Which Microsoft 365 connection to choose
Offision connects to Microsoft 365 three ways, and they differ in what syncs by itself. Read this once before you connect, because the choice sets what you can automate later.
Offision talks to Microsoft 365 through one connection, and that connection is made one of three ways. They all sync room calendars. What separates them is how much else arrives on its own, and who has to approve it.
Make this choice before you connect. You can change it later, but two of the changes are one-way.
The three ways
| Application mode | Delegate mode | Your own Entra app | |
|---|---|---|---|
| Whose app registration | Offision’s | Offision’s | yours |
| Who approves it | a Global Administrator, once | any one mailbox, by signing in | whoever owns your app registration |
| Calendars | sync | sync | sync |
| Rooms | sync by themselves | you add each one | depends on the mode you pick |
| People | sync by themselves | you import them | depends on the mode you pick |
| User groups | sync by themselves | not available | depends on the mode you pick |
| Stores a client secret | no | no | yes, yours |
The chooser shows the same thing as four small lights — green for automatic, amber for something you do by hand, grey for not available at all.

The connect dialog, on application mode, with the four sync lights.
Application mode
Your Microsoft 365 Global Administrator approves Offision once, for the whole organisation. Nobody else is ever asked to approve anything, and no individual mailbox is involved — which is why rooms, people and groups can all keep themselves up to date.
Offision stores no client id and no client secret for this mode. It records which Microsoft 365 directory was approved, and when.
This is the right choice for most organisations. See Connect Microsoft 365 in application mode.
Delegate mode
One person signs in with a Microsoft account, and everything Offision does runs on that account’s calendar permission. It is quicker to set up, and it needs nobody with administrator rights — but it can only see what that one mailbox can see.
So rooms are added one address at a time, people are imported rather than synced, and user groups are not available at all. That is the design of the mode, not a fault in it.
It suits a pilot, a single department, or an organisation whose administrators are not going to approve a tenant-wide application any time soon. See Connect Microsoft 365 in delegate mode.
Your own Entra ID app
If your security policy will not accept Offision’s app registration, register your own in Microsoft Entra ID and give Offision its credentials. You then choose the mode yourself, from five:
| Family | Mode | Room calendars | Single sign-on | People sync |
|---|---|---|---|---|
| Application | Complete mode | yes | yes | yes |
| Application | Resource only mode | yes | no | no |
| Delegated | Complete mode | yes | yes | yes |
| Delegated | Standard mode | yes | yes | no |
| Delegated | Resource calendar mode | yes | no | no |
The connect wizard lists the exact Microsoft Graph permissions each mode needs, with a Copy button, so you can hand the list to whoever owns the app registration. See Connect Microsoft 365 with your own Entra ID app.
The booking agent account
Microsoft 365 does not let an account outside your organisation book a resource. So when someone books an Offision-only account, the booking has to be made on behalf of a Microsoft 365 account — the Booking agent account.
Without one, only the accounts you have connected can book your synced rooms, and everyone else silently cannot. Set one up as part of Sync rooms from Microsoft 365, and use a new account created for the purpose rather than a real person’s.
You are not locked in
From the integration’s actions menu you can convert between modes later.
- The three modes that reach user calendars — delegate mode, Standard mode and the delegated Complete mode — convert freely among themselves.
- Resource calendar mode and Resource only mode convert both ways.
- Resource only mode to Complete mode is one-way.
- Application mode to your own application permission is one-way.
The two one-way conversions are one-way because going back means asking your administrator to approve Offision all over again, so Offision does not offer it as though it were a toggle.
Where to start
Open IntegrationsOnce connected, the things worth setting up next are people, rooms and sign-in.

