Key Takeaways

  1. Salesforce Outlook Integration is a free Microsoft add-in that lets Salesforce users log emails, sync events, and open records from inside Outlook.
  2. It replaced the retired Salesforce for Outlook and Lightning Sync tools and works on Microsoft 365, Office 365, and Exchange 2019 or later.
  3. Setup takes about 15 minutes and requires a Salesforce admin to enable Outlook Integration in Setup before end users install the add-in.
  4. The paid Inbox add-on unlocks email tracking, send-later scheduling, and shared templates, but each user needs a separate license.
  5. The most common install error is the "needs admin approval" screen, resolved by the Microsoft 365 admin granting consent in Azure.

Salesforce Outlook Integration connects Microsoft Outlook to your Salesforce org, so reps can log emails, sync events, and open Salesforce records without leaving their inbox. Setup takes about 15 minutes on the free version. Enabling admin approval or turning on the paid Inbox add-on adds a few extra steps.

Salesforce-outlook-integration-banner

This guide covers the setup process end to end, what changes when you add Inbox, and fixes for the most common install errors, including the "needs admin approval" screen and permission-related sync failures. If you're migrating from Salesforce for Outlook or Lightning Sync (both retired), the current Outlook Integration is what replaced them.

How to Set Up Salesforce Outlook Integration

Setting up Salesforce Outlook Integration takes about 15 minutes end to end. A Salesforce admin enables the integration in Setup. Each user then installs the free Salesforce add-in inside Outlook, connects their Salesforce account, and turns on calendar sync.

If your Microsoft 365 tenant requires admin consent, the M365 admin approves the app once. The steps below walk through the full flow in order. They also cover the fix for the "needs admin approval" screen and the test pass that confirms email logging and calendar sync work end to end.

System requirements

Before you begin, confirm your Salesforce and Microsoft environments meet the baseline for Outlook Integration:

  • Salesforce edition: Enterprise, Performance, Unlimited, Developer, or Professional with API access enabled.
  • Salesforce role: A user account with System Administrator permissions for the initial setup.
  • Outlook version: Microsoft 365, Office 365, Outlook on the web, or Outlook desktop 2019 or later, on Windows or Mac.
  • Mail server: Exchange Online, or on-premises Exchange 2019 or later with EWS enabled.
  • Microsoft 365 role: A Global Administrator or Cloud Application Administrator if your tenant blocks third-party apps by default.
  • Browser (for Outlook on the web): The latest version of Chrome, Edge, Firefox, or Safari.

Once every item on this list is in place, you're clear to move to the admin enablement inside Salesforce.

Step 1: Enable Outlook Integration in Salesforce (admin, about 5 minutes)

This first step is done once by a Salesforce admin, and it's what makes the integration available to everyone else in the org.

  1. Log in to Salesforce as a System Administrator.
  2. Go to Setup. In the Quick Find box, type Outlook Integration and Sync and open the page.
  3. Toggle Let users access Salesforce records from Outlook to On.
  4. Under Email Application Panes, keep the default assignment or customize which record layouts appear inside Outlook for different user profiles.
  5. If your team uses a non-standard Outlook Web App domain such as mail.yourcompany.com, scroll to Microsoft Outlook Web App Domain and add it to the allowed list.
  6. In Setup, search Permission Sets and assign the Salesforce Inbox Included permission set to every user who will use the integration.
  7. Turn on Enhanced Email and Email to Salesforce so every logged message associates itself with the right record automatically.

Once the toggle is saved and the permission set is assigned, your users are cleared to install the add-in on their side.

Step 2: Install the Salesforce add-in in Outlook (user, about 1 minute)

The next step happens inside Outlook, and each user runs it once from their own inbox:

  1. Open Outlook on desktop, web, or mobile.
  2. Open any email or click New Message. In the ribbon, click the three-dot menu.
  3. Choose Get Add-ins.
  4. In the Marketplace search bar, type Salesforce.
  5. Find the add-in published by Salesforce Inc. and click Add.

The Salesforce icon now appears in the Outlook ribbon on desktop, or the top bar on web and mobile, which means the user is ready to link it to their Salesforce account.

Step 3: Connect your Salesforce account to Outlook

With the add-in installed, the next step is authenticating against Salesforce so the two systems can exchange records:

  1. In Outlook, open any email and click the Salesforce icon in the ribbon.
  2. In the Salesforce pane that opens on the right, choose Production or Sandbox depending on which environment you're connecting to.
  3. Enter your Salesforce username and password.
  4. Click Allow on the OAuth authorization screen to grant the add-in access to your Salesforce data.

If a screen appears saying the app needs admin approval, follow the fix in the "needs admin approval" section below. Otherwise, the connection is now live, and you can move on to calendar sync.

Step 4: Sync your Outlook calendar with Salesforce

Calendar sync runs through Einstein Activity Capture (EAC), which handles both email and event sync in the background for Microsoft 365 and Office 365 users:

  1. In Salesforce Setup, search Einstein Activity Capture and open Settings.
  2. Click New Configuration and give it a name.
  3. Choose Microsoft Exchange or Office 365 / Microsoft 365 as the connection method.
  4. Pick your sync direction: Salesforce to Outlook, Outlook to Salesforce, or two-way.
  5. Assign the users or profiles that should be included.
  6. Save the configuration. Each user then authorizes Microsoft in their own account settings once.

For orgs on legacy setups without EAC, calendar sync happens per event through the Salesforce add-in pane inside Outlook, and once the first sync completes successfully, you're ready to run a final end-to-end test.

Step 5: Test the integration

Before rolling out to the wider team, confirm thatemail logging and calendar sync are both working end-to-end:

  1. Open any email in Outlook and click the Salesforce icon.
  2. Choose Log Email to Salesforce, search for a contact or opportunity, and log the message.
  3. Open the same record in Salesforce and confirm the email appears under Activity History.
  4. Create a test calendar event in Outlook.
  5. Wait about 10 to 15 minutes for sync to run, then check the record's Activities panel in Salesforce.

If both the logged email and the event appear against the same record, the connection is live and ready to roll out to the rest of the team.

What happens if you hit "needs admin approval"

If your Microsoft 365 tenant is locked down, the first user opening the Salesforce add-in sees an error asking for admin approval. This is a Microsoft 365 consent setting, not a Salesforce bug, and it happens because the tenant blocks third-party apps until an admin has granted consent.

The M365 Global Admin fixes it once in the Azure portal, and every user who opens the add-in after that is cleared automatically.

Optional: Turn on Salesforce Inbox features

If your org has purchased Salesforce Inbox licenses, the admin can enable the extra productivity features from the same Setup area:

  1. In Salesforce Setup, search Inbox under Sales Cloud.
  2. Assign the Inbox with Einstein Activity Capture or Inbox Included license to the relevant users.

Once assigned, users see email tracking, send-later scheduling, meeting availability inserts, and shared email templates inside the same Salesforce add-in pane in Outlook, with no reinstall required.

Salesforce Outlook Integration Needs Admin Approval: How to Fix It

The "needs admin approval" screen appears when your Microsoft 365 tenant blocks the Salesforce Outlook add-in from getting user permissions until an administrator approves it. The fix takes about 3 minutes for the M365 Global Administrator: grant tenant-wide consent in the Azure portal, and every user in the tenant is cleared going forward.

The error message:

"Needs admin approval"

or

"This app needs permission to access resources in your organization that only an admin can grant. Please ask an admin to grant permission to this app before you can use it."

Quick fix: What the M365 admin does

If you're the Microsoft 365 Global Administrator or Cloud Application Administrator, this resolves the block tenant-wide:

  1. Sign in tohttps://portal.azure.com orhttps://entra.microsoft.com as a Global Administrator.
  2. Go to Microsoft Entra ID → Enterprise applications and search for Salesforce.
  3. Open Security → Permissions.
  4. Click Grant admin consent for [your organization] and confirm the pop-up.
  5. Wait for the Successfully granted admin consent banner.

Every user in the tenant can now open the Salesforce add-in without hitting the wall.

Why the "needs admin approval" screen appears

The error is a Microsoft 365 security setting, not a Salesforce bug. Locked-down tenants intercept OAuth permission requests from third-party apps until an admin has explicitly consented, which typically means one of these is true:

  • User consent for apps is set to Do not allow user consent in your Azure Enterprise Apps settings.
  • The add-in is requesting permissions your tenant classifies as admin-restricted.
  • Admin consent has never been granted for the Salesforce publisher in your tenant.

Enterprise tenants almost always have at least one turned on, so the error is expected behavior, not a misconfiguration.

If the error appears on Salesforce Inbox specifically

Salesforce Inbox is a paid layer on top of the free Outlook Integration, and it registers as a separate app in Azure. In Enterprise Applications, check whether both Salesforce and Salesforce Inbox appear as separate entries. If both are listed, grant tenant consent to each app individually using the same Quick Fix steps above. If only one appears, the Inbox app registers when the first Inbox-licensed user attempts consent.

Once both apps have been approved separately, Inbox users can complete the OAuth flow without the same block.

Alternative: Grant consent for a single user

For a pilot, use per-user assignment instead of tenant-wide consent:

  1. In the Azure portal, go to Microsoft Entra ID → Enterprise applications → Salesforce.
  2. Open Users and groups → Add user/group.
  3. Select the users, then click Assign.
  4. Ask each assigned user to open the add-in and complete the standard consent screen.

This scope is user-specific and doesn't touch tenant-wide policy.

If you're not the M365 admin

End users can't grant themselves consent, but they can request it. Click Request approval on the error screen and add a short justification such as "I need Salesforce Outlook Integration to log customer emails to CRM." Some tenants let users email IT directly with the app name and publisher, and if neither option is available in your tenant, send IT a link to Microsoft'sadmin consent workflow documentation.

Salesforce for Outlook vs Outlook Integration: What's the difference?

Salesforce for Outlook was Salesforce's original desktop plugin for syncing emails, events, and contacts between Salesforce and Microsoft Outlook. The former retired it in June 2024 and replaced it with the Outlook Integration Microsoft add-in, which is what the setup section above covers. If your team is still on Salesforce for Outlook, you need to migrate.

Quick comparison

The two products serve the same purpose, but the delivery model, feature set, and status are different:

FeatureSalesforce for OutlookOutlook Integration
StatusRetired June 2024Current, actively developed
Install methodWindows desktop MSI installerMicrosoft Marketplace add-in
PlatformsWindows Outlook onlyDesktop, web, and mobile Outlook
Sync engineLocal sync clientCloud (Einstein Activity Capture)
ConfigurationPer-user, on each deviceCentral admin toggle in Salesforce Setup
CostFree, bundledFree base tier, paid Inbox add-on

Once you know which product your team is on, the migration path is short and straightforward.

If you're still on Salesforce for Outlook

Salesforce disabled the old plugin's sync engine when it retired the product, which means any existing installation stopped syncing in June 2024. To migrate, uninstall the desktop plugin from every user's machine, follow the setup section above to enable Outlook Integration in Salesforce, and have each user install the new add-in from Microsoft Marketplace.

If your team also relied on Lightning Sync for calendar and contact sync, that's retired too, and Einstein Activity Capture is the current replacement.

What you get with Outlook Integration (and what Inbox adds)

Salesforce Outlook Integration ships in two tiers: a free base tier that lets users log emails, sync calendar events, and view Salesforce records inside Outlook, and a paid Salesforce Inbox add-on that adds open tracking, send-later scheduling, meeting insert, and shared templates. The base tier covers CRM hygiene. The Inbox add-on is designed for high-volume outbound reps.

Base features included in Outlook Integration (free)

The free Outlook Integration base tier gives every enabled user five capabilities at no extra cost:

  • Log emails to Salesforce records: One-click attach to any lead, contact, opportunity, or case.
  • Calendar sync via Einstein Activity Capture: Outlook events appear in Salesforce, and vice versa.
  • View Salesforce records inside Outlook: Account, contact, or opportunity details in a side pane.
  • Cross-platform support: Outlook desktop (Windows and Mac), Outlook on the web, and Outlook mobile.
  • Multi-org routing: Connect to Production or Sandbox at login.

The free tier is enough on its own for teams that only need email logging and calendar sync.

What Salesforce Inbox adds (paid)

Salesforce Inbox is a per-user paid license that adds five productivity features to the base tier:email tracking, send-later scheduling, meeting insert, shared templates, and advanced Einstein Activity Capture:

  • Email open tracking: See when a recipient opens the message and how many times.
  • Send-later scheduling: Schedule a drafted message to send at a specific time.
  • Meeting insert: Share available meeting times inside an email for the recipient to pick.
  • Shared templates: Use Lightning email templates from the Outlook compose window.
  • Einstein Activity Capture (advanced): Extended activity capture with auto-BCC to Salesforce.

Inbox is licensed per user, so most orgs assign it to the reps who send the highest email volume.

Which tier should you use?

Choose the free tier for internal-facing teams that need CRM hygiene, and choose Inbox for outbound sales reps whose email volume justifies the license cost:

  • Free base tier: Customer success, support, and internal teams whose main need is logging and calendar sync.
  • Paid Inbox tier: Sales reps doing outbound prospecting, follow-up sequences, and meeting bookings.

If you're not sure, roll out the free tier to everyone and add Inbox licenses only for the reps whose email volume justifies it.

Common Sync and Permission Errors

Most Salesforce Outlook Integration sync errors trace to three root causes: revoked OAuth tokens, missing permission sets, or Einstein Activity Capture misconfiguration. Common symptoms include "plugin not working," "needs permission to access resources," failed email logging, and missing calendar events. The four fixes below cover each.

Emails aren't logging to Salesforce

If the Log Email to Salesforce button clicks through without saving, the fix is usually a missing permission set, an expired session, or disabled API access:

  • Missing permission set: Assign Salesforce Inbox in Setup → Permission Sets.
  • Expired session: Sign out of the Salesforce pane in Outlook and sign back in.
  • API access disabled: In Setup → Profiles, confirm API Enabled for the user's profile.

If none apply, check whether the record's page layout hides Activity History.

Calendar events aren't syncing

If Outlook events don't appear in Salesforce (or vice versa), the fix lives in Einstein Activity Capture (EAC), not the add-in:

  • EAC disabled: Activate the configuration in Setup → Einstein Activity Capture → Settings.
  • Wrong sync direction: Match the direction to your use case (two-way or one-way).
  • User not assigned: Add the user to the EAC configuration, then have them re-authorize Microsoft.

Legacy orgs without EAC sync per event through the add-in pane, not automatically.

The Salesforce add-in disappeared from Outlook

If the Salesforce icon is missing from the Outlook ribbon, the add-in was either uninstalled or revoked by the M365 admin:

  • Reinstall: Outlook → Get Add-ins → Salesforce → Add.
  • Admin revoked: If reinstall isn't available, ask the M365 admin to reapprove the app in Azure.
  • Cached credentials: Clear cached Office credentials, then sign back in.

The connection resumes once the icon returns to the ribbon.

"Session expired" or generic permission errors

Session errors appear when the Salesforce OAuth token is revoked, most often after a password reset or a license change:

  • Sign out and sign in: In the Salesforce pane, choose Sign out and reconnect.
  • Password recently changed: A Salesforce password reset revokes OAuth tokens. Reconnect after the reset.
  • License removed: Reassign the correct permission set if the user was moved to a different Salesforce license.

If none work, capture the exact error and timestamp, then open a Salesforce support case.

Not a sync error, but worth flagging

Salesforce Outlook Integration is built for one-to-one email logging and sync, not for outbound campaigns or bulk send-and-track workflows. Teams that push high outbound volume through the add-in tend to hit Salesforce's daily activity limits and see inconsistent logging.

A Salesforce-native mass email tool likeMassMailer handles campaign volume outside the Outlook Integration's scope, so it doesn't compete for the same governor limits.

Is Salesforce Outlook Integration enough for your team?

With Outlook Integration live, every customer email and calendar event flows into the right Salesforce record without the rep having to think about it. Managers see the full activity picture, forecasting reflects real pipeline motion, and reps spend the time they used to lose to manual logging in front of customers instead.

If your team's outbound volume outgrows the Outlook add-in's one-to-one scope, or you need campaign tracking, deliverability, and no daily send cap, MassMailer runs all of it directly inside Salesforce.

Ready to send campaign-volume email from Salesforce without leaving the CRM? Book a demo today.