Aug. 10, 2022, 1:40 p.m. | /u/TLShandshake

cybersecurity www.reddit.com

My organization uses 3rd parties that use [Microsoft Exchange Web Services (EWS)](https://docs.microsoft.com/en-us/exchange/client-developer/exchange-web-services/ews-applications-and-the-exchange-architecture) and I've seen how powerful the API is and it makes me really uncomfortable. Things like placing mail into mailboxes that can't be message traced (but do show up on a content search). The header data can be customized to what you want. Etc.

After reviewing their documents, I've found that they are geared towards developers being able to use the API, but not security staff to be …

cybersecurity exchange monitor service web

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Security Engineer II, Offensive Security Penetration Testing

@ Amazon.com | US, TX, Virtual Location - Texas

Cybersecurity Specialist (Security Engineering)

@ Triton AI Pte Ltd | Singapore, Singapore, Singapore

Information Systems Security Officer (ISSO)

@ ARA | Arlington, Virginia, United States

Lead - IT Risk compliance & Info Security

@ First Advantage | Bengaluru-560042, Karnataka

Embedded VSOC Analyst

@ Sibylline Ltd | Australia, Australia