如何排除指定Access Rights正确获取MailboxPermission结果?
Hey there, let's break down why your current command isn't filtering out the FullAccess entries and fix it properly.
The Root Cause
The issue here is that the AccessRights property returned by Get-MailboxPermission isn't a single string—it's a collection of MailboxRights enumeration values. When you use $_.AccessRights -ne "FullAccess", you're comparing the entire rights collection to a single string, which doesn't work the way you expect. PowerShell can't infer that you want to exclude any entry that contains FullAccess in its rights set.
Solution 1: Exclude Entries With FullAccess
To filter out any permission entry that includes FullAccess, use the -notcontains operator—it checks if the rights collection does not include the specific FullAccess right:
Get-MailboxPermission -Identity 'CCCC.XXXX.com/Users/test_50' | Where-Object { $_.AccessRights -notcontains "FullAccess" } | Select-Object AccessRights
Solution 2: Keep Other Rights, Only Remove FullAccess
If you have entries with multiple rights (like FullAccess + ReadPermission) and you want to retain the non-FullAccess rights instead of discarding the entire entry, you can modify the AccessRights collection directly:
Get-MailboxPermission -Identity 'CCCC.XXXX.com/Users/test_50' | ForEach-Object { # Remove FullAccess from the rights collection $filteredRights = $_.AccessRights | Where-Object { $_ -ne "FullAccess" } # Only output the entry if there are remaining rights if ($filteredRights.Count -gt 0) { $_ | Select-Object *, @{Name='AccessRights'; Expression={$filteredRights}} -ExcludeProperty AccessRights } } | Select-Object AccessRights
Quick Bonus Tip
If you're seeing inherited permissions cluttering your results, add the -InheritanceType None parameter to Get-MailboxPermission to only retrieve direct permissions assigned to the mailbox.
内容的提问来源于stack exchange,提问作者Ashwin Kumar

