Solved

restricting users from accessing another users mailbox via open other user

Posted on 2006-11-10
9
434 Views
Last Modified: 2010-08-05
Is there a way to block users from accessing other users mailboxes within Exchange 2003 SP2?

i.e. If a user clicks on file, open other users mailbox they can view there inbox/outbox/etc... Even thou within Outlook mailbox the user has no rights to the other users mailbox. (Is there another setting somewhere within Exchange 2003?
0
Comment
Question by:john_s99
9 Comments
 
LVL 7

Expert Comment

by:mcsa_2003
ID: 17920158
HI,
Click Start, point to Programs, point to Administrative Tools, and then click Active Directory Users and Computers.
1.Right Click the Users container.
2.users properites
3.Click the Exchange Advanced tab, and then click Mailbox Rights.
4.In the Permissions list unchek allow access

regards
0
 
LVL 27

Expert Comment

by:Exchange_Admin
ID: 17920187
Hmmmm
What exactly are you asking?
By default only the user has access.
0
 

Author Comment

by:john_s99
ID: 17921080
For some reason all users have access to all mailboxes. (i.e. everyone is set to full access on ALL mailboxes)

So if I remove everyone it should be ok after that.
0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 

Author Comment

by:john_s99
ID: 17921125
I'm trying to restrict other users from viewing everyone's mailbox. For some reason everyone can view everyone else's mailbox...

Further to this, the group everyone has full rights to each users mailbox. (i.e. so do I put deny instead of access to all of rights under the group everyone).

Thanks
0
 
LVL 104

Accepted Solution

by:
Sembee earned 250 total points
ID: 17921242
The behaviour you are seeing is not normal and needs to be investigated. You do not have access to all other mailboxes by default. In fact no one does - not even administrators.

Therefore you need to look to see whether the users have permissions that are too high.
First thing I would check is whether everyone is domain admin or administrators and that either or both of those groups has been granted the permission.

The next thing to look at is whether "Service Account" permissions has been granted to an inappropriate group.
This KB article explains how that permission is set, so check the end result and reverse it.
http://support.microsoft.com/default.aspx?kbid=821897

Do NOT go around setting denies in a number of places hoping that you will lock the users out of the mailboxes.
With Exchange, the most restrictive setting wins, so if you set a Deny on Everyone then you could find yourself locked out of Exchange totally. Exchange permissions are very complicated and should not be touched unless you really know what you are doing.

There are very few permission settings that can grant this sort of access - Send As and Full Mailbox are the usual two. What you need to find is the group that has the inappropriate permission and remove it.
If you find the permission is inheriting the right then you will have to find where that inheritance is taking place. Don't attempt to undo the inheritance as that can also screw up the Exchange permissions.

Simon.
0
 

Author Comment

by:john_s99
ID: 17925214

Where does one find the everyone group as I can't seem to find it in Windows Server 2003...
0
 
LVL 104

Expert Comment

by:Sembee
ID: 17925271
You will not find the "everyone" group listed anywhere. It is one of those built in things that you cannot modify.
You will have to look at the groups like Domain Admins to see if its membership has had Everyone included.

Simon.
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Keeping a local copy of Exchange mailbox over 50GB 21 76
Exchange Powershell Help 3 31
Exchange 2010 to Exchange 2016 - migrating [room] resources. 3 35
outlook 6 33
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
Read this checklist to learn more about the 15 things you should never include in an email signature.
In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …

815 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now