Re: Exchange 2003 "Send as" rights for local administrators PROBLEM
From: Keith (kschulenburg_at_alcco.com)
Date: 05/21/04
- Previous message: news.microsoft.com: "Re: Exchange 2003 "Send as" rights for local administrators PROBLEM"
- In reply to: Baris Eris [MS]: "Re: Exchange 2003 "Send as" rights for local administrators PROBLEM"
- Messages sorted by: [ date ] [ thread ]
Date: Fri, 21 May 2004 15:31:02 -0700
We are having a similar problem. We upgraded from Exchange 5.5 to 2000 a while back, and eventually got off of 5.5 and went native. We are also on Windows 2000 AD in native mode. Recently we added a second Exchange server and installed 2003.
Our problem is that anyone in the Domain admins group can send as anyone in the company, they can also open any other users folders from Outlook. This is a big security problem for us. I have created an eplicit denial of send and receive as for Domain Admins, and applied it at the very top of the Exchange hierarchy, and it inherits down all the way to the Information Store level. Domain admins now cannot open other folders but they can still send as all day long. This explicit denial should take precedance over any allow anywhere else but it does not work. What am I missing ?
----- Baris Eris [MS] wrote: -----
Actually domain admins group has explicit deny permissions set to prevent
this -- can you describe your problem in more detail?
Baris.
--
This posting is provided "AS IS" with no warranties, and confers no rights.
"crs" <cactus@cactus.com> wrote in message
news:ORN2torMEHA.3668@TK2MSFTNGP11.phx.gbl...
> On exchange 2003 servers, the local administrators group has "send as"
> rights on the server. Since Domain admins group is in the local
> administrators group this creates a Security issues.
>> I know this affected Exchange 2000 and was addressed with a hot fix.
>> Has anyone seen this in Exchange 2003 and / or have a work around.
>> Thanks.
>>
- Previous message: news.microsoft.com: "Re: Exchange 2003 "Send as" rights for local administrators PROBLEM"
- In reply to: Baris Eris [MS]: "Re: Exchange 2003 "Send as" rights for local administrators PROBLEM"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|