Re: Disabled Accounts [WP]

Tech-Archive recommends: Fix windows errors by optimizing your registry



Thank you for your response Ben.

I deleted the test account and re-created it and the new account has SELF
with READ, FULL and SPECIAL permissions. I disabled this new account and was
still able to logon to this mailbox via OWA for atleast 15/20 minutes and now
it is disabled but it can still receive e-mails and not generating any NDR's
:(

Any ideas?





"Ben Winzenz [Exchange MVP]" wrote:

> My experience with this in the past has always been that immediately after
> disabling an account, all e-mail sent to that account will NDR. I'm going
> to test this in my environment here to make sure it still does this.
>
> Are you absolutely positive that SELF doesn't show up in the list? What
> about on the Security tab? I disabled an account in my environment, and SELF
> still shows up, and the account is able to receive mail. This seems
> contrary to past Exchange 2000 experience. About 20 minutes later (I wasn't
> e-mailing every minute though) e-mailing the account generates an NDR as
> expected.
>
> I'm guessing that default behavior may have changed and that disabled
> accounts continue to receive e-mail for a little while. Either that, or
> there is a problem with AD replication. I suspect the former. I've
> complained in the past about accounts immediately issuing NDR's once
> disabled. I'll ask around and try and confirm whether it has changed.
>
> --
> Ben Winzenz
> Exchange MVP
> MessageOne
> Read my blog!
> http://winzenz.blogspot.com
> http://feeds.feedburner.com/winzenz (RSS Feed)
>
>
> "WILDPACKET" <WILDPACKET@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:747D312B-DACD-4E58-BFF4-1767E207FDC8@xxxxxxxxxxxxxxxx
> > Thank you for your response Ben.
> >
> > SELF is not listed and no other accounts have the Associated External
> > Account.
> >
> > Advise please.
> >
> >
> >
> >
> > "Ben Winzenz [Exchange MVP]" wrote:
> >
> >> Disabled accounts by default cannot receive mail. Note the "by default"
> >> part.
> >>
> >> Check the properties of the disabled account, Exchange Advanced tab,
> >> Mailbox
> >> Rights, and see if SELF is still listed under the ACL list. Barring
> >> that,
> >> see if any other accounts have been granted Associated External Account.
> >>
> >> If the disabled account is receiving mail, one of those 2 should be
> >> present.
> >>
> >> --
> >> Ben Winzenz
> >> Exchange MVP
> >> MessageOne
> >> Read my blog!
> >> http://winzenz.blogspot.com
> >> http://feeds.feedburner.com/winzenz (RSS Feed)
> >>
> >>
> >> "WILDPACKET" <WILDPACKET@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> >> news:1BAE22AC-491F-48FC-8B7A-E5E068BDF3E5@xxxxxxxxxxxxxxxx
> >> >I created a test account and disabled it for testing. I sent some mails
> >> >from
> >> > internal and from hotmail to this disabled account and it still
> >> > receives
> >> > and
> >> > send emails even while it is disabled.
> >> >
> >> > I thought disabled accounts are dead and cannot receive or send mail?
> >> >
> >> > All the disabled accounts in our domain are doing the same.
> >> >
> >> > Please HELP!
> >>
> >>
> >>
>
>
>
.



Relevant Pages

  • RE: Scavanging retired machine accounts
    ... Here's a script I wrote a while back that does exactly what you want. ... 'pull back a list of every user's account name and distinguished name ... we're probably only interested in the disabled computer accounts ... 'There is no point disabling PCs based on how many weeks it's been since the ...
    (microsoft.public.windows.server.scripting)
  • Re: "Enabling" an already enabled user account?
    ... Is that user having problems in all machines or just that one? ... (Logon failure: account currently disabled. ... see Help and Support Center at ... > I've tried actually disabling the account and then re-enabling and with ...
    (microsoft.public.windows.server.active_directory)
  • RE: Why should we disable local administrator accounts?
    ... I understand that you have concerns on disabling local Administrator ... Account on client workstations in SBS domain. ... At least if your local admin passwords are ...
    (microsoft.public.windows.server.sbs)
  • Re: "Enabling" an already enabled user account?
    ... ASF Gigabit Ethernet Controller ... I logged onto the account using another machine ... Windows cannot access the file gpt.ini for GPO ... I've tried actually disabling the account and then re-enabling and with ...
    (microsoft.public.windows.server.active_directory)
  • Re: "Enabling" an already enabled user account?
    ... I see that you've the DNS in different subnet, if you're running the logon script at site level with slow connection you probably miss that unless you force it through GPO. ... I logged onto the account using another machine ... >>> I've tried actually disabling the account and then re-enabling and ...
    (microsoft.public.windows.server.active_directory)