Microsoft 365 calendar invites for sessions
Turn session emails into real Outlook invites. Every learner email about an
ILT/VILT session already carries a .ics calendar attachment — but an
attachment is a file the learner must open, it cannot track responses, and if
they delete the email there is nothing left to update. With a Microsoft 365
connection, EmbayLMS creates one Outlook calendar event per published
session in an organizer mailbox you choose, with the registered learners as
attendees:
- The invite lands in each attendee’s calendar (Outlook, and any calendar client on the mailbox) and can be accepted or declined.
- On reschedule the event is updated in place — no second event, no stale time.
- On cancellation the event is withdrawn from every attendee’s calendar.
- The roster stays in step: learners who register (individually, in bulk, or through a series selection) are added; learners who unregister are removed.
The .ics email attachments keep working exactly as before — this connection
augments them, it never replaces them. Tenants without a connection lose
nothing.
How it behaves
- Events are created when a session is published (or when a session is created already-published) in the organizer mailbox’s calendar, and updated within moments of any change. A 6-hourly background pass re-checks every upcoming published session, so a transient failure heals itself.
- Attendees are the session’s registered learners, matched by their EmbayLMS account email. Waitlisted learners have no seat and get no invite — the invite arrives when they are promoted.
- Times are stored in UTC; Outlook shows the session in each viewer’s own time zone.
- Failure is visible, not silent: if an event cannot be created or updated, the error is shown on the connection card (and recorded per session). The session itself is never blocked by a calendar failure.
- The client secret is encrypted at rest (AES-256-GCM) and never displayed again after saving. Configuration changes are audit-logged.
Prerequisites
- The organization Owner, or a member holding a custom role that grants Settings → Integrations.
- Rights to create an app registration and grant admin consent in your Microsoft Entra tenant.
- A mailbox to act as organizer — a shared mailbox such as
training@yourdomain.comis recommended, because attendee responses (accept/decline) are delivered to it.
Step 1 — Register an application (Microsoft Entra admin center)
- In the Microsoft Entra admin center, go to Identity → Applications → App registrations → New registration.
- Name it e.g.
EmbayLMS calendar invites. Leave Supported account types on Accounts in this organizational directory only. No redirect URI is needed. - On the app’s Overview page, copy the Application (client) ID and the Directory (tenant) ID.
Already using the Entra ID group sync? That integration uses its own app registration with read-only group permissions. Keep the two registrations separate so each holds only the permissions it needs.
Step 2 — Grant the application permission and admin consent
-
On the app registration, open API permissions → Add a permission → Microsoft Graph → Application permissions and add:
Calendars.ReadWrite -
Click Grant admin consent for your tenant.
-
Open Certificates & secrets → New client secret, choose an expiry, and copy the secret Value immediately (it is only shown once).
-
Recommended:
Calendars.ReadWriteas an application permission covers every mailbox in your tenant. Scope it to just the organizer mailbox with an Exchange Online application access policy:New-ApplicationAccessPolicy -AppId <client-id> -PolicyScopeGroupId <mail-enabled-security-group-containing-the-organizer> -AccessRight RestrictAccessEmbayLMS only ever touches the organizer mailbox, so the policy costs nothing and caps the blast radius of the credential.
Step 3 — Connect EmbayLMS
- In EmbayLMS, go to Settings → Integrations → Calendar.
- Enter the Directory (tenant) ID, Application (client) ID, the client secret, and the organizer mailbox address.
- Click Connect. EmbayLMS validates the credentials by reading the organizer’s calendar live before saving; if the call fails, nothing is stored.
From that point on, publishing a session creates its Outlook event automatically. There is nothing to configure per session.
Configuration reference
| Field | Required | Description |
|---|---|---|
| Directory (tenant) ID | Yes | Your Entra tenant’s GUID (or a verified domain). From the app registration’s Overview page. |
| Application (client) ID | Yes | The app registration’s client ID. Shown as the connection fingerprint. |
| Client secret | Yes | A secret value from Certificates & secrets. Encrypted at rest; never displayed again. Re-enter a new one here before expiry. |
| Organizer mailbox | Yes | The mailbox (UPN) session events are created in and invites are sent from. A shared mailbox is recommended. |
| Enabled / Paused | — | Pausing keeps the credential but stops creating and updating events. |
Troubleshooting
| Symptom | Likely cause / fix |
|---|---|
| Connect fails: “Could not read the organizer’s calendar” | The usual causes: (1) admin consent was not granted for Calendars.ReadWrite (Step 2); (2) an application access policy excludes the organizer mailbox — add it to the policy’s group; (3) the organizer address is not a real mailbox (a distribution list won’t work); (4) the secret expired or its Secret ID was pasted instead of its Value. |
| Sessions publish but no invites arrive | Check the connection card for a sync error. If the connection is Paused, resume it — the next background pass (within 6 hours) reconciles every upcoming session, or edit and re-save the session to trigger it immediately. |
| A learner registered but didn’t get the invite | Their EmbayLMS account email must be a real mailbox reachable from your Microsoft 365 tenant. External addresses receive standard invitation emails from Exchange rather than an auto-placed calendar entry. |
| The event shows in the wrong time zone | Events are stored in UTC; Outlook renders them in each viewer’s configured time zone. Check the viewer’s Outlook time-zone setting — the stored session time is absolute. |
| Client secret is about to expire | Create a new secret in Certificates & secrets and re-enter the connection form — saving replaces the stored secret in place. |
Limitations (v1)
- Attendee responses (accept/decline) are visible in the organizer mailbox’s calendar, not inside EmbayLMS.
- One event per session in one organizer mailbox — instructor-mailbox organizers are not yet supported.
- Disconnecting or pausing leaves already-created events standing; cancel the sessions to withdraw their invites.