microsoft / microsoft/CSS-Exchange
[Feature Request] report Exchange permission model in HealthChecker
@dpaulson45 is already working on this.
Since Apr 24, 2025.
- Dominant language
- PowerShell
- Stars
- 1.3k
- Forks
- 395
- Avg merge
- 14h 7m
- Merged PRs (30d)
- 5
Description
Is your request related to a problem? Please describe.
A clear and concise description of what the problem is and the results it had on the environment.
Exchange can operate in 3 different permissions models and the healthchecker script should probably report which model is in use in an environment given the importance of that setting to overall domain security
Shared Permissions
RBAC Split Permissions
Active Directory Split Permissions
Describe The Request
A clear and concise description of the feature to add to a current tool or a new tool with what we all want to be checking with examples.
Given the risks of privilege escalation to Domain Admin inherent in the default Shared Permissions model it seems like its going to be increasingly important for Exchange deployments and admins to have better visibility to the attack paths currently enabled in their deployments
Additional context
Add any other context or screenshots about the feature request here.
reference: https://adsecurity.org/?p=4119
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.