Skip to Main Content
Digital Business Automation Ideas


This is an IBM Automation portal for Digital Business Automation products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Please use the following category to raise ideas for these offerings for all environments (traditional on premises, containers, on cloud):
  • Cloud Pak for Business Automation - including Business Automation Studio and App Designer, Business Automation Insights

  • Business Automation Workflow (BAW) - including BAW, Business Process Manager, Workstream Services, Business Performance Center, Advanced Case Management

  • Content Services - FileNet Content Manager

  • Content Services - Content Manager OnDemand

  • Content Services - Daeja Virtual Viewer

  • Content Services - Navigator

  • Content Services - Content Collector for Email, Sharepoint, Files

  • Content Services - Content Collector for SAP

  • Content Services - Enterprise Records

  • Content Services - Content Manager (CM8)

  • Datacap

  • Automation Document Processing

  • Automation Decision Services (ADS)

  • Operational Decision Manager

  • Robotic Process Automation

  • Robotic Process Automation with Automation Anywhere

  • Blueworks Live

  • Business Automation Manager Open Edition

  • IBM Process Mining


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


Status Under review
Workspace Datacap
Created by Guest
Created on Jun 11, 2026

Enhancement Request: Datacap Support Microsoft Graph App-Only Authentication for Office 365 Email Ingestion Using Client Secret or Certificate-Based Credentials

Customer security teams are increasingly restricting or prohibiting username and password-based authentication for application integrations. Many organizations now require vendors to support modern Microsoft Entra ID authentication patterns, including app-only authentication using confidential client credentials.

Currently, the IBM Datacap Office 365 / Microsoft Graph login action requires direct login using a Microsoft account username and password. This does not meet our customer’s security requirements, as their security policy explicitly prohibits the use of username and password credentials for application integrations.

In addition, Microsoft is deprecating Exchange Web Services (EWS) for Exchange Online, making continued reliance on EWS-based mail ingestion unsustainable. Customers need a supported Datacap path for Microsoft Graph-based Office 365 email ingestion that does not require mailbox username/password authentication.

While IBM IDEA DCAP-I-383 appears related, it does not address our requirement because our customer does not use ex_SetProxy or ex_SetProxy_FullURL. The requested enhancement is specifically for Microsoft Graph authentication using Microsoft Entra ID app-only credentials.

Proposed Enhancement
Add support in IBM Datacap for Microsoft Graph app-only authentication to Office 365 mailboxes using Microsoft Entra ID confidential client credentials. We plan to move Datacap onto the customer's Cloud platform.

The enhancement should support the following authentication options:

  1. Client Secret Authentication

    • Tenant ID

    • Application/Client ID

    • Client Secret

    • Mailbox/User Principal Name to monitor

    • Mail folder or folder path to process

  2. Certificate-Based Authentication

    • Tenant ID

    • Application/Client ID

    • Certificate thumbprint

    • Secure reference to the private key, certificate store, keystore, or protected certificate file

    • Mailbox/User Principal Name to monitor

    • Mail folder or folder path to process

Certificate-based authentication should be supported as the preferred production option because it aligns better with enterprise security standards than long-lived client secrets.

Microsoft Entra ID Configuration Requirements
The Microsoft Entra ID application should support Microsoft Graph application permissions required for Datacap email ingestion, such as:

  • Mail.Read or Mail.ReadWrite, depending on whether Datacap only reads messages or also moves, updates, flags, or deletes processed messages.

  • Additional permissions only if required by the Datacap mail-processing use case.

The solution should support admin consent for the Microsoft Entra ID application permissions.

Where application permissions grant broad mailbox access by default, the documentation should recommend that customers restrict the application to approved mailbox scopes using Microsoft-supported Exchange Online application access controls or RBAC mechanisms.

Datacap Configuration Requirements
In the Datacap configuration interface, provide an option to select the Office 365 / Microsoft Graph authentication method:

  • Username/password login, for backward compatibility where still permitted

  • Microsoft Graph app-only authentication with client secret

  • Microsoft Graph app-only authentication with certificate credential

The app-only authentication options should not require an interactive user login or mailbox password.

Security Requirements
The enhancement should ensure that:

  • Client secrets are encrypted at rest.

  • Certificate private keys are not exposed in plaintext.

  • Configuration supports credential rotation.

  • Error logging does not expose secrets, private keys, tokens, or certificate passwords.

  • Token acquisition uses Microsoft identity platform OAuth 2.0 client credentials flow.

  • Access tokens are securely cached and refreshed as required.

Encrypted Email Support — Optional Future Enhancement
If encrypted email processing is required, IBM may consider a separate optional enhancement to support S/MIME or encrypted message processing.

This optional enhancement could include:

  • A Decryption option in the mail configuration.

  • Upload or secure reference to a .pfx certificate file.

  • Validation that the .pfx contains:

    • One private key

    • One public certificate

    • The complete certificate chain required for decryption

  • A protected password field for accessing the private key.

  • Recommended file size limit, such as 1 MB.

  • Secure storage and masking of certificate passwords.

Because encrypted email handling may require additional processing outside standard Microsoft Graph message retrieval, this should be treated as a separate optional capability from the core Graph app-only authentication enhancement.

Business Justification
This enhancement is required to allow IBM Datacap customers to continue processing Office 365 email securely as Microsoft deprecates EWS and as enterprise security teams eliminate username/password-based application integrations.

Without this enhancement, customers may be unable to use Datacap for Office 365 email ingestion in environments where security policy prohibits direct mailbox credentials. This creates operational risk, compliance risk, and potential product adoption barriers for organizations modernizing their Microsoft 365 security posture.

Requested Outcome
IBM Datacap should provide a supported Microsoft Graph Office 365 email authentication method using Microsoft Entra ID app-only authentication with client secret and certificate-based credentials, with certificate-based authentication recommended for production enterprise deployments.

Idea priority Urgent
  • Guest
    Jun 11, 2026

    Reference support # Case Number: TS022373778