Delegation Audit

Shared Mailbox Delegation Audit

Find stale Full Access, Send As and disabled delegates and permission drift before they become an offboarding or security problem.

Start 30-day trial

Audit vs. reconciliation — they are not the same thing

Audit tells the administrator where current state looks wrong or suspicious. It is a read-only scan: it never changes AD group membership or Exchange permissions.

Reconciliation changes managed permissions so actual state matches desired state — adding missing managed grants and removing stale managed ones, only for permissions inside Tenvero's own management scope.

Not every audit finding is automatically remediated. A finding is a signal for the administrator to review, not a guarantee that Tenvero will act on it.

What the Delegation Audit checks

critical
Disabled AD user still granted Full Access
An account disabled in Active Directory retains a direct Exchange delegation that was never cleaned up.
critical
Orphaned trustee no longer resolves
A delegate on the mailbox no longer resolves to an Exchange recipient or an AD account.
warning
Mapped AD group missing or non-security
The group mapped as source of truth for a mailbox is missing, deleted, or no longer security-enabled.
info
Direct access exists outside the mapped group
A delegate has direct Full Access, Send As or Send on Behalf that was never adopted into the managed group.

Every run exports to CSV for review or ticketing outside Tenvero.

Offboarding is not complete until delegation is verified

Deleting or disabling a user in Active Directory does not clean up the Exchange delegation that pointed at them. The permission entry stays on the mailbox — it just stops resolving to anyone:

Offboarded user
S-1-5-21-... → Send As → [email protected]
Orphaned delegate detected

Full Access, Send As and Send on Behalf are separate Exchange grants, assigned and audited independently — a delegate can hold any combination of the three, and each is a separate finding. Audit checks all three per mailbox, not just Full Access.

Try it on one mailbox first — no trial required

The free Permission Audit Generator builds a read-only PowerShell script for a single shared mailbox: current Full Access, Send As, Send on Behalf, and any trustee that no longer resolves. Nothing is sent to Tenvero — the script runs in your own session.

See also: auditing Send As after a user is deleted.

Why this matters

Shared mailbox permissions accumulate over time. Role changes, disabled accounts, manual exceptions and incomplete offboarding can leave delegation behind long after it was intended. A one-time CSV export of current permissions tells you what exists today — it does not tell you which of those permissions are still supposed to exist, or catch what changes next week. Delegation Audit runs against the same mailbox mappings Tenvero already manages, so drift is visible on an ongoing basis rather than only during a one-off review.

Run a Delegation Audit on your own tenant

Adopt one existing shared mailbox and see what the audit surfaces. No credit card.

Start 30-day trial