Solved

Determine what IP address has accessed Exchange 2007

Posted on 2010-11-27
3
781 Views
Last Modified: 2012-06-27
One of my clients is concerned that some sensitive information has leaked from the CEO's email in the past few months

 Is there a way to determine what IP addresses have connected to the Exchange 2007 server?

The person who got in would probably have known his password.

I will go through the IIS logs, but are there also logs for IMAP and Active Sync?

0
Comment
Question by:dan_computerx
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 9

Accepted Solution

by:
losip earned 500 total points
ID: 34224485
Access via OWA will be logged in the IIS logs - by default at C:\Windows\system32\LogFiles\W3SVC1.

I don't suppose the CEO lost his BlackBerry in the past few months?

By default, IMAP logging is disabled.  It's a bit late now but see this article how to enable it: http://www.msexchange.org/articles_tutorials/exchange-server-2007/management-administration/managing-exchange-server-2007-log-files-part2.html
0
 

Author Closing Comment

by:dan_computerx
ID: 34251821
The answer didn't tell me anything I didn't already know, but I don't think there was a good answer.
0
 

Author Comment

by:dan_computerx
ID: 34251855
I forgot to mention.  Active Sync goes through IIS, as does Outlook Anywhere.  I should have remembered that; I had to raise the TCP timeouts on the firewall to avoid errors.  I just didn't think of it with management breathing down my neck.
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
Utilizing an array to gracefully append to a list of EmailAddresses
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question