microsoft / microsoft/CSS-Exchange

[Feature Request] report Exchange permission model in HealthChecker

Open
#2,274 0 comments 0 reactions 1 assignee View on GitHub

@dpaulson45 is already working on this.

Since Apr 24, 2025.

Enhancement Health Checker P2
Dominant language
PowerShell
Stars
1.3k
Forks
395
Avg merge
14h 7m
Merged PRs (30d)
5

Description

Is your request related to a problem? Please describe.
A clear and concise description of what the problem is and the results it had on the environment.

Exchange can operate in 3 different permissions models and the healthchecker script should probably report which model is in use in an environment given the importance of that setting to overall domain security

Shared Permissions
RBAC Split Permissions
Active Directory Split Permissions

Describe The Request
A clear and concise description of the feature to add to a current tool or a new tool with what we all want to be checking with examples.

Given the risks of privilege escalation to Domain Admin inherent in the default Shared Permissions model it seems like its going to be increasingly important for Exchange deployments and admins to have better visibility to the attack paths currently enabled in their deployments

Additional context
Add any other context or screenshots about the feature request here.

reference: https://learn.microsoft.com/en-us/exchange/permissions/split-permissions/split-permissions?view=exchserver-2019

reference: https://adsecurity.org/?p=4119

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.