To set calendar permissions in Exchange Online, run Add-MailboxFolderPermission -Identity owner@contoso.com:\Calendar -User viewer@contoso.com -AccessRights Reviewer, choosing a role such as AvailabilityOnly, LimitedDetails, Reviewer or Editor. Use Set-MailboxFolderPermission to change an entry that already exists, including the organization-wide Default entry, and add -SharingPermissionFlags Delegate to the Editor role when the person should act as a calendar delegate who receives meeting requests.
Who this is for and what you will have at the end
This guide is for Exchange Online administrators who get requests like "let the team see my calendar", "my assistant needs to manage my meetings" or "everyone should see subjects, not just busy blocks". These are folder-level permissions, which are different from mailbox-level Full Access, Send As and Send on Behalf; those are covered in Full Access, Send As and Send on Behalf in Exchange Online.
At the end you will know which role to pick, how to grant, change and remove calendar permissions for users and groups, how to change what the whole organization sees, how to add and remove delegates correctly, how to handle mailboxes whose Calendar folder has a localized name, and how to fix the errors these cmdlets return.
Calendar roles and what they allow
-AccessRights takes either a role or individual permissions. These are the roles that matter for calendars:
| Role | What the user can do | Typical use |
|---|---|---|
AvailabilityOnly | View free/busy only | Org-wide visibility |
LimitedDetails | View free/busy with subject and location | Teams that need to see what a slot is for |
Reviewer | Read items (FolderVisible, ReadItems) | Read-only access to the full calendar |
Author | Create and read items, edit and delete own items | Booking into a shared calendar |
Editor | Create, read, edit and delete all items | Assistants and co-managers |
Owner | Everything Editor can do plus create subfolders and manage the folder | Rarely needed for people |
None | No access | Explicitly removing visibility |
The two calendar-only roles are AvailabilityOnly and LimitedDetails. Editor is the only role that can be combined with delegate flags.
The Default and Anonymous entries
Every calendar has two built-in entries:
- Default applies to everyone in your organization who doesn't have their own entry. It is also what determines the free/busy detail users in a remote forest see in Scheduling Assistant in hybrid setups.
- Anonymous applies to unauthenticated users.
You can't remove either entry; an attempt fails with "Cannot remove default or anonymous permissions." You can only change them with Set-MailboxFolderPermission. When you check a calendar, always look at the Default entry first, because it is the baseline every other entry adds to.
Prerequisites
- Exchange Online PowerShell and an account with recipient management permissions.
- The owner's mailbox address and the delegate's address. The
-Uservalue can be a mailbox, a mail user or a mail-enabled security group (nested mail-enabled security groups are supported).
Connect-ExchangeOnline -UserPrincipalName admin@contoso.comThe folder identity always has the form Mailbox:\Folder, for example ayla@contoso.com:\Calendar. A secondary calendar is a subfolder: ayla@contoso.com:\Calendar\HR Leave. If the folder name contains spaces, quote the whole identity.
Step 1: Confirm the calendar folder name
The folder is only called Calendar in English mailboxes. If the owner's mailbox language is, for example, German or Swedish, the folder is Kalender, and ayla@contoso.com:\Calendar fails with "The operation couldn't be performed because '...:\Calendar' couldn't be found."
List the calendar folders and their real names:
Get-MailboxFolderStatistics -Identity ayla@contoso.com -FolderScope Calendar | Format-Table Name,FolderPath,FolderTypeThe default calendar is the folder whose FolderType is Calendar. In scripts, build the identity from that value instead of hard-coding the name:
$mbx = "ayla@contoso.com"
$name = (Get-MailboxFolderStatistics -Identity $mbx | Where-Object { $_.FolderType -eq "Calendar" } | Select-Object -First 1).Name
$cal = "$($mbx):\$name"
$calThe rest of this guide uses ayla@contoso.com:\Calendar; substitute the localized path where needed.
Step 2: Review the current permissions
Get-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar
Get-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User ed@contoso.comThe output lists each user or group with its access rights. Note whether the person you want to change already has an entry, because that decides whether you use Add- or Set-.
Step 3: Grant viewing access
Read-only access with full details:
Add-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User ed@contoso.com -AccessRights ReviewerSubject and location only, for a whole team through a mail-enabled security group:
Add-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User sales-team@contoso.com -AccessRights LimitedDetailsTo also send the person a normal calendar sharing invitation, add -SendNotificationToUser $true. This works only on calendar folders and only with AvailabilityOnly, LimitedDetails, Reviewer or Editor. The default is $false, so by default the person gets the access silently and has to open the calendar themselves.
Step 4: Change an existing entry
Set-MailboxFolderPermission replaces the user's access rights on the folder:
Set-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User ed@contoso.com -AccessRights EditorChange what everyone in the organization sees on one calendar by changing the Default entry:
Set-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User Default -AccessRights LimitedDetailsTo apply the same Default setting to every user mailbox, including those with localized folder names:
$mailboxes = Get-Mailbox -RecipientTypeDetails UserMailbox -ResultSize Unlimited
foreach ($m in $mailboxes) {
$name = (Get-MailboxFolderStatistics -Identity $m.UserPrincipalName | Where-Object { $_.FolderType -eq "Calendar" } | Select-Object -First 1).Name
Set-MailboxFolderPermission -Identity "$($m.UserPrincipalName):\$name" -User Default -AccessRights LimitedDetails
}This only changes existing mailboxes. Mailboxes created afterwards keep whatever Default permission they were created with until you run it again, so schedule it if you want the setting to stick.
Step 5: Add a calendar delegate
A delegate is more than an editor: they receive meeting requests and responses for the owner and can respond to them. In Exchange Online this is controlled by -SharingPermissionFlags, which only works with the Editor role and only on calendar folders.
# Delegate without access to private items
Add-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User julia@contoso.com -AccessRights Editor -SharingPermissionFlags Delegate
# Delegate who can also see private items
Add-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User laura@contoso.com -AccessRights Editor -SharingPermissionFlags Delegate,CanViewPrivateItemsThe flags:
| Flag | Effect |
|---|---|
None | No delegate behavior (default on Add) |
Delegate | The user becomes a calendar delegate and receives meeting invites and responses. If there are no other delegates, Exchange creates the meeting message rule; otherwise the user is added to it |
CanViewPrivateItems | The user can see private items; must be combined with Delegate |
Without the Delegate flag, an Editor can still accept or decline meetings, but only by opening the request in the owner's mailbox manually.
One setting can't be changed from PowerShell: Outlook's option that controls whether meeting requests go to the delegates only or to both the delegates and the owner. Microsoft documents that this has to be set in Outlook or through Exchange Web Services.
If you are tempted to give an assistant Full Access instead, remember that in Exchange Online Full Access exposes all items, including private calendar items. Folder permissions let you keep private appointments private.
Step 6: Change or remove a delegate
Set-MailboxFolderPermission has a subtle behavior with delegates. If you don't use -SendNotificationToUser or -SharingPermissionFlags, the user's delegate status is left alone. If you use -SendNotificationToUser without -SharingPermissionFlags, the flags fall back to None and the user stops being a delegate.
# Change rights, keep current delegate status
Set-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User ed@contoso.com -AccessRights Editor
# Remove access to private items, stay a delegate
Set-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User ed@contoso.com -AccessRights Editor -SharingPermissionFlags Delegate
# Turn a delegate back into a plain Editor
Set-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User ed@contoso.com -AccessRights Editor -SharingPermissionFlags NoneTo remove someone's access to the calendar completely:
Remove-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User ed@contoso.com -Confirm:$falseRemove-MailboxFolderPermission removes all of that user's permissions on the folder; it can't remove only some of them. To reduce access rather than remove it, use Set-. In Exchange Online you can add -SendNotificationToUser $true to tell the person their access was removed.
Verify
Get-MailboxFolderPermission -Identity ayla@contoso.com:\CalendarCheck that the person has the expected access rights. Then ask the person to open the calendar in Outlook on the web; for delegates, send a test meeting request to the owner and confirm the delegate receives it.
Troubleshooting
| Error or symptom | Cause | Fix |
|---|---|---|
| "An existing permission entry was found for user: ..." | Add- was used for someone who already has an entry, often Default | Use Set-MailboxFolderPermission |
| "Cannot remove default or anonymous permissions." | Remove- was used on Default or Anonymous | Use Set- with -AccessRights None or the role you want |
| "The operation couldn't be performed because '...:\Calendar' couldn't be found." | Localized folder name, a typo in the address, or the wrong path for a secondary calendar | Find the name with Get-MailboxFolderStatistics -FolderScope Calendar |
| A delegate stopped receiving meeting requests after a change | Set- was run with -SendNotificationToUser but no flags, resetting them to None | Run Set- again with -SharingPermissionFlags Delegate |
| Adding, changing or removing delegates fails repeatedly | Corrupted delegate information in the mailbox | Run Remove-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -ResetDelegateUserCollection, then grant delegate access again |
-SharingPermissionFlags is rejected | The role isn't Editor, or the folder isn't a calendar | Use -AccessRights Editor on the calendar folder |
About -ResetDelegateUserCollection: it deletes the delegate information files in the mailbox and downgrades every existing delegate to plain Editor, so you have to add each delegate again with -SharingPermissionFlags Delegate. The identity must be the user's primary calendar folder.
Sharing with people outside the organization
Folder permissions cover people inside your tenant. Sharing calendars with external people is a separate, tenant-level decision: in the Microsoft 365 admin center go to Settings > Org Settings > Services > Calendar and choose whether users can share with people in other Microsoft 365 or Exchange organizations, and whether anonymous access through an email invitation is allowed, with free/busy only, free/busy with subject and location, or all details. Users then share their own calendars from Outlook on the web.
Summary checklist
- Find the real calendar folder name before scripting.
- Read current permissions first; it decides between
Add-andSet-. - Pick the smallest role that works: AvailabilityOnly, LimitedDetails, Reviewer, then Editor.
- Change Default and Anonymous only with
Set-. - Delegates are
Editorplus-SharingPermissionFlags Delegate; addCanViewPrivateItemsonly when needed. - Don't use
-SendNotificationToUseron an existing delegate without also specifying the flags. - Use
-ResetDelegateUserCollectiononly for broken delegate data, and re-add delegates afterwards.
References
- Add-MailboxFolderPermission
- Set-MailboxFolderPermission
- Get-MailboxFolderPermission
- Remove-MailboxFolderPermission
- Get-MailboxFolderStatistics
- Add-MailboxPermission
- Office 365: Finding the name of the Calendar folder (archived Microsoft blog)
- PowerShell modify Default/Anonymous mailbox folder permissions (archived Microsoft forum)
- Exchange PowerShell: calendar couldn't be found (Microsoft Q&A)
- Share Microsoft 365 calendars with users outside your organization
- Only see basic free/busy mailbox information
- Connect to Exchange Online PowerShell