ISO 27001 Annex A control 7.2 requires secure areas to be protected by appropriate entry controls and access points, which means visitors should be authorized before they reach a restricted door or reception checkpoint. Microsoft Bookings secure area visitor approval settings can satisfy the pre-authorization and recordkeeping portion of this control by requiring a designated staff member to approve each visitor request before the visitor receives confirmation; the physical badge, identity check, and door-access decision must still occur on site.
How do you configure Microsoft Bookings secure area visitor approval settings?
Use a dedicated shared Bookings calendar for visitor requests rather than adding secure-area appointments to a general sales, support, or recruiting calendar. This keeps approvals, visitor details, and staff notifications separate from ordinary business appointments and gives an assessor a clearly defined workflow to review.
-
Confirm that shared Bookings is enabled for the tenant. Sign in as a Microsoft 365 administrator and go to
Microsoft 365 admin center > Settings > Org settings > Bookings. Confirm thatAllow your organization to use Bookingsis enabled. Also confirm that users who will own the process are permitted to create and manage shared Bookings pages.Limit Bookings administration to the facilities, security, reception, or operations staff who own the approval process. A finance or COO sponsor should ask for this ownership list, because a visitor workflow without a named business owner becomes an unattended mailbox risk.
-
Create a dedicated visitor-request calendar. Open the Microsoft 365 app launcher, select
Bookings, selectShared bookings, and chooseNew booking calendar. Name itSecure Area Visitor Requests. Enter the reception address, business hours, time zone, and a monitored operational email address.Add the people responsible for approval under
Staff. At least two trained approvers should be assigned so absence does not cause requests to be approved informally or left pending. Typical staff members are a facilities coordinator, reception lead, security lead, and the internal host’s delegate. -
Create a service that represents a visitor request, not a guaranteed visit. Go to
Services > Add a service. Use a clear service name such asSecure-Area Visitor Request. Set a short duration, such as15 minutes, because the scheduled slot represents the arrival and check-in window rather than the visitor’s full working day.Set
Locationto a controlled reception point, such asMain Reception — wait for host and badge issue. Do not list a data center room, laboratory suite, executive floor, records room, or other restricted destination as the public location. -
Turn on approval before confirmation. Within the new service, open
Scheduling policyorAdvanced options, depending on the Bookings interface displayed in your tenant. EnableRequire staff approval. Assign the designated approval staff to the service underStaff, then save the service.With this setting enabled, a visitor’s request is not automatically treated as an approved appointment. The assigned staff member must approve or decline it, creating the core Bookings visitor-approval workflow needed for pre-entry authorization.
-
Collect the information an approver needs to make a decision. From
Services > Secure-Area Visitor Request > Custom fields, selectAdd a questionand make each field required where appropriate. Useful fields include:Visitor legal name— required text field.Company or employer— required text field.Internal host name and email address— required text field.Purpose of visit— required text field.Requested secure area— required dropdown field, using non-sensitive choices such asEngineering suite,Operations office, orControlled work area.Will the visitor require escorted access?— required dropdown withYesandNo.
Do not use Bookings custom fields to collect government ID numbers, health information, security-clearance details, or other unnecessary sensitive data. The approval record should contain enough information to authorize a visit, not become an uncontrolled identity-document repository.
-
Publish only the visitor-request service. Go to
Booking page. UnderAccess control, select the option appropriate to the visitor population. If outside vendors need to request access, use the external/public booking-page option but publish only this dedicated calendar. If requests are limited to employees or authenticated contractors, selectAvailable to people in your organizationor the more restrictive organization-specific option available in your tenant.Enable
Disable direct search engine indexing of booking pageif that option is shown. SelectSave and publish, then distribute the booking-page link only through the vendor onboarding, visitor invitation, or internal host process.
| Bookings setting | Recommended secure-area value | Control purpose |
|---|---|---|
Require staff approval |
Enabled | Prevents automatic confirmation of visitor requests. |
Staff |
Reception lead, facilities coordinator, security delegate | Assigns accountable people to approve or decline requests. |
Location |
Main Reception — wait for host and badge issue | Directs visitors to a controlled entry point. |
Custom fields |
Visitor, employer, host, purpose, requested area, escort need | Provides decision-making and audit information. |
How should the approval workflow work in practice?
At a 180-person healthcare technology vendor called Meridian Care Systems, external implementation consultants periodically need access to an engineering suite where the company supports hospital interface deployments and maintains integration test systems. The internal project manager submits or sponsors the request, reception verifies the visitor’s name against the approved Bookings appointment, and the facilities coordinator confirms that an escort is assigned before approving the request.
The approval should follow a written business rule: verify the internal host, confirm the purpose and requested date, determine whether an escort is mandatory, and decline requests that lack a sponsor or request inappropriate access. The approver should not approve a request merely because the visitor selected an available time. Availability is scheduling information; approval is an authorization decision.
How do you verify that the Bookings approval setting took effect?
Open the published booking page in a private browser window or a non-administrator test account.
Submit a test request using a realistic external visitor name, internal host, and secure-area selection.
Confirm that the request appears in the
Secure Area Visitor Requestscalendar as requiring action rather than as an automatically approved visit.Confirm that the assigned approval staff receive the request notification and can approve or decline it.
Approve the test request, then confirm the visitor receives the confirmation only after approval.
Run a second test and decline it. Confirm that the visitor is not sent instructions that imply access has been granted.
For Meridian Care Systems, the operations manager performs this test quarterly and after any change to reception staffing, Bookings ownership, or the visitor-request form. This is a low-cost control check that identifies an accidentally disabled approval setting before a real visitor uses the page.
What evidence should you capture for an ISO 27001 assessor?
An assessor evaluating ISO 27001 control 7.2 will want to see that the process is configured, operating, and connected to the physical entry procedure. Capture evidence from both Bookings and the reception process.
A screenshot of
Services > Secure-Area Visitor Requestshowing the service name, controlled reception location, assigned staff, andRequire staff approvalenabled.A screenshot of the
Custom fieldsconfiguration showing required host, employer, purpose, requested-area, and escort questions.A screenshot of
Booking page > Access control, including the selected audience and search-engine indexing setting.A redacted example of a completed request showing the request status, approver, internal host, and approval date.
A redacted approval notification and confirmation email demonstrating that confirmation followed approval.
An export or screenshot from
Microsoft Purview portal > Audit > Search, where available, covering Bookings-related activity for the review period.The current visitor-management procedure describing identity verification, badge issuance, escort requirements, badge return, and how reception handles a visitor who arrives without an approved booking.
Where does Microsoft Bookings fall short for physical-entry control?
Microsoft Bookings is an approval and scheduling tool; it is not a physical access control system. It cannot inspect identification, print or disable badges, verify whether a person at reception is the person who made the request, enforce anti-tailgating rules, require an escort to remain with a visitor, or stop someone from entering through an unlocked door.
Fill those gaps with a documented reception procedure, trained reception or security staff, photo-ID verification, time-limited visitor badges, an escort policy, badge return procedures, and electronic door controls for the secure area. For higher-risk locations, integrate the Bookings approval record into a visitor-management or physical access control platform rather than treating an approved calendar event as permission to pass a secure door.
Next step: Ask your facilities or IT owner to configure the dedicated Bookings calendar and provide you with one approved-test record and one declined-test record before the next ISO 27001 control review.