Select the correct Microsoft access model
For a user-connected inbox, delegated permissions usually match the product boundary. App-only permissions are intended for background organizational access and normally require administrator consent; they should be a separate enterprise mode.