Solved

Exchange Address list security and best practice

Posted on 2010-09-03
6
692 Views
Last Modified: 2012-05-10
Im sure this has been raised many times-
I want to set the Global Address List in Exchange 2010 so that it is not accessable or viewable from the users. Each "Group/OU" will have there own Address list which is accessable by them and invisible to other Groups/OU's. Can any one point me towrds articles on securing the Address books and best practices. We do now want users E-mailing 10,000 other users and we have a duty of care with data protection etc.
Help with Powershell commands would great...

Thanks in advance
0
Comment
Question by:TCS-UK
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 11

Expert Comment

by:Coast-IT
ID: 33595137
This is a common request for things like hosted Exchange, and although this easy guide is for 2007, the same rules apply ;

http://www.kortekservices.com/lyle/
0
 
LVL 5

Accepted Solution

by:
michael_b_smith earned 500 total points
ID: 33598152
Note that if you are using RBAC in Exchange 2010, the traditional address-list segregation work discussed on the above website will not work, and will, in fact, break all address lists present on your server.

In Exchange 2010 sp1, there is a new hosting mode designed to address this specific issue.

At this time, address list segregation is officially not supported for Exchange 2010 outside of hosting mode. Dave Goldman, of Microsoft, has indicated that when it is possible and supported, he will provide an update on his website. See http://blogs.msdn.com/b/dgoldman/archive/2010/05/10/critical-update-exchange-2010-address-list-segregation-and-current-support-stances.aspx.
0
 

Author Comment

by:TCS-UK
ID: 33635331
Is it better to hide the GAL then or set the permission to "denied".
0
Comparison of Amazon Drive, Google Drive, OneDrive

What is Best for Backup: Amazon Drive, Google Drive or MS OneDrive? In this free whitepaper we look at their performance, pricing, and platform availability to help you decide which cloud drive is right for your situation. Download and read the results of our testing for free!

 
LVL 5

Expert Comment

by:michael_b_smith
ID: 33636564
I would probably go with "hide it".
0
 

Author Comment

by:TCS-UK
ID: 33670274
The SP1 release requires a totally different AD model and the multi-tenant package does not support Unified messaging and public folders to name but a few. This looks like one almighty MS cockup!
0
 

Author Closing Comment

by:TCS-UK
ID: 33734542
Although it does not answer the question (Even MS cannot do this) it did high light exactly why it cannot at this time be done. We await the MS White paper for AB segmentation. Thanks Michael.
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchange 2013 Message Tracking 3 36
DNS logs 1 31
email archiving on exchange 2010 16 29
SCCM 2012 Queries 2 12
What does UTC stand for?  “Coordinated Universal Time” – Think of this as the true time on Planet Earth that never changes with the exception of minor leap seconds here and there to account for the changes in the planet's rotation.   What does th…
Many people use more than one email account and so it becomes difficult for them to manage them when they use separate accounts,  so, in this article, I have shared an easy way to add Other Mail Accounts in your Google Inbox. It helps to combine all…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question