How to Approve Secure-Area Visitors in Microsoft Bookings

How to Approve Secure-Area Visitors in Microsoft Bookings

Configure Microsoft Bookings secure area visitor approval settings to require staff approval, document sponsor details, and retain visitor records.

LakeRidge Team
July 19, 2026
7 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

ISO 27001 Annex A control 7.2 requires secure areas to be protected by appropriate entry controls and access points, which means visitors should be authorized before they reach a restricted door or reception checkpoint. Microsoft Bookings secure area visitor approval settings can satisfy the pre-authorization and recordkeeping portion of this control by requiring a designated staff member to approve each visitor request before the visitor receives confirmation; the physical badge, identity check, and door-access decision must still occur on site.

How do you configure Microsoft Bookings secure area visitor approval settings?

Use a dedicated shared Bookings calendar for visitor requests rather than adding secure-area appointments to a general sales, support, or recruiting calendar. This keeps approvals, visitor details, and staff notifications separate from ordinary business appointments and gives an assessor a clearly defined workflow to review.

  1. Confirm that shared Bookings is enabled for the tenant. Sign in as a Microsoft 365 administrator and go to Microsoft 365 admin center > Settings > Org settings > Bookings. Confirm that Allow your organization to use Bookings is enabled. Also confirm that users who will own the process are permitted to create and manage shared Bookings pages.

    Limit Bookings administration to the facilities, security, reception, or operations staff who own the approval process. A finance or COO sponsor should ask for this ownership list, because a visitor workflow without a named business owner becomes an unattended mailbox risk.

  2. Create a dedicated visitor-request calendar. Open the Microsoft 365 app launcher, select Bookings, select Shared bookings, and choose New booking calendar. Name it Secure Area Visitor Requests. Enter the reception address, business hours, time zone, and a monitored operational email address.

    Add the people responsible for approval under Staff. At least two trained approvers should be assigned so absence does not cause requests to be approved informally or left pending. Typical staff members are a facilities coordinator, reception lead, security lead, and the internal host’s delegate.

  3. Create a service that represents a visitor request, not a guaranteed visit. Go to Services > Add a service. Use a clear service name such as Secure-Area Visitor Request. Set a short duration, such as 15 minutes, because the scheduled slot represents the arrival and check-in window rather than the visitor’s full working day.

    Set Location to a controlled reception point, such as Main Reception — wait for host and badge issue. Do not list a data center room, laboratory suite, executive floor, records room, or other restricted destination as the public location.

  4. Turn on approval before confirmation. Within the new service, open Scheduling policy or Advanced options, depending on the Bookings interface displayed in your tenant. Enable Require staff approval. Assign the designated approval staff to the service under Staff, then save the service.

    With this setting enabled, a visitor’s request is not automatically treated as an approved appointment. The assigned staff member must approve or decline it, creating the core Bookings visitor-approval workflow needed for pre-entry authorization.

  5. Collect the information an approver needs to make a decision. From Services > Secure-Area Visitor Request > Custom fields, select Add a question and make each field required where appropriate. Useful fields include:

    • Visitor legal name — required text field.
    • Company or employer — required text field.
    • Internal host name and email address — required text field.
    • Purpose of visit — required text field.
    • Requested secure area — required dropdown field, using non-sensitive choices such as Engineering suite, Operations office, or Controlled work area.
    • Will the visitor require escorted access? — required dropdown with Yes and No.

    Do not use Bookings custom fields to collect government ID numbers, health information, security-clearance details, or other unnecessary sensitive data. The approval record should contain enough information to authorize a visit, not become an uncontrolled identity-document repository.

  6. Publish only the visitor-request service. Go to Booking page. Under Access control, select the option appropriate to the visitor population. If outside vendors need to request access, use the external/public booking-page option but publish only this dedicated calendar. If requests are limited to employees or authenticated contractors, select Available to people in your organization or the more restrictive organization-specific option available in your tenant.

    Enable Disable direct search engine indexing of booking page if that option is shown. Select Save and publish, then distribute the booking-page link only through the vendor onboarding, visitor invitation, or internal host process.

Bookings setting Recommended secure-area value Control purpose
Require staff approval Enabled Prevents automatic confirmation of visitor requests.
Staff Reception lead, facilities coordinator, security delegate Assigns accountable people to approve or decline requests.
Location Main Reception — wait for host and badge issue Directs visitors to a controlled entry point.
Custom fields Visitor, employer, host, purpose, requested area, escort need Provides decision-making and audit information.

How should the approval workflow work in practice?

At a 180-person healthcare technology vendor called Meridian Care Systems, external implementation consultants periodically need access to an engineering suite where the company supports hospital interface deployments and maintains integration test systems. The internal project manager submits or sponsors the request, reception verifies the visitor’s name against the approved Bookings appointment, and the facilities coordinator confirms that an escort is assigned before approving the request.

The approval should follow a written business rule: verify the internal host, confirm the purpose and requested date, determine whether an escort is mandatory, and decline requests that lack a sponsor or request inappropriate access. The approver should not approve a request merely because the visitor selected an available time. Availability is scheduling information; approval is an authorization decision.

How do you verify that the Bookings approval setting took effect?

  1. Open the published booking page in a private browser window or a non-administrator test account.

  2. Submit a test request using a realistic external visitor name, internal host, and secure-area selection.

  3. Confirm that the request appears in the Secure Area Visitor Requests calendar as requiring action rather than as an automatically approved visit.

  4. Confirm that the assigned approval staff receive the request notification and can approve or decline it.

  5. Approve the test request, then confirm the visitor receives the confirmation only after approval.

  6. Run a second test and decline it. Confirm that the visitor is not sent instructions that imply access has been granted.

For Meridian Care Systems, the operations manager performs this test quarterly and after any change to reception staffing, Bookings ownership, or the visitor-request form. This is a low-cost control check that identifies an accidentally disabled approval setting before a real visitor uses the page.

What evidence should you capture for an ISO 27001 assessor?

An assessor evaluating ISO 27001 control 7.2 will want to see that the process is configured, operating, and connected to the physical entry procedure. Capture evidence from both Bookings and the reception process.

  • A screenshot of Services > Secure-Area Visitor Request showing the service name, controlled reception location, assigned staff, and Require staff approval enabled.

  • A screenshot of the Custom fields configuration showing required host, employer, purpose, requested-area, and escort questions.

  • A screenshot of Booking page > Access control, including the selected audience and search-engine indexing setting.

  • A redacted example of a completed request showing the request status, approver, internal host, and approval date.

  • A redacted approval notification and confirmation email demonstrating that confirmation followed approval.

  • An export or screenshot from Microsoft Purview portal > Audit > Search, where available, covering Bookings-related activity for the review period.

  • The current visitor-management procedure describing identity verification, badge issuance, escort requirements, badge return, and how reception handles a visitor who arrives without an approved booking.

Where does Microsoft Bookings fall short for physical-entry control?

Microsoft Bookings is an approval and scheduling tool; it is not a physical access control system. It cannot inspect identification, print or disable badges, verify whether a person at reception is the person who made the request, enforce anti-tailgating rules, require an escort to remain with a visitor, or stop someone from entering through an unlocked door.

Fill those gaps with a documented reception procedure, trained reception or security staff, photo-ID verification, time-limited visitor badges, an escort policy, badge return procedures, and electronic door controls for the secure area. For higher-risk locations, integrate the Bookings approval record into a visitor-management or physical access control platform rather than treating an approved calendar event as permission to pass a secure door.

Next step: Ask your facilities or IT owner to configure the dedicated Bookings calendar and provide you with one approved-test record and one declined-test record before the next ISO 27001 control review.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.