Space Connect Least Privilege Access
Overview
This “Privacy-First” enhancement rewrites the Space Connect security model so that the product can run with the minimum permissions required to perform MS Exchange room booking actions. This “Minimal Touch” approach enables full booking functionality and UI sync accuracy while ensuring the integration scope remains strictly confined to shared spaces, explicitly protecting the privacy of User calendars through the use of delegated user access.
Initial Setup
To enable Least Privilege Access the development team must be notified to enable the desired mode.
Delete Space Connect Rooms Enterprise Application (Optional)
If you have previously used the Space Connect solution then you can use Microsoft Entra to delete the Space Connect Rooms Enterprise Application. This is optional and can be done at your discretion. Space Connect when running in Least Privilege Access mode will NOT use this EA.
Grant Consent to Least Privilege Access Enterprise Application
- Login into admin.spaceconnect.co
- At the top of the login screen the following dialog box appears.

- Click “SIGN IN AND GRANT CONSENT”
- The Permissions Requested will appear as below.
- Grant consent to create the Enterprise Application as defined below. (Application ID: 57b914f1-36bc-44d6-a2d9-494916d72c52)

Permissions Requested - Enterprise Application dialog

Microsoft Entra - Permission list after acceptance of the EA dialog.
Create Application Access Policy
- Create the Application access policy using https://help.spaceconnect.co/article/211-optional-application-access-policies as a guide.
- Note that the Application ID that needs to be used is 57b914f1-36bc-44d6-a2d9-494916d72c52
New-ApplicationAccessPolicy -AccessRight RestrictAccess -AppId "57b914f1-36bc-44d6-a2d9-494916d72c52" -PolicyScopeGroupId "mail_enabled_security_email -Description "Restrict SpaceConnect to members of Mail Enabled Security Group (mail_enabled_security_name)."