How it works

Setup once. Manage daily. Audit periodically.

The Tenvero Manager organizes administration around three stages, navigated from a left rail rather than numbered tabs.

STAGE 1
Setup once
Nine guided tabs configure Exchange app-only auth, certificates, AD groups and Entra Connect mode — separate from daily admin.
STAGE 2
Manage daily
Shared mailboxes is the daily workspace: a searchable mailbox list next to a management overview card.
STAGE 3
Audit periodically
A read-only Delegation Audit health scan flags drift without ever changing AD membership or Exchange permissions.
01
Install and run Setup
Run Tenvero-Setup as Administrator and work through the guided tabs. Existing MailPilot or MailboxAutoMapping installs are migrated automatically before the wizard loads.
02
Provision the Entra app
Tab 3 opens the Microsoft device-login page automatically and copies the device code to the clipboard for certificate-based, unattended Exchange Online authentication.
03
Map a shared mailbox to AD groups
Create one mapping per mailbox: separate or shared AD security groups for Full Access, Send As and Send on Behalf, with AutoMapping enabled per mapping.
04
Import existing access (optional)
Preview current direct Exchange delegates, resolve them to on-prem AD, and adopt safe matches into Tenvero ownership without revoking current access.
05
Reconcile on schedule
The Tenvero Mailbox Sync task reads AD membership and applies only Tenvero-owned grants and revokes, protected by a global sync mutex.
06
AutoMapping takes effect
Outlook desktop and mobile pick up the mailbox automatically from the direct Full Access grant, without a manual Add mailbox step.
07
Review Access activity
Every Grant, Revoke, Takeover and AutoMapping event is logged with the expected Outlook client propagation behavior.
08
Run a Delegation Audit
Scan every mapping for disabled accounts, orphaned trustees, missing groups and unmanaged direct access — export findings to CSV.
09
Sync Entra Connect
Trigger a local or remote delta sync immediately after an address or attribute change, or leave sync disabled for manual cycles.