There are two authentication setup options for the Tango Reserve M365 (Exchange) Connector
Option 1: Standard Configuration (Application Access)
This setup is used as the default configuration for the Tango Reserve Connector and uses application access. It allows the customer to use various Reserve interfaces with the two-way integration.
Scenario: The customer is setting up a two-way integration between Microsoft 365 (M365) and Reserve. Their users will schedule meetings using Outlook, as well as various Reserve interfaces such as the Reserve Outlook Add-in, Reserve Web, Accessible Interface, Reserve Mobile, and other interfaces.
Pros: Fewer clicks when reserving conference rooms via the web application compared to Direct Access configuration.
Cons: The M365 Connector service account has the right to read the user’s calendar.
Requirements:
- Requires a service account with super authority.
- A Tango Reserve Connector for M365.
- The Connector must be registered as an application in the customer’s MS Azure/Entra account with specific permissions. Refer to this article for the required permissions.
- Provide the Client ID, Tenant ID and Secret Value to Tango.
- A service account in Reserve. The credentials will be used in the Connector.
Option 2: Direct Access (Permissions by Logged-in User)
Uses the permissions of the logged in user to create/modify appointments on the user’s Exchange calendar. All application interactions with M365/Exchange are done on behalf of the user, using the permissions of the logged in user instead of a single account with super user authority.
Requires a service account with read-only access to the room calendars.
Scenario: A customer has strict security requirements that prohibit them from using the default configuration that uses Application Access. The customer will only use Outlook, Reserve Web, and Reserve Add-in for Outlook. Reservation Protection is applied to all other Reserve interfaces.
Pros: More secure. The service account cannot read the user calendar.
Cons: More clicks because the user must go through M365 authentication within the web application. Users are limited to only using Outlook, Reserve Web and the Reserve Add-in. This means that they will not be able to use other Reserve interfaces like the Reserve mobile app, Room Kiosk and others to make reservations.
Requirements:
- A Tango Reserve Connector for M365.
- The connector must be registered as an application in the customer’s MS Azure/Entra accounts with specific permissions. Refer to this article with the required permissions.
- Provide the Client ID, Tenant ID and Secret Value to Tango.
- A service account in Reserve. The credentials will be used in the Connector.
- Entra setup for Redirect URI. Refer to this article for steps
Optional Set-up: Dual Connector
This setup is used when a Reserve client has one Reserve instance but has two separate M365 and Exchange Online tenants. Users of both tenants are active users in Reserve.
Scenario: User A in Tenant A needs Room A that is also in Tenant A (all are in the same domain) – this user will be able to book Reserve in both Outlook and Reserve. User B in Tenant B needs Room A in Tenant A. Whereas before, this user will not have access to book this room, with the Dual Connector, they can book Room A in Reserve through the Web, Accessible Interface or the Reserve Add-in. Because User B does not have an account in Tenant A, they will not be able to book the same room using the standard Outlook meeting workflow. They must book the room using a Reserve interface.
Pros: Enables sharing of rooms between two M365 tenants.
Cons: Cannot be implemented with “Direct Access,” therefore “Application Access” must be used. Requires two connectors.
Requirements:
- Two Tango Reserve Connectors for M365.
- Both Connectors must be registered as an application in each of the MS Azure/Entra accounts with specific permission.
- Provide the Client ID, Tenant ID and Secret Value to Tango.
- A service account in Reserve. The credentials will be used in the Connector.
- An Exchange Service User is required with permissions to book rooms and add Teams to meetings. This is typically a licensed user. Provide this email address to Tango for the Connector setup.
- This can only be used along with the Standard (Default) Application Access setup.
- Users in both tenants must be active users in Reserve.
Related Article:
- Graph API Permissions for Reserve M365 Connector
- Reserve M365 (Exchange) Connector - Register the Application for OAuth (Graph API)
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article