We are using an app as method of authentication in order to connect to user mailboxes and retrieve email for analyses purposes.
Everything is working, however, our "app" has to much access and I need to know how to limit it to only allow access to certain users / groups?
Current setup:
App was created by an admin (who is also an owner of the app)
Mail Read permissions are set
But this permission gives our "app" access to all of the mail boxes.
Question:
How can this app be limited to have access only to certain mail boxes / users / groups?