Skip to content
Joan Help

Security and data protection in Microsoft 365

With Microsoft 365, Joan uses standard authentication and APIs, stores some credentials encrypted and only the room's email, and caches events briefly in case the calendar goes down.

All communication between Joan devices, MyJoan account and the Microsoft 365 calendar is managed through the official, standard authentication, and APIs with access granted and certain credentials stored in encrypted form.

No calendar or event information is stored on our servers. Our cloud server only stores the email of the room’s resource, all other information is gained through an API call, parsed, and sent directly to the device. This information is temporarily stored in our cache, just to make sure the events are still displayed even if the calendar service experiences a downtime. Such information is never stored in our database.

Global Admin accounts are managed through Oauth2 authentication using the Outlook API and for Delegated users, standard, basic authentication using the EWS API is employed. User information, such as usernames and passwords, for Delegated users are kept encrypted in our database for seamless use but no worries, no information is or will be shared or sold to third parties as stated in our Privacy Policy.

*For more information regarding our data protection and security policy, please take a look at our security section on our website here -> https://getjoan.com/security/

Was this helpful?