Commands › Exchange Online

Get-MailboxIRMAccess

Exchange Online ExchangeOnlineManagement Get-*

View delegate access to IRM-protected messages in other mailboxes (shared mailboxes or user mailboxes where delegates have Full Access permission).

Quick start script

# Get-MailboxIRMAccess — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Run and inspect
Get-MailboxIRMAccess | Format-List

# 3. Export for evidence / drift tracking
Get-MailboxIRMAccess | Export-Clixml .\MailboxIRMAccess-$(Get-Date -Format yyyyMMdd).xml

Syntax

Get-MailboxIRMAccess [[-Identity] <MailboxIdParameter>]
 [-User <SecurityPrincipalIdParameter>]
 [<CommonParameters>]

Parameters (2)

ParameterTypeRequiredWhat it controls
-Identity MailboxIdParameter The Identity parameter specifies the mailbox where you want to view delegate access to IRM-protected messages. You can use any value that uniquely identifies the mailbox. For example
-User SecurityPrincipalIdParameter The User parameter filters the results in the mailbox by the specified delegate. The delegate must be a user mailbox or a mail user. You can use any value that uniquely identifies the delegate. For example:

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.