Why use this template?
Use this PowerShell template when you need to find shared mailboxes that have no explicit FullAccess assignment other than system principals. It can be previewed in the Builder; Pro access is required to generate it for your own environment.
The template uses ExchangeOnlineManagement and requires Mailbox permission read access. Output: CSV report. Level: Advanced. Action: Read-only. Risk: Low.
Review before running
The script remains preview-only until Pro access is enabled. Review it before running it, and test it outside production first. “Read-only” describes the script itself; anything you add around it can still change data.
Preview the script
- Open the template in the PowerShell Builder.
- Review the purpose, requirements, permissions, output and risk.
- Activate Pro when you are ready to generate the full script, then test it outside production.
Pro templates remain previewable before purchase or activation. No tenant connection is required. When you generate a Pro script, only the configuration values needed for that template are sent to Opselith after license validation.Preview Export shared mailboxes without explicit FullAccess assignments →
How to use this result
Use this report to find shared mailboxes where no explicit Full Access user assignment remains after system principals are excluded.
When this helps
- Review shared-mailbox delegation before migration or ownership cleanup.
- Find shared mailboxes that may no longer have an obvious interactive user delegate.
- Create a focused follow-up list instead of reviewing every mailbox permission row manually.
How to read the result
- Full Access allows a delegate to open and work with mailbox contents; it is separate from Send As and Send on Behalf permissions.
- No explicit Full Access user assignment does not prove a mailbox is unused: access can be provided through groups or other delegation patterns that require separate review.
Things to check
- Treat the result as an investigation list, not an automatic deletion or ownership decision.
- Review Send As, Send on Behalf, group-based access and the mailbox's business purpose separately.
What to do next: Check the mailbox's business owner and other delegation paths before deciding whether the lack of an explicit Full Access user assignment is a problem.
Related tasks
Official references