Permission configuration to send mails from only specific Mailboxes with Entra ID App Registration

Modified on Wed, 7 Oct at 1:04 PM

Microsoft is retiring Basic Authentication for SMTP AUTH in Exchange Online. Systems that send email through Microsoft 365 using only a username and password should be migrated to OAuth / Modern Authentication or another supported mail-sending method.

To allow our product to still send emails using your exchange online, we need to switch to OAuth.
To be able to send from our product as a specific Email-Account, the following steps will show you how to assign "Application Mail.Send" permissions to the app registration:

Configure secure Microsoft 365 mail sending with Application RBAC

This guide explains how to allow an application to send mail through Microsoft 365 by using Exchange Online Application RBAC and a scoped administrative unit.

This avoids exposing mailbox passwords and limits the application to the mailboxes included in the selected administrative unit.

Prerequisites

You need:

  • Exchange Online administrator permissions
  • Access to Microsoft Entra admin center
  • An existing Microsoft Entra App registration
  • The corresponding Enterprise Application Application ID and Object ID
  • An administrative unit that contains the allowed sender mailbox or mailboxes

Microsoft documents Application RBAC as the Exchange Online model for granting an application access to Exchange data with an optional resource scope, such as selected mailboxes. This replaces older Application Access Policies. (Microsoft Learn: Role Based Access Control for Applications in Exchange Online)


Step 1: Install the Exchange Online PowerShell module

Run PowerShell as administrator and install the Exchange Online module:

Install-Module -Name ExchangeOnlineManagement

Microsoft lists ExchangeOnlineManagement as the module required to connect to Exchange Online PowerShell. (Microsoft Learn: Exchange Online PowerShell)


Step 2: Import the module

Import-Module ExchangeOnlineManagement

Step 3: Connect to Exchange Online

Connect-ExchangeOnline

Sign in with an account that has sufficient Exchange Online permissions.



Step 4: Register the application service principal in Exchange Online

Create an Exchange Online service principal reference for the existing Microsoft Entra application:


New-ServicePrincipal `
  -AppId "<EnterpriseApplication.ApplicationId>" `
  -ObjectId "<EnterpriseApplication.ObjectId>" `
  -DisplayName "<YourDisplayName>"

For example:

New-ServicePrincipal `
  -AppId "00000000-0000-0000-0000-000000000000" `
  -ObjectId "11111111-1111-1111-1111-111111111111" `
  -DisplayName "SP-Application-Mail-Sending"

Do not use the App registration IDs here. Use the Enterprise Application IDs.


Step 5: Create or select an administrative unit

In the Microsoft Entra admin center:

  1. In Section Entra ID go to Roles & admins
  2. Select Admin units
  3. Select Add
  4. Enter a name for the administrative unit
  5. Select Review + create
  6. Open the administrative unit
  7. Add the mailbox users that the application is allowed to access

Microsoft describes administrative units as a way to restrict the scope of role permissions in Microsoft Entra ID. (Microsoft Learn: Create or delete administrative units)

Note: adding a group to an administrative unit brings the group object into scope, not necessarily all group members. For mailbox scoping, verify that the intended mailbox users are included as required. (Microsoft Learn: Add users, groups, or devices to an administrative unit)


Step 6: Copy the administrative unit Object ID

Open the administrative unit and copy its Object ID.


Step 7: Assign the Application Mail.Send role

Assign the Exchange Online application role to the service principal and scope it to the administrative unit:


New-ManagementRoleAssignment `
  -App "<EnterpriseApplication.ObjectId>" `
  -Role "Application Mail.Send" `
  -RecipientAdministrativeUnitScope "<AdministrativeUnit.ObjectId>"

Example: 

New-ManagementRoleAssignment `
  -App "11111111-1111-1111-1111-111111111111" `
  -Role "Application Mail.Send" `
  -RecipientAdministrativeUnitScope "22222222-2222-2222-2222-222222222222"



⚠️ Changes to service principals, administrative units, and Exchange Online role assignments are not always effective immediately.
It can take up to 2 hours before the application is able to send mail with the new permissions.
If the configuration looks correct but sending still fails, wait and test again before changing the setup.



Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article