• RSS
  • Twitter
  • FaceBook

Exchange Server Forums

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Mailbox Security

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [Microsoft Exchange 2003] >> Server Security >> Mailbox Security Page: [1]
Login
Message << Older Topic   Newer Topic >>
Mailbox Security - 17.Jun.2010 1:19:38 PM   
yrobley

 

Posts: 3
Joined: 17.Jun.2010
Status: offline
Hi,

I have a problem where users can add other users mailboxes to their account via "open these additional mailboxes" feature in outlook and view their emails. How can i prevent this from happening?
Post #: 1
RE: Mailbox Security - 17.Jun.2010 1:23:50 PM   
mark@mvps.org

 

Posts: 6812
Joined: 9.Jun.2004
From: Philadelphia PA
Status: offline
Well, you can't stop people from doing that.
What I suspect you want to do is to stop people getting INTO those mailboxes. That is the default behaviour so either you or a predecessor has done something bad.
Check your settings. Who has got rights over the mailboxes. Who/what appear in the Exchange security groups.
Respond back with some settings details.

_____________________________

Mark Arnold (Exchange MVP)
List Moderator

(in reply to yrobley)
Post #: 2
RE: Mailbox Security - 17.Jun.2010 1:46:39 PM   
yrobley

 

Posts: 3
Joined: 17.Jun.2010
Status: offline
When i go to AD, Advanced Exchange Tab, Mailbox rights i see these settings. Also its greyed, so it is inhereting. But where from?



Administrator
ALL ALLOW (EXCEPT Associated External Account PERMISSION)

Authenticated Users
ALL ALLOW (EXCEPT Associated External Account PERMISSION)

Domain Admin
ALL ALLOW (EXCEPT Associated External Account PERMISSION),
DENY FULL MAILBOX ACCESS

Enterprise Admin
ALL ALLOW (EXCEPT Associated External Account PERMISSION),
DENY FULL MAILBOX ACCESS

Everyone READ

Exchange Domain Servers
ALL ALLOW (EXCEPT Associated External Account PERMISSION),
DENY FULL MAILBOX ACCESS

Mail Operator READ

SELF READ & FULL MAILBOX ACCESS
SYSTEM ALL ALLOW (EXCEPT Associated External Account PERMISSION)
"Actual User" READ & FULL MAILBOX ACCESS

(in reply to mark@mvps.org)
Post #: 3
RE: Mailbox Security - 17.Jun.2010 1:57:31 PM   
mark@mvps.org

 

Posts: 6812
Joined: 9.Jun.2004
From: Philadelphia PA
Status: offline
Look at security props on the store.

_____________________________

Mark Arnold (Exchange MVP)
List Moderator

(in reply to yrobley)
Post #: 4
RE: Mailbox Security - 18.Jun.2010 7:58:58 AM   
yrobley

 

Posts: 3
Joined: 17.Jun.2010
Status: offline
Im a bit of a newbie with exchnage security. How does the store persmission affect mailbox rights? Plus the permissions dont look the same @ the store level.

(in reply to mark@mvps.org)
Post #: 5
RE: Mailbox Security - 18.Jun.2010 8:04:48 AM   
Exchange_Geek

 

Posts: 1249
Joined: 31.Dec.2006
Status: offline
quote:

ORIGINAL: yrobley

Im a bit of a newbie with exchnage security. How does the store persmission affect mailbox rights? Plus the permissions dont look the same @ the store level.


Store properties gets inherited into mailbox rights.
What everyone is trying to make out is that there is some permission which is allowing Everyone OR
Authenticated Users OR
Some group (which includes all users)

have a basic send as permission at store level, this permission if granted to anyone for a particular mailbox OR store, grants them to access the mailbox OR all mailboxes in store.

Hope this clarifies.

Regards,
Exchange_Geek

(in reply to yrobley)
Post #: 6
RE: Mailbox Security - 8.Nov.2010 1:36:33 PM   
JSchreibman

 

Posts: 1
Joined: 8.Nov.2010
Status: offline
I have a similar problem in that I am very out of date with my MS Exchange training.
We have just had a situation where a manager's mailbox has been breached and despite reading all of different posts, I am at a lost as to why.
And, in looking at everyone's mailbox security settings, they all seem the same.

Administrator
ALLOW All except Associated External Account and Special Permissions
Deny is just FULL MAILBOX ACCESS

Anonymous Logon:
ALLOW READ

Authenticated Users
ALLOW READ and FULL MAILBOX ACCESS
Deny is READ Permissions

Domain Admin
ALLOW All except Associated External Account and Special Permissions
Deny is just FULL MAILBOX ACCESS

Enterprise Admin
ALLOW All except Associated External Account and Special Permissions
Deny is just FULL MAILBOX ACCESS

Enterprise Admin
ALLOW All except Associated External Account and Special Permissions
Deny is just FULL MAILBOX ACCESS

Everyone
ALLOW READ Permissions

Exchange Domain Servers
ALLOW All except Associated External Account and Special Permissions
Deny is just FULL MAILBOX ACCESS

Exchange Services
ALLOW except Associated External Account and Special Permissions

MAIL$
ALLOW All except Associated External Account and Special Permissions

SELF
ALLOW READ, FULL MAILBOX ACCESS and SPECIAL PERMISSIONS

What is wrong and how do I fix is the main issue - I am not a programmer and am primarily the hardware guy.

(in reply to Exchange_Geek)
Post #: 7
RE: Mailbox Security - 9.Nov.2010 9:07:21 AM   
craigt

 

Posts: 8
Joined: 18.Mar.2009
Status: offline
I would also take a look at the permissions on the mailbox folders.

I use a tool called PFDAVAdmin.

< Message edited by craigt -- 9.Nov.2010 9:13:23 AM >

(in reply to JSchreibman)
Post #: 8
RE: Mailbox Security - 15.Aug.2011 11:24:23 PM   
taga_ipil

 

Posts: 55
Joined: 19.Jun.2010
Status: offline
I know this is late already.

But for me, the easiest way to configure this permission is by using ADSI.

Much easier when it comes to permission, because permission or security tabs is not visible by using the default ESM.

Look for the Configuration[domain] / Services / CN-Microsoft Exchange


Word of Advice: Be very Careful.


imho

(in reply to craigt)
Post #: 9
RE: Mailbox Security - 15.Sep.2011 9:03:36 AM   
johnmerchant

 

Posts: 23
Joined: 14.Sep.2011
Status: offline
Hi,
Access Security Manager solves problems to do with the complexity and challenge of managing permissions on large scale Exchange environments.  Access Security Manager provides administrators with control and verification of Exchange Mailbox and public folder access rights and permissions. This is very useful.Thanks
_________________________
External Wall Insulation Cork

(in reply to yrobley)
Post #: 10

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [Microsoft Exchange 2003] >> Server Security >> Mailbox Security Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts


Follow TechGenix on Twitter