There are two ways that permissions can be given to a service account for GAL or Public Folder sync to user mailboxes:
- The IT Admin can delegate user permissions to their service accounts.
- The IT Admin can also set impersonation mode on their service account.
This guide shows how to set up impersonation mode on a service account.
NOTE: More information on Application Impersonation and service account permissions can be found here: Exchange Service Account Permissions and itrezzo Contact Management.
- Launch the Office 365 Admin Portal.
- Click Admin centers > Exchange to display the Admin Exchange Center dialog box. (See figure below.)
- Click permissions in the navigation panel.
- Click + to add a new role group and name the group in admin roles. In this example, the new group is named App Impersonation.
- Click + under Roles, and add the Application Impersonation Role.
- Click + under Members, and add the service account of choice.
- Click Save. NOTE: It can take 30–40 minutes for the Application Impersonation role to apply on the service account and replicate across Office 365 services. (See figure below.)