CalPair guide · Microsoft 365

Which calendars can sync — with which permissions?

Choose the app's permissions. Then see which calendars it can read, change and synchronize, and how it can detect updates.

CalPair currently requests Calendars.ReadWrite for your own calendars. The selection below starts there.

1Which scopes has the user granted to the app?

All four are delegated permissions: the app acts through a personal user login. “Shared” expands the calendars it may access.

ReadWrite already includes reading. A tick means the permission is actually granted in the access token, not just configured in Microsoft Entra.

Other calendar in the sync pair:

The other calendar has its own connection and permissions. These two checks represent its effective app access.

2Compare the three calendar types

✓ Possible — requirements met× Blocked — missing scope or access? Check — needs explicit validation
Special case: a shared custom calendar visible in the user's own mailbox. Microsoft documents that some shared custom calendars can be accessed with standard Calendars.Read / ReadWrite through the user's mailbox. The shared/delegated panel above models direct access to the owner's mailbox. The local-copy case must be checked separately; it is not a general Shared Mailbox workaround.

This explorer shows Microsoft API capabilities. It does not claim that a specific sync app has implemented every permitted path. Free / busy access is not enough to copy appointment details.

3How the permissions and updates work together

Scope + user access = effective permission

The app needs the correct scope. For another person's or a shared mailbox's calendar, the user also needs a calendar grant. A scope never grants mailbox membership.

Push tells the app “something changed”

The app then processes the change. For shared/delegated calendars, this personal-login model cannot use push. App-only access is a different admin-approved model.

Polling checks for changes regularly

Possible whenever the app can read the calendar. Updates can arrive with a delay. Reliable deletion, recurrence and conflict handling depend on the sync app.

IT details: app-only access, private events and sources
  • Other CalPair sign-in scopes: User.Read identifies the signed-in user; offline_access lets the connection remain usable between sign-ins. Neither adds calendar access.
  • Own-calendar push: Microsoft's subscription documentation lists Calendars.Read as the least privileged permission. Calendars.ReadWrite also provides read access. A shared-only token still reads own calendars, but subscription acceptance should be validated; this explorer marks that combination “Check”.
  • Shared/delegated push: requires the corresponding application permission, such as Calendars.Read, with admin consent and an appropriate mailbox access scope. Delegated Shared permissions do not support subscriptions to these folders. This is not enabled by checking more delegated scopes above.
  • Shared mailbox access: Full Access normally includes its calendar. A calendar-specific grant may provide only reading or editing. No direct shared mailbox login is needed.
  • Private appointments: details can be hidden depending on the user's calendar grant. Send As / Send on Behalf, meeting invitations and meeting ownership are separate from copying calendar appointments.
  • Polling is not the same as Delta: reading allows regular checks. Availability of an incremental Delta path and safe deletion detection must be validated for the exact calendar access path.
  • Bidirectional: both calendars must allow reading and writing through their respective connections. Updates and deletions only propagate according to the sync app's selected rules.

Microsoft scope reference · Shared/delegated API access and local-copy exception · Push notification permissions and limits · Shared mailbox access