Reference

Mail User

Mail-enabled users that route to an external SMTP address. Common offboarding-leak signal.

Part of the Exchange inventory.

Scan settings

Default scanning intervalAllowed scanning intervalsData removal during incremental scan
MonthlyDaily, Weekly, Bi-Weekly, Monthly, Never, InitialYes

Properties

Property Type Description Automation placeholder
Initially Scanned DateTime Shows when this object was initially found in a scan. {{MailUser.CreatedTime}}
Display Name String {{MailUser.DisplayName}}
External Email Address String External SMTP address mail is forwarded to. {{MailUser.ExternalEmailAddress}}
Hidden From Address Lists Boolean {{MailUser.HiddenFromAddressListsEnabled}}
Last scan update DateTime Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. {{MailUser.LastModifiedTime}}
Identity String {{MailUser.MailUserId}}
Risk Score Int32 Stores risk score {{MailUser.RiskScore}}
Risk Score Update DateTime Stores risk score update {{MailUser.RiskScoreLastUpdate}}
Risk Score Value String Stores risk score value like Low_Low {{MailUser.RiskScoreValue}}
User User Entra ID user matching this mail user's UPN. {{MailUser.User}}
User Name String {{MailUser.UserName}}
User Principal Name String {{MailUser.UserPrincipalName}}

Relations

Relation Service Description
User Microsoft 365 All users registered in your tenant (internal, external)

Segments

This object does currently not have any segments.

Actions

This object does currently not have any actions.

Last updated: 7/19/2026