How to Restrict Microsoft 365 Application Access to Specific Mailboxes
Question details
The user needs to learn how to properly limit which Exchange Online mailboxes an enterprise application can access, as standard Enterprise Application assignments do not enforce this restriction.

- Product
- Microsoft 365 / Exchange Online
- Device & OS
- not provided
- Scenario
- Administrators configuring secure API access for Microsoft 365 enterprise applications need to ensure apps can only read or modify specific designated mailboxes rather than the entire organization.
- Observed behavior
- Assigning users or groups under an Enterprise Application only controls who can sign in to the app, but does not restrict the app's underlying permissions to specific Exchange Online mailboxes.
Ensure you are connected to Exchange Online PowerShell using an account with the appropriate administrative privileges before attempting to modify access policies.
Use PowerShell Application Access Policies
Configure an Application Access Policy to restrict an application's data access scope to a specific security group.
By default, application permissions grant access to all mailboxes in a tenant. Because assigning users or groups to an Enterprise Application in Azure AD only controls interactive sign-ins, you must use specific Exchange Online policies to limit programmatic mailbox access.
Run the Get-ApplicationAccessPolicy cmdlet in Exchange Online PowerShell to view current policy objects and understand which applications already have restricted scopes.
Ensure you have a mail-enabled security group configured in Microsoft 365 that contains the specific mailboxes you want the application to access.
Execute the New-ApplicationAccessPolicy cmdlet. Use the PolicyScopeGroupId parameter to specify the email address or ID of your security group, and the AppId parameter to target your enterprise application.
Use the Test-ApplicationAccessPolicy cmdlet to test a specific mailbox and verify whether your configured enterprise application is correctly granted or denied access.

Simplify Your Document Workflow with WPS Office
While configuring Microsoft 365 tenant security requires complex PowerShell administration, managing your daily documents doesn't have to be difficult. WPS Office is a lightweight, intuitive, and highly compatible alternative for individuals and teams seeking an efficient office suite without the heavy administrative overhead.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install WPS Office: Run the downloaded file and follow the straightforward on-screen prompts to complete the installation.
- 3. Start Creating: Open the application and immediately start viewing, editing, or creating compatible office documents with zero complex configuration.

Frequently Asked Questions
Why doesn't assigning users to an Enterprise Application restrict mailbox access?
Assigning users or groups to an Enterprise Application strictly controls who is authorized to sign into the application. It does not govern or restrict the Microsoft Graph or Exchange Web Services permissions the application uses to access mailbox data in the background.
What is the PolicyScopeGroupId parameter in PowerShell?
The PolicyScopeGroupId parameter is used alongside the New-ApplicationAccessPolicy cmdlet. It identifies the mail-enabled security group containing the mailboxes that the targeted application is permitted to access.
How long does it take for an Application Access Policy to take effect?
After creating or modifying an Application Access Policy via Exchange Online PowerShell, it can take up to 1 hour for the new permissions or restrictions to fully propagate and take effect across the Microsoft 365 tenant.




