We have an administrative level user that may be doing a bad thing...specifically, granting herself full mailbox access to other users mailboxes and then (we are guessing) reading their email.
We need to prove this if this really is happening.
The environment is Windows 2003 (with AD) and Exchange 2007.
Thus, is it possible to set up auditing to watch for this specific behavior and show what is happening and by whom? We do not want to stop it just yet, but record the activity.
This is for exchange 2003. You can set this a a guide and look for the same in exchange 2007. However, I don't think you will get auditing @ the same place in exchange 2007.
Hi...thats definately the right track, but Im also looking for a log entry of some kind when someone goes into the Exchange 2007 console, right-clicks a user and chooses "manage full access permissions"..then adds thier name in the list thus giving them full access to that mailbox. There has to be somewhere where this is being logged, but I havent found it yet on the servers (Im guessing mailbox server?, maybe DC? - we have a CCR cluster) nor have I found anything online.
The 1016 event logs are good if someone actually logs into that mailbox...but I also need to know when the persissions are actually given, who did it and where its logged. 1 bad thing about "new" technology is sometimes limited troubleshooting documentation.
Any additional help would be appreciated!..rather not burn a call to Microsoft if possible.