Last updated: 21 July 2026
How MailBroom for Business connects to Microsoft 365 mailboxes, what it can and can't see, and how that fits an organisation's GDPR obligations.
How access works
Sign-in goes through Microsoft Entra ID — the same login already used for Microsoft 365. MailBroom receives only a scoped Graph API access token, never the password itself.
An admin can revoke that access instantly from the organisation's own Microsoft admin settings — no need to contact MailBroom to cut off access.
Retention obligations
Smart Sweep and Storage Cleanup respect existing Exchange Online retention policies and litigation/in-place holds — items covered by a hold stay preserved regardless of what a user clears elsewhere in their own mailbox. This is the same requirement that applies to any bulk mailbox action, and matters specifically under GDPR where a retention or legal hold obligation overrides a general right to deletion.
No. Sign-in happens via Microsoft Entra ID — the same login your company already uses for Microsoft 365. MailBroom never sees or stores the password itself; it only ever receives a scoped, revocable Microsoft Graph access token, used to read and act on the mailbox on the signed-in user's behalf.
Yes, at any time, via the organisation's own Microsoft admin settings — the same place any other Entra ID-connected app's access is managed. Revoking access there immediately invalidates MailBroom's Graph API token for that user.
MailBroom's Smart Sweep and Storage Cleanup work within existing Exchange Online retention policies and legal/litigation holds, not around them — held or retained items stay preserved regardless of what a user clears elsewhere in their own mailbox. This matters for GDPR specifically where retention is a legal obligation (e.g. a litigation hold), not just a company preference.
Each employee (or, for an MSP, each client's own employees) signs in with their own Microsoft account and acts on their own mailbox directly — the company or MSP running MailBroom isn't accessing mailbox contents on their behalf without their own authentication in the loop. The underlying data is the organisation's own business correspondence, held for its own operational purposes, which is the same basis the organisation already relies on for holding that mail in Microsoft 365 at all.
MailBroom for Business connects to a mailbox via the Microsoft Graph API to act on it directly — it does not maintain its own separate copy of mailbox content as a matter of course. Some usage data (e.g. counts of storage freed, emails deleted) is retained at the account level to power the ROI/CO₂ dashboards; see the Privacy Policy for the full breakdown of exactly what's stored.
Every data category MailBroom for Business stores, and exactly why — no summary, the actual policy.