Tango Reserve M365/Exchange Connector - Authentication & Setup Options

Modified on Tue, 3 Mar at 1:20 AM

There are two authentication setup options for the Tango Reserve M365 (Exchange) Connector

Option 1: Standard Configuration (Application Access)

This setup is used as the default configuration for the Tango Reserve Connector and uses application access. It allows the customer to use various Reserve interfaces with the two-way integration.

Scenario: The customer is setting up a two-way integration between Microsoft 365 (M365) and Reserve. Their users will schedule meetings using Outlook, as well as various Reserve interfaces such as the Reserve Outlook Add-in, Reserve Web, Accessible Interface, Reserve Mobile, and other interfaces.

Pros: Fewer clicks when reserving conference rooms via the web application compared to Direct Access configuration.

Cons: The M365 Connector service account has the right to read the user’s calendar.

 

Requirements:

  1. Requires a service account with super authority.
  2. A Tango Reserve Connector for M365.
  3. The Connector must be registered as an application in the customer’s MS Azure/Entra account with specific permissions. Refer to this article for the required permissions.
  4. Provide the Client ID, Tenant ID and Secret Value to Tango.
  5. A service account in Reserve. The credentials will be used in the Connector.

 Option 2: Direct Access (Permissions by Logged-in User)

Uses the permissions of the logged in user to create/modify appointments on the user’s Exchange calendar. All application interactions with M365/Exchange are done on behalf of the user, using the permissions of the logged in user instead of a single account with super user authority.

Requires a service account with read-only access to the room calendars.

 

Scenario: A customer has strict security requirements that prohibit them from using the default configuration that uses Application Access. The customer will only use Outlook, Reserve Web, and Reserve Add-in for Outlook. Reservation Protection is applied to all other Reserve interfaces.

Pros: More secure. The service account cannot read the user calendar.

Cons: More clicks because the user must go through M365 authentication within the web application. Users are limited to only using Outlook, Reserve Web and the Reserve Add-in. This means that they will not be able to use other Reserve interfaces like the Reserve mobile app, Room Kiosk and others to make reservations.

Requirements:

  1. A Tango Reserve Connector for M365.
  2. The connector must be registered as an application in the customer’s MS Azure/Entra accounts with specific permissions. Refer to this article with the required permissions.
  3. Provide the Client ID, Tenant ID and Secret Value to Tango.
  4. A service account in Reserve. The credentials will be used in the Connector.
  5. Entra setup for Redirect URI. Refer to this article for steps

 

Optional Set-up: Dual Connector

This setup is used when a Reserve client has one Reserve instance but has two separate M365 and Exchange Online tenants. Users of both tenants are active users in Reserve.

Scenario:  User A in Tenant A needs Room A that is also in Tenant A (all are in the same domain) – this user will be able to book Reserve in both Outlook and Reserve. User B in Tenant B needs Room A in Tenant A. Whereas before, this user will not have access to book this room, with the Dual Connector, they can book Room A in Reserve through the Web, Accessible Interface or the Reserve Add-in. Because User B does not have an account in Tenant A, they will not be able to book the same room using the standard Outlook meeting workflow. They must book the room using a Reserve interface.

Pros: Enables sharing of rooms between two M365 tenants.

Cons: Cannot be implemented with “Direct Access,” therefore “Application Access” must be used. Requires two connectors.

 

Requirements:

  1. Two Tango Reserve Connectors for M365.
  2. Both Connectors must be registered as an application in each of the MS Azure/Entra accounts with specific permission.
  3. Provide the Client ID, Tenant ID and Secret Value to Tango.
  4. A service account in Reserve. The credentials will be used in the Connector.
  5. An Exchange Service User is required with permissions to book rooms and add Teams to meetings. This is typically a licensed user. Provide this email address to Tango for the Connector setup.
  6. This can only be used along with the Standard (Default) Application Access setup.
  7. Users in both tenants must be active users in Reserve.

Related Article:

 

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article