
The INRAE messaging system is based on the Microsoft Exchange infrastructure and uses the internal LDAP directory system of the institute to authenticate each agent. Accessing the webmail requires mastering three elements: the exact format of the identifier, the LDAP password, and the multi-factor validation now imposed on all accounts.
LDAP Login Format and Common Input Errors on INRAE Webmail
The webmail address is messagerie.inrae.fr. Once the page is loaded, the identification field expects a precise format: INRAidentifier (for example INRAdupont). The backslash is the one from the French keyboard, obtained with Alt Gr + 8. Using a regular slash or forgetting the INRA prefix results in a silent rejection, without an explicit error message.
The associated password is that of the LDAP account, the same one used to connect to other internal resources of the institute. It is not a password specific to the webmail. Any reset of the LDAP password will therefore also modify access to the messaging system.
A detailed guide explains the connection to INRAE messaging with corresponding screenshots, which can help in case of doubt about the interface.
INRAE Multi-Factor Authentication: Enable TOTP or FIDO2
Connecting to INRAE webmail now requires mandatory multi-factor authentication (MFA). Two methods are offered: TOTP and FIDO2. The choice is made during the first connection, and it conditions all subsequent connections.
TOTP: Mobile App Generating a Temporary Code
TOTP uses an authentication app installed on a smartphone. When activated, the MFA portal displays a QR code to scan with the app. Each connection then requires a six-digit code, valid for a few tens of seconds.
- Compatible apps include FreeOTP, Microsoft Authenticator, or any app adhering to the TOTP standard
- The code renews automatically, making it unnecessary to memorize anything beyond immediate entry
- In case of a phone change, MFA must be reactivated from an already authenticated workstation or by contacting the IT support of the unit

FIDO2: Hardware Security Key
FIDO2 relies on a physical key (USB or NFC) that is plugged in or brought close to the terminal at the time of connection. This method does not depend on a smartphone and works even without a mobile network.
FIDO2 remains the most reliable method if the phone is not available. The key must be registered only once on the MFA portal, then it is recognized at each connection without additional manipulation.
Technical Browser Requirements for INRAE Messaging
The MFA portal and the INRAE webmail interface impose conditions on the browser side. Ignoring these prerequisites leads to blank pages or redirection loops.
JavaScript must be enabled in the browser. Without it, neither the authentication form nor the MFA portal will load. Accepted browsers are Chrome, Firefox, and Edge in their recent versions.
Script-blocking extensions (like NoScript or uBlock in strict mode) may prevent the loading of the form. The domain inrae.fr must be added to the whitelist before attempting to connect.
- Temporarily disable any personal VPN that might interfere with the DNS resolution of the domain inrae.fr
- On a shared workstation, use a private browsing window to avoid session conflicts
Configure Outlook or Thunderbird in IMAP with the INRAE Exchange Server
The webmail is not the only entry point. A local email client (Outlook, Thunderbird) offers offline access and finer folder management. The configuration relies on the IMAP protocol coupled with the INRAE Exchange server.
IMAP Settings to Enter
In the email client, creating a new account requires the full email address ([email protected]), the incoming IMAP server, and the outgoing SMTP server. The expected encryption type is TLS/SSL. The standard IMAP port is 993, and the SMTP port is 587.
The identifier remains in the format INRAidentifier, identical to that of the webmail. The password is that of the LDAP account. Some clients like Thunderbird automatically detect the Exchange settings via autodiscover, but this detection sometimes fails behind an institutional proxy, requiring manual entry of the settings.

Calendar and Directory Synchronization
Thunderbird allows importing the INRAE calendar and the LDAP directory via dedicated add-ons (TbSync, for example). The shared calendar facilitates planning between units without resorting to third-party tools. Synchronization relies on the CalDAV protocol or the native Exchange connector depending on the chosen module.
Outlook, integrated into the Microsoft Office suite, natively supports Exchange. The connection to the calendar and directory occurs automatically as soon as the account is added, without additional configuration.
The INRAE messaging system combines a specific login format, mandatory MFA, and browser constraints that are not encountered on public webmails. Checking these three points before any connection attempt avoids the majority of reported blocks to IT support.