Business Email Compromise
Last updated
Last updated
Groups with full rights in Exchange:
Organization Management
Exchange Organization Administrators
By default, the âDomain Adminsâ group does not have âfull accessâ rights to mailboxes on Exchange.
BUT, the âDomain Adminsâ group has the ability to grant this access to any account. You can always resort to adding your own user to the group with a DA
From a workstation on the domain the following command can be run as a domain admin to add a user to the âExchange Organization Administratorsâ group:
Users with the âApplicationImpersonationâ role have the ability to access other user's mailboxes.
The âApplicationImpersonationâ role is a Microsoft Exchange server role that, when granted to a user, allows them to impersonate other users when accessing mailboxes. This role can be granted at the Exchange Management Shell with the following command: