Graph API Permissions for Reserve M365 Connector

Modified on Tue, 3 Mar at 1:09 AM

What permissions are used by the Reserve M365 Connector?

There are two possible authentication setup options for the Reserve M365 Connector and the permissions will depend on which option a customer chooses to implement.

Permissions Required Option 1: Application Access Option 2: Direct Access
Calendars.ReadWrite Application – Yes

Application – Yes

Delegated – Yes

Place.Read.All Application – Yes Delegated - Yes
User.Read.All Application – Yes N/A
Mail.Send Application - Yes N/A
Calendars.ReadWrite.Shared N/A Delegated – Yes

 

Explanation of Permissions

Calendars.ReadWrite Read and write calendars in all mailboxes Allows the app to create, read, update, and delete events of all calendars without a signed-in user.
Place.Read.All Read all company places Allows the app to read company places (conference rooms and room lists) for calendar events and other applications
User.Read.All Read all users' full profiles Allows the app the read the full set of profile properties, group membership, reports and managers of other users in your organization, without a signed in user.
Mail.Send Send mail as any user Allows the App to send mail as any user without a signed in user
Calendars.ReadWrite.Shared Read and write user and shared calendars Allows the app to create, read, update and delete events in all calendars in the organization user has permissions to access. This includes delegate and shared calendars.

 

How are these permissions used by the Reserve Connector?

Calendars.ReadWrite

This is used for searching for appointments in the room and the owner's calendars. Also for loading appointments by their IDs (these are 'read' operations) and for creating and updating meetings based on the data from Reserve (these are 'write' operations).

Searching for meetings is needed for the initial load as well as sync with the Reserve Add-In and pulling for missed events process.

Loading meetings by their IDs is needed every time the Connector syncs changes to Reserve or when an update is made to the Exchange meeting with the data from Reserve.

The Connector does not delete meetings. The app will only delete rooms from the meeting which is an update meeting request and requires Calendars.ReadWrite. An exception to this is an instance where the user disables the MS TEAMS option for a reservation in Reserve AND the reservation was made for a room(s) NOT mapped in the Connector, AND the user exists in M365.

In the Direct Access option, this permission supports declining a meeting in M365 when the sync to Reserve fails. Application permission must be used with application access policies configured to limit the scope of application permissions to the room mailboxes.  Calendars.ReadWrite (Application) is to sync meetings from Outlook to Reserve. Calendars.ReadWrite (Delegated) along with Calendars.ReadWrite.Shared (Delegated) is to sync reservations from Reserve Web to Outlook.

Place.Read.All

This is needed to search for room names by their emails in order to populate the meeting Location field correctly.

 User.Read.All

This is needed to check if a user with the given email exists in M365.

 Mail.Send

This permission is needed to send a rejection email to a meeting organizer in M365 in cases where the corresponding reservation cannot be created/updated in Reserve.

Calendars.ReadWrite.Shared

In the Direct Access option, this Delegated permission along with Calendar.ReadWrite (Delegated) is used to sync reservations from Reserve Web to Outlook.

 

Alternate Permission

For the Direct Access setup option, the recommended permission to use is Calendars.ReadWrite. This is needed to allow the Connector to decline a meeting in M365 when the sync to Reserve fails. As an alternative, Calendars.Read (Application) can be used, however this will prevent the Connector from declining the meeting which can create usability concerns.


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article