How to Integrate Salesforce with Outlook
The Complete Guide to Connecting Microsoft Outlook, Microsoft 365, Exchange Online, Email Logging, Calendar Sync, Contacts, and Salesforce

A sales representative spends the entire day working inside Outlook. Emails go out. Meetings get scheduled. Appointments change. Conversations continue for weeks. None of that activity actually reaches Salesforce. CRM records stay incomplete. Managers lose confidence in their own pipeline reporting. Forecasts drift away from what is actually happening. Customer history ends up fragmented across two separate systems that were supposed to work together.
Outlook integration exists specifically to eliminate this gap and reduce manual data entry, but only when it is actually implemented correctly. This guide covers what that genuinely requires, beyond simply enabling an add-in and hoping for the best.
01What Is Salesforce Outlook Integration?

The current, modern setup pairs the Salesforce Outlook Integration add-in with Einstein Activity Capture as the actual sync engine underneath it. The add-in gives a sales rep a side panel directly inside Outlook, showing the Salesforce record related to whatever email or contact they are currently looking at, along with quick actions like viewing today's tasks or creating a new record without leaving Outlook at all. Einstein Activity Capture is the engine that actually captures emails and calendar events in the background and automatically relates them to Salesforce records, populating the activity timeline without a rep manually logging anything. It is genuinely important to know directly that Salesforce for Outlook, the original legacy desktop application, was retired in 2024 and should not be used in any new deployment; if your organization is still running it, that alone is a reason to plan a migration rather than build anything new on top of it. Lightning Sync, a separate, older tool that synced only contacts and calendar events, without ever capturing email the way people often assume it did, is also being phased out; anything still relying on it needs a deliberate migration plan, covered specifically later in this guide given how time-sensitive it currently is. Einstein Activity Capture itself is included at no additional cost with Sales Cloud Enterprise Edition and above. Salesforce Inbox, a separate paid add-on layering in engagement features like send tracking, availability links, and email templates, requires its own additional license. Confirming your organization's specific Salesforce edition, and whether Inbox is genuinely needed, is worth doing before planning the rest of the implementation.
02Before You Begin

Confirm your actual Salesforce edition and whether it includes Einstein Activity Capture by default. Confirm your organization is running Microsoft 365 with Exchange Online, since the modern integration is built around that environment rather than an on-premise Exchange server, though on-premise configurations remain possible through specific connection options covered below. Confirm which users actually need access and what permission sets they currently hold. Confirm which Outlook versions your organization is actually running, including whether reps use classic Outlook, new Outlook, Outlook on the web, or Outlook mobile, since behavior and support can differ across these. Confirm licensing for both Einstein Activity Capture and, if desired, Salesforce Inbox specifically. And confirm you genuinely have both Salesforce admin access and Microsoft 365 tenant admin access available, since, as covered directly below, one specific and easily overlooked step in this setup can only be completed by the Microsoft 365 side, not the Salesforce side.
03Step 1: Define Your Business Goals
Automatically logging emails without manual effort, syncing calendars so meetings booked in either system appear in both, capturing a complete record of customer communication for reporting and continuity, improving actual CRM adoption among reps who currently avoid logging into Salesforce directly, reducing manual data entry generally, and supporting more accurate forecasting and pipeline reporting are all legitimate, common goals, but they are not identical, and the specific configuration choices that support one do not automatically support all the others equally well. Defining which of these actually matter most for your organization before configuring anything produces a considerably cleaner, more focused implementation than attempting to satisfy every possible goal simultaneously.
04Step 2: Plan Authentication
This is the single most important step to get right, and it is worth understanding directly why. Following Microsoft's own Secure Future Initiative, legacy Exchange authentication tokens have been deprecated, and connecting Einstein Activity Capture to a Microsoft 365 tenant now requires the tenant's own Microsoft 365 administrator to complete an Admin Consent Flow inside Microsoft Entra, explicitly granting the Salesforce application the specific Microsoft Graph API scopes it needs at the tenant level. This is a one-time action, but it is not something a Salesforce administrator can complete on their own; it genuinely requires Microsoft 365 tenant-level access. Skipping this step, or assuming your Salesforce admin alone can handle the entire setup, is one of the most common causes of users hitting authentication errors immediately after what looked like a complete configuration. Beyond this specific tenant-level consent, Einstein Activity Capture supports several different connection models depending on your organization's structure: user-level authentication, where each individual Salesforce user connects their own Microsoft 365 account directly; org-level OAuth 2.0, where a single connection applies across every Salesforce user at once; service account OAuth 2.0, where a dedicated service account with impersonation rights is used to configure many users simultaneously; and a Microsoft Exchange endpoint connection using Exchange Web Services directly, which requires EWS to be exposed externally and is specifically the option currently being phased out, covered in more detail below. The right choice depends on your organization's size, existing security posture, and whether Exchange Web Services is something your security team is comfortable exposing at all.
05Step 3: Configure Outlook Integration
Inside Salesforce Setup, search for Outlook Integration and Sync, enable it, and select Einstein Activity Capture as the actual sync engine. Separately, search Setup for Einstein Activity Capture itself, open its Settings, and create a new configuration, selecting Microsoft Exchange as the email provider and choosing the specific connection method that fits your organization based on the authentication planning covered above. Deploy to a small pilot group of users first rather than the entire sales team at once, confirm the side panel and activity capture are both genuinely working correctly for that pilot group, and only then expand deployment more broadly. Exact menu labels and configuration screens can shift slightly between Salesforce releases, so confirm the specific current path directly inside your own org's Setup rather than assuming an older screenshot or tutorial still matches exactly.
06Step 4: Configure Email Logging
Decide explicitly whether email logging should happen automatically through Einstein Activity Capture, manually through a rep choosing to log a specific email, or some combination of both depending on the specific team or role involved. Configure how incoming and outgoing emails actually get matched to the correct Salesforce record, whether a lead, a contact, an account, an opportunity, or a case, since match quality here directly determines whether the resulting activity data is actually useful for reporting or simply noise nobody trusts. It is worth knowing that where email content actually gets stored depends directly on how this is configured: a legacy capture configuration can store email content on external infrastructure that is not queryable or reportable inside Salesforce itself and is subject to its own rolling retention period, while enabling the Sync Email as Salesforce Activity setting stores captured emails as genuine, standard Salesforce Email Message activity records that are fully reportable. If your organization actually needs to report on email activity, rather than merely see it referenced, confirming this specific setting is configured the way you actually expect matters directly.
07Step 5: Configure Calendar Synchronization
Meetings, appointments, and their subsequent updates all need to sync in a direction and with a set of rules your organization has actually decided on deliberately, whether that is one-way sync from Outlook into Salesforce, two-way sync allowing changes on either side to flow to the other, recurring meeting handling specifically, since recurring events behave differently than one-time appointments across most sync tools, and correct handling when an organizer reschedules or cancels a meeting that has already synced. These are exactly the same fundamental synchronization considerations that apply to any calendar integration generally: a clearly defined direction, a clearly defined system of record, and explicit handling for edits made after the initial sync rather than only at creation.
08Step 6: User Permissions
On the Salesforce side, users need the Standard Einstein Activity Capture permission set, or an equivalent custom permission set granting the same access, assigned directly to their user record, alongside whatever underlying feature license the specific Salesforce edition requires. On the Microsoft side, the tenant-level admin consent covered in Step 2 has to already be in place before individual users can successfully authenticate at all. Security roles and general feature visibility should be reviewed specifically for which teams actually need Outlook integration access, rather than granting it organization-wide by default regardless of whether every team genuinely needs it.
09The Lightning Sync And Exchange Web Services Migration Deadline
This deserves its own dedicated section specifically because of how time-sensitive it currently is. Organizations still running Lightning Sync, the older Salesforce tool that historically synced only contacts and calendar events, not email despite what many teams assume, connected through Microsoft 365 using Exchange Web Services, are working against a real, currently active deadline. Salesforce has stated that orgs in this specific configuration need to migrate from Lightning Sync to Einstein Activity Capture, and separately upgrade the underlying Microsoft connection method to Microsoft Graph, before August 2026. Microsoft, on its own separate timeline, is disabling Exchange Web Services entirely within Exchange Online in October 2026. Salesforce's broader, overall retirement date for Lightning Sync generally is listed as April 2027, but any organization specifically using EWS is on the considerably shorter clock described above, not the later general date. This should genuinely be treated as a two-step migration, moving off Lightning Sync onto Einstein Activity Capture, and separately moving the underlying Microsoft connection from EWS onto Microsoft Graph, rather than assumed to be a single, one-click wizard that handles both at once. If your organization has not yet confirmed which sync method and which underlying Microsoft connection type you are currently running, this is worth confirming immediately given how close both deadlines already are.
10Common Outlook Integration Problems
Outlook Add-In Not Loading
Symptoms include the side panel simply never appearing inside Outlook at all. Likely causes include the add-in never actually being deployed to that specific user, a browser or Outlook version genuinely not supporting the current add-in, or a conflicting add-in already installed. Diagnosing this means confirming deployment status directly in Salesforce Setup for the specific user, and testing in a clean browser profile or a different Outlook client to isolate whether the issue is user-specific or organization-wide.
Something Went Wrong Errors
This generic error frequently traces back to an authentication problem rather than the add-in itself. Confirm the Microsoft 365 tenant-level admin consent covered in Step 2 was genuinely completed, confirm the specific user's own Microsoft 365 credentials and permissions are current, and check whether a password change or a security policy update on the Microsoft side invalidated an existing connection.
Authentication Failures
Expired or revoked Microsoft tokens, a tenant-level admin consent that was never actually completed in the first place, or a user whose Microsoft 365 account permissions changed after the integration was originally configured are the most common causes. Given the deprecation of legacy Exchange tokens covered above, an integration that worked previously and then suddenly stopped is worth checking specifically against whether the required Entra admin consent flow has genuinely been completed for your tenant.
Microsoft 365 Permission Issues
A specific user lacking the Microsoft-side permissions the integration actually requires, or a broader Conditional Access policy blocking the connection at the tenant level, can both prevent a user from connecting even when everything on the Salesforce side is configured correctly.
Emails Not Logging
Confirm whether automatic logging is actually enabled for the specific user or profile involved, confirm the matching rules connecting emails to Salesforce records are actually configured correctly, and confirm the user's Einstein Activity Capture configuration genuinely includes email capture rather than only calendar sync.
Calendar Not Syncing
Confirm the specific calendar sync direction configured actually matches what the user expects, confirm the user's Einstein Activity Capture configuration includes calendar sync at all, and check for a delay, since sync is not always instantaneous, before assuming a genuine failure rather than simply a normal processing lag.
Missing Meetings
A meeting created directly in Outlook that never appears in Salesforce, or the reverse, often points to a matching rule that failed to associate the meeting with the correct record, or a recurring meeting specifically, since recurring events are handled differently than one-time ones and are a common source of this specific symptom.
Duplicate Activities
More than one sync mechanism active simultaneously, such as a legacy tool and Einstein Activity Capture both still running at once, is a common and avoidable cause of duplicate activity records. Confirming that exactly one sync mechanism is genuinely active for a given user, rather than a legacy tool left running alongside the new one, resolves most instances of this.
Contacts Not Matching
Inconsistent email formatting, multiple contact or lead records for the same actual person, or a contact that genuinely does not exist yet in Salesforce can all prevent correct matching. This mirrors the same record-matching discipline that matters for any CRM integration generally.
Users Unable To Connect
Missing tenant-level admin consent, a missing permission set assignment, or a licensing gap for the specific user are the most common causes, and checking each of these directly, rather than assuming the add-in itself is broken, resolves most connection failures.
Side Panel Not Refreshing
A cached browser session, an outdated add-in version, or a genuine temporary service issue can all cause the side panel to display stale information. Refreshing the specific Outlook session, and confirming the add-in is running its current version, resolves most instances of this.
Update-Related Issues
A Microsoft 365 update, a Salesforce release, or a change to either platform's own security policy can each independently affect a previously working integration without any change having been made on the customer's own side at all. Reviewing both platforms' recent release notes is worth doing when a previously stable integration suddenly behaves differently with no known internal change to explain it.
11Data Ownership
Understand directly where captured emails actually live, whether stored externally under a legacy capture configuration or as genuine, reportable Salesforce activity records under the Sync Email as Salesforce Activity setting, since these have meaningfully different implications for reporting, compliance, and data retention. Understand which system genuinely owns calendar data going forward. Understand what your organization's actual retention requirements are for captured communications, and confirm the chosen configuration genuinely satisfies them, rather than assuming a default setting happens to align with whatever your compliance obligations actually require.
12Security Considerations
OAuth-based authentication should be used throughout rather than any legacy authentication method still technically available but actively being deprecated. Apply least-privilege principles when choosing between user-level, org-level, and service-account authentication models. Review access periodically rather than assuming initial configuration remains correct indefinitely. Apply Conditional Access policies deliberately on the Microsoft 365 side where your organization's security posture calls for them. Ensure new users are provisioned into the integration deliberately as part of onboarding, rather than left to request access informally. And confirm the whole configuration genuinely satisfies your organization's actual compliance obligations, which vary by industry and jurisdiction and are worth confirming with appropriate internal or legal counsel rather than assumed from a general guide.
13Testing
Test email logging directly, calendar sync in both directions if two-way sync is configured, meeting updates and rescheduling specifically, recurring meetings specifically given how differently they behave, multiple distinct users rather than only an administrator's own test account, shared mailboxes if any are in use, actual permission behavior for a standard user rather than only an admin, downstream reporting built on the resulting activity data, and behavior across mobile Outlook, desktop Outlook, and the newer Outlook client specifically, since behavior is not guaranteed to be identical across all of them.
14Monitoring
Monitor authentication status on an ongoing basis, sync failures specifically, actual user adoption rather than assuming the integration is being used simply because it was deployed, activity logging completeness, calendar synchronization accuracy, Microsoft's own release notes for changes that could affect the integration, Salesforce's own release notes for the same reason, and error logs on both platforms. Given the current, active Lightning Sync and Exchange Web Services deprecation timeline covered earlier, monitoring specifically for any org still running a legacy configuration matters considerably more right now than it would in a period without an active platform deadline.
15Common Mistakes
Skipping deliberate planning and jumping straight to configuration, ignoring the specific Microsoft 365 tenant-level admin consent requirement and assuming the Salesforce side alone is sufficient, poor permission design that either grants too much access broadly or too little to the teams that genuinely need it, no real user training on how the integration is actually supposed to be used day to day, assuming every Outlook version and client behaves identically, no ongoing monitoring once initial deployment is complete, no real governance over who can change the configuration later, and running more than one synchronization method simultaneously, such as a legacy tool left active alongside Einstein Activity Capture, are the recurring mistakes across Salesforce-Outlook implementations.
16Best Practices
Document the actual architecture chosen, including which authentication model is in use and why. Standardize deployment across the organization rather than configuring each user ad hoc. Monitor regularly rather than only when a problem is reported. Review Microsoft's own platform updates specifically, given how directly they have already affected authentication requirements once. Review Salesforce's own release notes similarly. Audit permissions periodically. Train users genuinely, not just during initial rollout. And maintain clear, documented ownership over the integration so a specific person is actually accountable for its ongoing health.
17The Bigger Problem: Integration Is About Business Process
Companies often ask us to simply connect Salesforce to Outlook. During implementation, we usually discover undefined sales processes that predate the integration entirely, poor existing CRM adoption the integration alone will not fix, inconsistent email logging practices across different teams, duplicate customer records already accumulated in Salesforce, weak reporting nobody currently trusts, permission issues layered on top of all of it, Microsoft-side configuration problems nobody on the Salesforce team was even aware existed, and no single person actually accountable for the integration's ongoing health. The technology itself is only ever one part of the actual solution. A reliable integration requires genuinely good operational design underneath it, not simply a correctly configured add-in.
18Why Businesses Reach Out To Us About This
Our team helps organizations plan Outlook integrations deliberately from the start, configure Microsoft 365 correctly, including the specific tenant-level admin consent step that is easy to miss, configure Salesforce and Einstein Activity Capture properly, improve email logging accuracy and matching, configure calendar synchronization with a genuinely defined direction and ownership, review permissions on both platforms, troubleshoot authentication failures down to their actual root cause, improve real CRM adoption rather than just technical connectivity, audit resulting reporting for accuracy, and optimize long-term performance as both platforms continue to evolve. We also help organizations still running Lightning Sync or legacy Exchange Web Services connections plan and execute the current, time-sensitive migration to Einstein Activity Capture and Microsoft Graph before the relevant deadlines arrive. Rather than simply installing an add-in, we design reliable CRM ecosystems built around how sales teams actually work.
19If You're Planning A Salesforce-Outlook Integration
If you are planning to integrate Salesforce with Outlook, start by confirming whether your organization is still running the retired Salesforce for Outlook desktop application or Lightning Sync, since both require a deliberate migration rather than incremental configuration on top of them. Confirm your Salesforce edition includes Einstein Activity Capture. Confirm you have both Salesforce admin access and genuine Microsoft 365 tenant admin access available, since the tenant-level consent step cannot be completed by the Salesforce side alone. And define your actual goals, whether that is automatic email logging, calendar synchronization, improved adoption, or more accurate reporting, before configuring anything. If you need help planning, implementing, or troubleshooting your Salesforce-Outlook integration, our team can help.
20A Reliable Integration Is Architecture, Not An Add-In
A successful Salesforce-Outlook integration depends on proper authentication, including the Microsoft 365 tenant-level consent step that only an M365 admin can complete, clear and deliberately designed permissions, thoughtful synchronization rules covering both email and calendar data, genuine user training, ongoing monitoring, real governance over who can change the configuration, and regular testing across the actual range of Outlook clients your team uses.
The best Salesforce Outlook integration is not simply one that technically connects two platforms. It is one that gives sales teams a genuinely seamless experience while ensuring every email, meeting, and customer interaction is accurately captured, securely synchronized, and actually available for reporting and relationship management, long after the day it was first configured.
Sources
Frequently Asked Questions
How do I integrate Salesforce with Outlook?+
Does Salesforce work with Microsoft Outlook?+
How do I log Outlook emails in Salesforce?+
Why isn't Salesforce Outlook Integration working?+
Why aren't my Outlook emails syncing?+
How do I sync Outlook calendar with Salesforce?+
What is Einstein Activity Capture?+
Do I need Microsoft 365?+
Why does Outlook say Something went wrong?+
How do I troubleshoot Salesforce Outlook Integration?+
Stop Fighting Authentication Errors. Build The Architecture Behind The Add-In.
Book a free strategy call and we will help you plan, implement, or troubleshoot a reliable Salesforce and Outlook integration.
