Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Feature Request] report Exchange permission model in HealthChecker #2274

Open
boogieshafer opened this issue Jan 26, 2025 · 0 comments
Open

Comments

@boogieshafer
Copy link

boogieshafer commented Jan 26, 2025

Is your request related to a problem? Please describe.
A clear and concise description of what the problem is and the results it had on the environment.

Exchange can operate in 3 different permissions models and the healthchecker script should probably report which model is in use in an environment given the importance of that setting to overall domain security

Shared Permissions
RBAC Split Permissions
Active Directory Split Permissions

Describe The Request
A clear and concise description of the feature to add to a current tool or a new tool with what we all want to be checking with examples.

Given the risks of privilege escalation to Domain Admin inherent in the default Shared Permissions model it seems like its going to be increasingly important for Exchange deployments and admins to have better visibility to the attack paths currently enabled in their deployments

Additional context
Add any other context or screenshots about the feature request here.

reference: https://learn.microsoft.com/en-us/exchange/permissions/split-permissions/split-permissions?view=exchserver-2019

reference: https://adsecurity.org/?p=4119

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant