-
Notifications
You must be signed in to change notification settings - Fork 63
Open
Description
Running ACLight suggests "Exchange Recipient Administrators" has generic_all permissions over "Organization Admins" but it does not. Equally I don't think "Organization Admins" provides a route to domain admin.
Reviewing the results, its because (I think) because of generic_all rights on sensitive groups with the object "ms-Exch-Dynamic-Distribution-List". Is this a false positive?