Powershell - Enumerate all mailboxes user has permissions to

Can someone help me with this please i would like to have a report that would enumerate all mailboxes a user "XYZ" has permissions to

Any mailbox permission = owner, editor, publishingeditor, etc...

Thanks !
Jean-François GuénetNetwork AdministratorAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Will SzymkowskiSenior Solution ArchitectCommented:
Try the following command below...
Get-Mailbox -ResultSize "unlimited" | Get-MailboxPermissions | ? {$_.User -like "*user1*"} | 
Select Identity, User, AccessRights, IsInherited

Open in new window


If you want to export this results to a csv use the below command...
Get-Mailbox -ResultSize "unlimited" | Get-MailboxPermissions | ? {$_.User -like "*user1*"} | 
Select Identity, User, AccessRights, IsInherited | 
Export-csv "c:\mailboxpermissions.csv" -NoTypeInformation

Open in new window


Will.
0
Jean-François GuénetNetwork AdministratorAuthor Commented:
It don't return anything...

[PS] C:\Windows\system32>Get-MailboxFolderPermission -identity patrtrem | Format-List


RunspaceId   : 4908e9b2-05f5-4880-bdfa-e99d7e4f539e
Identity     : xxx.xxx.xx.xx/Domain_Users/Patrick Tremblay:\
FolderName   : Top of Information Store
User         : Default
AccessRights : {None}
IsValid      : True
ObjectState  : New

RunspaceId   : 4908e9b2-05f5-4880-bdfa-e99d7e4f539e
Identity     : xxx.xxx.xx.xx/Domain_Users/Patrick Tremblay:\
FolderName   : Top of Information Store
User         : Anonymous
AccessRights : {None}
IsValid      : True
ObjectState  : New

RunspaceId   : 4908e9b2-05f5-4880-bdfa-e99d7e4f539e
Identity     : xxx.xxx.xx.xx/Domain_Users/Patrick Tremblay:\
FolderName   : Top of Information Store
User         : Manon Beaudoin
AccessRights : {PublishingEditor}
IsValid      : True
ObjectState  : New

RunspaceId   : 4908e9b2-05f5-4880-bdfa-e99d7e4f539e
Identity     : xxx.xxx.xx.xx/Domain_Users/Patrick Tremblay:\
FolderName   : Top of Information Store
User         : NT:S-1-5-21-1467955570-1331981634-1851928258-1105
AccessRights : {Editor}
IsValid      : True
ObjectState  : New



[PS] C:\Windows\system32>Get-Mailbox -ResultSize "unlimited" | Get-MailboxPermission | ? {$_.User -like "manobeau"} |
>> Select Identity, User, AccessRights, IsInherited
>>
[PS] C:\Windows\system32>
[PS] C:\Windows\system32>Get-Mailbox -ResultSize "unlimited" | Get-MailboxPermission | ? {$_.User -like "Manon Beaudoin"
} | Select Identity, User, AccessRights, IsInherited
[PS] C:\Windows\system32>
0
Will SzymkowskiSenior Solution ArchitectCommented:
You need to copy/paste the script and save it as a .PS1. You also need to make sure that you are running this in the Exchange Management Shell. If you are running this in a Native Powershell Session you need to make sure that you have the appropriate Snap-ins for Exchange in the session as well for this to work.

I have tested this in my Lab and it works without issues.

ALso just to add, you need to make sure that when you run this script you will need to be in the location where you saved it.

You will also need to run the script like below

.\scriptname.ps1

You will also need to ensure that your Execution Policy is set to RemoteSigned as well.

Set-ExecutionPolicy RemoteSigned

Once you have done that you should have no issues at all.

Will.
0
Determine the Perfect Price for Your IT Services

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden with our free interactive tool and use it to determine the right price for your IT services. Download your free eBook now!

Jean-François GuénetNetwork AdministratorAuthor Commented:
ive create the file ListUserMailboxAccess.ps1 and put in it

Get-Mailbox -ResultSize "unlimited" | Get-MailboxPermission | ? {$_.User -like "*manobeau*"} |
Select Identity, User, AccessRights, IsInherited

[PS] C:\Windows\system32>.\ListUserMailboxAccess.ps1

Identity                      User                          AccessRights                                    IsInherited
--------                      ----                          ------------                                    -----------
ville.blainville.qc.ca/Vil... BLAINVILLE\manobeau           {FullAccess}                                          False

It return only her mailbox and not other mailbox

Thanks for your help
0
Will SzymkowskiSenior Solution ArchitectCommented:
So that being said she should only have access to her mailbox and nothing else.

You can verify this by manually checking other mailboxes you might think this account has access to.

Will.
0
Jean-François GuénetNetwork AdministratorAuthor Commented:
well if i do this

[PS] C:\Windows\system32>Get-MailboxFolderPermission -identity patrtrem | Format-List


RunspaceId   : 4908e9b2-05f5-4880-bdfa-e99d7e4f539e
Identity     : xxx.xxx.xx.xx/Domain_Users/Patrick Tremblay:\
FolderName   : Top of Information Store
User         : Default
AccessRights : {None}
IsValid      : True
ObjectState  : New

RunspaceId   : 4908e9b2-05f5-4880-bdfa-e99d7e4f539e
Identity     : xxx.xxx.xx.xx/Domain_Users/Patrick Tremblay:\
FolderName   : Top of Information Store
User         : Anonymous
AccessRights : {None}
IsValid      : True
ObjectState  : New

RunspaceId   : 4908e9b2-05f5-4880-bdfa-e99d7e4f539e
Identity     : xxx.xxx.xx.xx/Domain_Users/Patrick Tremblay:\
FolderName   : Top of Information Store
User         : Manon Beaudoin
AccessRights : {PublishingEditor}
IsValid      : True
ObjectState  : New

RunspaceId   : 4908e9b2-05f5-4880-bdfa-e99d7e4f539e
Identity     : xxx.xxx.xx.xx/Domain_Users/Patrick Tremblay:\
FolderName   : Top of Information Store
User         : NT:S-1-5-21-1467955570-1331981634-1851928258-1105
AccessRights : {Editor}
IsValid      : True
ObjectState  : New

She have access to patrtrem mailbox in Publishing editor

I want to know that information
0
Will SzymkowskiSenior Solution ArchitectCommented:
The Get-MailboxPermission shows what users have access directly on the mailbox. You are using a completely different command Get-MailboxFolderPermissions. These are permissions directly on the folder within the mailbox itself.

If you want to run the script against that cmdlet it needs to be modified slightly. See below...
Get-Mailbox -ResultSize "unlimited" | Get-MailboxFolderPermissions | ? {$_.User -like "*user1*"} | 
Select RunSpaceId, FolderName, User, AccessRights, Identity, 

Open in new window


Will.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Minecraft_ EndermanCommented:
This command is almost the same as what Will Szymkowski provided expect the Export section.

Get-Mailbox | Get-MailboxFolderPermission | where {$_.User -like "xyz"} | Select-object Identity,User,AccessRights | Export-CSV C:\permission.CSV

Good luck.
0
Will SzymkowskiSenior Solution ArchitectCommented:
As stated in my first post I had already added the export-csv command. The same was implied for the second one as well as I just forgot to add it to the script.

This was also done to test on screen. The user already knows how to export-csv based on my first comment.

Will.
0
Jean-François GuénetNetwork AdministratorAuthor Commented:
Thanks everything work fine

Here is my final code

#List All Mailbox Folder a users have access to

[CmdletBinding()]
param (
      [Parameter( Mandatory=$true)]
      [string]$User

)

Get-Mailbox -ResultSize "unlimited" | Get-MailboxFolderPermission | ? {$_.User -like $User} |
Select RunSpaceId, FolderName, User, AccessRights, Identity
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Exchange

From novice to tech pro — start learning today.