Need Help Configuring Application Access Policy for One Outlook Mailbox

ANDRIANA LAZANA 0 Reputation points
2025-10-07T15:18:17.5733333+00:00

I need assistance with configuring our Azure AD App Registration so that it can access only one specific Outlook mailbox through Microsoft Graph API — and not any other mailboxes in the organization.

Here’s what I’ve done so far:

Created a new Azure AD App Registration

Type: Accounts in this organizational directory only (Single tenant)

  Not using any Redirect URI (no user sign-in required)
  
     Recorded the **Application (Client) ID** and **Directory (Tenant) ID**
     
     **Created a Client Secret**
     
        Added a new secret under *Certificates & Secrets*
        
           Copied the Value for later use (for Power Automate / agent connection)
           
           **Added Microsoft Graph Application Permissions**
           
              Permission: `Mail.ReadWrite`
              
                 Granted **Admin Consent** for the organization
                 

So the app now has application (app-only) access. By default, this level of permission gives access to all mailboxes, but I only want it to access one.

I really could use some help please on how exactly to do this!!

I believe this is the solution https://learn.microsoft.com/en-us/exchange/permissions-exo/application-rbac but I face a lot of errors.

Microsoft Security | Microsoft Graph

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.