Configure Security Tokens for External Applications
- Last Updated: June 27, 2025
- 3 minute read
- MOVEit Transfer
- Version 2026
- Version 2025
- Documentation
MOVEit Transfer provides the option to couple a MOVEit Transfer client with another application. The Trusted Application Token Provider panel enables the Remember Me setting for the MOVEit Transfer client embedded in MS Outlook (the Add Hoc Add-in). Add-in users that choose Remember Me at first sign on, persist a security token, which validates user authorization between sessions. (Coupling with an external application such as MS Outlook means the user will not need to continually enter their MOVEit Transfer user credentials).
To Couple MOVEit Transfer with MS Outlook (External Application)
You must be signed-on as Org admin to make these changes.
- From the Trusted Applications view (SETTINGS > Security Policies >
User Auth - Trusted Applications) , click Add Provider.
The Add Trusted Application Provider page displays.
- Provide the trusted identity management service information.
- Provider Name. Provide a name that describes the external application and the purpose for coupling it with MOVEit Transfer.
- Provider URL.The external
application's Identity Service Provider (IdP). This is the trusted
end-point MOVEit Transfer uses to couple the
external application user with the MOVEit Transfer user. (When you use MOVEit Transfer from an external application, such as Microsoft
Outlook, you can provide users the option to maintain an authorized
session to MOVEit Transfer).
Table 1. Example Token Provider URL Values for Specific External Applications External Application Endpoint Microsoft 365 https://outlook.office365.com:443/autodiscover/metadata/json/1 Microsoft or exchange using a custom domain https://mailhost.example.com:443/autodiscover/metadata/json/1
--Where mailhost.example.com is the host and domain name for your mail service.

Delete Org-wide Identity Management Relationship
From the Trusted Applications table, you can click
on the delete icon (
) to remove the identity
relationship used to federate with the third-party application the identity provider
represents. Once their session tokens expire, any MOVEit Transfer clients embedded
in the third-party application's workflow will need to renew the sign-on process for
the next and all subsequent MOVEit Transfer sessions it initiates.

Edit the Trusted Application Configuration
From the Trusted Applications table, you can click on the
edit icon (
) on any row edit the configuration
record for a Trusted Application identity service used by the current Org.