LoFP LoFP / T1098.002


fullaccess mailbox delegation may be assigned for legitimate purposes, filter as needed.
mailbox folder permissions may be configured for legitimate purposes, filter as needed.
the full_access_as_app api permission may be assigned to legitimate applications. filter as needed.
while infrequent, the applicationimpersonation role may be granted for leigimate reasons, filter as needed.
while there are legitimate scenarios for these permissions, such as an executive assistant needing access to an executive's mailbox, there are also malicious scenarios. investigate and filter as needed.