Solved

Domain Administrators open other Exchange Mailboxes

Posted on 2006-07-19
8
313 Views
Last Modified: 2010-03-06
I'm running Microsoft Exchange Server 2003; Currently, I have several user accounts which are part of the 'Domain Administrators' group, and many more accounts which are 'Domain Users'.

Domain Admins are able to open MS Outlook 2003 on their desktop, and go to FILE -> OPEN -> OTHER USER'S FOLDER and then open any other user's mailbox and view all of their mail.

Domain Users are not able to open any other mailbox besides their own.

I believe it is possible to also limit Domain Admins in the same way, but how?

I've spent many hours already looking for the exact fix, but I have not found a solution yet which matches my situation.

Thanx in advance for your help!
0
Comment
Question by:mlcurry
8 Comments
 
LVL 5

Accepted Solution

by:
DhammikaWee earned 500 total points
Comment Utility
Hi,

       In Exchange 2003 by default the full mail box permissions are not given to enterprise admins or domain admins, but in your case it seems they are given the access. You can remove those access rights to domain admin group from Exchange Manager.

Open Exchange manager > Administrative group > "First Administrative Group" ( or name of the administrative group) > "server" > "first storage group" (or storage group name) > Mail box store

right click on the Mailbox Store and goto properties
in Security tab
u can allow or deny access to the all mail boxes within that store.

So what u can do is create a different security group for deny full control for mail boxes and add all the admins to that group
then add that group to the security tab of the Mailbox store and deny full controll to the store that will solve the problem.

be carefull do not let those ppl to log in to the mail server then they can change the permissions as they are Administrators.

0
 
LVL 8

Expert Comment

by:bilbus
Comment Utility
on exchange 2003 domain admins by default are not permited to open other ppl's mailboxes. In exchange 5.5 they could.

sounds like somone set that up

http://www.petri.co.il/grant_full_mailbox_rights_on_exchange_2000_2003.htm

read that and undo it
0
 
LVL 5

Expert Comment

by:DhammikaWee
Comment Utility
yeah I read that too just to confirm about what default rights are.
0
Want to promote your upcoming event?

Attending an event? Speaking at a conference? Or exhibiting at a tradeshow? Easily inform your contacts by using a promotional banner in your email signature. This will ensure your organization’s most important contacts are in the know.

 

Author Comment

by:mlcurry
Comment Utility
thanx for the quick responses; i haven't had a chance to look into the suggestions yet, but i will as soon as i have a chance. I've not abandoned this question!
0
 
LVL 8

Expert Comment

by:bilbus
Comment Utility
How come i did not get a points split?
0
 
LVL 39

Expert Comment

by:redseatechnologies
Comment Utility
Hi bilbus,

You didnt provide any more useful information than DhammikaWee - they had a complete set of instructions posted to achieve the desired result.

Yes the link was accurate, and also provided a solution, but DhammikaWee got in first, with a perfectly correct answer.


In future, it is far better to object to a recommendation BEFORE the moderators have closed the question.

-red
0

Featured Post

Want to promote your upcoming event?

Are you going to an event? Are you going to be exhibiting at a tradeshow? Talking at a conference? Using a promotional banner in your email signature ensures that your organization’s most important contacts stay in the know and can potentially spread the word about the event.

Join & Write a Comment

Resolve DNS query failed errors for Exchange
Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now