Exchange Online - Default and Anonymous permissions access?

romatlo 41 Reputation points
2020-07-29T20:55:41.95+00:00

Hi Folks,

I am trying to research what exactly Default and Anonymous means when giving permission in Outlook and Exchange Online.
Specifically:
If I give Default owner rights to my inbox (as a user from outlook), does that mean that anyone in my organization (or beyond) has access to do whatever they want?
If I give Anonymous account owner rights to my inbox (as a user from outlook), does that mean that anyone in my organization (or beyond) has access to do whatever they want?

Also, trying to understand the difference between Default and Anonymous.

Does anyone have a good explanation or link about it?

14441-mailboxperms.jpg

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,492 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 147.6K Reputation points MVP
    2020-07-29T21:07:43.293+00:00

    Default = Default Permission set on that folder for authenticated users
    Anonymous = Permission set for external, non-authenticated users

    You don't want to change those defaults typically for a user mailbox.

    If you were to set Default to Owner, any user in your org could, in theory, open your inbox and have full access to it.
    Same with anonymous.

    Its not common to delegate any folder but your calendar. Often, users set their calendar to Default Reviewer so anyone in the org can view it.
    Delegates who need higher permissions are then added explicitly.

    1 person found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Joyce Shen - MSFT 16,661 Reputation points
    2020-07-30T05:48:53.337+00:00

    Agree with what Andy said:

    Default is for users that authenticated with the domain but don't have specific permission.

    Anonymous is for users that not authenticated with the domain.

    1 person found this answer helpful.
    0 comments No comments

  2. Jeffrey Moore | US Cloud 0 Reputation points
    2024-09-17T19:25:29.9+00:00

    These setting are awful security policy's, Microsoft does not allow you to remove the Default or Anonymous permission on an Exchange Online mailbox? Wow just WOW If Joe user wants to open his Inbox to the world I guess organizations can't stop them. No DLP no nothing. Corporate data exposed because Joe user opens it up to the world. I can't believe you can't control this as an admin or an organization. This is atrocious security.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.