You're almost there! Please answer a few more questions for access to the Applications content. Complete registration
Interested in joining? Complete your registration by providing Areas of Interest here. Register

Microsoft Office 365 'Send On Behalf Of' Feature Allowing Bypass of Oracle Delegation Framework Secu

edited Jul 19, 2021 5:46AM in Applications Security 1 comment

Summary

Microsoft Office 365 'Send On Behalf Of' Feature Allowing Bypass of Oracle Delegation Framework Security

Content

In Microsoft Office 365 there are 3 settings for Mailbox permissions:
‘Send as’ – send email from another user's mailbox. You will essentially be that person.
‘Read and Manage’ – allows a user to read another users mailbox.
‘Send on behalf of’ – Send emails on behalf of another user. The email will appear to come from the person you have permission to send on behalf of. At the top of the email you will see delegate on behalf of delegator.

Our focus is on option 3.

In Oracle, in the past, with option 3, if the delegate tries to approve a BPM notification, let’s say for purchase order approval, it will violate a security rule:

Howdy, Stranger!

Log In

To view full details, sign in.

Register

Don't have an account? Click here to get started!