Reference

Exchange Role Assignment

Direct RBAC role assignments outside of role groups. Direct assignments bypass role-group governance — auditor blind spot.

Part of the Exchange inventory.

Scan settings

Default scanning intervalAllowed scanning intervalsData removal during incremental scan
WeeklyDaily, Weekly, Bi-Weekly, Monthly, Never, InitialYes

Properties

Property Type Description Automation placeholder
Assignment Method String Allowed values: Direct, RoleAssignmentPolicy, RoleGroup, SecurityGroup. {{ExchangeRoleAssignment.AssignmentMethod}}
Initially Scanned DateTime Shows when this object was initially found in a scan. {{ExchangeRoleAssignment.CreatedTime}}
Custom Config Write Scope String {{ExchangeRoleAssignment.CustomConfigWriteScope}}
Custom Recipient Write Scope String {{ExchangeRoleAssignment.CustomRecipientWriteScope}}
Assignment Name String {{ExchangeRoleAssignment.DisplayName}}
Effective User Name String When AssignmentMethod = Direct, the actual user (after group expansion). {{ExchangeRoleAssignment.EffectiveUserName}}
Is Direct Assignment Boolean True for direct role assignments that bypass role-group governance. {{ExchangeRoleAssignment.IsDirectAssignment}}
Last scan update DateTime Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. {{ExchangeRoleAssignment.LastModifiedTime}}
Risk Score Int32 Stores risk score {{ExchangeRoleAssignment.RiskScore}}
Risk Score Update DateTime Stores risk score update {{ExchangeRoleAssignment.RiskScoreLastUpdate}}
Risk Score Value String Stores risk score value like Low_Low {{ExchangeRoleAssignment.RiskScoreValue}}
Role String {{ExchangeRoleAssignment.Role}}
Role Assignee String User, role group, or security group the role is assigned to. {{ExchangeRoleAssignment.RoleAssignee}}
Assignment Id String {{ExchangeRoleAssignment.RoleAssignmentId}}

Relations

This object does currently not have any relations.

Segments

Segment Description
Direct role assignments Exchange RBAC role assignments made directly to users, bypassing role groups.

Actions

This object does currently not have any actions.

Policy Severity Description
Direct role assignment bypassing role groups Medium Detects Exchange RBAC role assignments granted directly to users instead of via role groups.

Last updated: 7/19/2026