Solved

restricting users from accessing another users mailbox via open other user

Posted on 2006-11-10
9
432 Views
Last Modified: 2010-08-05
Is there a way to block users from accessing other users mailboxes within Exchange 2003 SP2?

i.e. If a user clicks on file, open other users mailbox they can view there inbox/outbox/etc... Even thou within Outlook mailbox the user has no rights to the other users mailbox. (Is there another setting somewhere within Exchange 2003?
0
Comment
Question by:john_s99
9 Comments
 
LVL 7

Expert Comment

by:mcsa_2003
Comment Utility
HI,
Click Start, point to Programs, point to Administrative Tools, and then click Active Directory Users and Computers.
1.Right Click the Users container.
2.users properites
3.Click the Exchange Advanced tab, and then click Mailbox Rights.
4.In the Permissions list unchek allow access

regards
0
 
LVL 27

Expert Comment

by:Exchange_Admin
Comment Utility
Hmmmm
What exactly are you asking?
By default only the user has access.
0
 

Author Comment

by:john_s99
Comment Utility
For some reason all users have access to all mailboxes. (i.e. everyone is set to full access on ALL mailboxes)

So if I remove everyone it should be ok after that.
0
What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 

Author Comment

by:john_s99
Comment Utility
I'm trying to restrict other users from viewing everyone's mailbox. For some reason everyone can view everyone else's mailbox...

Further to this, the group everyone has full rights to each users mailbox. (i.e. so do I put deny instead of access to all of rights under the group everyone).

Thanks
0
 
LVL 104

Accepted Solution

by:
Sembee earned 250 total points
Comment Utility
The behaviour you are seeing is not normal and needs to be investigated. You do not have access to all other mailboxes by default. In fact no one does - not even administrators.

Therefore you need to look to see whether the users have permissions that are too high.
First thing I would check is whether everyone is domain admin or administrators and that either or both of those groups has been granted the permission.

The next thing to look at is whether "Service Account" permissions has been granted to an inappropriate group.
This KB article explains how that permission is set, so check the end result and reverse it.
http://support.microsoft.com/default.aspx?kbid=821897

Do NOT go around setting denies in a number of places hoping that you will lock the users out of the mailboxes.
With Exchange, the most restrictive setting wins, so if you set a Deny on Everyone then you could find yourself locked out of Exchange totally. Exchange permissions are very complicated and should not be touched unless you really know what you are doing.

There are very few permission settings that can grant this sort of access - Send As and Full Mailbox are the usual two. What you need to find is the group that has the inappropriate permission and remove it.
If you find the permission is inheriting the right then you will have to find where that inheritance is taking place. Don't attempt to undo the inheritance as that can also screw up the Exchange permissions.

Simon.
0
 

Author Comment

by:john_s99
Comment Utility

Where does one find the everyone group as I can't seem to find it in Windows Server 2003...
0
 
LVL 104

Expert Comment

by:Sembee
Comment Utility
You will not find the "everyone" group listed anywhere. It is one of those built in things that you cannot modify.
You will have to look at the groups like Domain Admins to see if its membership has had Everyone included.

Simon.
0

Featured Post

Wish Marketing would stop bothering you?

Is your marketing department constantly asking for new email signature updates? Are they requesting a different design for every department? Do they need yet another banner added? Don’t let it get you down! There is an easy way to manage all of these requests...

Join & Write a Comment

Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
This video discusses moving either the default database or any database to a new volume.

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now