who has access to a mailbox in Office 365
Who else can read the CFO's mailbox? Answer it in one click.
A typical mid-size tenant runs hundreds of shared mailboxes and thousands of delegate, send-as and send-on-behalf grants that nobody has reviewed since they were created - and reviewing them mailbox by mailbox is a job nobody finishes. 1Security records how every message was actually sent, makes each sending method a filter across the whole tenant, and flags the pattern that looks like a successful phish on its own.
The problem
Every mailbox has more keys than its owner knows about.
An assistant with Full Access from 2021. A shared mailbox created for a campaign that ended two years ago, still with six delegates. A send-as grant from a project nobody remembers. Each one is a way to read or impersonate a mailbox, and each is granted per mailbox, per permission type. Auditing them across the whole tenant by hand ends in a spreadsheet nobody trusts a week later.
Attackers know this. A compromised account rarely mails from itself: it sends on behalf of someone trusted, or from a shared mailbox where nobody owns the Sent folder. The message looks internal because, technically, it is. Business email compromise still costs organisations more than ransomware, and delegated sending is its favourite disguise.
1Security classifies every message by how it was really sent - direct, send as, send on behalf, shared mailbox, delegate access - and keeps that classification filterable across the tenant, next to who the recipients were, what was attached and whether the exchange got replies.
In practice
The mailbox access review, as one filter.
From "who can touch this mailbox" to a standing watch, in four steps.
- 01
Filter by sending method
Open Emails and filter to send as, send on behalf, shared mailbox or delegate access. Pull it across the tenant or scope it to one mailbox. Delegated sending becomes a list with dates and counterparties - typically hundreds of delegated sends a month in a mid-size tenant, most legitimate, a handful not.
- 02
Flag the two-way exchange
Switch to Conversations. Every thread rolls into one row and an outside sender who is getting internal replies is flagged - what a successful phish or invoice-fraud attempt looks like, a signal no single message carries. Combine with the phishing flag and you have the exchanges to look at first.
- 03
Follow what left
Classic attachments, cloud attachments and unique uploads - files sent by mail that exist nowhere in your SharePoint or OneDrive - are separate columns, with sensitive-information detections on top. "What left through this mailbox last quarter" has a precise answer instead of a search of the Sent folder.
- 04
Turn the review into a standing watch
Save the filter as a policy: sending method + external recipients + sensitive content. From then on the review runs continuously and you get an instant alert or a daily digest when a delegated identity is used to send something sensitive outside.
What makes it work
Email as a security signal, not an archive.
The mailbox access review rides on the platform's email intelligence and the permission graph around it.
Office 365 Access Management
The permission graph resolves who can reach what - mailboxes included - through every kind of grant, group and delegation.
Explore access management →Microsoft 365 Monitoring Tool
Email activity flows through the same real-time engine as files and sign-ins - a delegated send shows up in minutes.
Explore monitoring →Microsoft 365 Audit Tool
Up to three years of history behind every mailbox question, each event tied to the actor, device and location.
Explore the audit tool →
FAQ
Common questions.
Does 1Security read everyone's email?
No. The platform stores message metadata and detection results, not a browsable archive of message bodies. Content is streamed into analysis for sensitive-data detection and discarded; matched values are never written to the database. Nobody in IT gets a new way to read a colleague's inbox.
Is this a mailbox permission export?
It answers a better question. A permission export tells you who could use a mailbox on the day you ran it. 1Security shows who actually did - every send-as, send-on-behalf, delegate and shared-mailbox send, with dates, recipients and attachments, up to three years back - and keeps that view live instead of a snapshot you re-run each quarter.
Can 1Security act on a malicious message?
Yes, through the separately approved Mailbox Management module: delete to Deleted Items, move to Junk, mark read or unread. There is no permanent deletion, so nothing is destroyed by an automated action, and every action is logged.
What about shared mailboxes specifically?
Shared-mailbox sending is one of the five first-class methods, so you can list every message that left through a shared mailbox, who sent it, who received it and whether sensitive content travelled with it - the review most tenants have never done for the hundreds of shared mailboxes they run.
Make mailbox access a question with an answer.
Connect read-only and the sending-method classification starts the same day - the delegation review becomes a filter, and the filter becomes a standing watch.
Or keep auditing delegates one mailbox at a time.