CTD-000030

Exchange Online mailbox with Full Access permission assigned

Informational
Entra ID Exchange Online
Collection Defense Evasion
v50

Signature Identity

CTD-000030
Threat ID
50
Version
IOC-IOE
Indicator Type

Threat Description

Exchange Online mailbox with Full Access permissions assigned might be an indication of threat activities. A threat actor might configure permissions to access the compromised mailbox without being noticed.

MITRE ATT&CK: Attack Tactics

Collection Defense Evasion

D3FEND: Defend Tactics

User Account Permissions

Remediation

  1. Review list of trustees in Evidence section.
  2. To remove the user’s full access permission from the mailbox using Exchange Online PowerShell module:
    1. Connect to Exchange Online PowerShell using cmdlet Connect-ExchangeOnline.
    2. Remove the user's full access permission from the mailbox using Remove-MailboxPermission -Identity <MailboxIdentity> -User <UserIdentity> -AccessRights FullAccess.

Frequently Asked Questions

What does Exchange Online mailbox with Full Access permission assigned mean?

When a user or group is granted full access to an Exchange Online mailbox, it allows them to view and manage the mailbox contents. This setting can be used by administrators for legitimate purposes but may also indicate misconfigured permissions if not properly managed.

This condition indicates a potential exposure or misconfiguration, which can increase the risk of unauthorized access and data manipulation. The presence of full access permissions can facilitate attacker activity, such as accessing compromised mailboxes.

Attackers can use the granted permissions to access the compromised mailbox without being detected, potentially facilitating data exposure or mail manipulation. This requires the attacker to already have access to the compromised account's credentials.

Cayosoft Guardian continuously monitors permissions across Exchange Online mailboxes and flags issues when full access permissions are found, allowing administrators to review and address the potential exposure. This provides visibility into unauthorized access attempts.

Cayosoft Guardian helps reduce the risk by alerting administrators to review and remove unnecessary permissions, limiting the blast radius of potential exposure and helping teams maintain better control over mailbox access. This supports investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID Exchange Online
Themes
Account protection
Attack Tactics
Collection Defense Evasion
Defend Tactics
User Account Permissions
Indicator Types
IOC IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical