Back to Admin Workflows

Mailbox Access Outlived the Request—Audit Exchange Online Permissions

Temporary mailbox access has a habit of becoming permanent. Build a scoped evidence set for delegation, folder permissions, forwarding, and audit activity before removing anything.

Shared mailboxes and delegated access change quickly during leave coverage, team moves, and investigations. Months later, the original ticket may be closed while Full Access, Send As, folder access, or forwarding remains.

PSForge can generate a repeatable Exchange Online evidence workflow. Collection is not remediation: mailbox owners and security staff must confirm business need before access is changed.

Prerequisites and safe scope

Define named mailboxes, review period, expected owners, and permitted reviewers. Use Exchange Online roles sufficient for reports and logs, protect exported recipient data, and document any audit-log retention limit.

Begin read-only. Exclude permission changes and forwarding disablement until findings are confirmed against approved requests and emergency access.

Collect the access picture

Run the bulk mailbox permission audit and delegation report for the same scope. Run the forwarding task with its ReportOnly action, then export mailbox audit logs for relevant activity.

PSForge generates those supported commands. The reviewer manually inspects folder permissions with approved Exchange tooling, normalizes identities, distinguishes inherited or expected entries, and maps each principal to an owner and request.

Verify evidence before remediation

Reconcile mailbox counts, sample entries in the Exchange admin center, record failed queries, and preserve timestamps and filters. Ask mailbox owners to attest to retained access and create separate approved changes for stale grants.

Reports show configured access and available activity; they do not prove that every grant was used, authorized, or harmless. Keep that limitation in the review record.

Ordered mailbox access review

  1. Manually approve mailbox scope, reviewers, expected owners, and output handling
  2. Generate bulk permission and delegation reports, then manually inspect folder permissions
  3. Collect external-forwarding and mailbox audit evidence
  4. Manually reconcile principals to requests and owner attestations
  5. Submit separately approved removals and rerun reports to verify changes

Final thoughts

Mailbox access reviews work best when configuration, activity, owner intent, and remediation evidence stay connected.

Use generated collection steps to reduce repetition, but keep access decisions with accountable reviewers.

Related guides