Microsoft Bookings is an appointment scheduling tool that provides effective ways to manage your services and schedule appointments for your customers with just a few clicks. Bookings is integrated with your Office 365 calendar to help your customers quickly find available times and avoid your staff from being double-booked.
Please note that in order to use Microsoft Bookings it must be enabled for your tenant. If you are a tenant admin, here you can find detailed information to enable Bookings.
Once Bookings is enabled on the tenant, users can start using it.
If you are new to Bookings please visit this link for Frequently Asked Questions on Microsoft Bookings
Let’s spend some time covering what actually happens in the backend when a user creates a Bookings calendar, specifically:
Where the data is stored
How Admins can track/audit events and usage
Where the data is stored:
Bookings calendar data and other information is stored in the scheduling mailbox in Microsoft Exchange Online. This might lead you to wonder what a scheduling mailbox is, and when is it created.
A scheduling mailbox is the mailbox that gets automatically created in Exchange Online as soon as a user creates a Bookings calendar in Office 365. Scheduling mailbox is where all the relevant information/data about Bookings calendar is stored. This includes
Business information, logo, and working hours added when the booking calendar was created
Relevant staff and services added when the booking calendar was created
All bookings and appointments added to the booking calendar once it was created.
Note- Once the booking calendar are deleted, the data is permanently lost and cannot be retrieved.
How admins can track/audit events and usage
An admin can use the below command to list the scheduling mailboxes in their tenant.
To list the scheduling mailboxes with users who have full access to it you can use the below command;
When a user creates the Bookings calendar, they will receive an email notification like the one below and a similar kind of notification will be sent to all users who will be added as staff members for this Bookings calendar.
However, if the admin has enabled the “Require Staff Approval” setting at the tenant level then employees added as staff in a Bookings calendars will also get an Approve or Reject link in the email notification they receive.
This setting is available in the Microsoft 365 admin center under Settings > Org Settings > Bookings.
An admin can also track the creation of Bookings calendars using Exchange Online admin audit logs (look for the New-Schedulingmailbox in the logs and it will also have the name of the user who created it, as shown below.
You can also use the following PowerShell command to fetch these logs;
You will notice a corresponding user object created with the name of the Bookings calendar under Active Users in Microsoft 365 Admin center. This new mystery user is simply the new Bookings calendar.
As there is an object being created in Microsoft 365 directory you will also see the event in Azure audit logs, you will find it was initiated by Microsoft Substratemanagement which is responsible for provisioning corresponding user objects for the scheduling mailbox that got created for the Bookings calendar.
This can be surprising or might seem like a security concern to several administrators when performing audits for their tenant as it shows a mystery user being created without their knowledge, hopefully this mystery will now be solved.
For more details on such unknown actors in Azure audit reports, please refer to the following article-