# Microsoft 365 Integration Developers UK

Source: https://dijituldevelopments.co.uk/microsoft-365-integration/
Updated: 2026-10-10

> dijitul developments builds Microsoft 365 integrations for UK businesses using Microsoft Graph: connecting your software to Outlook mail and calendars, Teams, SharePoint, OneDrive, Excel and Entra ID single sign-on. We also move old Exchange Web Services code onto Graph before it's switched off. Every project is a fixed-price quote after a free chat.

## Problems this solves

- Staff copy details from emails into your system all day
- An old tool reads a shared mailbox using Exchange Web Services and is about to stop working
- Documents live in SharePoint but your app keeps its own copies
- People have yet another username and password for your in-house software
- Bookings in your system don't appear in Outlook calendars
- Alerts go by email when the team actually lives in Teams

## Key facts

- Microsoft Graph is one REST endpoint (graph.microsoft.com) for mail, calendars, Teams, SharePoint, OneDrive, Excel and users
- Apps are registered in Microsoft Entra ID and authenticate with OAuth 2.0 using delegated or application permissions
- Microsoft began phasing out Exchange Web Services in Exchange Online from 1 October 2026, with full retirement planned for 1 April 2027
- Change notifications (webhooks) and delta queries replace constant polling
- Graph throttles with HTTP 429 and a Retry-After header, which our code respects
- Single sign-on with Entra ID lets staff use their Microsoft 365 login in your bespoke software
- Access is limited by permission scope and, where possible, to specific mailboxes or sites

## Your business already runs on Microsoft 365

For most UK offices, email, calendars, files and chat all live in Microsoft 365. Your line-of-business software usually doesn't, which is why people spend their day moving information between the two: forwarding an email to the right person, saving an attachment to the correct folder, typing a booking into Outlook. A Microsoft 365 integration removes those steps by letting your software read and write Microsoft 365 data directly.

Everything goes through **Microsoft Graph**, Microsoft's single REST API for the platform. That means one authentication model, one set of conventions and one place to manage permissions.

## Exchange Web Services is being retired

If you have a tool that reads a mailbox, books meetings or syncs contacts, check what it's built on. Microsoft has announced that Exchange Web Services (EWS) in Exchange Online is being phased out from 1 October 2026, with full retirement planned for 1 April 2027, and that Microsoft Graph is the replacement. Tenants can temporarily allow specific applications, but that is a stopgap, not a plan.

We audit the code, map each EWS call to its Graph equivalent (messages, mailFolders, events, contacts, attachments), switch authentication to OAuth 2.0 with an Entra ID app registration, and test against a copy of your real mailbox structure. If the old tool can't be updated, we'll rebuild the part you need. Wider rebuild work is covered under [legacy software modernisation](https://dijituldevelopments.co.uk/legacy-software-modernisation/).

## What we connect

- **Outlook mail:** process a shared inbox such as orders@ or accounts@, extract data from emails and attachments, create records in your system, then move or tag the message. Pairing this with [AI document processing](https://dijituldevelopments.co.uk/ai-document-processing/) handles PDFs and scanned forms.
- **Calendars:** create Outlook events when a job or appointment is booked in your system, and read free/busy to avoid clashes.
- **SharePoint and OneDrive:** store generated documents in the right site and folder, apply metadata, and link to them from your app instead of keeping duplicates.
- **Excel:** read and write workbook ranges and tables through Graph for teams that still run part of the process in a spreadsheet.
- **Teams:** post alerts and approval requests to a channel, or chat messages with adaptive cards.
- **Users and groups:** sync staff and roles from Entra ID so access in your app follows HR changes.

## Authentication, permissions and security

Every integration starts with an app registration in Microsoft Entra ID. Where a person is signed in, we use **delegated permissions**, so the app can only do what that person could. For background jobs we use **application permissions** with a certificate rather than a client secret where possible, and we limit mailbox access to the specific mailboxes required using Exchange application access policies or RBAC for Applications, instead of granting access to every mailbox in the tenant.

For your own web app, single sign-on via OpenID Connect means staff use their Microsoft 365 login, get multi-factor authentication from your existing policy, and lose access automatically when they leave. Your IT admin grants consent once, and we document exactly which permissions were requested and why.

## What your IT admin will want to know

Microsoft 365 integrations touch your tenant's security, so we involve whoever manages it early. We provide a short document covering the app registration name, every Graph permission requested and why, whether each is delegated or application, which mailboxes or SharePoint sites are in scope, and how credentials are stored. We prefer certificates over client secrets for unattended jobs, record their expiry dates, and set reminders well before they lapse, because an expired credential is the most common reason a working integration suddenly stops.

We also check how your Conditional Access policies apply to the app, and make sure ownership of the app registration sits with your organisation rather than with one person's account.

## Built to stay within Graph's limits

Microsoft's documentation advises against frequent polling and recommends change notifications and delta queries instead. We subscribe to change notifications for mailboxes, calendars or files, renew subscriptions before they expire, handle lifecycle notifications, and use delta queries to catch up after any gap. When Graph returns HTTP 429, we wait for the time given in the `Retry-After` header before trying again. Batching (up to 20 requests in one call) keeps busy jobs efficient. You get a fixed-price quote after a free chat: [get in touch](https://dijituldevelopments.co.uk/contact/).

## What we deliver

- Entra ID app registration with least-privilege Graph permissions
- Single sign-on for your web app using Entra ID (OpenID Connect)
- Shared mailbox processing: read, file, tag and extract data from incoming email
- Two-way calendar sync between your system and Outlook
- Document storage and retrieval in SharePoint or OneDrive from your app
- Teams notifications and adaptive cards for approvals and alerts
- Migration of Exchange Web Services code to Microsoft Graph

Technologies: Microsoft Graph, Microsoft Entra ID, OAuth 2.0, OpenID Connect, SharePoint, Node.js, Laravel, C#

## FAQs

### Our software uses Exchange Web Services. Do we need to act now?

Yes. Microsoft started phasing out EWS in Exchange Online on 1 October 2026 and plans full retirement on 1 April 2027. dijitul can audit your EWS usage, move it to Microsoft Graph and switch authentication to an Entra ID app registration.

### Can staff log into our bespoke software with their Microsoft 365 account?

Yes. dijitul adds Entra ID single sign-on using OpenID Connect, so staff use their normal Microsoft login and MFA, and access stops automatically when their Microsoft 365 account is disabled.

### Can you process emails from a shared mailbox automatically?

Yes. We use Microsoft Graph to watch a shared mailbox, extract data from the email and attachments, create records in your system and then file or tag the message. Access can be restricted to that one mailbox.

### Does the integration need access to all our mailboxes?

No. Application permissions can be scoped to specific mailboxes using Exchange policies, and delegated permissions only act as the signed-in user. dijitul requests the minimum permissions and documents each one for your IT admin.

### Is Power Automate enough for this?

For simple flows inside Microsoft 365, often yes. Custom Graph integration makes sense when you need to connect your own software, handle volume, or apply logic that's awkward to maintain in flows. See our workflow automation page for a fair comparison.

### Can our app save documents straight into SharePoint?

Yes. dijitul can write generated documents into the correct SharePoint site and folder with metadata, and show links in your app, so there's one copy of each file and SharePoint permissions still apply.

## Pricing and contact

Every project gets a fixed-price quote after a free initial chat and a short scoping stage. You own the code and the data. Book a free chat: https://dijituldevelopments.co.uk/contact/ · 01623 650333 · info@dijitul.uk
