Solved

POP Access for Non-Domain users

Posted on 2002-05-13
4
215 Views
Last Modified: 2010-03-05
I'm having a Exchange 2000 server, running in a Windows 2000 Active Directory/Domain running in mixed mode (Some old NT DC's)

I'm using MCC - Active Directory Users and Computers to administrate the mailserver.

There is access to the Exchange Server from the Internet, for receiving and sending mail. Users can pick-up their mail from home using SecurePOP3.

Now I would like to be able to create some POP3-accounts, without having to create users on the Domain (And thereby giving them some access to the servers on the domain)

Does anyone have any ideas on how I can do that??
0
Comment
Question by:flopperman
  • 2
4 Comments
 
LVL 13

Accepted Solution

by:
hstiles earned 200 total points
Comment Utility
You can't.  Mailboxes are inexorably linked to domain user accounts.  The only way around it would be to create a single user account and assign multiple mailboxes to this account - hardly secure though.
0
 
LVL 4

Expert Comment

by:bluezoo7
Comment Utility
Hstiles is right that Exchange 2000 and AD domains are indelibly linked. You can't have the mailboxes without the domain accounts.

However, you cannot assign a single user to multiple mailboxes. Each mailbox must have a unique owner account, although users can be given rights to view multiple mailboxes.

You do have options, in order of most secure/difficult to least:

1. Create child domain in AD that contains all the users that you do not want in the parent domain. Use group policy to limit the acessibility of this domain to only the resources needed to get mail.

2. Use an OU and group policy to accomplish the same thing if child domains are too extreme for your environment.

3. Put all the "non-domain" users in a global group. Remove the group's rights except for those needed for Exchange (perhaps none except "log on locally"...you will have to test). Remove the users from the "Domain Users" group. Ensure that your servers specifically deny this group access via NTFS or share perms depending on your security policy.
0
 
LVL 13

Expert Comment

by:hstiles
Comment Utility
You could also place the accounts in the domain guests group.
0
 

Author Comment

by:flopperman
Comment Utility
hstiles gets the points even though it wasn't the answer I was hopeing for :-)
0

Featured Post

Promote certifications in your email signature

Has your company recently won an award or achieved a certification? They'll no doubt want to show it off. Email signature images used to promote certifications & awards can instantly establish credibility with a recipient and provide you with numerous benefits.

Join & Write a Comment

Not sure what the best email signature size is? Are you worried about email signature image size? Follow this best practice guide.
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now