Requires
A common cause of connection problems
If you have trouble connecting to Exchange calendars in Robin, or you get "Cannot find calendar" errors, 90% of the time your service account does not have impersonation rights for room calendars. Follow these steps to fix it.
When you finish, test the results with the Microsoft connectivity tool in the connection troubleshooting guide.
The connected service account must be able to create, edit and delete meetings. Robin uses these permissions to end meetings early from the room display or remove abandoned events automatically, for example.
Exchange Impersonation lets the service account manage events on behalf of your office's room resource calendars, no matter who created the event. It also gives you auditable logs.
From Microsoft's article "Exchange Impersonation vs. Delegate Access":
Exchange Impersonation is used in scenarios in which a single account needs to access many accounts. Line-of-business applications that work with mail typically use Exchange Impersonation.
To learn more, see why Robin does not use account delegation.
Assign the ApplicationImpersonation role
These steps apply to Exchange 2010, 2013 and 2016. Exchange 2007 handles Impersonation a little differently. To run the equivalent commands, see the MSDN article on Exchange 2007 impersonation.
Heads up
Robin recommends that you limit the scope of access to fit your team's security needs. Before you assign your service account the ApplicationImpersonation role, update which accounts Robin can impersonate. At a minimum, Robin recommends that you include all room resource accounts that you plan to manage with Robin.
For more specific groups, see how to configure Exchange Impersonation and limit access to a custom set of users or account types.
The easy way: No management scope
The service account has access to all calendars, of any type.
-
In the Exchange management shell, run this command:
New-ManagementRoleAssignment –Role:ApplicationImpersonation –User:YOURSERVICEACCOUNTUSERNAMEHERE
Replace the "User" in the command with your service account.
The advanced way: Limited management scope
With a limited scope, the service account has access to room and equipment calendars only.
-
In the Exchange management shell, run this command:
New-ManagementScope -Name "RobinResourceMailboxes" -RecipientRestrictionFilter {RecipientTypeDetails -eq "RoomMailbox" -or RecipientTypeDetails -eq "EquipmentMailbox"}
This command creates a management scope for only rooms and equipment. The scope acts as a filter for the impersonation.
Extra limited options
To allow access to rooms only, remove the EquipmentMailbox filter from the command above:
New-ManagementScope -Name "RobinResourceMailboxes" -RecipientRestrictionFilter {RecipientTypeDetails -eq "RoomMailbox"}
For more control, create a dedicated Role Group in Exchange that contains the mailboxes for Robin to manage. Then assign the service account a management scope for the mailboxes in that group. With this, you choose mailbox access one by one.
-
Assign the impersonation to the service account:
New-ManagementRoleAssignment –Name "ResourceImpersonation" –Role ApplicationImpersonation –User "YOURSERVICEACCOUNTUSERNAMEHERE" –CustomRecipientWriteScope "RobinResourceMailboxes"
Extra references
- MSDN - How to Configure Impersonation
- MSDN - Impersonation and EWS in Exchange
- MSDN - New-ManagementScope
Next step
After you set up impersonation permissions, connect the service account to Robin.