Поделиться через

Mailbox inherited permissions

Евгений Котляревский 61 Баллы репутации
2025-08-26T14:35:40.0466667+00:00

Hi!
Some time ago our exchange administrator quit. His account was disabled and removed from all AD security groups.
But now if I do Get-MailboxPermissions cmdlet against any mailbox (old one or created after our administrator quit), I can see this:
Пользовательское изображение

This user has FullAccess permission for any mailboxes. And judging by the screenshot, these rights are inherited from somewhere.
My question is: how can I find from where this permissions are inherited, or how can prevent granting this permissions on newly created mailboxes?

Обмен онлайн
Обмен онлайн

Облачная служба, включенная в Microsoft 365, обеспечивает масштабируемую функцию обмена сообщениями и совместной работы с упрощенным управлением и автоматическими обновлениями.

Комментариев: 0 Без комментариев

Ответ, принятый автором вопроса

  1. Vergil-V 12,785 Баллы репутации Внешний персонал Microsoft Модератор
    2025-08-27T02:10:23.2366667+00:00

    Hi Евгений Котляревский 
    Thanks for reaching out to the Microsoft Q&A forum.   

    Based on your inquiry, I understand that you're looking to identify the source of inherited permissions. 

    Based on my research, your assumption is correct. The admin user may still be inheriting permissions from other Active Directory groups such as Administrators or Domain Admins. undefined To investigate further, I recommend using the Get-ADPrincipalGroupMembership PowerShell cmdlet. This command can help identify whether the admin account is still a member of any AD groups that might be contributing to inherited permissions. 

    As moderators of this forum, we unfortunately do not have access to a dedicated testing environment to replicate every scenario. However, your feedback and updates are incredibly valuable. If you’re able to share the results after running Get-ADPrincipalGroupMembership, it would help us better understand your situation and refine our guidance. 

    Please know that while our initial response may not have resolved the issue immediately, we are committed to working with you to find the best solution. Your input plays a crucial role in that process. 

    Thank you again for your understanding and collaboration. 


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment". 

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Этот ответ помог вам?


Дополнительные ответы: 0

Сортировать по: Наиболее полезные

Ваш ответ

Автор вопроса может устанавливать для ответов пометку "Принято", а модераторы — пометку "Рекомендуется". Благодаря этому пользователям становится проще понять, какой из ответов помог решить проблему автора.