Reference

Mailbox Folder Permission

Per-folder ACLs on user mailboxes (Calendar, Inbox, Top of Information Store). Anonymous calendar sharing is a silent data leak no admin UI surfaces.

Part of the Exchange inventory.

Scan settings

Default scanning intervalAllowed scanning intervalsData removal during incremental scan
MonthlyDaily, Weekly, Bi-Weekly, Monthly, Never, InitialYes

Properties

Property Type Description Automation placeholder
Access Rights String[] Reviewer / Editor / PublishingEditor / Owner / AvailabilityOnly / etc. {{MailboxFolderPermission.AccessRights}}
Can View Private Items Boolean True when delegate has CanViewPrivateItems sharing flag. {{MailboxFolderPermission.CanViewPrivateItems}}
Initially Scanned DateTime Shows when this object was initially found in a scan. {{MailboxFolderPermission.CreatedTime}}
Folder Permission String {{MailboxFolderPermission.DisplayName}}
Folder Path String {{MailboxFolderPermission.FolderPath}}
Folder Type String Allowed values: Calendar, Contacts, Inbox, Other, TopOfInformationStore. {{MailboxFolderPermission.FolderType}}
Granted To String User identity granted the permission. 'Default' = all internal users; 'Anonymous' = anyone with the link. {{MailboxFolderPermission.GrantedTo}}
Has Write Access Boolean True when access rights include Editor / PublishingEditor / Owner / Author / PublishingAuthor. {{MailboxFolderPermission.HasWriteAccess}}
Is Default Or Anonymous Boolean True when GrantedTo is 'Default' or 'Anonymous' — i.e. broad sharing. {{MailboxFolderPermission.IsDefaultOrAnonymous}}
Last scan update DateTime Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. {{MailboxFolderPermission.LastModifiedTime}}
Mailbox Mailbox Mailbox the folder belongs to. {{MailboxFolderPermission.MailBox}}
Mailbox name String {{MailboxFolderPermission.MailBoxName}}
Risk Score Int32 Stores risk score {{MailboxFolderPermission.RiskScore}}
Risk Score Update DateTime Stores risk score update {{MailboxFolderPermission.RiskScoreLastUpdate}}
Risk Score Value String Stores risk score value like Low_Low {{MailboxFolderPermission.RiskScoreValue}}
Sharing Permission Flags String[] Delegate, CanViewPrivateItems, etc. {{MailboxFolderPermission.SharingPermissionFlags}}
User User {{MailboxFolderPermission.User}}
User name String {{MailboxFolderPermission.UserName}}

Relations

Relation Service Description
Mailbox Exchange All Exchange mailboxes of your users, rooms & equipment
User Microsoft 365 All users registered in your tenant (internal, external)

Segments

Segment Description
Default/Anonymous permissions Folder permissions granted to the Default or Anonymous identity.
Permissions with write access Folder permissions that grant write or higher access.

Actions

This object does currently not have any actions.

Policy Severity Description
Mailbox folder shared with Default or Anonymous High Detects mailbox folders (calendar, inbox) granted to 'Default' or 'Anonymous' permission entries.

Last updated: 7/19/2026