You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Running ACLight suggests "Exchange Recipient Administrators" has generic_all permissions over "Organization Admins" but it does not. Equally I don't think "Organization Admins" provides a route to domain admin.
Reviewing the results, its because (I think) because of generic_all rights on sensitive groups with the object "ms-Exch-Dynamic-Distribution-List". Is this a false positive?
The text was updated successfully, but these errors were encountered:
Hi @SimonGurney, can you share the results file with us?
Inside the folder of zBang, search for the folder of "ACLight" results, there should be csv files there. Please send it to [email protected].
Then I could see the exact path to admins that the tool discovered and share with you more insights.
Running ACLight suggests "Exchange Recipient Administrators" has generic_all permissions over "Organization Admins" but it does not. Equally I don't think "Organization Admins" provides a route to domain admin.
Reviewing the results, its because (I think) because of generic_all rights on sensitive groups with the object "ms-Exch-Dynamic-Distribution-List". Is this a false positive?
The text was updated successfully, but these errors were encountered: