Re: Mailbox Permissions - Deny Access
- From: "andy webb" <awebb@xxxxxxxxxxxxxxxxxxxxxxx>
- Date: Wed, 19 Oct 2005 23:57:41 -0500
The problem is that at some point someone removed the security blocks that
would normally prevent this (so now you also have an auditing problem).
By default, the Domain Admins group has an explicit deny on the Send As and
Receive As rights on the Exchange configuration container in AD. This deny
is inherited by all the containers below including the mailbox stores.
Now, why does your domain admin account have a mailbox at all (making the
assumption that you're logged into a mailbox associated with the admin level
account when doing the Open Other User's Folder). You should be using a
non-privileged account for day-to-day work including email and using a
domain admin account (you-a for example) /only/ for domain admin tasks and
absolutely nothing else (like web browsing).
<sjcoggins@xxxxxxxxx> wrote in message
news:1129686377.528216.142890@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
> Having read through numerous posts, it seems my request may be the
> opposite to most others:
>
> Exchange 2003: As domain administrator, I am able to "Open Other User's
> Folder" and get their inbox open in my Outlook.
>
> I need to prevent access to mailboxes to anyone other than the owner
> and maybe any other system required entities. We are in the financial
> sector, and are heavily regulated. This goes against our security
> policies.
>
> I can see where I might remove permissions (mailbox
> store>properties>security>, however, I am concerned that by making
> changes I might break something.
>
> Is there some information that lets me know the minimum/maximum
> security permissions that still allow the system to function correctly?
>
> Has anyone else undertaken such an exercise ?
>
> Thanks to anyone that might take an interest in my predicament!
>
.
- References:
- Mailbox Permissions - Deny Access
- From: sjcoggins
- Mailbox Permissions - Deny Access
- Prev by Date: Re: Install SP2 for Exchange 2003
- Next by Date: Install Exchange on Windows 2003 SP1 Server
- Previous by thread: Mailbox Permissions - Deny Access
- Next by thread: 5.5 server and 2003 client
- Index(es):
Relevant Pages
|