Skip to main content

Admin Accounts With Mailboxes

The Risk

An administrator account is a powerful identity. Using these accounts for anything other than the configuration of users and settings and by a certain user leaves your business unnecessarily vulnerable.

  • Accidental exposure of administration credentials to malicious actors due to:

    • Unnecessary Sharing of Credentials.

    • Unnecessary Overuse of sensitive credentials.

  • Unintentional or accidental damage caused by a user in a nonadmin capacity.

  • Lack of auditing/trackability for all admin activities.

The Solution

If the mailbox is required, remove administrative privileges from these accounts and, if necessary, create a new separate administrative account (unlicenced) for that user.

If the mailbox is not required, remove it, and you will save the cost of a mailbox license.