Configure impersonation roles for Exchange service accounts

Requires

  • Exchange 2010+
  • Admin access to Exchange
  • Under 5 minutes

A common cause of connection problems

If you have trouble connecting to Exchange calendars in Robin, or you get "Cannot find calendar" errors, 90% of the time your service account does not have impersonation rights for room calendars. Follow these steps to fix it.

When you finish, test the results with the Microsoft connectivity tool in the connection troubleshooting guide.

The connected service account must be able to create, edit and delete meetings. Robin uses these permissions to end meetings early from the room display or remove abandoned events automatically, for example.

Exchange Impersonation lets the service account manage events on behalf of your office's room resource calendars, no matter who created the event. It also gives you auditable logs.

From Microsoft's article "Exchange Impersonation vs. Delegate Access":

Exchange Impersonation is used in scenarios in which a single account needs to access many accounts. Line-of-business applications that work with mail typically use Exchange Impersonation.

To learn more, see why Robin does not use account delegation.

Assign the ApplicationImpersonation role

These steps apply to Exchange 2010, 2013 and 2016. Exchange 2007 handles Impersonation a little differently. To run the equivalent commands, see the MSDN article on Exchange 2007 impersonation.

Heads up

Robin recommends that you limit the scope of access to fit your team's security needs. Before you assign your service account the ApplicationImpersonation role, update which accounts Robin can impersonate. At a minimum, Robin recommends that you include all room resource accounts that you plan to manage with Robin.

For more specific groups, see how to configure Exchange Impersonation and limit access to a custom set of users or account types.

The easy way: No management scope

The service account has access to all calendars, of any type.

  1. In the Exchange management shell, run this command:

    New-ManagementRoleAssignment –Role:ApplicationImpersonation –User:YOURSERVICEACCOUNTUSERNAMEHERE

Replace the "User" in the command with your service account.

The advanced way: Limited management scope

With a limited scope, the service account has access to room and equipment calendars only.

  1. In the Exchange management shell, run this command:

    New-ManagementScope -Name "RobinResourceMailboxes" -RecipientRestrictionFilter {RecipientTypeDetails -eq "RoomMailbox" -or RecipientTypeDetails -eq "EquipmentMailbox"}

This command creates a management scope for only rooms and equipment. The scope acts as a filter for the impersonation.

Extra limited options

To allow access to rooms only, remove the EquipmentMailbox filter from the command above:

New-ManagementScope -Name "RobinResourceMailboxes" -RecipientRestrictionFilter {RecipientTypeDetails -eq "RoomMailbox"}

For more control, create a dedicated Role Group in Exchange that contains the mailboxes for Robin to manage. Then assign the service account a management scope for the mailboxes in that group. With this, you choose mailbox access one by one.

  1. Assign the impersonation to the service account:

    New-ManagementRoleAssignment –Name "ResourceImpersonation" –Role ApplicationImpersonation –User "YOURSERVICEACCOUNTUSERNAMEHERE" –CustomRecipientWriteScope "RobinResourceMailboxes"

Extra references

Next step

After you set up impersonation permissions, connect the service account to Robin.

Articles in this section

Was this article helpful?
11 out of 18 found this helpful
Share