Robin's calendar syncing for Exchange connects through UserImpersonation on each managed room calendar. Exchange has different ways to manage permissions, and this article explains why Robin uses Impersonation.
Why Microsoft recommends Impersonation for apps
These explanations from Microsoft's developer blogs show the differences.
From The importance of EWS Impersonation while using an application account:
Accordingly, Delegate access is a user-manager permission, as it presumes that the user/owner of the mailbox is explicitly granting access. Impersonation, on the other hand, has been designed to support enterprise applications, and is an administratively controlled access methodology that requires no intervention from the mailbox owner
One way to think of the differences is that Impersonation is access for applications, whereas Delegate access is access for users.
Impersonation also supports better logging by default. This helps you audit how applications access your data:
Note that both Impersonation and Impersonation activity can be logged by both IIS and EWS native logging functionality, providing a full audit trail.
From Exchange Impersonation vs. Delegate Access:
Exchange Impersonation is used in scenarios in which a single account needs to access many accounts. Line-of-business applications that work with mail typically use Exchange Impersonation.
Delegate access is used in scenarios in which there needs to be a one-to-one relationship between users.
If your organization does not allow Impersonation
If your organization has policies about impersonation, they usually cover 2 concerns:
- Service accounts should not be able to impersonate people (for example, your CEO).
- Requests made through Impersonation are harder to log than delegate access.
In both cases, Robin does not need any kind of user (human) impersonation access to work. For the specific roles, see Configure impersonation roles for Exchange service accounts.
The service account's impersonation rights can cover only the room resources you want it to manage. With this limit, Impersonation access usually fits more easily into your organization's security frameworks.