Background#

Groups in AzureAD can be configured to be "Public". If it is the emails sent to those groups are readible to any authenticated user. If a group is misconfigured anyone would be able to read those emails.

Pre-requisites#

Risks#

How to check for#

get-msol

How to exploit#

Recommendation#

References#