Rise Up Help Center — Apps and Integrations › Integrations Set Up
Replaces the previous EWS-based version of this article — updated September
2026.
If your Rise Up calendar sync was set up before this article was updated, your integration runs on Exchange Web Services (EWS), which Microsoft is retiring — enforcement begins 1 October 2026 and EWS is fully removed on 1 April 2027. Do not follow this article — see the dedicated guide "Migrating Your Outlook Integration from EWS to Microsoft Graph". The administrator steps it describes must be completed before the end of September 2026.
- A Microsoft 365 tenant with Exchange Online mailboxes.
- A Microsoft Entra ID (formerly Azure AD) account holding the Global Administrator or Privileged Role Administrator role. A regular user or a lesser admin role (e.g. Helpdesk Administrator) will not see the admin consent button required in Section I.
- Access to Exchange Online PowerShell (required to restrict mailbox access, and to create a room list if you use room management).
- Administrator access to your Rise Up platform (Settings › Developer › Calendar synchronisation).
This article explains how to connect Rise Up to your Microsoft 365 environment so that training sessions are automatically synchronised to Outlook calendars, and how to set up meeting-room management. The integration uses the Microsoft Graph API with application (client-credentials) authentication.
- Automatic calendar synchronisation — training sessions created in Rise Up appear in Outlook calendars, and updates or cancellations follow automatically.
- Security by design — OAuth 2.0 client-credentials authentication over Microsoft Graph, with access restricted to a single dedicated service mailbox.
- Simplified room booking — meeting rooms from your Exchange room list can be booked directly when scheduling sessions in Rise Up.
- App registration: the Microsoft Entra application Rise Up authenticates as — created once in Section I.
- Client secret: the credential the app uses to authenticate — generated in Section I, expires and must be renewed periodically.
- Graph application permissions: Calendars.ReadWrite (required) and Place.Read.All (room management only), added and consented on the app registration.
- Admin consent: the approval step, performable only by a Global Administrator or Privileged Role Administrator, that activates the declared Graph permissions.
- Service-account mailbox: the dedicated mailbox Rise Up creates events through.
- Application Access Policy: an Exchange Online PowerShell policy that restricts the Graph app permission to the service-account mailbox only.
- Room List (optional): an Exchange distribution group grouping bookable rooms, used for room management.
I. Create and configure the Azure application
Step 1 — Register a new application
- Go to portal.azure.com and open Microsoft Entra ID › App registrations › New registration.
- Give the application a recognisable name, e.g. Rise Up Calendar Sync.
- Under Supported account types, select Accounts in this organizational directory only (single tenant).
- Leave Redirect URI empty — this integration uses application (client-credentials) authentication, not a user sign-in flow.
- Click Register.
Step 2 — Record the Tenant ID and Client ID
On the app's Overview page, copy the following two values — you will enter them in Rise Up later:
- Directory (tenant) ID → this is your Tenant ID.
- Application (client) ID → this is your Client ID.
Step 3 — Create a client secret
- In the left-hand menu, open Certificates & secrets › Client secrets › New client secret.
- Add a description and choose an expiry period.
- Click Add, then immediately copy the secret Value (not the Secret ID) — it is shown only once. This is your client secret.
Step 4 — Add the Microsoft Graph API permissions
- In the left-hand menu, open API permissions.
- Click Add a permission › Microsoft Graph › Application permissions.
- Search for and check Calendars.ReadWrite. If you plan to use room management (Section V), also check Place.Read.All. Then click Add permissions.
| Permission | Why it is needed |
|---|---|
| Calendars.ReadWrite | Required. Create, update, read, and cancel calendar events. |
| Place.Read.All | Optional. Room-list lookups, only needed if you use the room management feature (Section V). |
The permissions now appear with the status "Not granted for [Tenant]" — they are declared, but not yet approved. That is expected at this stage.
Why Calendars.ReadWrite? Microsoft Graph does not offer a write-only calendar permission, so
Calendars.ReadWrite
is required. It is scoped down to a single mailbox in Section III,
so Rise Up cannot access employee or unrelated mailboxes.User.Read.All is not needed for this setup. It is only used when migrating an existing integration from EWS to Microsoft Graph.
full_access_as_app (an Office
365 Exchange Online permission). It is an EWS permission:
it does not grant any Microsoft Graph permission and must not be used
for Graph access — EWS and Graph are separate authorization boundaries.
Step 5 — Grant admin consent
- Click Grant admin consent for [Company Name] at the top of the API permissions list.
- In the confirmation dialog, click Yes.
- Confirm success: the Status column shows a green checkmark reading "Granted for [Company Name]" next to each permission.
II. Set up the service-account mailbox
Rise Up creates calendar events through one dedicated mailbox. Choose
(or create) a dedicated shared/service mailbox — e.g.
bookings@yourcompany.com. This is your
service-account mailbox. Using a dedicated mailbox
keeps access scoped and auditable.
- Go to portal.office.com › Admin › Active users and create the account (or pick an existing dedicated one).
- Assign a licence that includes an Exchange Online mailbox (e.g. E3, Business Standard, or equivalent).
III. Restrict the application to the service mailbox
Calendars.ReadWrite as an application
permission defaults to every mailbox in the tenant
unless scoped down. Restrict it in
Exchange Online PowerShell (this cannot be done
in the Azure portal):
Connect-ExchangeOnline
New-ApplicationAccessPolicy -AppId <ClientID> -PolicyScopeGroupId <ServiceAccountEmail> -AccessRight RestrictAccess -Description "Restrict to booking mailbox"
Replace <ClientID> with the Client ID from Section
I / Step 2 and <ServiceAccountEmail> with the
service-account mailbox from Section II. This ensures Rise Up can
access only the dedicated service mailbox — never
employee or unrelated mailboxes.
Verify the policy applies (allowed for the service mailbox, denied for any other):
Test-ApplicationAccessPolicy -Identity <ServiceAccountEmail> -AppId <ClientID>
Test-ApplicationAccessPolicy -Identity <SomeOtherMailbox> -AppId <ClientID>
The first command should return Granted, the second Denied.
IV. Configure and validate in Rise Up
- Open the settings: in Rise Up, go to Settings › Developer › Calendar synchronisation.
- Activate the synchronisation: activate calendar synchronisation and select Microsoft Office 365 (the page offers two options — Google Calendar and Microsoft Office 365). New configurations run on the Microsoft Graph API.
- Configure credentials: enter your Tenant ID, Client ID, Secret ID (paste the secret Value copied in Section I / Step 3), and Service account. Add your Room list and Booking email address in CC if you use those features.
- Test the configuration: click Test configuration to validate the setup.
- Save: click Save.
- Validate the result: create a real training session and check that it appears correctly in Outlook — subject, description, session link, virtual classroom link, location, attendees, and room.
There are no Host or Version fields on this screen — these were removed with the move to Graph. If you are used to the legacy EWS form, do not expect to find them.
V. Room management (optional)
Room management requires the Place.Read.All permission (Section I, Step 4). If you did not add it during setup, add it and grant admin consent again before continuing.
To book meeting rooms from Rise Up, group your rooms into a Room List in Exchange Online PowerShell:
New-DistributionGroup -Name "Rise Up Rooms" -RoomList
Add-DistributionGroupMember -Identity "Rise Up Rooms" -Member <RoomMailbox>
Repeat Add-DistributionGroupMember for each room, then
enter the Room List address in the Rise Up calendar synchronisation
settings.
VI. Security and access control
Two access models are possible with application permissions. Rise Up requires the restricted model described in Section III.
| Approach | Security level | Configuration | Recommendation |
|---|---|---|---|
| No access policy (tenant-wide access) | Low — the app can reach every mailbox | None (default) | Not recommended |
| Application access policy (Section III) | Enhanced — access limited to the service mailbox only | One PowerShell policy | Required for Rise Up |
FAQ & Troubleshooting
Issue Solution The configuration test fails Verify the Tenant ID, Client ID, and client secret (make sure you copied the secret Value, not the Secret ID), and confirm admin consent shows a green checkmark on Calendars.ReadWrite (and on Place.Read.All if you use room management). The "Grant admin consent" button is not visible The signed-in account must hold the Global Administrator or Privileged Role Administrator role. Sessions do not sync to Outlook Confirm the configuration was saved after a successful Test configuration, and run Test-ApplicationAccessPolicyto confirm the service mailbox returns Granted.Rooms or the room list do not appear Confirm Place.Read.All is added and granted on the app registration, check the Room List address and its members, and allow up to 48 hours for Graph to return a new or updated room list. Sync stops working after months of running fine The client secret has probably expired — create a new secret in Certificates & secrets and update it in Rise Up. The app can access more mailboxes than expected Apply the application access policy from Section III and verify it with Test-ApplicationAccessPolicy.-
Which permissions does Rise Up need?
Microsoft Graph application permissions:Calendars.ReadWrite(always required) andPlace.Read.All(only if you use room management). The legacyfull_access_as_appExchange Online permission is no longer used and must not be added for Graph.
I granted Place.Read.All and User.Read.All but don't use rooms. Can I remove them?
Yes.User.Read.Allis only used when migrating from EWS and is not needed for a new Graph setup.Place.Read.Allis only needed for room management. Remove the permissions you don't need from API permissions in your app registration, then run Test configuration in Rise Up to confirm the sync still validates.
Can I limit which mailboxes Rise Up can access?
Yes — and you should. The application access policy in Section III restricts access to the single dedicated service mailbox; every other mailbox returns Denied.
Why does Rise Up need read-write calendar access?
Microsoft Graph does not offer a write-only calendar permission, soCalendars.ReadWriteis required. It is scoped down to the service mailbox, so Rise Up cannot access employee or unrelated mailboxes.
Which Microsoft licences are compatible?
Any licence that includes an Exchange Online mailbox for the service account (e.g. E3, Business Standard, or equivalent).
I already have a working calendar sync — do I need to redo this setup?
No. If your sync was set up on EWS, keep your existing app registration — nothing new needs to be created. Follow the dedicated guide "Migrating Your Outlook Integration from EWS to Microsoft Graph" to switch to Graph. -
Contact Support
Migrating Your Outlook Integration from EWS to Microsoft Graph