Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Exchange Address list security and best practice

Posted on 2010-09-03
6
Medium Priority
?
700 Views
Last Modified: 2012-05-10
Im sure this has been raised many times-
I want to set the Global Address List in Exchange 2010 so that it is not accessable or viewable from the users. Each "Group/OU" will have there own Address list which is accessable by them and invisible to other Groups/OU's. Can any one point me towrds articles on securing the Address books and best practices. We do now want users E-mailing 10,000 other users and we have a duty of care with data protection etc.
Help with Powershell commands would great...

Thanks in advance
0
Comment
Question by:TCS-UK
  • 3
  • 2
6 Comments
 
LVL 11

Expert Comment

by:Coast-IT
ID: 33595137
This is a common request for things like hosted Exchange, and although this easy guide is for 2007, the same rules apply ;

http://www.kortekservices.com/lyle/
0
 
LVL 5

Accepted Solution

by:
michael_b_smith earned 2000 total points
ID: 33598152
Note that if you are using RBAC in Exchange 2010, the traditional address-list segregation work discussed on the above website will not work, and will, in fact, break all address lists present on your server.

In Exchange 2010 sp1, there is a new hosting mode designed to address this specific issue.

At this time, address list segregation is officially not supported for Exchange 2010 outside of hosting mode. Dave Goldman, of Microsoft, has indicated that when it is possible and supported, he will provide an update on his website. See http://blogs.msdn.com/b/dgoldman/archive/2010/05/10/critical-update-exchange-2010-address-list-segregation-and-current-support-stances.aspx.
0
 

Author Comment

by:TCS-UK
ID: 33635331
Is it better to hide the GAL then or set the permission to "denied".
0
Veeam Disaster Recovery in Microsoft Azure

Veeam PN for Microsoft Azure is a FREE solution designed to simplify and automate the setup of a DR site in Microsoft Azure using lightweight software-defined networking. It reduces the complexity of VPN deployments and is designed for businesses of ALL sizes.

 
LVL 5

Expert Comment

by:michael_b_smith
ID: 33636564
I would probably go with "hide it".
0
 

Author Comment

by:TCS-UK
ID: 33670274
The SP1 release requires a totally different AD model and the multi-tenant package does not support Unified messaging and public folders to name but a few. This looks like one almighty MS cockup!
0
 

Author Closing Comment

by:TCS-UK
ID: 33734542
Although it does not answer the question (Even MS cannot do this) it did high light exactly why it cannot at this time be done. We await the MS White paper for AB segmentation. Thanks Michael.
0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Are you looking for the options available for exporting EDB files to PST? You may be confused as they are different in different Exchange versions. Here, I will discuss some options available.
Stellar Exchange Toolkit: this 5 in 1 toolkit comes loaded with mega-software tool. Here’s an introduction to tools’ usage and advantages:
This video shows how to quickly and easily deploy an email signature for all users in Office 365 and prevent it from being added to replies and forwards. (the resulting signature is applied on the server level in Exchange Online) The email signat…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Suggested Courses
Course of the Month12 days, 15 hours left to enroll

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question