Access control for Azure Active Directory Application to EWS mailboxes

%3CLINGO-SUB%20id%3D%22lingo-sub-121202%22%20slang%3D%22en-US%22%3EAccess%20control%20for%20Azure%20Active%20Directory%20Application%20to%20EWS%20mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-121202%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20uncertain%20if%20this%20is%20in%20the%20correct%20place%2C%20so%20please%20bear%20with%20me.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20currently%20in%20process%20of%20migrating%20our%20Exchange%20environment%20from%20On-Premise%20to%20Exchange%20365.%26nbsp%3B%20Our%20developer%20team%20has%20an%20on%20premise%20application%20that%20uses%20EWS%20to%20read%20mailbox%20contents%2C%20then%20delete%20those%20messages.%26nbsp%3B%20We%20were%20able%20to%20create%20an%20application%20registration%20in%20Azure%20Active%20Directory%2C%20and%20are%20able%20to%20access%20our%20mailboxes%20in%20365%20through%20impersonation%20and%20read%20contents%20-%20Our%20application%20is%20using%20OAuth%20with%20certificate%20authentication%20(no%20login%20credentials)%2C%20and%20we%20have%20granted%20our%20Application%20the%20Use%20Exchange%20Web%20Services%20with%20full%20access%20to%20all%20mailboxes%20rights.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20problem%2C%20however%2C%20is%20that%20we%20don't%20want%20this%20application%20to%20be%20able%20to%20access%20all%20mailboxes%2C%20only%20a%20specific%20set%20of%20mailboxes.%26nbsp%3B%20Currently%20it%20is%20able%20to%20access%20any%20mailbox.%26nbsp%3B%20My%20question%20is%20how%20can%20we%20properly%20secure%20this%20application%20to%20only%20be%20able%20to%20access%20mailboxes%20that%20we%20specify%3F%26nbsp%3B%20I've%20seen%20different%20suggestions%20on%20scoping%20and%20roles%2C%20but%20have%20not%20been%20able%20to%20find%20a%20definitive%20answer.%26nbsp%3B%20%26nbsp%3BIf%20we%20do%20not%20use%20OAuth%2C%20and%20use%20user%20credentials%20to%20log%20into%20EWS%2C%20we%20have%20a%20means%20of%20defining%20write%20scope%20in%20Exchange%20365%2C%20which%20will%20limit%20that%20impersonation%20access.%26nbsp%3B%20I've%20been%20unable%20to%20find%20similar%20means%20when%20using%20OAuth%20with%20a%20certificate%2C%20and%20not%20using%20specific%20login%20credentials.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20anyone%20can%20provide%20some%20help%20or%20direction%20here%2C%20it%20would%20be%20greatly%20apprediated.%26nbsp%3B%20Please%20let%20me%20know%20if%20any%20additional%20details%20are%20required.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-121202%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EEWS%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Occasional Visitor

I'm uncertain if this is in the correct place, so please bear with me. 

 

We are currently in process of migrating our Exchange environment from On-Premise to Exchange 365.  Our developer team has an on premise application that uses EWS to read mailbox contents, then delete those messages.  We were able to create an application registration in Azure Active Directory, and are able to access our mailboxes in 365 through impersonation and read contents - Our application is using OAuth with certificate authentication (no login credentials), and we have granted our Application the Use Exchange Web Services with full access to all mailboxes rights.

 

The problem, however, is that we don't want this application to be able to access all mailboxes, only a specific set of mailboxes.  Currently it is able to access any mailbox.  My question is how can we properly secure this application to only be able to access mailboxes that we specify?  I've seen different suggestions on scoping and roles, but have not been able to find a definitive answer.   If we do not use OAuth, and use user credentials to log into EWS, we have a means of defining write scope in Exchange 365, which will limit that impersonation access.  I've been unable to find similar means when using OAuth with a certificate, and not using specific login credentials.

 

If anyone can provide some help or direction here, it would be greatly apprediated.  Please let me know if any additional details are required.

0 Replies