Reference
Exchange Role Assignment
Direct RBAC role assignments outside of role groups. Direct assignments bypass role-group governance — auditor blind spot.
Part of the Exchange inventory.
Scan settings
| Default scanning interval | Allowed scanning intervals | Data removal during incremental scan |
|---|---|---|
| Weekly | Daily, Weekly, Bi-Weekly, Monthly, Never, Initial | Yes |
Properties
| Property | Type | Description | Automation placeholder |
|---|---|---|---|
| Assignment Method | String | Allowed values: Direct, RoleAssignmentPolicy, RoleGroup, SecurityGroup. | {{ExchangeRoleAssignment.AssignmentMethod}} |
| Initially Scanned | DateTime | Shows when this object was initially found in a scan. | {{ExchangeRoleAssignment.CreatedTime}} |
| Custom Config Write Scope | String | {{ExchangeRoleAssignment.CustomConfigWriteScope}} | |
| Custom Recipient Write Scope | String | {{ExchangeRoleAssignment.CustomRecipientWriteScope}} | |
| Assignment Name | String | {{ExchangeRoleAssignment.DisplayName}} | |
| Effective User Name | String | When AssignmentMethod = Direct, the actual user (after group expansion). | {{ExchangeRoleAssignment.EffectiveUserName}} |
| Is Direct Assignment | Boolean | True for direct role assignments that bypass role-group governance. | {{ExchangeRoleAssignment.IsDirectAssignment}} |
| Last scan update | DateTime | Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. | {{ExchangeRoleAssignment.LastModifiedTime}} |
| Risk Score | Int32 | Stores risk score | {{ExchangeRoleAssignment.RiskScore}} |
| Risk Score Update | DateTime | Stores risk score update | {{ExchangeRoleAssignment.RiskScoreLastUpdate}} |
| Risk Score Value | String | Stores risk score value like Low_Low | {{ExchangeRoleAssignment.RiskScoreValue}} |
| Role | String | {{ExchangeRoleAssignment.Role}} | |
| Role Assignee | String | User, role group, or security group the role is assigned to. | {{ExchangeRoleAssignment.RoleAssignee}} |
| Assignment Id | String | {{ExchangeRoleAssignment.RoleAssignmentId}} |
Relations
This object does currently not have any relations.
Segments
| Segment | Description |
|---|---|
| Direct role assignments | Exchange RBAC role assignments made directly to users, bypassing role groups. |
Actions
This object does currently not have any actions.
Policies that check this object
| Policy | Severity | Description |
|---|---|---|
| Direct role assignment bypassing role groups | Medium | Detects Exchange RBAC role assignments granted directly to users instead of via role groups. |