Technology Blog Posts by Members
cancel
Showing results for 
Search instead for 
Did you mean: 

Dear All,


Writing this blog to share the details of Microsoft Graph API configuration in SAP CPI to avoid using SMTP with basic authentication which is a bigger risk now a days.

Please go through this link for the configuration done in Azure account for this implementation.
I will be sharing details about CPI configuration.

 

Cloud Integration - Send Mail via Microsoft Graph ... - SAP Community

Once you have done this configuration in azure ,Please follow these step for SAP CPI ( BTP Integration Suite).

Step 1- configure the credentials: 
1.  Login to system and navigate to "monitor'.

2.  click 'security materials'

3. Create OAuth2 Authorization Code

4.  select Provider: Microsoft 365

5. give it a suitable name

6.enter authorization and token URL ,client id , client secret received from configuration azure account.

7. enter 'user name ' - the email which will be sending emails and respective password.

8.in the scope , enter this:

openid profile offline_access https://graph.microsoft.com/Mail.Send

oauth_graphapi.png

 

9. click deploy, then click on 3 dots after deployment and  select Authorize.

10.Make sure to follow the step 9 in your VPN system ( if this is customer specific email/Azure account).

This will allow you activate the authorization.

oauth_graphapi1.png

 

Step 2 - configure the IFlow:

Create an iflow like below: 

graph_iflow.png

 

1. configure times to run the iflow as required.

2. configure the Content Modifier (CM_SetAttachmentbody) here I am storing the csv data in text format in message body of CM.

3. configure 'Base64 Encoder' to convert the attachment in base 63 as Graph API process the attachment in this format.
4.  configure CM_HTMLMail, here in the property, store the output from base encoder and in message body store the HTML data( for mail body ).
here important point to note that in HTML body there are alot of " (double quote)used , so for Graph API to process this " , make sure the replace all " with \".

graph2.png

 

graph3.png

 

5. CM_Property_GrpahAPIBody- create properties like below: these values will be used in graphAPI json body

use the email ids in BCC separated by ;.
if you need, you can create email or CC email as well instead of bccemailgraph6.png

Configure the  message body like below:
graph5.png

Please make sure to use this JSON correctly otherwise mail will not be triggered:

{
  "message": {
    "subject": "${property.MAIL_SUBJECT}",
    "body": {
      "contentType": "HTML",
      "content": "${property.mailbody}"
    },
    "toRecipients": [
      {
        "emailAddress": {
          "address": "[email protected]"
        }
      }
    ],
    "ccRecipients": [
      {
        "emailAddress": {
          "address": "[email protected]"
        }
      }
    ]
    "bccRecipients": [
      {
        "emailAddress": {
          "address": "${property.BccEmails}"
        }
      }
    ],
"attachments": [
      {
        "@odata.type": "#microsoft.graph.fileAttachment",
        "name": "attachment_30Sept2026.csv",
        "contentType": "text/plain",
        "contentBytes": "${property.attfile}"
      }
    ]
  },
  "saveToSentItems": "false"
}

 

6. use this groovy to fetch the oauth code configured in Step1.

import com.sap.gateway.ip.core.customdev.util.Message
import com.sap.it.api.securestore.SecureStoreService
import com.sap.it.api.securestore.AccessTokenAndUser
import com.sap.it.api.ITApiFactory

def Message processData(Message message) {

    def properties = message.getProperties();


    SecureStoreService secureStoreService =
            ITApiFactory.getService(SecureStoreService.class, null);

    String oauth2AuthorizationCodeCred =
            properties.get("OAUTH2_AUTHORIZATION_CODE_CRED");

    if (oauth2AuthorizationCodeCred == null ||
            oauth2AuthorizationCodeCred.trim().isEmpty()) {

        throw new IllegalStateException(
                "Property OAUTH2_AUTHORIZATION_CODE_CRED is not specified"
        )
    }

    AccessTokenAndUser accessTokenAndUser =
            secureStoreService.getAccesTokenForOauth2AuthorizationCodeCredential(
                    oauth2AuthorizationCodeCred
            )

    String token = accessTokenAndUser.getAccessToken();

   
    message.setHeader("Authorization", "Bearer " + token) ;
    message.setHeader("Content-Type", "application/json") ;
    return message;
}

7. use request reply with Http sender to configure GraphAPI as give:
URL- https://graph.microsoft.com/v1.0/me/sendMail
graph7.png

 

8. CM_delete_auth, configrure to delete the auth header.

graph8.png

 

9.deploy the iflow, you should get the email  as per HTML and attachment you configured.

graph9.png

 Regards,
Pooja Tiwari

Labels in this area