---
sourceDocument: Zurich Employee Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/employee-service-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Employee Service Management

ft:clusterId :

    - emplsm

bundleId :

    - emplsm

workflow :

    - Employee


---

# Create a personal authentication mode connection

# Create a personal authentication mode connection with Microsoft Exchange Online {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Create a personal authentication mode connection with Microsoft Exchange Online

This guide explains how ServiceNow administrators can establish a personal authentication mode connection with Microsoft Exchange Online to synchronize reservations.
Personal authentication mode uses a user-level token that allows users to create, update, or cancel reservations, syncing these events directly with their Microsoft Outlook calendars.
This mode is particularly relevant for user-triggered actions, while system-to-system integrations handle automated synchronization.
Show full answer Show less  

## Key Features

* **Personal Authentication Token:** Enables user-level access to manage reservations on Microsoft Outlook calendars.
* **Subsource Identification:** The new `snwsdrestapi` subsource differentiates reservations coming from REST API calls, facilitating system-to-system credential use within personal mode.
* **Upgrade Handling:** The system automatically sets the synchronization mode (Strict or Normal) based on previous configurations, now controlled by the `snwsdrsvsync.syncintegrationmode` system property at the instance level.
* **Reservation Restrictions:** Personal mode imposes specific restrictions such as:
  * Blocker reservations are created on delegated user calendars with requesters as invitees.
  * On-behalf reservations are disabled for synchronized calendars but allowed for non-synchronized rooms.
  * Group reservations are not supported in personal mode for synchronized rooms but allowed for non-synced rooms.
  * Reservations can only be created by the session user matching the requested-for user.
  * Update and cancellation of reservations depend on the mode and mailbox sync settings, with certain restrictions applied in personal and strict modes.
* **Microsoft Azure Configuration:** Set up OAuth connectivity and a personal authentication mode application registry to authorize Exchange Online connections.
* **Connection and Credential Alias Management:** Create and configure connection and credential aliases for personal authentication mode, with options to customize aliases beyond the defaults.
* **Calendar Provider Setup:** Configure Microsoft Exchange Online as the calendar provider to enable reservation synchronization within the Workplace Calendar Synchronization application using personal authentication mode.

## What Customers Can Expect

By implementing personal authentication mode, ServiceNow customers gain secure, user-centric synchronization of calendar reservations with Microsoft Outlook. This facilitates seamless reservation management for end users while maintaining administrative control through system properties and controlled access. The integration supports various reservation types with defined restrictions to ensure data integrity and compliance with delegated permissions.

Upgrade processes are simplified with automatic mode transitions, and administrators can fine-tune synchronization behavior through instance-level system properties. The configuration steps, including OAuth setup and alias management, provide flexibility to tailor the connection to organizational needs.  
As an admin, establish a personal authentication mode connection with Microsoft Exchange Online to synchronize reservations. A user-level authentication token is generated that enables you to create, update, or cancel reservations to synchronize events on the Microsoft Outlook calendar.

## Integrations {#personal-auth-mode-connection-with-msex__section_g4m_rb3_tdc}

System-to-system integrations are used for all actions that aren't triggered by the user and that must be synchronized with Microsoft Outlook. For all other user-triggered actions, the user's personal token is used.

## Subsources to cater to reservations {#personal-auth-mode-connection-with-msex__section_ul1_bc3_tdc}

A new Subsource, `sn_wsd_rest_api`, has been introduced to distinguish the reservations originating from the REST API. This action enables the use of system-to-system credentials to synchronize the reservations with Microsoft Outlook in personal authentication mode.

## Handling upgrade scenarios {#personal-auth-mode-connection-with-msex__section_jzk_3mh_tdc}

If the Strict mode is enabled for active calendar providers before the upgrade, the system property is automatically set to Strict after the upgrade.

If the Normal mode is configured for active calendar providers before the upgrade, the system property is automatically set to Normal after the upgrade.

The Strict Mode check box is no longer displayed in the calendar provider because the corresponding column has been deprecated in the calendar provider. To configure the Strict mode, you must set the system
property `sn_wsd_rsvsync.sync_integration_mode` at instance level.

Strict mode can now be configured using the system property at the instance level. For more information, see [Set Workplace Calendar Synchronization properties](https://www.servicenow.com/docs/xUaVW9mEzE50IB2LGwcEfQ "Configure the properties for the Workplace Calendar Synchronization to set the Exchange Online Sync Integration Mode to Strict, Personal Authentication, or Normal mode to synchronize reservations.").

## Reservation restrictions {#personal-auth-mode-connection-with-msex__section_ihq_5y2_vdc}

Review the restrictions for creating, updating, or deleting user reservations, as well as for blocker and group reservations, when personal authentication mode is enabled.
{#personal-auth-mode-connection-with-msex__table_dqt_hz2_vdc__entry__2}

| Reservation type | Description |
|-|-|
| Blocker reservations | When Personal mode is enabled, blocker reservations are created in the delegated user's calendar, with the requested for user added as an invitee. If the `sn_wsd_rsv.blocker_user` system property specifies a blocker user, the system creates the reservation in the delegated user's calendar and adds the blocker user as an invitee. |
| Onbehalf user reservation | The This reservation is for field is not displayed in personal authentication mode. In personal mode, you can't create Onbehalf user reservations because you don't have access to other user's calendar. However, you can create on-behalf reservations for non-synchronized rooms. |
| Group reservations | Group reservations aren't supported in Personal mode for synchronize-enabled rooms, even if the Enable group reservations check box is selected in the reservable module. You can create group reservations for non-synced rooms. |
| Create reservation | The following restrictions apply when creating reservations from theWorkplace Service Delivery (WSD) portal, Event planner, Quick Reservation, and Now Mobile: In Personal mode :   If the requested-for user doesn't match the session user, the reservation can't be created. In Strict or Normal mode :   Reservations can be created without any restrictions. |
| Update or cancel reservation | The following restrictions apply when updating or canceling reservations from the WSD portal, Event planner, and Now Mobile: In Normal mode :   All reservations can be updated or canceled. In Personal authentication mode : * If the Sync mailbox of the reservation is set to other (a reservation created in the delegated user calendar), the reservation can be updated or canceled in the delegated user calendar. * If the Sync mailbox is set to user, the following rules apply: * If the reservation is edited or canceled from sources other than WSD Portal, Quick Reservation, WSD Mobile, or Event Planner, it can't be updated or canceled. * If the session user (the person who is updating or canceling the reservation) doesn't match the requested-for user, the reservation can't be edited or canceled. * If a personal token doesn't exist for the user updating or canceling the reservation, the reservation can't be updated or canceled. * In all other cases, the reservation can be updated or canceled. {#personal-auth-mode-connection-with-msex__ul_qqm_d3p_tdc} {#personal-auth-mode-connection-with-msex__ul_phg_c3p_tdc} Note: All the above reservations that can't be updated or canceled appear dimmed in the schedule view of event planner workspace. In Strict mode :   Users can only update or cancel a reservation if the Sync mailbox is set to other in Strict mode. |
[Table 1. Restrictions]

{#personal-auth-mode-connection-with-msex__table_dqt_hz2_vdc}
* **[Configure Microsoft Azure](https://www.servicenow.com/docs/QVzwsBf5kJnVF7_bMsojiQ)**   
  Set up a personal mode of authentication with Microsoft Azure to connect Microsoft Exchange Online with Workplace Calendar Synchronization.
* **[Configure resource rooms in Microsoft Exchange Online](https://www.servicenow.com/docs/tcfhWx~MrNsRKziJvMX5RQ)**   
  Specify your delegated user email in the Microsoft portal to access the resource calendar.
* **[Set up personal authentication mode OAuth connectivity with Microsoft Exchange Online](https://www.servicenow.com/docs/ClOxPNJa0iRmVbMBsVeRyw)**   
  Create a personal authentication mode application registry for Microsoft Exchange Online with your instance for OAuth authorization.
* **[Configure a personal authentication mode Connection and Credential alias for Microsoft Exchange Online](https://www.servicenow.com/docs/38qRtE_oOb0NkFsYME_5Cg)**   
  Establish a personal authentication mode connection and credential alias for Microsoft Exchange Online. Confirm that the values for the connection and credentials alias are set as specified.
* **[Configure your own connection and credential alias for personal authentication mode](https://www.servicenow.com/docs/ZOVtstMplJvHxbve~2o3aQ)**   
  Configure your own connection and credential alias if you don't want to use the default alias created during the personal authentication mode application registration. You can configure your calendar to use the alias as an override alias.
* **[Configure the Microsoft Exchange Online calendar provider in personal authentication mode](https://www.servicenow.com/docs/T7aOz0tq69a77zUgOk12qw)**   
  Enhance your workplace reservation experience with the Workplace Calendar Synchronization application to synchronize reservations with your calendar provider. Configure Microsoft Exchange Online to synchronize reservations with your calendar provider using personal authentication mode.

