Your mailbox is on Microsoft 365, Booked Solid is asking for an app password, and Microsoft will only hand you one if you weaken your account security first. I don't want to lower my security is a fair place to stop. A performer wrote in with the same question, word for word: Is there any way to not use an app password to connect the email? Mine is on Microsoft 365 and I have to downgrade my security to use the app password. Yes, there is a way, it is the correct one, and it does not change a single Microsoft security setting.
First: do not add a Microsoft 365 mailbox as IMAP
Almost everyone tries this first, and it is a dead end. The Connections tab opens on Mail & calendars with an Add an email account button right there, and that form defaults to Any email (IMAP). That is the route that demands an app password, and on Microsoft 365 getting one means loosening the account security you came here to protect. Skip that step for this mailbox. IMAP is the right road for Gmail, iCloud, Fastmail, and your own domain elsewhere. It is the wrong road for a mailbox that lives in Microsoft's cloud.
Microsoft 365 has its own connection further down the same tab, and it signs you in on Microsoft's own website instead.
Connect Microsoft 365 by device code
This is the Microsoft 365 device code sign-in. You type a short code on a Microsoft page, Microsoft hands the app a token, and no password ever touches Booked Solid. The only thing kept on your computer is that token, in your operating system keychain.
- Open the Connections tab in Booked Solid.
- Scroll past the Mail & calendars section, down to Tool access (optional). This is where people go wrong: they stop at Add an email account at the top and take the IMAP road by accident.
- Find the card called Microsoft 365 (Outlook, Teams) and tap it to open it.
- Click Sign in to Microsoft. The card shows you a short code.
- On any device, open microsoft.com/devicelogin, type the code, sign in with your Microsoft 365 account, and approve the permissions if it shows them to you.
- The card flips to Signed in as your address on its own. There is nothing to paste back into the app.
- Press Turn on on that same card. This is a separate step from signing in, and it is the one most people stop short of. Until you press it, the connection is not live for Otto.
The sign-in code lasts about 15 minutes. If it expires before you finish, start the sign-in again and you get a fresh one. If Turn on refuses with Sign in to Microsoft first (on its card), then switch it on, the sign-in did not actually complete - run it again and watch for the green line.
No permissions screen came up. Is it broken?
Usually not, and this trips up careful people in particular. Because this sign-in uses Microsoft's own pre-consented client, many tenants sign you straight through without showing a separate "approve these permissions" list, especially if you or your administrator have already consented to Microsoft Graph at some point. So the thing to check is not whether a permissions screen appeared. It is whether the card inside Booked Solid went green and reads Signed in as your email address. The app watches in the background and flips the card the moment Microsoft finishes.
Do I need Outlook installed?
No. Once the card says signed in, Booked Solid reads the mailbox straight from Microsoft's cloud. The Outlook desktop program does not need to be installed and does not need to be running. Your mail can keep landing in Apple Mail, on your phone, or wherever you actually read it, and this connection still works.
You should not need to open Microsoft 365 yourself either. Ask Otto what needs my attention? or draft a reply to the latest email and he reads the mailbox and prepares the draft without you opening a mail app at all.
The wording on the card, can save Outlook drafts, is only a description of where drafts go. It means any draft Otto prepares lands in that mailbox's own Drafts folder up in the cloud, which you can open from Outlook on the web, your phone, Apple Mail, or anywhere else that account is signed in. It does not mean the Outlook program is required.
What Azure app is this, and what is it allowed to do?
If you or your IT person want the security answer before you sign anything in, here it is straight.
- Booked Solid registers no Azure app of its own for this. It uses Microsoft's own public client,
14d82eec-204b-4c2f-b7e8-296a70dab67e- the same client Microsoft's Graph command-line tools and the Microsoft Graph PowerShell module use. - That client ID is a public identifier by design. Device-code apps are public clients, so there is no app secret anywhere in the picture.
- It authenticates against the
/commonendpoint, which is the multi-tenant authority, so work, school, and personal Microsoft accounts all sign in. - Publisher verification comes from Microsoft, because it is a Microsoft-published client. You are not consenting to a Kivi-registered app here.
- If you would rather pin it to your own Azure app registration, the app honours a
BOOKED_M365_CLIENT_IDenvironment variable, which overrides the default. Normal use does not need it.
What Otto can and cannot do in that mailbox
The sign-in asks Microsoft for a deliberately small set of permissions: read access to your profile, mail, calendars, Teams chats, and files. The only write permission is creating drafts. Permission to send mail is never requested, and no send tool exists on this connection at any setting - so a message cannot leave your mailbox on its own. Anything Otto writes waits for you as a draft.
With writing allowed, Otto can also file mail he has handled: archive a message, or move it into a folder you already have. Filing is reversible, nothing is ever deleted, and moves into Deleted Items or Junk are refused outright.
You can narrow or widen that reach on Settings > Permissions. One snag is worth knowing before it bites you: the permissions Microsoft grants are fixed at the moment you sign in, so if you allow drafts after a read-only sign-in, you have to sign out on the Microsoft 365 card and sign back in before drafts can appear. The full permission list and that fix are in Microsoft 365 by device code: what Otto can and cannot do in Outlook.
The wrong card: "Outlook app on this computer"
Lower down there is a separate connection called Outlook on this computer, which also appears as a method named Outlook app on this computer inside the Add an email account form. That card drives the Outlook desktop program you already have set up, and nothing else. It is available on Mac and Windows only. If you do run that classic Outlook program on this computer, it is the simple one: it asks for no sign-in and no key at all, so switching it on is the whole setup, and Otto then reads recent mail from the inbox already there and, with writing allowed, prepares drafts in Outlook's own Drafts folder.
If you read your mail in Apple Mail, in webmail, or anywhere other than the Outlook desktop program, ignore that card completely. Choosing Mail app on this computer is the same dead end from the other direction: it ends at Found a mail app for your address, but Booked Solid cannot read it yet. Choose IMAP and use a provider-issued app password for background inbox listening - which walks you straight back to the app password you were avoiding. Reading the Apple Mail app directly is not something Booked Solid can do yet. There is no workaround for that, and the Microsoft 365 cloud sign-in above is the real answer for a Microsoft mailbox.
Two more honest notes on that local card. New Outlook for Mac composes fine but hides its inbox from other apps, so the connection check will tell you plainly that the inbox is unreadable there and point you at Microsoft 365, which reads it reliably. And on a Mac, if the Outlook app connection is blocked outright, allow it under System Settings > Privacy & Security > Automation, then try again.
Can I sign into multiple Microsoft 365 accounts?
Is there a way to sign into multiple Microsoft 365 accounts? Not in this version, and you need to know that before you try, because the failure is silent. The Microsoft 365 (Outlook, Teams) card holds one Microsoft account at a time. Signing in a second Microsoft 365 account replaces the first rather than adding to it - the first mailbox simply stops being connected, with no warning that you traded one for the other. There is no supported way to sign into more than one account on that card, and no app-password-free way to run two Microsoft 365 mailboxes side by side today.
If you have read elsewhere in this help center that multiple inboxes are welcome, that is true, but it describes the IMAP path, not this one. Multi-inbox support shipped in version 1.11.0: under Connections > Mail & calendars you can add several Any email (IMAP) accounts at once, one per act, brand, or persona, each with its own address, its own app password, and its own purpose tag (bookings, personal, support, or business). Every enabled inbox rides along in the same session, and Otto places each draft in the right account's Drafts folder and names which inbox he is working in. The step-by-step is in Connect your Gmail with an app password (step by step) and Add any inbox by IMAP: app passwords and every "Check it" error explained.
We are not going to tell you to add a second Microsoft mailbox over IMAP as a workaround. Nobody here has tested that, and whether IMAP and app passwords are permitted on your tenant at all is a decision for your Microsoft administrator - ask them first if you want to explore it.
If you need two Microsoft accounts connected at the same time, write in and name the two mailboxes and what each one is for, for example one for bookings and one personal. That gets logged as a real feature request with your case attached, which is worth considerably more than a vote.
If it still does not work
- The sign-in code expired. It lasts about 15 minutes - start the sign-in again for a fresh one.
- You cannot switch Microsoft 365 on. Finish the sign-in on its card first and wait for the green Signed in as line, then press Turn on.
- The sign-in fails with a keyring or keychain error rather than a Microsoft error. That is a separate problem with where the token is stored - see Connecting Microsoft 365 or Google fails with a keyring error (Mac, Windows, and Linux).
- To disconnect, press Sign out on the Microsoft 365 card. That clears the stored token from your keychain.
Still stuck? Email bookedsolid@kivimedia.freshdesk.com and a person will help. If the sign-in is the problem, tell us exactly what the Microsoft 365 card shows right now - the code, a green signed-in line, or a red line of text - and what microsoft.com/devicelogin said after you typed the code. Those two answers usually pin it down in one reply.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article