Reference

Mailbox Delegate

Mailbox delegations: Full Access, Send-As, and Send-on-Behalf permissions on user mailboxes.

Part of the Exchange inventory.

Scan settings

Default scanning intervalAllowed scanning intervalsData removal during incremental scan
MonthlyDaily, Weekly, Bi-Weekly, Monthly, Never, InitialYes

Properties

Property Type Description Automation placeholder
Initially Scanned DateTime Shows when this object was initially found in a scan. {{MailboxDelegate.CreatedTime}}
Delegate Email String Email address of the user/group granted access. {{MailboxDelegate.DelegateEmail}}
Delegate User User Internal user granted the delegation (if internal). {{MailboxDelegate.DelegateUser}}
Delegate user name String {{MailboxDelegate.DelegateUserName}}
Deny Boolean True when this is a deny entry rather than an allow. {{MailboxDelegate.Deny}}
Delegation String {{MailboxDelegate.DisplayName}}
Is External Boolean True when the delegate is in an external domain. {{MailboxDelegate.IsExternal}}
Is Inherited Boolean {{MailboxDelegate.IsInherited}}
Last scan update DateTime Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. {{MailboxDelegate.LastModifiedTime}}
Mailbox Mailbox Mailbox the permission applies to. {{MailboxDelegate.MailBox}}
Mailbox name String {{MailboxDelegate.MailBoxName}}
Permission Type String Type of delegation granted on the mailbox. Allowed values: ChangeOwner, ChangePermission, ExternalAccount, FullAccess, ReadPermission, SendAs, SendOnBehalf. {{MailboxDelegate.PermissionType}}
Risk Score Int32 Stores risk score {{MailboxDelegate.RiskScore}}
Risk Score Update DateTime Stores risk score update {{MailboxDelegate.RiskScoreLastUpdate}}
Risk Score Value String Stores risk score value like Low_Low {{MailboxDelegate.RiskScoreValue}}
User User Mailbox owner {{MailboxDelegate.User}}
User name String {{MailboxDelegate.UserName}}

Relations

Relation Service Description
Mailbox Exchange All Exchange mailboxes of your users, rooms & equipment
User Microsoft 365 All users registered in your tenant (internal, external)
User Microsoft 365 All users registered in your tenant (internal, external)

Segments

Segment Description
External delegates Mailbox delegations granted to external users.
Full Access delegates Mailbox delegations granting Full Access permission.

Actions

This object does currently not have any actions.

Policy Severity Description
Mailbox delegation granted to external user High Detects Full Access or Send-As permissions granted to users outside the mailbox owner's domain.

Last updated: 7/19/2026