Role Based Access Control (RBAC) setup

Use Role Based Access Control (RBAC) in PowerShell to limit the Robin app to room and equipment mailboxes only. Do these steps after you connect through the app.

  1. Find the Robin Powered (Admin Consent) app in the Enterprise apps section of Azure.

  2. In Exchange Online PowerShell, run this command:

    New-ServicePrincipal -AppId [app ID]  -ObjectId [object ID] -DisplayName "Robin"
  3. Create a limited scope. With it, the app has access to room and equipment calendars only. In the Exchange management shell, run this command:

    New-ManagementScope -Name "RobinCalendars" -RecipientRestrictionFilter {RecipientTypeDetails -eq "RoomMailbox" -or RecipientTypeDetails -eq "EquipmentMailbox"}
  4. Apply the management scope:

    New-ManagementRoleAssignment -Role “Application Calendars.ReadWrite” -App [Robin app ID] -CustomResourceScope “RobinCalendars”
  5. Revoke the Calendars.ReadWrite permission in the Permissions section of the app in Azure.

    Screenshot 2025-01-28 at 3.07.18 PM.png

To restrict calendar access further, see Microsoft's examples to limit the management scope.

For reference, see Role Based Access Control for Applications in Exchange Online.

Articles in this section

Was this article helpful?
0 out of 0 found this helpful
Share