- Joined
- Jul 10, 2026
- Messages
- 3
- Reaction score
- 1
Hi, I have recently enables m365 synchronisation and found that the configuration wizard had given the 3CX application file.readwrite.all permissions in azure.
I would suggest that it is wildly inappropriate for the 3CX pbx to and read/write permissions to EVERY file stored in m365 especially when that PBX is an appliance that is controlled by a third party.
To spell that out at its most basic, Anyone that has control of the PBX appliance has read/write files to ALL files stored in M365. In many cases this would be all the corporate data completely!!!
Not to mention that if an attacker gained control of the PBX host the they to would also be bestowed this access, This probably warrants a CVE in its own right.
I’d be interested to know what the 3CX representatives think of this situation.
I would suggest that it is wildly inappropriate for the 3CX pbx to and read/write permissions to EVERY file stored in m365 especially when that PBX is an appliance that is controlled by a third party.
To spell that out at its most basic, Anyone that has control of the PBX appliance has read/write files to ALL files stored in M365. In many cases this would be all the corporate data completely!!!
Not to mention that if an attacker gained control of the PBX host the they to would also be bestowed this access, This probably warrants a CVE in its own right.
I’d be interested to know what the 3CX representatives think of this situation.