> ## Documentation Index
> Fetch the complete documentation index at: https://docs.abbyy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Import documents from an email service

> Import email attachments (and optionally the email body) into Vantage from a Microsoft 365 mailbox through Microsoft Graph, a Microsoft account, or any other IMAP mailbox.

You can import email attachments from your mailbox into ABBYY Vantage, and optionally include the email body. The Input activity accesses a single email folder per skill.

<Info>
  After the skill is published, Vantage checks the specified email folder once per minute.
</Info>

Vantage processes each new email as follows:

* If the email contains attachments, a new transaction is created for all attachments in the email.
* If email-body import is enabled, the email body is converted to HTML and appended to the same transaction. Vantage also processes first-level embedded emails and their attachments.

Vantage imports at most 50 emails per check. If more than 50 are waiting, it imports the 50 oldest and picks up the rest on later checks.

<Tip>
  If throughput becomes a bottleneck, split the work across two skills, each with its own mail folder, so two agents pick up emails in parallel.
</Tip>

## Transaction registration parameters

Vantage saves the following data to the transaction registration parameters:

| Parameter name | Description |
| :- | :- |
| **EmailSubject** | The email subject. |
| **EmailDate** | Date and time when the email was sent, including time zone. Format: `MM/DD/YYYY HH:MM:SS +/-HH:MM`. |
| **EmailSender**\* | The sender's email address. |
| **EmailAddressee**\* | The addressees' email addresses, separated by commas with no spaces. |
| **EmailCopyAddressee**\* | The copy addressees' email addresses, separated by commas with no spaces. |

*\* Vantage stores only the email addresses, not the sender's or addressees' names.*

<Note>
  Vantage doesn't create parameters with empty values. For example, if an email has no subject, the transaction won't have an `EmailSubject` registration parameter.
</Note>

Vantage saves the source type (`MailImport`) and the source file name to the **SourceType** and **SourceFileName** document registration parameters.

To see document and transaction registration parameters, add the matching columns in the **Transactions** section of **Skill Monitor**.

Vantage also exports them to the output JSON file, which you configure in the **Exported Data** section of the Output activity. Transaction registration parameters are available through the Vantage API as well.

File names can't contain the following characters, and Vantage replaces each one with an underscore when you upload the file: `/ : ? # [ ] @ ! $ & ' ( ) * + , ; = \`. Vantage saves the original file names to the document registration parameters. Retrieve them using a [Custom activity sample script](/vantage/documentation/skill-designer/process/custom-activity/sample-scripts).

## Import results

If an attachment's format is unsupported, the transaction fails and processing stops for all other documents in it. See the specific error in the **Error log** section of Skill Monitor.

If an email has no attachments and body import is turned off, Vantage creates no transaction but still marks the email as processed.

Vantage either permanently deletes processed emails or moves them to a folder you specify when you set up the mailbox connection. Emails that can't be imported go to the exceptions folder you specify.

<Note>
  If an email imports successfully but the transaction fails, the email is placed in the `Processed` folder.
</Note>

If Vantage can't access the import folder, it records an error in the **Error log** section of Skill Monitor.

## Grant ABBYY Vantage access to Microsoft Graph

Before anyone in your organization can use **Sign in with Microsoft Graph**, a Microsoft 365 administrator runs a PowerShell script once. The script adds the ABBYY Vantage enterprise application to your Microsoft Entra tenant if it isn't there yet. It then grants ABBYY Vantage the permissions it needs, on behalf of all users in the tenant.

If you use only **Sign in with Microsoft** or **Sign in with other email account**, you don't need to run the script.

To run the script, you need an account with at least the Cloud Application Administrator role in Microsoft Entra ID. For more information, see [Grant or revoke API permissions programmatically](https://learn.microsoft.com/en-us/graph/permissions-grant-via-msgraph).

<Steps>
  <Step title="Install the Microsoft Graph PowerShell SDK">
    If the SDK isn't installed on your computer, install it. For more information, see [Install the Microsoft Graph PowerShell SDK](https://learn.microsoft.com/en-us/powershell/microsoftgraph/installation).
  </Step>

  <Step title="Find your tenant ID">
    Copy the ID of your Microsoft Entra tenant. For more information, see [How to find your tenant ID](https://learn.microsoft.com/en-us/entra/fundamentals/how-to-find-tenant).
  </Step>

  <Step title="Run the script">
    In PowerShell, run the following script. Replace `<your-tenant-id>` with your tenant ID. When prompted, sign in with your administrator account and accept the permissions that Microsoft Graph PowerShell requests.

    ```powershell theme={null}
    Connect-MgGraph -TenantId "<your-tenant-id>" `
      -Scopes "Application.ReadWrite.All","DelegatedPermissionGrant.ReadWrite.All"

    $appId = "084b980d-4a5f-4014-8309-6f8fe7187193"

    # 1. Create the service principal (Enterprise Application) if it's missing
    $sp = Get-MgServicePrincipal -Filter "appId eq '$appId'"
    if (-not $sp) {
        $sp = New-MgServicePrincipal -AppId $appId
    }

    # 2. Microsoft Graph's service principal in this tenant (always exists)
    $graph = Get-MgServicePrincipal -Filter "appId eq '00000003-0000-0000-c000-000000000000'"

    # 3. Scopes to grant, space-separated
    $scopes = "openid profile email offline_access User.Read Mail.ReadWrite Mail.ReadWrite.Shared IMAP.AccessAsUser.All"

    # 4. Create the grant, or update it if one already exists
    $grant = Get-MgOauth2PermissionGrant -Filter "clientId eq '$($sp.Id)' and resourceId eq '$($graph.Id)' and consentType eq 'AllPrincipals'"

    if ($grant) {
        Update-MgOauth2PermissionGrant -OAuth2PermissionGrantId $grant.Id -Scope $scopes
    } else {
        New-MgOauth2PermissionGrant -BodyParameter @{
            clientId    = $sp.Id
            consentType = "AllPrincipals"
            resourceId  = $graph.Id
            scope       = $scopes
        }
    }
    ```

    The script grants ABBYY Vantage the following delegated permissions: `openid`, `profile`, `email`, `offline_access`, `User.Read`, `Mail.ReadWrite`, `Mail.ReadWrite.Shared`, and `IMAP.AccessAsUser.All`.

    If ABBYY Vantage already has a grant in your tenant, the script updates it. You can safely run the script again.
  </Step>
</Steps>

After the script finishes, users in your organization can connect their mailboxes with **Sign in with Microsoft Graph**.

## Set up email import

<Steps>
  <Step title="Open the Input activity">
    Click the **Input** activity block in your document processing flow. If the flow has no Input activity yet, add one from the **Activities** pane.
  </Step>

  <Step title="Select Email as an additional source">
    In the **Actions** pane, check **Select additional source** and choose **Email**.

    <Frame caption="Selecting Email as an additional Input source">
      <img src="https://mintcdn.com/abbyy/vsKEkGDuRLNqo_T3/images/vantage/skill-designer/screen_process_input_email_settings.png?fit=max&auto=format&n=vsKEkGDuRLNqo_T3&q=85&s=1c5b86a8d79c5d0b5d466c576fb748c1" alt="Input activity Actions pane with the Email option selected" style={{ width: "38%" }} width="339" height="508" data-path="images/vantage/skill-designer/screen_process_input_email_settings.png" />
    </Frame>
  </Step>

  <Step title="Open settings and choose account type">
    Click **Settings**. The **Input Settings: Email** dialog box opens. Select an account type and click **Continue**.

    The account types are **Sign in with Microsoft**, **Sign in with Microsoft Graph**, and **Sign in with other email account**. **Sign in with Microsoft Graph** appears only when Microsoft Graph is enabled for your environment.
  </Step>

  <Step title="Sign in to the account">
    Sign in using one of the following methods. See [Connect to a Microsoft account](#connect-to-a-microsoft-account), [Connect with Microsoft Graph](#connect-with-microsoft-graph), or [Connect to other email accounts](#connect-to-other-email-accounts).
  </Step>

  <Step title="Specify import and exceptions folders">
    After you sign in, the dialog box shows **Select required folders**. In **Import folder**, select the folder Vantage imports emails from. In **Exception folder for emails that could not be imported**, select the folder for emails that Vantage can't import.

    After you publish the skill, Vantage creates a `VantageProcessing` folder inside the import folder you specified. Emails move to this service folder first, and Vantage then processes them according to your settings.

    <Warning>
      Don't select the same import folder used by another Process skill in your tenant. If multiple skills share an import folder, you can't control which skill processes a given email.
    </Warning>
  </Step>

  <Step title="Choose the action for processed emails">
    In **What to do with successfully imported emails**, select **Delete** to permanently delete processed emails. **Delete** is the default and needs no folder.

    To keep processed emails, select **Move to a folder**. A required field, **Folder for successfully imported emails**, appears. Select the folder to move them to.

    <Frame caption="Folder and post-processing settings in the Input Settings: Email dialog box">
      <img src="https://mintcdn.com/abbyy/BOi6cuhJtmULxuoH/images/vantage/skill-designer/screen_process_input_email_actionforimported.png?fit=max&auto=format&n=BOi6cuhJtmULxuoH&q=85&s=7f4f221bc68aff21f71cb99e6cc4d982" alt="Folders section of the Input Settings: Email dialog box, with Move to a folder selected for successfully imported emails and the Folder for successfully imported emails field shown" style={{ width: "80%" }} width="1198" height="402" data-path="images/vantage/skill-designer/screen_process_input_email_actionforimported.png" />
    </Frame>
  </Step>

  <Step title="(Optional) Enable email body import">
    **Import mail body** is off by default. Turn it on to import the email body. Vantage converts the body to HTML and adds it to the same transaction as the attachments.
  </Step>

  <Step title="Save">
    Click **Save**. Vantage stores the settings and closes the dialog box.
  </Step>
</Steps>

The email address connected to the activity appears in the **Actions** pane when you select the Input block. Click **Settings** under the email address to view or change the current mail import settings. To disconnect the email account, click **Sign out** in the **Input Settings: Email** dialog box. Changes to settings take effect only after the skill is published.

<Warning>
  Signing out of the email account resets all settings.
</Warning>

### Connect to a Microsoft account

In the Microsoft sign-in dialog box, select your current account if you are already signed in, or use a different one. After authentication succeeds, the sign-in dialog box closes.

The first time you sign in with a Microsoft account, Vantage asks for permission to:

* Sign in to the app using a work or school account.
* Access the primary email address and basic user profile data.
* Access and update user details, even when the user isn't using the app.
* Access, update, create, and delete (but not send) emails in the user's mailboxes.

<Note>
  If you use an Exchange hybrid configuration, move the mailbox from on-premises to Exchange Online. See [Microsoft's mailbox migration guide](https://learn.microsoft.com/en-us/exchange/hybrid-deployment/move-mailboxes).
</Note>

### Connect with Microsoft Graph

**Sign in with Microsoft Graph** connects to a Microsoft 365 mailbox through the Microsoft Graph API instead of IMAP. It is the recommended option for a Microsoft 365 mailbox. There is no mail server address or port to enter.

Before anyone in your organization can use this option, your Microsoft 365 administrator must run a one-time setup script. For more information, see [Grant ABBYY Vantage access to Microsoft Graph](#grant-abbyy-vantage-access-to-microsoft-graph).

Sign in to the Microsoft account that owns the mailbox. After authentication succeeds, the sign-in dialog box closes and you continue to folder selection.

Microsoft Graph imports the same attachment formats as the other account types, and processes them the same way.

If sign-in succeeds but Vantage cannot reach the mailbox, the dialog box reports an HTTP 403. The account signed in, but it does not hold the mailbox permission Vantage needs.

If the option is missing from the **Input Settings: Email** dialog box, Microsoft Graph is not enabled for your environment. Contact your ABBYY account team.

### Connect to other email accounts

Specify your email address and password, the IMAP server address, and the IMAP port. The default port is 993 and rarely needs changing. Click **Sign in**.

If Vantage can't connect to the server, the account sign-in dialog box stays open and an error icon appears next to the input fields.

<Frame caption="Email-connection error indicators in the Input Settings: Email dialog box">
  <img src="https://mintcdn.com/abbyy/vsKEkGDuRLNqo_T3/images/vantage/skill-designer/screen_process_input_email_error.png?fit=max&auto=format&n=vsKEkGDuRLNqo_T3&q=85&s=9c10e9abf0723d089eae5e74d7898a44" alt="Input Settings: Email dialog box showing connection error icons" style={{ width: "56%" }} width="745" height="474" data-path="images/vantage/skill-designer/screen_process_input_email_error.png" />
</Frame>

If all the details are correct, one of the following usually causes the connection error.

| Cause | What to do |
| :- | :- |
| The email server blocked a suspicious sign-in attempt. | Check your email. If you received a notice about a blocked sign-in attempt, confirm that the attempt was yours. |
| The account is a Google account without two-factor authentication, and access for less secure apps is restricted. | Allow access for less secure applications, and confirm the Vantage access attempt if prompted. |
| The server requires an application-specific password. | Some services, such as Yahoo and Google with two-factor authentication, require app-specific passwords for third-party applications. Generate one by following the service's instructions, and use it in the Input activity settings. |

After authentication succeeds, the connected email address appears in the **Input Settings: Email** dialog box.

## Disable imports

Administrators can disable document import from [Skill Monitor](/vantage/documentation/runtime/skill-monitor/skill-monitor). Disabling email import does not affect document import via the API.

## Cleanup on skill deletion

When you delete a skill, Vantage stops checking its email folder.

## Related topics

* [Input activity](/vantage/documentation/skill-designer/process/input-activity/input-activity)
* [Import documents from a shared folder](/vantage/documentation/skill-designer/process/input-activity/import-shared-folder)
* [Skill Monitor](/vantage/documentation/runtime/skill-monitor/skill-monitor)
* [Supported File Formats](/vantage/documentation/tenant-admin/technical-specs/formats)
