Reference

Exchange

Rencore Governance inventories 22 object types for Exchange and ships 31 policies and 15 automations.

Inventories

ObjectDescriptionProperties
Accepted DomainDNS domains the tenant accepts mail for, joined with DKIM signing status.15
Calendar PermissionPermissions configured on Exchange mailbox calendars (sharing and delegation).15
Distribution GroupExchange-style distribution lists and dynamic distribution lists. Open DLs accepting external mail are a phishing relay risk.19
Exchange Audit EventExchange administrative and mailbox audit events ingested from the Office 365 Management Activity API.17
Exchange Organization ConfigurationTenant-wide Exchange Online configuration settings.19
Exchange Role AssignmentDirect RBAC role assignments outside of role groups. Direct assignments bypass role-group governance — auditor blind spot.14
Exchange Role GroupExchange Online RBAC role groups (Org Management, Recipient Management, etc.).11
Exchange Security PolicyMicrosoft Defender for Office 365 / EOP security policies — anti-phish, anti-spam, Safe Links, Safe Attachments, malware filter, outbound spam, and quarantine policies.42
Journal RuleExchange journal rules that capture copies of messages to a journal recipient (compliance / legal hold).12
Mail ContactExternal recipients in the GAL. Stale contacts pointing at compromised or expired domains are a quiet leak vector.10
Mail Flow ConnectorInbound and outbound mail flow connectors. Misconfigured connectors are a common spoofing / smart-host hijack vector.20
Mail UserMail-enabled users that route to an external SMTP address. Common offboarding-leak signal.12
Mailbox Audit BypassAccounts excluded from mailbox audit logging. Bypassed service accounts can read mail invisibly — high-signal finding most products miss.11
Mailbox DelegateMailbox delegations: Full Access, Send-As, and Send-on-Behalf permissions on user mailboxes.17
Mailbox Folder PermissionPer-folder ACLs on user mailboxes (Calendar, Inbox, Top of Information Store). Anonymous calendar sharing is a silent data leak no admin UI surfaces.18
Redirect RuleAll registered Exchange mailbox redirect rules19
Mobile DeviceExchange ActiveSync mobile device partnerships.20
Mobile Device PolicyExchange ActiveSync mailbox policies controlling device password, encryption, and feature access.17
Remote DomainExchange remote domain entries that govern message handling for specific external domains.14
Resource MailboxRoom and equipment mailboxes with Place metadata and calendar booking policies.28
Transport RuleExchange mail flow / transport rules. Top governance signal for BEC and data exfiltration patterns.21
MailboxAll Exchange mailboxes of your users, rooms & equipment54

Last updated: 7/19/2026