. |
| MSGraphMail.Folders.ID | string | Target folder ID. |
| MSGraphMail.Folders.ParentFolderID | string | Parent folder ID. |
| MSGraphMail.Folders.TotalItemCount | number | The total number of email messages in the folder. |
| MSGraphMail.Folders.UnreadItemCount | number | The number of unread emails in the folder. |
msgraph-mail-list-child-folders
Returns the folder list under the specified folder.
Base Command
msgraph-mail-list-child-folders
Input
| Argument Name | Description | Required |
|---|---|---|
| parent_folder_id | The ID of the parent folder. | Required |
| limit | The maximum number of mail folder lists to return. Default is 20. Default is 20. | Optional |
| ran_once_flag | Flag for the rate limit retry. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| MSGraphMail.Folders.ChildFolderCount | Number | The number of child folders. |
| MSGraphMail.Folders.DisplayName | String | The folder display name. |
| MSGraphMail.Folders.ID | String | The folder ID. |
| MSGraphMail.Folders.ParentFolderID | String | The parent folder ID. |
| MSGraphMail.Folders.TotalItemCount | Number | The total number of email messages in the folder. |
| MSGraphMail.Folders.UnreadItemCount | Number | The number of unread email messages in the folder. |
msgraph-mail-list-rules
List email rules for a user’s mailbox using Microsoft Graph API.
Base Command
msgraph-mail-list-rules
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | Maximum number of results to return. Default is 50. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| MSGraphMail.Rule.conditions | Unknown | Conditions that when fulfilled, will trigger the corresponding actions for that rule. |
| MSGraphMail.Rule.actions | Unknown | Actions to be taken on a message when the corresponding conditions are fulfilled. |
| MSGraphMail.Rule.displayName | String | The display name of the rule. |
| MSGraphMail.Rule.exceptions | Unknown | Exception conditions for the rule. |
| MSGraphMail.Rule.hasError | Boolean | Indicates whether the rule is in an error condition. |
| MSGraphMail.Rule.id | String | The ID of the rule. |
| MSGraphMail.Rule.isEnabled | Boolean | Indicates whether the rule is enabled to be applied to messages. |
| MSGraphMail.Rule.isReadOnly | Boolean | Indicates if the rule is read-only and cannot be modified or deleted by the rules REST API. |
| MSGraphMail.Rule.sequence | Number | Indicates the order in which the rule is executed, among other rules. |
msgraph-mail-get-rule
Get details of a specific email rule by ID for a user’s mailbox using Microsoft Graph API.
Base Command
msgraph-mail-get-rule
Input
| Argument Name | Description | Required |
|---|---|---|
| rule_id | The ID of the rule to retrieve. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| MSGraphMail.Rule.conditions | Unknown | Conditions that when fulfilled, will trigger the corresponding actions for that rule. |
| MSGraphMail.Rule.actions | Unknown | Actions to be taken on a message when the corresponding conditions are fulfilled. |
| MSGraphMail.Rule.displayName | String | The display name of the rule. |
| MSGraphMail.Rule.exceptions | Unknown | Exception conditions for the rule. |
| MSGraphMail.Rule.hasError | Boolean | Indicates whether the rule is in an error condition. |
| MSGraphMail.Rule.id | String | The ID of the rule. |
| MSGraphMail.Rule.isEnabled | Boolean | Indicates whether the rule is enabled to be applied to messages. |
| MSGraphMail.Rule.isReadOnly | Boolean | Indicates if the rule is read-only and cannot be modified or deleted by the rules REST API. |
| MSGraphMail.Rule.sequence | Number | Indicates the order in which the rule is executed, among other rules. |
msgraph-mail-delete-rule
Delete a specific email rule by ID for a user’s mailbox using Microsoft Graph API.
Base Command
msgraph-mail-delete-rule
Input
| Argument Name | Description | Required |
|---|---|---|
| rule_id | The ID of the rule to delete. | Required |
Context Output
There is no context output for this command.
Troubleshooting
In case of a hash verification error:
- Use the Oproxy flow to generate a new pair of credentials. This is crucial as it ensures that any issues related to authentication can be mitigated with fresh credentials.
- Execute the command !msgraph-mail-auth-reset. This command resets the authentication mechanism, allowing for the new credentials to be accepted.
- Insert the newly created credentials into the original instance where the error occurred. Make sure the credentials are entered correctly to avoid further errors.
- After updating the credentials, test the integration.
<~PLATFORM>
License Requirements
The following configuration parameters require one of these licenses: Cortex XSIAM or Agentix:
- Fetch incidents
</~PLATFORM>
Configuration parameters
creds_auth_id—creds_refresh_token—creds_enc_key—auth_id— ID or Client IDrefresh_token— Token or Tenant IDenc_key— Key or Client Secretcreds_certificate— Certificate Thumbprint (optional for self-deployed Azure app)certificate_thumbprint— Certificate Thumbprint (optional for self-deployed Azure app)private_key— Private Keycreds_auth_code—auth_code— Authorization code (required for self-deployed Azure app)redirect_uri— Application redirect URI (required for self-deployed Azure app)self_deployed— Use a self-deployed Azure applicationuse_managed_identities— Use Azure Managed Identitiesmanaged_identities_client_id—isFetch— Fetch incidentsmailbox_to_fetch— Email address to associate for this integration.folder_to_fetch— Name of the folder from which to fetch incidents (supports Folder ID and sub-folders e.g., Inbox/Phishing)first_fetch— First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)fetch_limit— Maximum number of emails to pull per fetchincidentType— Incident typedisplay_full_email_body— Display full email bodyfetch_html_formatting— Fetch emails in HTML formatmark_fetched_read— Mark fetched emails as readincidentFetchInterval— Incidents Fetch Intervalinsecure— Trust any certificate (not secure)proxy— Use system proxy settingslegacy_name— Use legacy attachment name
Commands (21)
-
msgraph-email-security-send-email-to-recipients-office-365-quick-actionSends an email using Microsoft Graph.
-
msgraph-mail-auth-resetRun this command if for some reason you need to rerun the authentication process.
-
msgraph-mail-create-draftCreates a draft message in the specified user's mailbox.
-
msgraph-mail-create-folderCreates a new folder under the specified folder (parent).
-
msgraph-mail-delete-ruleDelete a specific email rule by ID for a user's mailbox using Microsoft Graph API.
-
msgraph-mail-generate-login-urlGenerate the login url used for Authorization code flow.
-
msgraph-mail-get-attachmentGets an attachment from the email.
-
msgraph-mail-get-email-as-emlRetrieves an email message by message ID and uploads the content as an EML file.
-
msgraph-mail-get-ruleGet details of a specific email rule by ID for a user's mailbox using Microsoft Graph API.
-
msgraph-mail-list-attachmentsLists all attachments of an email.
-
msgraph-mail-list-child-foldersReturns the folder list under the specified folder.
-
msgraph-mail-list-emailsGets the properties of returned emails. Typically shows partial results, use the "page_size" and "pages_to_pull" arguments to get all results. This command lists emails only from the mailbox specified in the integration configuration.
-
msgraph-mail-list-foldersReturns the mail folder list directly under the root folder.
-
msgraph-mail-list-rulesList email rules for a user's mailbox using Microsoft Graph API.
-
msgraph-mail-move-emailMove a message to another folder. This operation creates a new copy of the message in the destination folder and deletes the original message. As a result, the message ID changes.
-
msgraph-mail-reply-toThe replies to the recipients of a message.
-
msgraph-mail-send-draftSends a draft email using Microsoft Graph.
-
msgraph-mail-testTests connectivity of the email.
-
msgraph-update-email-statusUpdate the status of an email to read / unread.
-
reply-mailReplies to an email using Graph Mail Single User.
-
send-mailSends an email using Microsoft Graph.
category: Email provider: Microsoft sectionorder: - Connect - Collect commonfields: id: Microsoft Graph Mail Single User version: -1 configuration: - name: creds_auth_id type: 9 displaypassword: Application ID or Client ID hiddenusername: true section: Connect required: false - name: creds_refresh_token type: 9 displaypassword: Token or Tenant ID hiddenusername: true section: Connect advanced: false required: false - name: creds_enc_key type: 9 displaypassword: Key or Client Secret hiddenusername: true section: Connect required: false - display: ID or Client ID name: auth_id type: 4 hidden: true section: Connect required: false - display: Token or Tenant ID name: refresh_token type: 4 hidden: true section: Connect required: false - display: Key or Client Secret name: enc_key type: 4 hidden: true section: Connect required: false - display: Certificate Thumbprint (optional for self-deployed Azure app) name: creds_certificate type: 9 displaypassword: Private Key section: Connect advanced: true required: false - display: Certificate Thumbprint (optional for self-deployed Azure app) name: certificate_thumbprint type: 4 additionalinfo: Used for certificate authentication. As appears in the "Certificates & secrets" page of the app. hidden: true section: Connect advanced: true required: false - display: Private Key name: private_key type: 14 additionalinfo: Used for certificate authentication. The private key of the registered certificate. hidden: true section: Connect required: false - name: creds_auth_code type: 9 displaypassword: Authorization code (required for self-deployed Azure app) hiddenusername: true section: Connect advanced: false required: false - display: Authorization code (required for self-deployed Azure app) name: auth_code type: 4 hidden: true section: Connect advanced: true required: false - display: Application redirect URI (required for self-deployed Azure app) name: redirect_uri type: 0 section: Connect advanced: false required: false - additionalinfo: Select this checkbox if you are using a self-deployed Azure application. display: Use a self-deployed Azure application name: self_deployed type: 8 section: Connect advanced: false required: false - additionalinfo: Relevant only if the integration is running on Azure VM. If selected, authenticates based on the value provided for the Azure Managed Identities Client ID field. If no value is provided for the Azure Managed Identities Client ID field, authenticates based on the System Assigned Managed Identity. For additional information, see the Help tab. name: use_managed_identities type: 8 section: Connect advanced: true required: false display: Use Azure Managed Identities - name: managed_identities_client_id type: 9 section: Connect required: false additionalinfo: The Managed Identities client ID for authentication - relevant only if the integration is running on Azure VM. displaypassword: Azure Managed Identities Client ID hiddenusername: true advanced: true - display: Fetch incidents name: isFetch required: false type: 8 section: Collect supportedModules: - agentix - xsiam - display: Email address to associate for this integration. name: mailbox_to_fetch required: false type: 0 section: Connect additionalinfo: The single mailbox this integration operates against. During authentication, ensure you are logged in to this email address. This mailbox is used by fetch-incidents and by all mail commands. Because this integration uses delegated permissions, it can only access this signed-in user's mailbox. - display: Name of the folder from which to fetch incidents (supports Folder ID and sub-folders e.g., Inbox/Phishing) name: folder_to_fetch type: 0 defaultvalue: Inbox section: Collect required: false - display: First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days) name: first_fetch defaultvalue: '15 minutes' type: 0 section: Collect required: false - display: Maximum number of emails to pull per fetch name: fetch_limit type: 0 section: Collect required: false defaultvalue: '50' - display: Incident type name: incidentType type: 13 section: Connect required: false supportedModules: - agentix - xsiam - additionalinfo: If not active, only a preview of the email will be fetched. display: Display full email body name: display_full_email_body type: 8 section: Collect advanced: true required: false defaultvalue: 'false' - display: Fetch emails in HTML format name: fetch_html_formatting type: 8 section: Collect required: false additionalinfo: Select this checkbox to retrieve the body of an email in HTML format. If this checkbox is not selected, a psuedo-text representation of HTML emails will be returned and some functionality in other packs (e.g., email previews in the Email Communication pack) may not provide their full capabilities. defaultvalue: 'false' advanced: false - display: Mark fetched emails as read name: mark_fetched_read defaultvalue: 'false' type: 8 additionalinfo: Relevant only if fetch incidents is active. section: Collect advanced: true required: false - defaultvalue: '1' display: Incidents Fetch Interval name: incidentFetchInterval type: 19 section: Collect advanced: true required: false supportedModules: - agentix - xsiam - display: Trust any certificate (not secure) name: insecure type: 8 section: Connect advanced: true required: false - display: Use system proxy settings name: proxy type: 8 section: Connect advanced: true required: false - display: Use legacy attachment name name: legacy_name section: Collect type: 8 advanced: true defaultvalue: 'false' description: Microsoft Graph grants Cortex XSOAR authorized access to a user's Microsoft Outlook mail data in a personal account or organization account. display: Microsoft Graph Mail Single User name: Microsoft Graph Mail Single User script: commands: - arguments: - description: A comma-separated list of email addresses for the 'to' field. isArray: true name: to - description: A comma-separated list of email addresses for the 'cc' field. isArray: true name: cc - description: A comma-separated list of email addresses for the 'bcc' field. isArray: true name: bcc - description: The subject for the draft. name: subject required: true - description: The contents (body) of the draft. name: body - auto: PREDEFINED defaultValue: text description: 'The body type of the email. Can be: "text", or "HTML".' name: body_type predefined: - text - HTML - auto: PREDEFINED defaultValue: notFlagged description: The flag value that indicates the status of the draft. name: flag predefined: - notFlagged - complete - flagged - auto: PREDEFINED defaultValue: Low description: The importance of the draft. name: importance predefined: - Low - Normal - High - description: A comma-separated list of additional headers in the format, headerName:headerValue. For example, "headerName1:headerValue1,headerName2:headerValue2". isArray: true name: headers - description: A comma-separated list of War Room entry IDs that contain files, which are used to attach files to the draft. For example, attachIDs=15@8,19@8. isArray: true name: attach_ids - description: A comma-separated list of names of attachments to be displayed in the draft. Must be the same number of elements as attachIDs. isArray: true name: attach_names - description: A comma-separated list of CIDs to embed attachments within the actual email. isArray: true name: attach_cids - deprecated: true description: Flag for rate limit retry. name: ran_once_flag description: Creates a draft message in the specified user's mailbox. name: msgraph-mail-create-draft outputs: - contextPath: MicrosoftGraph.Draft.Cc description: The CC recipients of the draft email. type: String - contextPath: MicrosoftGraph.Draft.IsRead description: The "Is read" status of the draft email. type: String - contextPath: MicrosoftGraph.Draft.Bcc description: The BCC recipients of the draft email. type: String - contextPath: MicrosoftGraph.Draft.Body description: The body of the draft email. type: String - contextPath: MicrosoftGraph.Draft.MessageID description: The message ID of the draft email. type: String - contextPath: MicrosoftGraph.Draft.SentTime description: The sent time of the draft email. type: Date - contextPath: MicrosoftGraph.Draft.Headers description: The headers of the draft email. type: String - contextPath: MicrosoftGraph.Draft.From description: The user that sent the draft email. type: String - contextPath: MicrosoftGraph.Draft.Subject description: The subject of the draft email. type: String - contextPath: MicrosoftGraph.Draft.ReceivedTime description: The received time of the draft email. type: String - contextPath: MicrosoftGraph.Draft.Importance description: The importance status of the draft email. type: String - contextPath: MicrosoftGraph.Draft.CreatedTime description: The created time of the draft email. type: String - contextPath: MicrosoftGraph.Draft.Sender description: The sender of the draft email. type: String - contextPath: MicrosoftGraph.Draft.ModifiedTime description: The modified time of the draft email. type: Date - contextPath: MicrosoftGraph.Draft.IsDraft description: Whether it is a draft email. type: Boolean - contextPath: MicrosoftGraph.Draft.ID description: The ID of the draft email. type: String - contextPath: MicrosoftGraph.Draft.To description: The 'to' recipients of the draft email. type: String - contextPath: MicrosoftGraph.Draft.BodyType description: The body type of the draft email. type: Unknown - contextPath: MicrosoftGraph.Draft.ConversationID description: The conversation ID of the draft email. type: String polling: true - arguments: - description: A comma-separated list of email addresses for the 'to' field. isArray: true name: to required: true - description: The contents (body) of the email to be sent. name: body - description: Subject for the email to be sent. name: subject required: true - name: inReplyTo required: true description: ID of the item to reply to. - description: 'A comma-separated list of War Room entry IDs that contain files, and are used to attach files to the outgoing email. For example: attachIDs=15@8,19@8.' isArray: true name: attachIDs - description: A comma-separated list of email addresses for the 'cc' field. isArray: true name: cc - description: A comma-separated list of email addresses for the 'bcc' field. isArray: true name: bcc - description: HTML formatted content (body) of the email to be sent. This argument overrides the "body" argument. name: htmlBody - description: A comma-separated list of names of attachments to send. Should be the same number of elements as attachIDs. isArray: true name: attachNames - description: A comma-separated list of CIDs to embed attachments within the email itself. isArray: true name: attachCIDs - deprecated: true description: Flag for rate limit retry. name: ran_once_flag description: Replies to an email using Graph Mail Single User. name: reply-mail outputs: - contextPath: MicrosoftGraph.SentMail.body description: The body of the email. type: String - contextPath: MicrosoftGraph.SentMail.bodyPreview description: The body preview of the email. type: String - contextPath: MicrosoftGraph.SentMail.subject description: The subject of the email. type: String - contextPath: MicrosoftGraph.SentMail.toRecipients description: The 'To' recipients of the email. type: String - contextPath: MicrosoftGraph.SentMail.ccRecipients description: The CC recipients of the email. type: String - contextPath: MicrosoftGraph.SentMail.bccRecipients description: The BCC recipients of the email. type: String - contextPath: MicrosoftGraph.SentMail.ID description: The immutable ID of the message. type: String polling: true - arguments: - description: A comma-separated list of email addresses for the 'to' field. isArray: true name: to - description: A comma-separated list of email addresses for the 'cc' field. isArray: true name: cc - description: A comma-separated list of email addresses for the 'bcc' field. isArray: true name: bcc - description: The subject of the email. name: subject required: true - description: The contents (body) of the email. name: body - description: The content in html format (htmlBody) of the email. name: htmlBody - auto: PREDEFINED description: 'The body type of the email. Can be: "text", or "HTML".' name: body_type predefined: - text - HTML - description: Indicates whether to render the email body. name: renderBody auto: PREDEFINED predefined: - 'true' - 'false' - auto: PREDEFINED defaultValue: notFlagged description: The flag value that indicates the status for the email. name: flag predefined: - notFlagged - complete - flagged - description: The importance of the email. name: importance auto: PREDEFINED defaultValue: Low predefined: - Low - Normal - High - description: 'A comma-separated list of additional headers in the format: headerName:headerValue. For example: "headerName1:headerValue1,headerName2:headerValue2".' isArray: true name: headers - description: A comma-separated list of War Room entry IDs that contain files, which are used to attach files for the email to send. For example, attachIDs=15@8,19@8. isArray: true name: attach_ids hidden: true - description: A comma-separated list of names of attachments to display in the email to send. Must be the same number of elements as attachIDs. isArray: true name: attach_names hidden: true - description: A comma-separated list of CIDs to embed attachments within the actual email. name: attach_cids isArray: true hidden: true - description: A comma-separated list of War Room entry IDs that contain files, which are used to attach files for the email to send. For example, attachIDs=15@8,19@8. isArray: true name: attachIDs - description: A comma-separated list of names of attachments to display in the email to send. Must be the same number of elements as attachIDs. name: attachNames isArray: true - description: A comma-separated list of CIDs to embed attachments within the actual email. name: attachCIDs isArray: true - description: Email addresses that need to be used to reply to the message. Supports comma-separated values. isArray: true name: replyTo - deprecated: true description: Flag for rate limit retry. name: ran_once_flag description: Sends an email using Microsoft Graph. name: send-mail outputs: - contextPath: MicrosoftGraph.Email.internetMessageHeaders description: The email headers. type: String - contextPath: MicrosoftGraph.Email.body description: The body of the email. type: String - contextPath: MicrosoftGraph.Email.bodyPreview description: The body preview of the email. type: String - contextPath: MicrosoftGraph.Email.subject description: The subject of the email. type: String - contextPath: MicrosoftGraph.Email.flag description: The flag status of the email. type: String - contextPath: MicrosoftGraph.Email.importance description: The importance status of the email. type: String - contextPath: MicrosoftGraph.Email.toRecipients description: The 'to' recipients of the email. type: String - contextPath: MicrosoftGraph.Email.ccRecipients description: The CC recipients of the email. type: String - contextPath: MicrosoftGraph.Email.bccRecipients description: The BCC recipients of the email. type: String - contextPath: MicrosoftGraph.Email.replyTo description: The replyTo recipients of the email. type: String polling: true - arguments: - description: The ID of the message. name: message_id required: true - description: The comment of the replied message. name: comment required: true - description: A comma-separated list of email addresses for the 'to' field. isArray: true name: to required: true - description: A comma-separated list of War Room entry IDs that contain files, which are used to attach files for the email to send. For example, attachIDs=15@8,19@8. isArray: true name: attach_ids - description: A comma-separated list of names of attachments to display in the email to send. Must be the same number of elements as attach_ids. isArray: true name: attach_names - description: A comma-separated list of CIDs to embed attachments within the actual email. isArray: true name: attach_cids - deprecated: true description: Flag for rate limit retry. name: ran_once_flag description: The replies to the recipients of a message. name: msgraph-mail-reply-to polling: true - arguments: - description: The ID of the draft email. name: draft_id required: true - deprecated: true description: Flag for rate limit retry. name: ran_once_flag description: Sends a draft email using Microsoft Graph. name: msgraph-mail-send-draft polling: true - description: Tests connectivity of the email. name: msgraph-mail-test arguments: [] - description: Run this command if for some reason you need to rerun the authentication process. name: msgraph-mail-auth-reset arguments: [] - name: msgraph-mail-list-emails arguments: - name: folder_id description: 'A comma-separated list of folder IDs, in the format: "mail_box,child_mail_box,child_mail_box".' - name: odata description: An OData query. See REDAME for OData usage examples. - name: search description: 'The term for which to search. This argument cannot contain reserved characters such as !, $, #, @, etc. For further information, see https://tools.ietf.org/html/rfc3986#section-2.2' - name: page_size description: The maximum number of emails to fetch in one request. defaultValue: '20' - name: pages_to_pull description: The number of pages of emails to return (maximum is 10 emails per page). defaultValue: '1' - deprecated: true description: Flag for rate limit retry. name: ran_once_flag outputs: - contextPath: MSGraphMail.ID description: The ID of the email. type: String - contextPath: MSGraphMail.Created description: The time the email was created. type: Date - contextPath: MSGraphMail.LastModifiedTime description: The time the email was last modified. type: Date - contextPath: MSGraphMail.ReceivedTime description: The time the email was received. type: Date - contextPath: MSGraphMail.SendTime description: The time the email was sent. type: Date - contextPath: MSGraphMail.Categories description: Categories of the email. type: String - contextPath: MSGraphMail.HasAttachments description: Whether the email has attachments. type: Boolean - contextPath: MSGraphMail.Subject description: The subject of the email. type: String - contextPath: MSGraphMail.IsDraft description: Whether the email is a draft. type: Boolean - contextPath: MSGraphMail.Body description: The content (body) of the email. type: String - contextPath: MSGraphMail.Sender.Name description: The name of the sender. type: String - contextPath: MSGraphMail.Sender.Address description: The email address of the sender. type: String - contextPath: MSGraphMail.From.Name description: The name of the user in the 'from' field of the email. type: String - contextPath: MSGraphMail.From.Address description: The email address of the user in the 'from' field of the email. type: String - contextPath: MSGraphMail.CCRecipients.Name description: The names of the CC recipients. type: String - contextPath: MSGraphMail.CCRecipients.Address description: The email address of the user in the 'cc' field of the email. type: String - contextPath: MSGraphMail.BCCRecipients.Name description: The names of the users in the 'bcc' field of the email. type: String - contextPath: MSGraphMail.BCCRecipients.Address description: The email address of the user in the 'bcc' field of the email. type: String - contextPath: MSGraphMail.ReplyTo.Name description: The name in the 'replyTo' field of the email. type: String - contextPath: MSGraphMail.ReplyTo.Address description: The email address in the 'replyTo' field of the email. type: String - contextPath: MSGraphMail.UserID description: The ID of the user. type: String - contextPath: MSGraphMail.ConversationID description: The ID of the conversation. type: String - contextPath: MSGraphMail.InternetMessageID description: Internet Message ID of the message. type: String - contextPath: MSGraphMail.Recipients.Name description: The name of the user in the 'toRecipients' field of the email. type: String - contextPath: MSGraphMail.Recipients.Address description: The email address of the user in the 'toRecipients' field of the email. type: String - contextPath: MSGraphMail.NextPage description: A token to pass to the next list command to retrieve additional results. type: String description: Gets the properties of returned emails. Typically shows partial results, use the "page_size" and "pages_to_pull" arguments to get all results. This command lists emails only from the mailbox specified in the integration configuration. polling: true - name: msgraph-mail-list-attachments arguments: - name: message_id description: The email message id. required: true - name: folder_id description: The id of the folder. - deprecated: true description: Flag for rate limit retry. name: ran_once_flag outputs: - contextPath: MSGraphMailAttachment.ID description: The email ID. type: String - contextPath: MSGraphMailAttachment.Attachment.ID description: The ID of the attachment. type: String - contextPath: MSGraphMailAttachment.Attachment.Name description: The name of the attachment. type: String - contextPath: MSGraphMailAttachment.Attachment.Type description: The attachment type. type: String - contextPath: MSGraphMailAttachment.UserID description: The ID of the user. type: String description: Lists all attachments of an email. polling: true - name: msgraph-mail-get-attachment arguments: - name: message_id required: true description: The unique ID of the mail. You cannot use the 'MessageID' key in the form '<message-id>'. - description: 'A comma-separated list of folder IDs, in the format: (mail_box,child_mail_box,child_mail_box).' name: folder_id - description: The ID of the attachment. In case not supplied, the command will return all the attachments. name: attachment_id - deprecated: true description: Flag for rate limit retry. name: ran_once_flag outputs: - contextPath: File.Size description: The size of the file. type: Number - contextPath: File.SHA1 description: The SHA1 hash of the file. type: String - contextPath: File.SHA256 description: The SHA256 hash of the file. type: String - contextPath: File.Name description: The name of the file. type: String - contextPath: File.SSDeep description: The SSDeep hash of the file. type: String - contextPath: File.EntryID description: The entry ID of the file. type: String - contextPath: File.Info description: File information. type: String - contextPath: File.Type description: The file type. type: String - contextPath: File.MD5 description: The MD5 hash of the file. type: String - contextPath: File.Extension description: The file extension. type: String description: Gets an attachment from the email. polling: true - name: msgraph-mail-get-email-as-eml arguments: - description: The unique ID of the email. You cannot use the 'MessageID' key in the form '<message-id>'. name: message_id required: true - description: Flag for rate limit retry. name: ran_once_flag deprecated: true description: Retrieves an email message by message ID and uploads the content as an EML file. outputs: - contextPath: File.Size description: The size of the file. type: String - contextPath: File.SHA1 description: The SHA1 hash of the file. type: String - contextPath: File.SHA256 description: The SHA256 hash of the file. type: String - contextPath: File.SHA512 description: The SHA512 hash of the file. type: String - contextPath: File.Name description: The name of the file. type: String - contextPath: File.SSDeep description: The SSDeep hash of the file. type: String - contextPath: File.EntryID description: The EntryID of the file. type: String - contextPath: File.Info description: Information about the file. type: String - contextPath: File.Type description: The file type. type: String - contextPath: File.MD5 description: The MD5 hash of the file. type: String - contextPath: File.Extension description: The extension of the file. type: String polling: true - description: Update the status of an email to read / unread. name: msgraph-update-email-status arguments: - description: Unique ID of the emails to update. You cannot use the 'MessageID' key in the form '<message-id>'. Can be a list of comma-separated values. isArray: true name: message_ids required: true - description: The folder ID. name: folder_id - auto: PREDEFINED description: Status to set the email to. name: status required: true predefined: - Read - Unread - description: Generate the login url used for Authorization code flow. name: msgraph-mail-generate-login-url arguments: [] - arguments: - description: display name of new folder. name: new_folder_name required: true - description: The ID of the parent folder under which to create a new folder. name: parent_folder_id - description: Flag for rate limit retry. name: ran_once_flag description: Creates a new folder under the specified folder (parent). name: msgraph-mail-create-folder outputs: - contextPath: MSGraphMail.Folders.ChildFolderCount description: The number of child folders. type: number - contextPath: MSGraphMail.Folders.DisplayName description: The folder display name. type: string - contextPath: MSGraphMail.Folders.ID description: The Folder ID. type: string - contextPath: MSGraphMail.Folders.ParentFolderID description: The parent folder ID. type: string - contextPath: MSGraphMail.Folders.TotalItemCount description: The total number of email messages in the folder. type: number - contextPath: MSGraphMail.Folders.UnreadItemCount description: The number of unread email messages in the folder. type: number - arguments: - description: The unique ID of the mail. You cannot use the the 'MessageID' key in the form '<message-id>'. name: message_id required: true - description: The ID of the destination folder. name: destination_folder_id required: true - description: Flag for rate limit retry. name: ran_once_flag description: Move a message to another folder. This operation creates a new copy of the message in the destination folder and deletes the original message. As a result, the message ID changes. name: msgraph-mail-move-email outputs: - contextPath: MSGraphMail.MovedEmails.DestinationFolderID description: The folder where the email message was moved. type: string - contextPath: MSGraphMail.MovedEmails.ID description: The new ID of the moved email message. type: string - contextPath: MSGraphMail.MovedEmails.UserID description: The user ID. - arguments: - description: The maximum number of mail folder lists to return. Default is 20. name: limit - description: Flag for rate limit retry. name: ran_once_flag description: Returns the mail folder list directly under the root folder. name: msgraph-mail-list-folders outputs: - contextPath: MSGraphMail.Folders.ChildFolderCount description: Number of child folders. type: number - contextPath: MSGraphMail.Folders.DisplayName description: Folder display name. type: string - contextPath: MSGraphMail.Folders.ID description: Target folder ID. type: string - contextPath: MSGraphMail.Folders.ParentFolderID description: Parent folder ID. type: string - contextPath: MSGraphMail.Folders.TotalItemCount description: The total number of email messages in the folder. type: number - contextPath: MSGraphMail.Folders.UnreadItemCount description: The number of unread emails in the folder. type: number - arguments: - description: The ID of the parent folder. name: parent_folder_id required: true - defaultValue: '20' description: The maximum number of mail folder lists to return. name: limit - description: Flag for the rate limit retry. name: ran_once_flag description: Returns the folder list under the specified folder. name: msgraph-mail-list-child-folders outputs: - contextPath: MSGraphMail.Folders.ChildFolderCount description: The number of child folders. type: Number - contextPath: MSGraphMail.Folders.DisplayName description: The folder display name. type: String - contextPath: MSGraphMail.Folders.ID description: The folder ID. type: String - contextPath: MSGraphMail.Folders.ParentFolderID description: The parent folder ID. type: String - contextPath: MSGraphMail.Folders.TotalItemCount description: The total number of email messages in the folder. type: Number - contextPath: MSGraphMail.Folders.UnreadItemCount description: The number of unread email messages in the folder. type: Number - arguments: - description: Maximum number of results to return. name: limit required: true defaultValue: 50 description: List email rules for a user's mailbox using Microsoft Graph API. name: msgraph-mail-list-rules outputs: - contextPath: MSGraphMail.Rule.conditions description: Conditions that when fulfilled, will trigger the corresponding actions for that rule. type: Unknown - contextPath: MSGraphMail.Rule.actions description: Actions to be taken on a message when the corresponding conditions are fulfilled. type: Unknown - contextPath: MSGraphMail.Rule.displayName description: The display name of the rule. type: String - contextPath: MSGraphMail.Rule.exceptions description: Exception conditions for the rule. type: Unknown - contextPath: MSGraphMail.Rule.hasError description: Indicates whether the rule is in an error condition. type: Boolean - contextPath: MSGraphMail.Rule.id description: The ID of the rule. type: String - contextPath: MSGraphMail.Rule.isEnabled description: Indicates whether the rule is enabled to be applied to messages. type: Boolean - contextPath: MSGraphMail.Rule.isReadOnly description: Indicates if the rule is read-only and cannot be modified or deleted by the rules REST API. type: Boolean - contextPath: MSGraphMail.Rule.sequence description: Indicates the order in which the rule is executed, among other rules. type: Number - arguments: - description: The ID of the rule to retrieve. name: rule_id required: true description: Get details of a specific email rule by ID for a user's mailbox using Microsoft Graph API. name: msgraph-mail-get-rule outputs: - contextPath: MSGraphMail.Rule.conditions description: Conditions that when fulfilled, will trigger the corresponding actions for that rule. type: Unknown - contextPath: MSGraphMail.Rule.actions description: Actions to be taken on a message when the corresponding conditions are fulfilled. type: Unknown - contextPath: MSGraphMail.Rule.displayName description: The display name of the rule. type: String - contextPath: MSGraphMail.Rule.exceptions description: Exception conditions for the rule. type: Unknown - contextPath: MSGraphMail.Rule.hasError description: Indicates whether the rule is in an error condition. type: Boolean - contextPath: MSGraphMail.Rule.id description: The ID of the rule. type: String - contextPath: MSGraphMail.Rule.isEnabled description: Indicates whether the rule is enabled to be applied to messages. type: Boolean - contextPath: MSGraphMail.Rule.isReadOnly description: Indicates if the rule is read-only and cannot be modified or deleted by the rules REST API. type: Boolean - contextPath: MSGraphMail.Rule.sequence description: Indicates the order in which the rule is executed, among other rules. type: Number - arguments: - description: The ID of the rule to delete. name: rule_id required: true description: Delete a specific email rule by ID for a user's mailbox using Microsoft Graph API. name: msgraph-mail-delete-rule - arguments: - description: A comma-separated list of email addresses for the 'to' field. isArray: true name: to prettyname: To - description: A comma-separated list of email addresses for the 'cc' field. isArray: true name: cc prettyname: CC - description: A comma-separated list of email addresses for the 'bcc' field. isArray: true name: bcc prettyname: BCC required: true prettypredefined: Email Recipients: ${issue.xdmemailrecipients} - description: The subject of the email. name: subject prettyname: Subject defaultValue: '[Security Alert] Malicious Email Removed From Your Mailbox' - description: The contents (body) of the email. name: body prettyname: Body - description: The content in html format (htmlBody) of the email. name: htmlBody prettyname: HTML Body defaultValue: | <p>Dear recipient</p> <p>Our security team has identified and removed a potentially malicious email that was previously delivered to your inbox.</p> <p><strong>Email Details:</strong><br> - Delivery Time: ${issue.timestamp}<br> - Sender: ${issue.xdmemailsender}</p> <p>This message was deemed suspicious or malicious and has been automatically deleted to protect your account and our organization.</p> <p><strong>Important:</strong><br> Please do not attempt to reopen retrieve or interact with the email if you have it cached or archived in any personal folders or devices.</p> <p>If you clicked any links or downloaded attachments from the original message or if you experience any suspicious system behavior. Please notify the Security Team immediately.</p> <p>Thank you for your cooperation in keeping our environment secure.</p> <p>—<br>Security Operations Team</p> - auto: PREDEFINED description: 'The body type of the email. Can be: "text", or "HTML".' name: body_type prettyname: Body Type predefined: - text - HTML - description: Indicates whether to render the email body. name: renderBody prettyname: Render Body auto: PREDEFINED predefined: - 'true' - 'false' - auto: PREDEFINED defaultValue: notFlagged description: The flag value that indicates the status for the email. name: flag prettyname: Rate Limit Retry Flag predefined: - notFlagged - complete - flagged - description: The importance of the email. name: importance prettyname: Importance auto: PREDEFINED defaultValue: Low predefined: - Low - Normal - High - description: 'A comma-separated list of additional headers in the format: headerName:headerValue. For example: "headerName1:headerValue1,headerName2:headerValue2".' isArray: true name: headers prettyname: Headers - description: A comma-separated list of War Room entry IDs that contain files, which are used to attach files for the email to send. For example, attachIDs=15@8,19@8. isArray: true name: attach_ids hidden: true - description: A comma-separated list of names of attachments to display in the email to send. Must be the same number of elements as attachIDs. isArray: true name: attach_names hidden: true - description: A comma-separated list of CIDs to embed attachments within the actual email. name: attach_cids isArray: true hidden: true - description: A comma-separated list of War Room entry IDs that contain files, which are used to attach files for the email to send. For example, attachIDs=15@8,19@8. isArray: true name: attachIDs - description: A comma-separated list of names of attachments to display in the email to send. Must be the same number of elements as attachIDs. name: attachNames isArray: true - description: A comma-separated list of CIDs to embed attachments within the actual email. name: attachCIDs isArray: true - description: Email addresses that need to be used to reply to the message. Supports comma-separated values. isArray: true name: replyTo - deprecated: true description: Flag for rate limit retry. name: ran_once_flag description: Sends an email using Microsoft Graph. name: msgraph-email-security-send-email-to-recipients-office-365-quick-action prettyname: "[Email Security] Send Email to Recipients - Office 365" quickaction: true hidden: true outputs: - contextPath: MicrosoftGraph.Email.internetMessageHeaders description: The email headers. type: String - contextPath: MicrosoftGraph.Email.body description: The body of the email. type: String - contextPath: MicrosoftGraph.Email.bodyPreview description: The body preview of the email. type: String - contextPath: MicrosoftGraph.Email.subject description: The subject of the email. type: String - contextPath: MicrosoftGraph.Email.flag description: The flag status of the email. type: String - contextPath: MicrosoftGraph.Email.importance description: The importance status of the email. type: String - contextPath: MicrosoftGraph.Email.toRecipients description: The 'to' recipients of the email. type: String - contextPath: MicrosoftGraph.Email.ccRecipients description: The CC recipients of the email. type: String - contextPath: MicrosoftGraph.Email.bccRecipients description: The BCC recipients of the email. type: String - contextPath: MicrosoftGraph.Email.replyTo description: The replyTo recipients of the email. type: String polling: true dockerimage: demisto/crypto:1.0.0.10120494 isfetch: true script: '' type: python subtype: python3 tests: - MicrosoftGraphMailSingleUser-Test_dev defaultclassifier: Microsoft Graph Mail Single User defaultmapperin: Microsoft Graph Mail Single User-mapper fromversion: 5.0.0 supportsquickactions: true