Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

restricting users from accessing another users mailbox via open other user

Posted on 2006-11-10
9
Medium Priority
?
439 Views
Last Modified: 2010-08-05
Is there a way to block users from accessing other users mailboxes within Exchange 2003 SP2?

i.e. If a user clicks on file, open other users mailbox they can view there inbox/outbox/etc... Even thou within Outlook mailbox the user has no rights to the other users mailbox. (Is there another setting somewhere within Exchange 2003?
0
Comment
Question by:john_s99
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
9 Comments
 
LVL 7

Expert Comment

by:mcsa_2003
ID: 17920158
HI,
Click Start, point to Programs, point to Administrative Tools, and then click Active Directory Users and Computers.
1.Right Click the Users container.
2.users properites
3.Click the Exchange Advanced tab, and then click Mailbox Rights.
4.In the Permissions list unchek allow access

regards
0
 
LVL 27

Expert Comment

by:Exchange_Admin
ID: 17920187
Hmmmm
What exactly are you asking?
By default only the user has access.
0
 

Author Comment

by:john_s99
ID: 17921080
For some reason all users have access to all mailboxes. (i.e. everyone is set to full access on ALL mailboxes)

So if I remove everyone it should be ok after that.
0
Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

 

Author Comment

by:john_s99
ID: 17921125
I'm trying to restrict other users from viewing everyone's mailbox. For some reason everyone can view everyone else's mailbox...

Further to this, the group everyone has full rights to each users mailbox. (i.e. so do I put deny instead of access to all of rights under the group everyone).

Thanks
0
 
LVL 104

Accepted Solution

by:
Sembee earned 1000 total points
ID: 17921242
The behaviour you are seeing is not normal and needs to be investigated. You do not have access to all other mailboxes by default. In fact no one does - not even administrators.

Therefore you need to look to see whether the users have permissions that are too high.
First thing I would check is whether everyone is domain admin or administrators and that either or both of those groups has been granted the permission.

The next thing to look at is whether "Service Account" permissions has been granted to an inappropriate group.
This KB article explains how that permission is set, so check the end result and reverse it.
http://support.microsoft.com/default.aspx?kbid=821897

Do NOT go around setting denies in a number of places hoping that you will lock the users out of the mailboxes.
With Exchange, the most restrictive setting wins, so if you set a Deny on Everyone then you could find yourself locked out of Exchange totally. Exchange permissions are very complicated and should not be touched unless you really know what you are doing.

There are very few permission settings that can grant this sort of access - Send As and Full Mailbox are the usual two. What you need to find is the group that has the inappropriate permission and remove it.
If you find the permission is inheriting the right then you will have to find where that inheritance is taking place. Don't attempt to undo the inheritance as that can also screw up the Exchange permissions.

Simon.
0
 

Author Comment

by:john_s99
ID: 17925214

Where does one find the everyone group as I can't seem to find it in Windows Server 2003...
0
 
LVL 104

Expert Comment

by:Sembee
ID: 17925271
You will not find the "everyone" group listed anywhere. It is one of those built in things that you cannot modify.
You will have to look at the groups like Domain Admins to see if its membership has had Everyone included.

Simon.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
One-stop solution for Exchange Administrators to address all MS Exchange Server issues, which is known by the name of Stellar Exchange Toolkit.
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
Suggested Courses

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question