Mail.send API permission

Dipronil Dey 5 Reputation points
2026-07-30T14:45:54.5033333+00:00

I have a doubt. Granting mail.Send (application) permission to the application object or managed identity (service principal), does it matter anymore. If I directly create a App RBAC policy and restrict the application object or managed identity (Service principal) to a mailbox, The restriction works perfectly even if I remove the mail.send permission from App object/service principal. So whats the need for mail.send? I may be wrong. Please let me know if today mail.send is even required to be assigned on app object or service principal if we need to restrict a mailbox or shared mailbox?

Exchange Online
Exchange Online

A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Vasil Michev 127.4K Reputation points MVP Volunteer Moderator
    2026-07-30T17:27:46.39+00:00

    You don't need it, if you are already leveraging Exchange's RBAC for applications. It was needed with previous implementations, such as application access policies.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.