Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Exchange 2007 group permissions

Posted on 2011-09-05
3
Medium Priority
?
294 Views
Last Modified: 2012-08-14
Hi All,
  It seems we have had a security group that has been given a number of read permissions to mailboxes that it shouldnt. We have secured the system now but we are looking to track back how the permissions were put in place. We are compiling a list of user accounts that had the read permission attached to confirm if a patten of OU/Location/Group can be found as currently this seems to be random.

Is there any way we can track back the changes within the accounts to find who assigned the permissions? None of our engineers were remember pushing out such a change and so we want to be 100% that the network is secure.

Many thanks
0
Comment
Question by:ncomper
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 5

Author Comment

by:ncomper
ID: 36483299
On Additional Digging it seems the Read permisison was pushed out to Two of the Exchange databases. Inorder for this to happen would this have needed to be pushed out by powershell?

Many thanks,
0
 
LVL 7

Accepted Solution

by:
Praveen Balan earned 2000 total points
ID: 36484026
Yes, the ADPermissions are pushed through PowerShell

Command will be like,

get-mailboxdatabase - identity "<mailbox database identitiy>" | Add-adpermission -user <user or group name> -accessrights GenericAll -extendedrights <permissions>

you can get the current rights by

Get-MailboxDatabase -Identity "DB Name" |get-adpermission

-Praveen

0
 
LVL 5

Author Closing Comment

by:ncomper
ID: 36598112
Thanks
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After hours on line I found a solution which pointed to the inherited Active Directory permissions . You have to give/allow permissions to the "Exchange trusted subsystem" for the user in the Active Directory...
I don't pretend to be an expert at this, but I have found a few things that are useful. I hope that sharing them here will help others, so they will not have to face some rather hard choices. Since I felt this to be a topic of enough importance and…
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question