Microsoft 365

Calendar permissions in Exchange Online: Add-MailboxFolderPermission guide

Share calendars, change the organization-wide Default permission and add calendar delegates in Exchange Online with Add-, Set- and Remove-MailboxFolderPermission, including localized folder names.

9 min read
On this page

To set calendar permissions in Exchange Online, run Add-MailboxFolderPermission -Identity owner@contoso.com:\Calendar -User viewer@contoso.com -AccessRights Reviewer, choosing a role such as AvailabilityOnly, LimitedDetails, Reviewer or Editor. Use Set-MailboxFolderPermission to change an entry that already exists, including the organization-wide Default entry, and add -SharingPermissionFlags Delegate to the Editor role when the person should act as a calendar delegate who receives meeting requests.

Who this is for and what you will have at the end

This guide is for Exchange Online administrators who get requests like "let the team see my calendar", "my assistant needs to manage my meetings" or "everyone should see subjects, not just busy blocks". These are folder-level permissions, which are different from mailbox-level Full Access, Send As and Send on Behalf; those are covered in Full Access, Send As and Send on Behalf in Exchange Online.

At the end you will know which role to pick, how to grant, change and remove calendar permissions for users and groups, how to change what the whole organization sees, how to add and remove delegates correctly, how to handle mailboxes whose Calendar folder has a localized name, and how to fix the errors these cmdlets return.

Calendar roles and what they allow

-AccessRights takes either a role or individual permissions. These are the roles that matter for calendars:

RoleWhat the user can doTypical use
AvailabilityOnlyView free/busy onlyOrg-wide visibility
LimitedDetailsView free/busy with subject and locationTeams that need to see what a slot is for
ReviewerRead items (FolderVisible, ReadItems)Read-only access to the full calendar
AuthorCreate and read items, edit and delete own itemsBooking into a shared calendar
EditorCreate, read, edit and delete all itemsAssistants and co-managers
OwnerEverything Editor can do plus create subfolders and manage the folderRarely needed for people
NoneNo accessExplicitly removing visibility

The two calendar-only roles are AvailabilityOnly and LimitedDetails. Editor is the only role that can be combined with delegate flags.

The Default and Anonymous entries

Every calendar has two built-in entries:

  • Default applies to everyone in your organization who doesn't have their own entry. It is also what determines the free/busy detail users in a remote forest see in Scheduling Assistant in hybrid setups.
  • Anonymous applies to unauthenticated users.

You can't remove either entry; an attempt fails with "Cannot remove default or anonymous permissions." You can only change them with Set-MailboxFolderPermission. When you check a calendar, always look at the Default entry first, because it is the baseline every other entry adds to.

Prerequisites

  • Exchange Online PowerShell and an account with recipient management permissions.
  • The owner's mailbox address and the delegate's address. The -User value can be a mailbox, a mail user or a mail-enabled security group (nested mail-enabled security groups are supported).
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com

The folder identity always has the form Mailbox:\Folder, for example ayla@contoso.com:\Calendar. A secondary calendar is a subfolder: ayla@contoso.com:\Calendar\HR Leave. If the folder name contains spaces, quote the whole identity.

Step 1: Confirm the calendar folder name

The folder is only called Calendar in English mailboxes. If the owner's mailbox language is, for example, German or Swedish, the folder is Kalender, and ayla@contoso.com:\Calendar fails with "The operation couldn't be performed because '...:\Calendar' couldn't be found."

List the calendar folders and their real names:

Get-MailboxFolderStatistics -Identity ayla@contoso.com -FolderScope Calendar | Format-Table Name,FolderPath,FolderType

The default calendar is the folder whose FolderType is Calendar. In scripts, build the identity from that value instead of hard-coding the name:

$mbx  = "ayla@contoso.com"
$name = (Get-MailboxFolderStatistics -Identity $mbx | Where-Object { $_.FolderType -eq "Calendar" } | Select-Object -First 1).Name
$cal  = "$($mbx):\$name"
$cal

The rest of this guide uses ayla@contoso.com:\Calendar; substitute the localized path where needed.

Step 2: Review the current permissions

Get-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar
Get-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User ed@contoso.com

The output lists each user or group with its access rights. Note whether the person you want to change already has an entry, because that decides whether you use Add- or Set-.

Step 3: Grant viewing access

Read-only access with full details:

Add-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User ed@contoso.com -AccessRights Reviewer

Subject and location only, for a whole team through a mail-enabled security group:

Add-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User sales-team@contoso.com -AccessRights LimitedDetails

To also send the person a normal calendar sharing invitation, add -SendNotificationToUser $true. This works only on calendar folders and only with AvailabilityOnly, LimitedDetails, Reviewer or Editor. The default is $false, so by default the person gets the access silently and has to open the calendar themselves.

Step 4: Change an existing entry

Set-MailboxFolderPermission replaces the user's access rights on the folder:

Set-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User ed@contoso.com -AccessRights Editor

Change what everyone in the organization sees on one calendar by changing the Default entry:

Set-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User Default -AccessRights LimitedDetails

To apply the same Default setting to every user mailbox, including those with localized folder names:

$mailboxes = Get-Mailbox -RecipientTypeDetails UserMailbox -ResultSize Unlimited
foreach ($m in $mailboxes) {
    $name = (Get-MailboxFolderStatistics -Identity $m.UserPrincipalName | Where-Object { $_.FolderType -eq "Calendar" } | Select-Object -First 1).Name
    Set-MailboxFolderPermission -Identity "$($m.UserPrincipalName):\$name" -User Default -AccessRights LimitedDetails
}

This only changes existing mailboxes. Mailboxes created afterwards keep whatever Default permission they were created with until you run it again, so schedule it if you want the setting to stick.

Step 5: Add a calendar delegate

A delegate is more than an editor: they receive meeting requests and responses for the owner and can respond to them. In Exchange Online this is controlled by -SharingPermissionFlags, which only works with the Editor role and only on calendar folders.

# Delegate without access to private items
Add-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User julia@contoso.com -AccessRights Editor -SharingPermissionFlags Delegate
 
# Delegate who can also see private items
Add-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User laura@contoso.com -AccessRights Editor -SharingPermissionFlags Delegate,CanViewPrivateItems

The flags:

FlagEffect
NoneNo delegate behavior (default on Add)
DelegateThe user becomes a calendar delegate and receives meeting invites and responses. If there are no other delegates, Exchange creates the meeting message rule; otherwise the user is added to it
CanViewPrivateItemsThe user can see private items; must be combined with Delegate

Without the Delegate flag, an Editor can still accept or decline meetings, but only by opening the request in the owner's mailbox manually.

One setting can't be changed from PowerShell: Outlook's option that controls whether meeting requests go to the delegates only or to both the delegates and the owner. Microsoft documents that this has to be set in Outlook or through Exchange Web Services.

If you are tempted to give an assistant Full Access instead, remember that in Exchange Online Full Access exposes all items, including private calendar items. Folder permissions let you keep private appointments private.

Step 6: Change or remove a delegate

Set-MailboxFolderPermission has a subtle behavior with delegates. If you don't use -SendNotificationToUser or -SharingPermissionFlags, the user's delegate status is left alone. If you use -SendNotificationToUser without -SharingPermissionFlags, the flags fall back to None and the user stops being a delegate.

# Change rights, keep current delegate status
Set-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User ed@contoso.com -AccessRights Editor
 
# Remove access to private items, stay a delegate
Set-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User ed@contoso.com -AccessRights Editor -SharingPermissionFlags Delegate
 
# Turn a delegate back into a plain Editor
Set-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User ed@contoso.com -AccessRights Editor -SharingPermissionFlags None

To remove someone's access to the calendar completely:

Remove-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -User ed@contoso.com -Confirm:$false

Remove-MailboxFolderPermission removes all of that user's permissions on the folder; it can't remove only some of them. To reduce access rather than remove it, use Set-. In Exchange Online you can add -SendNotificationToUser $true to tell the person their access was removed.

Verify

Get-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar

Check that the person has the expected access rights. Then ask the person to open the calendar in Outlook on the web; for delegates, send a test meeting request to the owner and confirm the delegate receives it.

Troubleshooting

Error or symptomCauseFix
"An existing permission entry was found for user: ..."Add- was used for someone who already has an entry, often DefaultUse Set-MailboxFolderPermission
"Cannot remove default or anonymous permissions."Remove- was used on Default or AnonymousUse Set- with -AccessRights None or the role you want
"The operation couldn't be performed because '...:\Calendar' couldn't be found."Localized folder name, a typo in the address, or the wrong path for a secondary calendarFind the name with Get-MailboxFolderStatistics -FolderScope Calendar
A delegate stopped receiving meeting requests after a changeSet- was run with -SendNotificationToUser but no flags, resetting them to NoneRun Set- again with -SharingPermissionFlags Delegate
Adding, changing or removing delegates fails repeatedlyCorrupted delegate information in the mailboxRun Remove-MailboxFolderPermission -Identity ayla@contoso.com:\Calendar -ResetDelegateUserCollection, then grant delegate access again
-SharingPermissionFlags is rejectedThe role isn't Editor, or the folder isn't a calendarUse -AccessRights Editor on the calendar folder

About -ResetDelegateUserCollection: it deletes the delegate information files in the mailbox and downgrades every existing delegate to plain Editor, so you have to add each delegate again with -SharingPermissionFlags Delegate. The identity must be the user's primary calendar folder.

Sharing with people outside the organization

Folder permissions cover people inside your tenant. Sharing calendars with external people is a separate, tenant-level decision: in the Microsoft 365 admin center go to Settings > Org Settings > Services > Calendar and choose whether users can share with people in other Microsoft 365 or Exchange organizations, and whether anonymous access through an email invitation is allowed, with free/busy only, free/busy with subject and location, or all details. Users then share their own calendars from Outlook on the web.

Summary checklist

  • Find the real calendar folder name before scripting.
  • Read current permissions first; it decides between Add- and Set-.
  • Pick the smallest role that works: AvailabilityOnly, LimitedDetails, Reviewer, then Editor.
  • Change Default and Anonymous only with Set-.
  • Delegates are Editor plus -SharingPermissionFlags Delegate; add CanViewPrivateItems only when needed.
  • Don't use -SendNotificationToUser on an existing delegate without also specifying the flags.
  • Use -ResetDelegateUserCollection only for broken delegate data, and re-add delegates afterwards.

References

Questions people ask

How do I give someone read access to another user's calendar?

Run Add-MailboxFolderPermission -Identity user@contoso.com:\Calendar -User viewer@contoso.com -AccessRights Reviewer. Reviewer shows full item details; use LimitedDetails for subject and location only, or AvailabilityOnly for free/busy only.

What is the difference between Add-MailboxFolderPermission and Set-MailboxFolderPermission?

Add creates a new permission entry for a user who has none on that folder. Set changes an existing entry and replaces its access rights. If you run Add for someone who already has an entry, including the built-in Default user, the command fails with "An existing permission entry was found for user".

How do I make someone a calendar delegate with PowerShell?

Use the Editor role with -SharingPermissionFlags Delegate, for example Add-MailboxFolderPermission -Identity manager@contoso.com:\Calendar -User assistant@contoso.com -AccessRights Editor -SharingPermissionFlags Delegate. Add CanViewPrivateItems to the flags if the delegate should see private appointments.

Why does PowerShell say the Calendar folder couldn't be found?

A common cause is a mailbox in another language, where the folder has a localized name such as Kalender. Find the real name with Get-MailboxFolderStatistics -FolderScope Calendar and use it in the Identity value instead of Calendar.

Exchange OnlineExchange Online PowerShellOutlook calendar
  1. Convert a user mailbox to a shared mailbox and remove the license safely

    Keep a leaver's email and calendar in Exchange Online without paying for a license: secure the account, convert the mailbox, grant access, then remove the license in the right order.

    Microsoft 36511 min read
  2. EWS retirement in Exchange Online: find EWS apps and set EWSAllowedAppIDs

    Find every app that still calls Exchange Web Services, build an EWSAllowedAppIDs allow list and set EWSEnabled so critical apps keep working while EWS is switched off from October 2026.

    Microsoft 36513 min read
  3. Exchange hybrid remote move migration: endpoints, batches and completion

    Move mailboxes from on-premises Exchange to Exchange Online with remote move migration: enable MRS Proxy, test the endpoint, build batches, schedule completion and clean up.

    Microsoft 36512 min read