Exchange Administrator
Attack path
An Exchange Administrator controls mailboxes, transport settings and much of Exchange Online. An attacker could create inbox or mail-flow rules that copy password-reset messages, enrolment links and other sensitive correspondence to a mailbox they control, using the captured information to compromise additional identities. They could also search or export business data and abuse access to Microsoft 365 group resources where permitted. This role does not directly grant full Entra control, but email's role in account recovery makes it a strong route to lateral movement.
Description
Can manage all aspects of the Exchange product.
Details
Users with this role have global permissions within Microsoft Exchange Online, when the service is present.
Directory Actions25
| Action | Condition |
|---|---|
microsoft.azure.serviceHealth/allEntities/allTasks | null |
microsoft.azure.supportTickets/allEntities/allTasks | null |
microsoft.backup/exchangeProtectionPolicies/allProperties/allTasks | null |
microsoft.backup/exchangeRestoreSessions/allProperties/allTasks | null |
microsoft.backup/restorePoints/userMailboxes/allProperties/allTasks | null |
microsoft.backup/userMailboxProtectionUnits/allProperties/allTasks | null |
microsoft.backup/userMailboxRestoreArtifacts/allProperties/allTasks | null |
microsoft.directory/contacts/allProperties/read | null |
microsoft.directory/contacts/memberOf/read | null |
microsoft.directory/contacts/standard/read | null |
microsoft.directory/groups/hiddenMembers/read | null |
microsoft.directory/groups.unified/assignedLabels/update | null |
microsoft.directory/groups.unified/basic/update | null |
microsoft.directory/groups.unified/create | null |
microsoft.directory/groups.unified/delete | null |
microsoft.directory/groups.unified/members/update | null |
microsoft.directory/groups.unified/owners/update | null |
microsoft.directory/groups.unified/restore | null |
microsoft.directory/onPremisesSynchronization/standard/read | null |
microsoft.office365.exchange/allEntities/basic/allTasks | null |
microsoft.office365.network/performance/allProperties/read | null |
microsoft.office365.serviceHealth/allEntities/allTasks | null |
microsoft.office365.supportTickets/allEntities/allTasks | null |
microsoft.office365.usageReports/allEntities/allProperties/read | null |
microsoft.office365.webPortal/allEntities/standard/read | null |
Graph API Permissions37
Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.
BackupRestore-Monitor.Read.AllBackupRestore-Restore.Read.AllCalendars.ReadCalendars.ReadWriteChangeManagement.Read.AllContacts.ReadContacts.ReadWriteDirectory.Read.AllEntraBackup.Read.AllEntraBackup.ReadWrite.PreviewEntraBackup.ReadWrite.RecoveryExchangeMessageTrace.Read.AllGroup.Read.AllGroup.ReadWrite.AllGroupMember.Read.AllGroupMember.ReadWrite.AllGroupSettings.Read.AllMail.ReadMail.ReadWriteMailboxSettings.ReadMailboxSettings.ReadWriteNetworkAccess-Reports.Read.AllOnPremDirectorySynchronization.Read.AllOrgContact.Read.AllPlace.Read.AllPlace.ReadWrite.AllReports.Read.AllReportSettings.Read.AllRoleManagement.Read.ExchangeRoleManagement.ReadWrite.ExchangeServiceActivity-Exchange.Read.AllServiceActivity-Microsoft365Web.Read.AllServiceActivity-OneDrive.Read.AllServiceActivity-Teams.Read.AllServiceHealth.Read.AllServiceMessage.Read.AllServiceMessageViewpoint.Write