Checking what exchange mailbox have been accessed by an account?

Hey All,

I am the lone system admin at my company looking after all the desktops/servers/network etc.  A few weeks ago I took some vacation so my boss asked me to create a temp admin account for one of the more technical users here so if they needed to logon while I was away to reset passwords etc they could.

No worries there, but when I came back I noticed that person had decided to email the main password file which they were given access too, around to some of the developers as they wanted to make some changes!!!  This pee'ed me off, but as I get zero backup when I tackle these issues I let it slide, but today I found something which has worried me.

I added a new mail account into Exchange and when I was looking at the permissions I noticed this temporary admin account had inherited Full Access rights?!?!  I did some digging and yep this temp account I created has been given Full Access rights at the top level, so they can open up any mailbox in my company!  I had disabled the account when I came back in so nothing has been accessed since, but someone has given this account access to everything and I want to find out who and what was accessed.

I have Exchange 2003 but don't know how I would go about finding what this account would have access during the period I was away, specifically what mailboxes have been opened up with it!  Any help on this please?


Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

First thing you need to do is disable the account, if you havent already

Next thing you can do is, log onto the Exchange Server
OPen the Exchange System Manager

Under the domain expand
Administrative Groups
Exchange Server Name
First Storage Group
Mailboxe Store
Click ON Mailnboxes

On the right you shoudl get a view of the mailboxes
You should see a column of Last logged on by

If the admin account was used to logon to any of the mailboxes recently, it will be listed here.

Now the tricky bit is.....

If the admin account was used to access an mailbox.
If a user, went to check somones calendar, this last logged on by will be overwritten.

If the admin account was simply used to check a calendar (which is not necissarily malicious) it would be listed here.

If various staff members used the admin account to access mailboxes
you would not see their account info, you would simply see the admin account you created.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
manic_andyAuthor Commented:
Thanks.  Yep i disabled the account the day I came back to work anyway.

I looked at the Mailbox to see the last logged on account but as its been a few weeks since I disabled the account nothing shows up.

I have found that they added the permissions in at the store level, giving that temp account allow on every permissions level for the entire mailbox store.  I have found the TS session which logged onto the exchange server during the period I was away, there was only the one session so I know which user has logged onto the Exchange server where the change was made so that narrows it down.  Now I just want to find out if they have been opening up mailboxes on the sly as there is no good reason for them to be adding that temp account in like that.

If you dont see any info in last logged on by, the info is gone

You only chance would be to re-enable the account
Open an outlook session (Hopefully they were using outlook 2003/2007)
Then go to file Open

You should have some options to open various itmes
but you would also see a cache of last 10 er so Inbox, Calendar, Tasks ect that were opened using the account

Other than that, theres really no other way.
manic_andyAuthor Commented:
Thanks.  Yep thats what I feared, its just been too long since the account has been disabled to check.

Oh well.  I opened up Outlook on a VM signed in as this user but couldn't see anything in the recent items list, so they may have opened them up via the Account Settings as they know how to do this as they have some shared mailboxes they access like this.

Oh well, I'll keep this one under my hat for now and will just mention it to my boss that I found out this has happened, can't prove whats been accessed but this person logged on at x time and permissions have been set to access all mailboxes, so just letting you know.

Thanks guys, appreciate your help.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.