logo
search
Security Policy Errors

How to Restrict Microsoft 365 Application Access to Specific Mailboxes

Muhammad TalhaMuhammad Talha Oct 1, 2026 869 views

Question details

The user needs to learn how to properly limit which Exchange Online mailboxes an enterprise application can access, as standard Enterprise Application assignments do not enforce this restriction.

How to Restrict Microsoft 365 Application Access to Specific Mailboxes
Product
Microsoft 365 / Exchange Online
Device & OS
not provided
Scenario
Administrators configuring secure API access for Microsoft 365 enterprise applications need to ensure apps can only read or modify specific designated mailboxes rather than the entire organization.
Observed behavior
Assigning users or groups under an Enterprise Application only controls who can sign in to the app, but does not restrict the app's underlying permissions to specific Exchange Online mailboxes.
Before you start

Ensure you are connected to Exchange Online PowerShell using an account with the appropriate administrative privileges before attempting to modify access policies.

Solution 1Recommended

Use PowerShell Application Access Policies

Configure an Application Access Policy to restrict an application's data access scope to a specific security group.

By default, application permissions grant access to all mailboxes in a tenant. Because assigning users or groups to an Enterprise Application in Azure AD only controls interactive sign-ins, you must use specific Exchange Online policies to limit programmatic mailbox access.

1
Review existing access policies

Run the Get-ApplicationAccessPolicy cmdlet in Exchange Online PowerShell to view current policy objects and understand which applications already have restricted scopes.

2
Create a mail-enabled security group

Ensure you have a mail-enabled security group configured in Microsoft 365 that contains the specific mailboxes you want the application to access.

3
Apply a new Application Access Policy

Execute the New-ApplicationAccessPolicy cmdlet. Use the PolicyScopeGroupId parameter to specify the email address or ID of your security group, and the AppId parameter to target your enterprise application.

4
Verify the policy enforcement

Use the Test-ApplicationAccessPolicy cmdlet to test a specific mailbox and verify whether your configured enterprise application is correctly granted or denied access.

Use PowerShell Application Access Policies
Consider Exchange Online RBAC: Microsoft is transitioning to newer Exchange Online RBAC for Applications. Check current Microsoft documentation to see if RBAC options better suit your tenant's compliance and security requirements.
Free Microsoft Office alternative

Simplify Your Document Workflow with WPS Office

While configuring Microsoft 365 tenant security requires complex PowerShell administration, managing your daily documents doesn't have to be difficult. WPS Office is a lightweight, intuitive, and highly compatible alternative for individuals and teams seeking an efficient office suite without the heavy administrative overhead.

  1. 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
  2. 2. Install WPS Office: Run the downloaded file and follow the straightforward on-screen prompts to complete the installation.
  3. 3. Start Creating: Open the application and immediately start viewing, editing, or creating compatible office documents with zero complex configuration.
Seamlessly compatible with Microsoft Word, Excel, and PowerPoint file formats.Lightweight design ensures fast installation and smooth operation on older hardware.All-in-one tabbed interface for managing documents, spreadsheets, and presentations.Built-in PDF editing tools available without additional subscriptions.
microsoft office alternative - wps office

Frequently Asked Questions

Why doesn't assigning users to an Enterprise Application restrict mailbox access?

Assigning users or groups to an Enterprise Application strictly controls who is authorized to sign into the application. It does not govern or restrict the Microsoft Graph or Exchange Web Services permissions the application uses to access mailbox data in the background.

What is the PolicyScopeGroupId parameter in PowerShell?

The PolicyScopeGroupId parameter is used alongside the New-ApplicationAccessPolicy cmdlet. It identifies the mail-enabled security group containing the mailboxes that the targeted application is permitted to access.

How long does it take for an Application Access Policy to take effect?

After creating or modifying an Application Access Policy via Exchange Online PowerShell, it can take up to 1 hour for the new permissions or restrictions to fully propagate and take effect across the Microsoft 365 tenant.