# 1. Settings

# E-mail settings

**To send emails** from Cloudex TMS:  
1\) Click on the Your User Name icon   
2\) Select the "My Profile" menu

[![image-1742462603046.png](https://ozols.lv/doc/uploads/images/gallery/2025-03/scaled-1680-/image-1742462603046.png)](https://ozols.lv/doc/uploads/images/gallery/2025-03/image-1742462603046.png)

**In the "Email password" field:**  
1\) Enter your email password  
2\) Click the "Save" button<svg class="svg-icon" data-icon="link" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg>

[![image-1742462758441.png](https://ozols.lv/doc/uploads/images/gallery/2025-03/scaled-1680-/image-1742462758441.png)](https://ozols.lv/doc/uploads/images/gallery/2025-03/image-1742462758441.png)

# Create google email password

1\) Open google account and login:  
[https://myaccount.google.com/](https://myaccount.google.com/)

<div id="bkmrk-2%29-open-dro%C5%A1%C4%ABba%2Fsecu">2) Open **Drošība/Security**<svg class="svg-icon" data-icon="link" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg></div>[![image-1761208935394.png](https://ozols.lv/doc/uploads/images/gallery/2025-10/scaled-1680-/image-1761208935394.png)](https://ozols.lv/doc/uploads/images/gallery/2025-10/image-1761208935394.png)

<p class="callout warning">If 2-step verification is not available in the section, your company's email administrator must first enable it: [instrukction how to do it read here](https://ozols.lv/doc/link/382#bkmrk-uz%C5%86%C4%93mumiem-ir-j%C4%81b%C5%ABt-)</p>

**3) Ieslēgt "2-pakāpju verifikāciju / 2-Step verification"**

[![image-1742982231557.png](https://ozols.lv/doc/uploads/images/gallery/2025-03/scaled-1680-/image-1742982231557.png)](https://ozols.lv/doc/uploads/images/gallery/2025-03/image-1742982231557.png)

**4) Create a password/key for emails**

<p class="callout warning">If there is no "App passwords" section in the Two-step verification / 2-step verification section, you must exit the page and re-enter it. Or use the link **[https://myaccount.google.com/apppasswords](https://myaccount.google.com/apppasswords)**</p>

[![image-1761209173707.png](https://ozols.lv/doc/uploads/images/gallery/2025-10/scaled-1680-/image-1761209173707.png)](https://ozols.lv/doc/uploads/images/gallery/2025-10/image-1761209173707.png)

**5) Create password**

[![image-1761209442553.png](https://ozols.lv/doc/uploads/images/gallery/2025-10/scaled-1680-/image-1761209442553.png)](https://ozols.lv/doc/uploads/images/gallery/2025-10/image-1761209442553.png)

6\) Copy new password and enter it in OZOLS or CLOUDEX TMS

Instructions for entering your email password in Ozols: [https://ozols.lv/doc/books/ozols-tms-english/page/5-e-mail-settings](https://ozols.lv/doc/books/ozols-tms-english/page/5-e-mail-settings)

Instructions for entering your email password in CLOUDEX TMS: [https://ozols.lv/doc/books/cloudex-tms-english/page/e-mail-settings](https://ozols.lv/doc/books/cloudex-tms-english/page/e-mail-settings)

[![image-1761209548234.png](https://ozols.lv/doc/uploads/images/gallery/2025-10/scaled-1680-/image-1761209548234.png)](https://ozols.lv/doc/uploads/images/gallery/2025-10/image-1761209548234.png)

#### Companies must have the option enabled that is available

[Instrukction from google](https://support.google.com/a/answer/9176657?product_name=UnuFlow&visit_id=01742980293793-8471960249317013911&rd=1&src=supportwidget0)

[![image-1742980788837.png](https://ozols.lv/doc/uploads/images/gallery/2025-03/scaled-1680-/image-1742980788837.png)](https://ozols.lv/doc/uploads/images/gallery/2025-03/image-1742980788837.png)

# Office365: HOW TO GET TenantId, ClientId and ClientSecret

If you use Microsoft office 365 for email sending. Your company Microsoft admin need to get following settings from **Azure AD Application**

- **Directory (Tenant) ID**
- **Application (Client) ID**
- **Client Secret Value**

These three values are required for integrating CLOUDEX TMS with Microsoft Graph using OAuth2.

---

#### **1️⃣ Sign in to Azure Portal**

Open: [https://portal.azure.com<svg class="block h-[0.75em] w-[0.75em] stroke-current stroke-[0.75]" data-rtl-flip="" fill="currentColor" height="20" viewbox="0 0 20 20" width="20" xmlns="http://www.w3.org/2000/svg"></svg>](https://portal.azure.com)Sign in with a Microsoft 365 **Global Admin** or **Application Administrator** account.

---

#### **2️⃣ Open “Microsoft Entra ID” (Azure AD)**

Left menu → **Microsoft Entra ID**  
(or search “Entra ID” in the top search bar)

[![image-1764595464188.png](https://ozols.lv/doc/uploads/images/gallery/2025-12/scaled-1680-/image-1764595464188.png)](https://ozols.lv/doc/uploads/images/gallery/2025-12/image-1764595464188.png)

<div id="bkmrk--2"><div></div></div>---

#### **3️⃣ Create a new App Registration**

1. Left menu: **App registrations**
2. Click **New registration**

[![image-1764595545977.png](https://ozols.lv/doc/uploads/images/gallery/2025-12/scaled-1680-/image-1764595545977.png)](https://ozols.lv/doc/uploads/images/gallery/2025-12/image-1764595545977.png)

[![image-1764595721522.png](https://ozols.lv/doc/uploads/images/gallery/2025-12/scaled-1680-/image-1764595721522.png)](https://ozols.lv/doc/uploads/images/gallery/2025-12/image-1764595721522.png)

<div id="bkmrk-url-type-must-be-%22we"><div>URL type must be "<span style="color: #ff0000;">Web" NOT "Single page application"</span></div><div><span style="color: #ff0000;">Looks like beter to register as Single tenant. If you register as multi tenant then can be so than you need to enter CLOUDEX <span data-olk-copy-source="MessageBody">MpnId 7086574</span> </span></div><div></div><div>**Fill the form:**</div></div><div id="bkmrk-field-value-name-clo"><div><table class="w-fit min-w-(--thread-content-width)" data-end="1440" data-start="1145"><thead data-end="1162" data-start="1145"><tr data-end="1162" data-start="1145"><th data-col-size="sm" data-end="1153" data-start="1145" style="width: 86.8594px;">Field</th><th data-col-size="md" data-end="1162" data-start="1153" style="width: 811.531px;">Value</th></tr></thead><tbody data-end="1440" data-start="1181"><tr data-end="1239" data-start="1181"><td data-col-size="sm" data-end="1192" data-start="1181" style="width: 86.8594px;">**Name**</td><td data-col-size="md" data-end="1239" data-start="1192" style="width: 811.531px;">CLOUDEX TMS Email Integration (or any name)</td></tr><tr data-end="1335" data-start="1240"><td data-col-size="sm" data-end="1270" data-start="1240" style="width: 86.8594px;">**Supported account types**</td><td data-col-size="md" data-end="1335" data-start="1270" style="width: 811.531px;">✔️ **Accounts in any organizational directory (multitenant)**</td></tr><tr data-end="1440" data-start="1336"><td data-col-size="sm" data-end="1355" data-start="1336" style="width: 86.8594px;">**Redirect URI**</td><td data-col-size="md" data-end="1440" data-start="1355" style="width: 811.531px;">Select **Web** → Enter your redirect:   
`https://my.cloudex.app/<strong>YourCompanyCode</strong>/Services/Office365Callback.aspx`

<span style="background-color: #ffff99;">1) Replace `<strong>YourCompanyCode</strong>` with your web app CompanyCode</span>

<span style="background-color: #ffff99;">2) Redirect URL is case-sensitive</span>``

</td></tr></tbody></table>

</div></div>Click **Register**.

---

#### **4️⃣ Get the Tenant ID and Client ID**

After creation, you will be redirected to the app’s **Overview** page.  
Here you will see:  
**✔ Directory (Tenant) ID**  
**✔ Application (Client) ID**

[![image-1764596895074.png](https://ozols.lv/doc/uploads/images/gallery/2025-12/scaled-1680-/image-1764596895074.png)](https://ozols.lv/doc/uploads/images/gallery/2025-12/image-1764596895074.png)

<div id="bkmrk-copy-them-and-save."><div>Copy them and save.</div></div>You already have **2/3 values**.

---

#### **5️⃣ Create Client Secret**

Side menu → **Certificates &amp; secrets**

1. Click **New client secret**
2. Enter a name: `CLOUDEX Secret`
3. Choose expiration:
    
    
    - 6 months (not recommended)
    - 12 months
    - **24 months** (recommended)
    - Or “Custom”
4. Click **Add**

[![image-1764596973920.png](https://ozols.lv/doc/uploads/images/gallery/2025-12/scaled-1680-/image-1764596973920.png)](https://ozols.lv/doc/uploads/images/gallery/2025-12/image-1764596973920.png)

[![image-1765269172104.png](https://ozols.lv/doc/uploads/images/gallery/2025-12/scaled-1680-/image-1765269172104.png)](https://ozols.lv/doc/uploads/images/gallery/2025-12/image-1765269172104.png)

<div id="bkmrk-important-%E2%9A%A0%EF%B8%8F"><div><span style="color: #222222; font-size: 1.666em; font-weight: 400;">IMPORTANT ⚠️</span></div></div>**Copy the Client Secret VALUE immediately.**  
You will never be able to see it again later.

Store it securely (Azure Key Vault, password manager, etc).

Now you have:

- **ClientId**
- **TenantId**
- **ClientSecret Value**

---

#### **6️⃣ Add Required API Permissions**

Side menu → **API permissions**

Click:

- **Add a permission**
- **Microsoft Graph**
- **Delegated permissions**

Search + select:

✔ `Mail.Send`  
✔ `Mail.ReadWrite<br data-end="2524" data-start="2521"></br>✔ User.Read`  
✔ `offline_access`

Then click **Add permissions**.

Then click **Grant admin consent**.

[![image-1779801024445.png](https://ozols.lv/doc/uploads/images/gallery/2026-05/scaled-1680-/image-1779801024445.png)](https://ozols.lv/doc/uploads/images/gallery/2026-05/image-1779801024445.png)

Can be in new interface need to choose Microsoft Graph API

[![image-1768998214141.png](https://ozols.lv/doc/uploads/images/gallery/2026-01/scaled-1680-/image-1768998214141.png)](https://ozols.lv/doc/uploads/images/gallery/2026-01/image-1768998214141.png)

---

#### **7️⃣ Final Check: Authentication Settings**

Side menu → **Authentication**

Ensure:

✔ Your redirect URI is correct  
✔ “Allow public client flows” is **OFF**  
✔ “Access tokens” and “ID tokens” are **ON**

[![image-1764598136406.png](https://ozols.lv/doc/uploads/images/gallery/2025-12/scaled-1680-/image-1764598136406.png)](https://ozols.lv/doc/uploads/images/gallery/2025-12/image-1764598136406.png)

<div id="bkmrk--16"><div></div></div>#### 🎉 DONE — Values ready to use

You now have everything:

<div id="bkmrk-parameter-where-to-f"><div><table class="w-fit min-w-(--thread-content-width)" data-end="3236" data-start="2994"><thead data-end="3026" data-start="2994"><tr data-end="3026" data-start="2994"><th data-col-size="sm" data-end="3006" data-start="2994">Parameter</th><th data-col-size="sm" data-end="3026" data-start="3006">Where to find it</th></tr></thead><tbody data-end="3236" data-start="3059"><tr data-end="3116" data-start="3059"><td data-col-size="sm" data-end="3074" data-start="3059">**TenantId**</td><td data-col-size="sm" data-end="3116" data-start="3074">App → Overview → Directory (tenant) ID</td></tr><tr data-end="3176" data-start="3117"><td data-col-size="sm" data-end="3132" data-start="3117">**ClientId**</td><td data-col-size="sm" data-end="3176" data-start="3132">App → Overview → Application (client) ID</td></tr><tr data-end="3236" data-start="3177"><td data-col-size="sm" data-end="3196" data-start="3177">**ClientSecret**</td><td data-col-size="sm" data-end="3236" data-start="3196">App → Certificates &amp; Secrets → **Value**</td></tr></tbody></table>

</div></div>#### Problem solution

In case you have any problems sending out emails from CLOUDEX TMS or Ozols you can run **"Diagnose and solve problems"** tool

[![image-1768999877635.png](https://ozols.lv/doc/uploads/images/gallery/2026-01/scaled-1680-/image-1768999877635.png)](https://ozols.lv/doc/uploads/images/gallery/2026-01/image-1768999877635.png)

# Microsoft email configuration

#### 1. Enable “Authenticated SMTP” for the mailbox

Open the Microsoft 365 Admin Center: [ https://admin.microsoft.com](https://admin.microsoft.com)

### Steps to enable Authenticated SMTP

[![image-1764062017876.png](https://ozols.lv/doc/uploads/images/gallery/2025-11/scaled-1680-/image-1764062017876.png)](https://ozols.lv/doc/uploads/images/gallery/2025-11/image-1764062017876.png)

1. In the left menu, click **Users → Active users**.
2. Click on the user/mailbox you will use for CLOUDEX TMS.
3. In the user details pane, go to the **Mail** tab.
4. Click **Manage email apps** (or *Email apps*).
5. In the list of email apps, find **Authenticated SMTP** and make sure the checkbox or toggle is **ON / enabled**.
6. Click **Save**.

<div id="bkmrk-%E2%9A%A0%EF%B8%8F"><div>⚠️</div></div>#### 2. Create an app password (if MFA is enabled)

If Multi-Factor Authentication (MFA) is enabled for the mailbox you use (recommended), SMTP cannot use your normal password. In that case you must create a special **app password** and use it in CLOUDEX TMS.

<div id="bkmrk-%F0%9F%94%90-if-mfa-is-not-enab"><div>🔐</div><div>If MFA is **not** enabled for this user, you can use the normal account password instead of an app password. However, using MFA + app password is more secure and recommended.</div></div>### Instruction to generate an app password

[https://ozols.lv/doc/books/ozols-tms-english/page/8-e-mail-server-configuration-for-work-with-ozols-tms](https://ozols.lv/doc/books/ozols-tms-english/page/8-e-mail-server-configuration-for-work-with-ozols-tms)

#### ❗ What to do if “Authenticated SMTP” switch does NOT appear

1. Turn off Checkbox "Turn off SMTP AUTH protocol for your organization""
2. Turn on use of old legacy TLS clients.
3. After enabling, wait **3–5 minutes**, then check the user mailbox again.

[![image-1764064038680.png](https://ozols.lv/doc/uploads/images/gallery/2025-11/scaled-1680-/image-1764064038680.png)](https://ozols.lv/doc/uploads/images/gallery/2025-11/image-1764064038680.png)

#### **Confirm the mailbox type (SMTP is NOT available for some accounts)**

The **Authenticated SMTP** switch is available ONLY for:

- User mailboxes with Exchange Online Plan 1 or 2
- Shared mailboxes
- Microsoft 365 E3/E5 Business Standard/Business Premium accounts

It will **NOT appear** for:

❌ Mailboxes with no Exchange license  
❌ Accounts converted to *Microsoft 365 Groups*  
❌ Mailboxes that were soft-deleted or recently restored  
❌ Resource mailboxes (Room / Equipment)

### How to check:

In Microsoft 365 Admin Center:

**Users → Active users → Select user → Licenses and Apps**

Make sure:  
✔ **Exchange Online** is enabled

If Exchange Online is missing → SMTP will NOT be available.

---

#### **Ensure modern authentication SMTP is not forced**

Microsoft sometimes blocks SMTP for users with strict conditional access.

### Check these items:

- Conditional Access policy requiring MFA for all protocols
- Legacy auth blocked at the tenant level
- Security defaults enabled (this disables SMTP)

### To check Security Defaults:

1. Go to Azure Portal  
    [https://portal.azure.com<svg class="block h-[0.75em] w-[0.75em] stroke-current stroke-[0.75]" data-rtl-flip="" fill="currentColor" height="20" viewbox="0 0 20 20" width="20" xmlns="http://www.w3.org/2000/svg"></svg>](https://portal.azure.com)
2. Search for **Azure Active Directory**
3. Open **Properties**
4. Click **Manage Security Defaults**
5. If **Security defaults = Enabled**, you must turn it **OFF** to allow SMTP.

> After disabling, wait up to 15 minutes, then check Manage Email Apps again.

---

#### **If none of the above works – your tenant may have SMTP permanently disabled**

Microsoft has been turning off SMTP AUTH for security reasons.  
Admins must manually re-enable it per mailbox.

### To force-enable for a specific mailbox (Admin only):

1. Go to:  
    [https://admin.exchange.microsoft.com<svg class="block h-[0.75em] w-[0.75em] stroke-current stroke-[0.75]" data-rtl-flip="" fill="currentColor" height="20" viewbox="0 0 20 20" width="20" xmlns="http://www.w3.org/2000/svg"></svg>](https://admin.exchange.microsoft.com)
2. Navigate to:  
    **Users → Active Users → select user → Mail → Email apps → Manage**
3. If still missing, enable via PowerShell:

<div id="bkmrk-set-casmailbox--iden"><div><div><div></div></div></div><div>`<span class="hljs-built_in">Set-CASMailbox</span> <span class="hljs-literal">-Identity</span> user@domain.com <span class="hljs-literal">-SmtpClientAuthenticationEnabled</span> <span class="hljs-variable">$true</span>`</div></div>*(Admins only — if customer cannot run PowerShell, you can give them this line to pass to their IT provider.)*

---

#### **Summary: Why SMTP may not appear**

<div id="bkmrk-reason-solution-tena"><div><table class="w-fit min-w-(--thread-content-width)" data-end="4368" data-start="3883"><thead data-end="3904" data-start="3883"><tr data-end="3904" data-start="3883"><th data-col-size="md" data-end="3892" data-start="3883">Reason</th><th data-col-size="md" data-end="3904" data-start="3892">Solution</th></tr></thead><tbody data-end="4368" data-start="3927"><tr data-end="4016" data-start="3927"><td data-col-size="md" data-end="3955" data-start="3927">Tenant-wide SMTP disabled</td><td data-col-size="md" data-end="4016" data-start="3955">Enable under Exchange Admin Center → Settings → Mail flow</td></tr><tr data-end="4086" data-start="4017"><td data-col-size="md" data-end="4043" data-start="4017">New UI hides the option</td><td data-col-size="md" data-end="4086" data-start="4043">Use Classic Exchange Admin Center (ECP)</td></tr><tr data-end="4133" data-start="4087"><td data-col-size="md" data-end="4116" data-start="4087">No Exchange Online license</td><td data-col-size="md" data-end="4133" data-start="4116">Add a license</td></tr><tr data-end="4191" data-start="4134"><td data-col-size="md" data-end="4162" data-start="4134">Security Defaults enabled</td><td data-col-size="md" data-end="4191" data-start="4162">Disable Security Defaults</td></tr><tr data-end="4255" data-start="4192"><td data-col-size="md" data-end="4236" data-start="4192">Legacy auth blocked by Conditional Access</td><td data-col-size="md" data-end="4255" data-start="4236">Update policies</td></tr><tr data-end="4324" data-start="4256"><td data-col-size="md" data-end="4283" data-start="4256">Mailbox type unsupported</td><td data-col-size="md" data-end="4324" data-start="4283">Use a licensed user or shared mailbox</td></tr><tr data-end="4368" data-start="4325"><td data-col-size="md" data-end="4344" data-start="4325">Needs PowerShell</td><td data-col-size="md" data-end="4368" data-start="4344">Run `Set-CASMailbox`</td></tr></tbody></table>

</div></div>

# Order conditions update

In order to edit Order for carrier rules or Order for Client rules Click on Your name &gt; Settings &gt; Classifications &gt; Agreement rules &gt; Edit

[![image-1765206565501.png](https://ozols.lv/doc/uploads/images/gallery/2025-12/scaled-1680-/image-1765206565501.png)](https://ozols.lv/doc/uploads/images/gallery/2025-12/image-1765206565501.png)

# Set up Office365 e-mail

If your email provider is Microsoft Office365 You need o set up email sending following this instruction

1\) Click on your name  
2\) Choose My user profile

[![image-1765283087826.png](https://ozols.lv/doc/uploads/images/gallery/2025-12/scaled-1680-/image-1765283087826.png)](https://ozols.lv/doc/uploads/images/gallery/2025-12/image-1765283087826.png)

Press comand button \[Office365 setup\]

[![image-1765283215435.png](https://ozols.lv/doc/uploads/images/gallery/2025-12/scaled-1680-/image-1765283215435.png)](https://ozols.lv/doc/uploads/images/gallery/2025-12/image-1765283215435.png)

Then press command button \[Connect to Microsoft\]

[![image-1765283367634.png](https://ozols.lv/doc/uploads/images/gallery/2025-12/scaled-1680-/image-1765283367634.png)](https://ozols.lv/doc/uploads/images/gallery/2025-12/image-1765283367634.png)

Login with your email and follow further instructions

# HOW TO CHANGE APPLICATION Callback URL in Azure Portal

#### **1️⃣ Open Azure Portal**

Go to: [https://portal.azure.co](https://portal.azure.com)m  
  
Sign in using a **Global Administrator** or **Application Administrator** account.

---

#### **2️⃣ Open *Microsoft Entra ID***

1\) In the left menu, click: **Microsoft Entra ID or Search for App registrations** 2) Open All Applications  
3\) Open CLOUDEX TMS application

[![image-1765285865602.png](https://ozols.lv/doc/uploads/images/gallery/2025-12/scaled-1680-/image-1765285865602.png)](https://ozols.lv/doc/uploads/images/gallery/2025-12/image-1765285865602.png)

Choose Redirect URLs

[![image-1765286018399.png](https://ozols.lv/doc/uploads/images/gallery/2025-12/scaled-1680-/image-1765286018399.png)](https://ozols.lv/doc/uploads/images/gallery/2025-12/image-1765286018399.png)

Press edit button and set correct URL

!!!! In <span style="color: #ff0000;">YourCompanyCode</span> you should place your company code https://my.cloudex.app/<span style="color: #ff0000;">YourCompanyCode</span>/Services/Office365Callback.aspx

[![image-1765286250615.png](https://ozols.lv/doc/uploads/images/gallery/2025-12/scaled-1680-/image-1765286250615.png)](https://ozols.lv/doc/uploads/images/gallery/2025-12/image-1765286250615.png)

<span style="color: #ff0000;">Redirect URL should be under Web NOT under SIngle-application</span>