When you connect an organization-wide Outlook account, Tekst is granted application-level access that can reach every mailbox in your tenant by default. This guide explains how an administrator can restrict that access to only the mailboxes that are relevant for Tekst.
This guide limits which mailboxes Tekst can reach. It does not change what Tekst may do inside them: in the mailboxes it can still reach, Tekst keeps its default read and write access. Narrowing that as well, so Tekst can read without sending or without changing email, is a separate restriction, covered in Microsoft Graph permissions Tekst requests and how to restrict them.
This applies to organization-wide accounts only. A personal account is already limited to the mailboxes its signed-in user can reach, so no extra scoping is needed.
How scoping works
Microsoft lets you limit an application's mailbox access with an application access policy. The policy ties Tekst's application to a mail-enabled security group: Tekst can then access the mailboxes that are members of the group, and no others.
Note that application access policies are a long-standing Exchange Online feature that Microsoft is gradually replacing with Role Based Access Control (RBAC) for Applications. The steps below still work today; if your organization has standardized on App RBAC, you can scope the same application using that newer model instead.
Prerequisites
- Administrator access to your Microsoft 365 / Exchange Online environment.
- The Exchange Online PowerShell module installed.
- A mail-enabled security group containing the mailboxes Tekst should access.
Step 1: Connect to Exchange Online PowerShell
Open PowerShell and connect to Exchange Online:
Connect-ExchangeOnline
For details, see Microsoft's guide on how to connect to Exchange Online PowerShell.
Step 2: Identify the app client ID and security group
You will need the following:
-
Application (client) ID of the Tekst Outlook application:
b2094c09-0651-49c4-b2c2-ed3b739e2a8c -
Mail-enabled security group: create a new mail-enabled security group or use an existing one, and add only the mailboxes Tekst should access. All other mailboxes in the tenant will be excluded. Note the group's email address to use as the
PolicyScopeGroupId.
Step 3: Create the application access policy
Run the following, replacing the group address with your security group and adjusting the description:
New-ApplicationAccessPolicy `
-AppId b2094c09-0651-49c4-b2c2-ed3b739e2a8c `
-PolicyScopeGroupId <your-group@yourdomain.com> `
-AccessRight RestrictAccess `
-Description "Restrict Tekst app to members of the security group"
Step 4: Test the application access policy
Verify the policy by testing it against specific mailboxes:
Test-ApplicationAccessPolicy `
-Identity <user@yourdomain.com> `
-AppId b2094c09-0651-49c4-b2c2-ed3b739e2a8c
The output indicates whether the app has access to that mailbox. Test with a user inside the group and a user outside it to confirm the policy behaves as expected.
Troubleshooting
PowerShell version errors
The Exchange Online PowerShell module requires PowerShell 3.0 or higher. Check your version:
$PSVersionTable.PSVersion
Refer to Microsoft's installation documentation if you need to update.
Policy not taking effect
Application access policies can take up to 30 minutes to propagate. If the policy does not seem to apply right after creation, wait and test again.
Reference
This guide is based on Microsoft's documentation on limiting application permissions to specific mailboxes.
Appendix: maintain the list with a security group
A group is optional. The policy can point straight at a single mailbox, and for one mailbox that is the shortest path. A mail-enabled security group is worth the extra step when Tekst should reach several mailboxes, or when that set will change over time: the policy is created once, and from then on the group membership is the only thing you edit.
Create the group
The policy can only point at a security principal, which for a group means a mail-enabled security group. Distribution groups, Microsoft 365 Groups, and dynamic distribution groups are not accepted. If you are unsure what an existing group is, check it:
Get-Recipient -Identity tekst-mailboxes@yourdomain.com |
Select-Object RecipientTypeDetails, IsValidSecurityPrincipal
RecipientTypeDetails should read MailUniversalSecurityGroup and IsValidSecurityPrincipal should be True.
Create a new group in the Exchange admin center under Recipients > Groups > Add a group > Mail-enabled security, or from PowerShell:
New-DistributionGroup `
-Name "Tekst mailboxes" `
-Type Security `
-PrimarySmtpAddress tekst-mailboxes@yourdomain.com
Then add the mailboxes Tekst should be able to reach:
Add-DistributionGroupMember `
-Identity tekst-mailboxes@yourdomain.com `
-Member orders@yourdomain.com
A shared mailbox cannot scope a policy on its own, but it can be a member of the group. Since shared mailboxes are usually the reason to connect Tekst, this is how you bring them in scope.
Use the group's email address as the PolicyScopeGroupId in Step 3.
Maintain the list
Once the policy exists, you do not run New-ApplicationAccessPolicy again. Onboarding and offboarding a mailbox is a change to the group, either on its Members tab in the Exchange admin center or from PowerShell:
# Bring a mailbox in scope
Add-DistributionGroupMember `
-Identity tekst-mailboxes@yourdomain.com `
-Member invoices@yourdomain.com
# Take a mailbox out of scope
Remove-DistributionGroupMember `
-Identity tekst-mailboxes@yourdomain.com `
-Member old-inbox@yourdomain.com
# See what is currently in scope
Get-DistributionGroupMember -Identity tekst-mailboxes@yourdomain.com
A membership change needs the same propagation time as the policy itself, so allow up to 30 minutes and then re-run the test from Step 4 against the mailbox you added or removed.
Add a mailbox to the group before you connect it in Tekst. A mailbox that is connected in Tekst but missing from the group shows as Disconnected, which is covered in Add shared and child mailboxes.
0 comments
Please sign in to leave a comment.