---
title: "Exchange Online Setup"
manual: "Microsoft Exchange 365 Mailer"
version: "main"
permalink: "https://docs.typo3.org/permalink/oliverkroener/ok-exchange365-mailer:exchange-setup@main"
source: "ExchangeSetup/Index.rst"
rendered: "2026-10-04T20:03:13+00:00"
---

# Exchange Online Setup {#exchange-setup}

To restrict app access to specific mailboxes, you need the Exchange Online PowerShell module.

> [!NOTE]
> Application Access Policies can currently *only* be configured via **PowerShell**. There is no option in the Microsoft Entra ID or Exchange Admin Center web interfaces at this time.

**Prerequisites**

**PowerShell 7.x** (latest recommended) is required for best compatibility. Windows PowerShell 5.1 works but may have limitations with newer module versions.

Check your version:

```powershell
$PSVersionTable.PSVersion
```

Install or update to PowerShell 7:

```powershell
winget install Microsoft.PowerShell
```

Install the **ExchangeOnlineManagement** module. Run PowerShell as **Administrator**:

```powershell
Install-Module -Name ExchangeOnlineManagement -Force -AllowClobber
```

-   [Shared Mailboxes](https://docs.typo3.org/permalink/oliverkroener/ok-exchange365-mailer:using-shared-mailboxes@main)
-   [Sender Display Name](https://docs.typo3.org/permalink/oliverkroener/ok-exchange365-mailer:configuring-the-sender-display-name@main)

## Import and connect {#import-and-connect}

```powershell
Import-Module ExchangeOnlineManagement
Connect-ExchangeOnline -UserPrincipalName your-admin@yourdomain.com
```

This opens a browser window for authentication. Use an account with Exchange Admin rights.

## Create the Application Access Policy {#create-the-application-access-policy}

The `New-ApplicationAccessPolicy` cmdlet restricts your application to only access specific mailboxes instead of all mailboxes in the tenant.

**Parameters:**

-   `-AppId`: The Application (client) ID from your Microsoft Entra ID app registration
-   `-PolicyScopeGroupId`: The email address of the mailbox or mail-enabled security group the app is allowed to access
-   `-AccessRight RestrictAccess`: Limits the app to *only* the specified mailbox(es)
-   `-Description`: A human-readable description for the policy

```powershell
New-ApplicationAccessPolicy -AppId "<your-app-id>" -PolicyScopeGroupId "shared@yourdomain.com" -AccessRight RestrictAccess -Description "Restrict to shared mailbox"
```

> [!TIP]
> Replace `<your-app-id>` with your actual Application ID and `shared@yourdomain.com` with the mailbox address you want to allow.

To verify the policy was created:

```powershell
Get-ApplicationAccessPolicy | Format-List
```

To test if the policy works correctly:

```powershell
Test-ApplicationAccessPolicy -Identity "shared@yourdomain.com" -AppId "<your-app-id>"
```

## Troubleshooting {#troubleshooting}

```powershell
# Check if connected
Get-ConnectionInformation

# Verify cmdlet exists
Get-Command New-ApplicationAccessPolicy

# Check PowerShell version (needs 5.1+)
$PSVersionTable.PSVersion

# List all existing policies
Get-ApplicationAccessPolicy | Format-List

# Remove a policy if needed
Remove-ApplicationAccessPolicy -Identity "<policy-id>"
```
