Solved

Disabling non admin users making changes on the email distribution group through Outlook

Posted on 2013-06-11
5
399 Views
Last Modified: 2013-06-12
Hi People,

Does anyone here know as to why some of the users in my organization can add or remove themselves from the distribution group through the Outlook 2007 ?

This sounds like a security flaw or issue that must be mitigated since some distribution group contains sensitive recipients.

I have checked from the Exchange Server 2007 SP1 management console Organization Configuration | Exchange Administrators tab that this user is not listed in any Exchange Administrator group.
0
Comment
5 Comments
 
LVL 20

Assisted Solution

by:Lazarus
Lazarus earned 100 total points
ID: 39240041
Go to your EMC (console) and then Recipient Configuration, Find the Distribution Group you want under Distribution Groups. Go to the Membership Approval tab and check the appropriate box.
0
 
LVL 52

Assisted Solution

by:Manpreet SIngh Khatra
Manpreet SIngh Khatra earned 100 total points
ID: 39240116
There is a permission at the DL level in Security tab that says that the Owner\Managedby user can himself add\remove users from the DL itself

- Rancy
0
 
LVL 7

Author Comment

by:Senior IT System Engineer
ID: 39240127
Thanks all, but in this case, our company doesn't use "Managed By" filed so I wonder how can he make the cahnges on any distribution group.
0
 
LVL 9

Accepted Solution

by:
Marshal Hubs earned 300 total points
ID: 39240169
Hi,

Use ADUS (or ADSIEDIT) and check the "Security" tab on one of the Distribution Groups. Click the "Advanced..." button and then sort the list by "Permission".
 
Who has "Full Control"? Who has "Write Members" permission?
 
I expect you'll find something like the Everyone group has. If not, check what groups the people are in that shouldn't be able to change the membership of the group. Maybe you've added "Everyone" to the Domain Administrators group?
 
Whatever you do, do NOT deny the Everyone group permissions, just remove the permission (not having permission isn't the same as being denied permission)!
0
 
LVL 7

Author Closing Comment

by:Senior IT System Engineer
ID: 39240270
Thanks !
0

Featured Post

Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question