Solved

Exchange mailbox and disabled AD accounts

Posted on 2011-03-01
11
1,336 Views
Last Modified: 2012-08-13
Hello Experts

Something I've always wondered what *should* be the correct answer to :)

I'm running Exchange 2007 SP2 and AD 2008.

Let's say I have a mailbox named Temp1 used by a casual worker. She leaves, so we disable her AD account.

Should I still be able to access her mailbox, assuming I have Full Mailbox access, either via my OWA or my Outlook profile?

Is the only way I can't access this mailbox when I try and actually log in as Temp1?

Secondly, let's say I then deleted the Temp1 AD account using ADUC. I know the Exchange mailbox still lives in the EDB database for another 35 days, but in disconnnected state, am I correct (well it was in E2003)? Should I still be able to access this mailbox now in the same fashion as before?

Thirdly, in either situation, what happens if people email the Temp1 mailbox?

Finally, can email forwarding work when the associated AD account is disabled/deleted?
0
Comment
Question by:kam_uk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
  • 2
  • +3
11 Comments
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35010467
No, if the primary user account is disabled you won't be able to access the mailbox the same is true if it has been disconnected.  There is one exception to this rule and that is the shared mailbox in Exchange 2010.

No, email forwarding will not work either
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35010474
Sorry  that's wrong, if disabled then the forward robustas recipient under delivery options should still function.
0
 
LVL 4

Expert Comment

by:Llacy80
ID: 35010517
What I normally do is reset the users password if I need access to their email, etc or need to set up forwarding. I usually do this for about 30 days until email access is no longer needed

Also, you asked how else you could access their mailbox rather than loggin in with their username. You can access it also by going to Outlook client --> File --> Open --> other users' folder and then type in their name and click ok. If you have full access it should open their email. (if the account is not disabled.
0
Veeam gives away 10 full conference passes

Veeam is a VMworld 2017 US & Europe Platinum Sponsor. Enter the raffle to get the full conference pass. Pass includes the admission to all general and breakout sessions, VMware Hands-On Labs, Solutions Exchange, exclusive giveaways and the great VMworld Customer Appreciation Part

 
LVL 31

Accepted Solution

by:
MegaNuk3 earned 500 total points
ID: 35010525
If the account associated with the mailbox is disabled then other accounts can still access the mailbox. This is how resource mailboxes work.

Demazter - can you access ' Disconnected' mailboxes in Exchange 2010 via Outlook/OWA? I havent tested that on Exchange 2010.
0
 
LVL 5

Expert Comment

by:Ruscal
ID: 35010567
DeMazter is correct (when including his second post).

If you need access, the best practice is to export the mailbox (the server literally creates a pst) and then either import it into another account, or just attach the pst file in outlook (depending on if you're transferring old email to a new person who will fill that position, or just looking at the old email for a bit).

But once the primary user is disabled forwarding is the only thing that should work.  And a disconnect should just leave the MB around for a reconnect at a later date (up to {by default} 30 days later)

0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35010616
>>can you access ' Disconnected' mailboxes in Exchange 2010 via Outlook/OWA? I havent tested that on Exchange 2010.

I didn't say you could ;)

In Exchange 2010 there is a recipient type of "Shared Mailbox" this can only be created using the EMS and the account associated with it is disabled.

Unless it's a resource mailbox or shared mailbox then accessing the mailbox when the primary user account is disabled is not possible, at least if it is I have never witnessed it.
0
 
LVL 3

Author Comment

by:kam_uk
ID: 35010864
Hi demazter

> Unless it's a resource mailbox or shared mailbox then accessing the mailbox when the primary user account is disabled is not possible

How do you define a shared mailbox though? Going back to my example, if I gave myself Full Mailbox Access to Temp1 mailbox, and then disabled the Temp1 AD account, would I still be able to acccess the Temp1 mailbox if it was added to my Outlook profile?
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35010924
A shared mailbox is a type of recipient in Exchange 2010, you can only create it using the command line.

A mailbox that has been shared is exactly that a mailbox that has been shared.  It's not a shared mailbox.
0
 

Expert Comment

by:Donniebman
ID: 35012272
Under the Mailbox Features tab on that user, just disable their features to connect to the exchange box, which will still allow anyone who has full access permissions the ability to connect to it.
0
 
LVL 3

Author Comment

by:kam_uk
ID: 35151642
Actually, I tested this and I can access a mailbox via a seperate account if the associated AD account (to the mailbox) is disabled?
0
 
LVL 31

Expert Comment

by:MegaNuk3
ID: 35154331
Yep, that's how it is supposed to work.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
This Experts Exchange video Micro Tutorial shows how to tell Microsoft Office that a word is NOT spelled correctly. Microsoft Office has a built-in, main dictionary that is shared by Office apps, including Excel, Outlook, PowerPoint, and Word. When …
CodeTwo Sync for iCloud (http://www.codetwo.com/sync-for-icloud?sts=6554) automatically synchronizes your Outlook 2016, 2013, 2010 or 2007 folders with iCloud folders available via iCloud Control Panel. This lets you automatically sync them with…

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question