Forum Discussion

JanRezab's avatar
JanRezab
Copper Contributor
May 21, 2025
Solved

ApplicationAccessPolicy vs Azure Automation Account

Hi all.

I have an Azure Automation Account (AAA) with enabled system managed identity. I added Graph API permission Mail.Send (application) to this identity and in script I'm able to send behalf of any email mailboxes. It works correctly.

I want to restrict this AAA to specific mailboxes. So, I followed the Limiting application permissions to specific Exchange Online mailboxes - Microsoft Graph | Microsoft Learn. I created Service Principal for AAA by "New-ServicePrincipal" command and created new Application Access Policy.

When I test it via Test-ApplicationAccessPolicy command I see correct result.

 

But AAA is still able to send an email behalf of an email mailbox. Do you have the same experience?

2 Replies

Resources