A permission in Exchange Online that allows a delegate to open another person's mailbox and read, create or delete items in it. It does not allow sending messages as or for the owner; that requires Send As or Send on Behalf.
Also called Read and manage.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Full Access in context, with comparison tables and the common traps.
Terms in this definition
- Exchange Online
Microsoft 365's hosted service for mail, calendars and contacts. Defender for Office 365 protects these mailboxes.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Agents (classic) API
First-generation Foundry Agent Service API, based on threads, messages and runs. It is deprecated, replaced by conversations and responses, and retires on 31 March 2027.
- Full control
Gives every right over protected content, EXTRACT included, plus the ability to alter or strip the encryption. Owners and the Rights Management issuer always hold it.
- Send As
An Exchange Online delegate permission under which messages look as though the mailbox or group itself sent them, with nothing revealing who actually did. Send on Behalf is the alternative that shows the delegate.
- Send on Behalf
An Exchange Online delegate permission under which recipients see that the delegate sent the message for the mailbox owner. Send As, by contrast, conceals the delegate entirely.
Related terms
- API key (Foundry)
Secret shared by callers of an Azure OpenAI or Microsoft Foundry endpoint, conferring full access without any role check. Passing it around eliminates separation of roles, and it offers no network isolation.
- Auto-mapping
An Exchange Online feature that adds a mailbox to a person's Outlook by itself once they're given Full Access directly. Granting that permission via a group doesn't trigger it.
- DefaultReader
Every lakehouse gets this OneLake security role, which lets anyone with ReadAll permission read all of its data. If you add stricter roles without editing it or removing people from it, those people still have full access.
- Shared mailbox
An Exchange Online mailbox owned by no single person, such as a team's info address. Several people get Full Access to read it and send from it using Send As or Send on Behalf.