To allow our product to still send emails using your exchange online, we need to switch to OAuth.
To be able to send from our product as a specific Email-Account, the following steps will show you how to assign "Application Mail.Send" permissions to the app registration:
Configure secure Microsoft 365 mail sending with Application RBAC
This guide explains how to allow an application to send mail through Microsoft 365 by using Exchange Online Application RBAC and a scoped administrative unit.
This avoids exposing mailbox passwords and limits the application to the mailboxes included in the selected administrative unit.
Prerequisites
You need:
- Exchange Online administrator permissions
- Access to Microsoft Entra admin center
- An existing Microsoft Entra App registration
- The corresponding Enterprise Application Application ID and Object ID
- An administrative unit that contains the allowed sender mailbox or mailboxes
Microsoft documents Application RBAC as the Exchange Online model for granting an application access to Exchange data with an optional resource scope, such as selected mailboxes. This replaces older Application Access Policies. (Microsoft Learn: Role Based Access Control for Applications in Exchange Online)
Step 1: Install the Exchange Online PowerShell module
Run PowerShell as administrator and install the Exchange Online module:
Install-Module -Name ExchangeOnlineManagement
Microsoft lists ExchangeOnlineManagement as the module required to connect to Exchange Online PowerShell. (Microsoft Learn: Exchange Online PowerShell)
Step 2: Import the module
Import-Module ExchangeOnlineManagement
Step 3: Connect to Exchange Online
Connect-ExchangeOnline
Sign in with an account that has sufficient Exchange Online permissions.
Step 4: Register the application service principal in Exchange Online
Create an Exchange Online service principal reference for the existing Microsoft Entra application:
New-ServicePrincipal ` -AppId "<EnterpriseApplication.ApplicationId>" ` -ObjectId "<EnterpriseApplication.ObjectId>" ` -DisplayName "<YourDisplayName>"
For example:
New-ServicePrincipal ` -AppId "00000000-0000-0000-0000-000000000000" ` -ObjectId "11111111-1111-1111-1111-111111111111" ` -DisplayName "SP-Application-Mail-Sending"
Do not use the App registration IDs here. Use the Enterprise Application IDs.
Step 5: Create or select an administrative unit
In the Microsoft Entra admin center:
- In Section Entra ID go to Roles & admins
- Select Admin units
- Select Add
- Enter a name for the administrative unit
- Select Review + create
- Open the administrative unit
- Add the mailbox users that the application is allowed to access
Microsoft describes administrative units as a way to restrict the scope of role permissions in Microsoft Entra ID. (Microsoft Learn: Create or delete administrative units)
Note: adding a group to an administrative unit brings the group object into scope, not necessarily all group members. For mailbox scoping, verify that the intended mailbox users are included as required. (Microsoft Learn: Add users, groups, or devices to an administrative unit)
Step 6: Copy the administrative unit Object ID
Open the administrative unit and copy its Object ID.
Step 7: Assign the Application Mail.Send role
Assign the Exchange Online application role to the service principal and scope it to the administrative unit:
New-ManagementRoleAssignment ` -App "<EnterpriseApplication.ObjectId>" ` -Role "Application Mail.Send" ` -RecipientAdministrativeUnitScope "<AdministrativeUnit.ObjectId>"
Example:
New-ManagementRoleAssignment ` -App "11111111-1111-1111-1111-111111111111" ` -Role "Application Mail.Send" ` -RecipientAdministrativeUnitScope "22222222-2222-2222-2222-222222222222"
⚠️ Changes to service principals, administrative units, and Exchange Online role assignments are not always effective immediately. It can take up to 2 hours before the application is able to send mail with the new permissions. If the configuration looks correct but sending still fails, wait and test again before changing the setup.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article