Solved

Disabling non admin users making changes on the email distribution group through Outlook

Posted on 2013-06-11
5
397 Views
Last Modified: 2013-06-12
Hi People,

Does anyone here know as to why some of the users in my organization can add or remove themselves from the distribution group through the Outlook 2007 ?

This sounds like a security flaw or issue that must be mitigated since some distribution group contains sensitive recipients.

I have checked from the Exchange Server 2007 SP1 management console Organization Configuration | Exchange Administrators tab that this user is not listed in any Exchange Administrator group.
0
Comment
5 Comments
 
LVL 20

Assisted Solution

by:Lazarus
Lazarus earned 100 total points
ID: 39240041
Go to your EMC (console) and then Recipient Configuration, Find the Distribution Group you want under Distribution Groups. Go to the Membership Approval tab and check the appropriate box.
0
 
LVL 52

Assisted Solution

by:Manpreet SIngh Khatra
Manpreet SIngh Khatra earned 100 total points
ID: 39240116
There is a permission at the DL level in Security tab that says that the Owner\Managedby user can himself add\remove users from the DL itself

- Rancy
0
 
LVL 7

Author Comment

by:Senior IT System Engineer
ID: 39240127
Thanks all, but in this case, our company doesn't use "Managed By" filed so I wonder how can he make the cahnges on any distribution group.
0
 
LVL 9

Accepted Solution

by:
Marshal Hubs earned 300 total points
ID: 39240169
Hi,

Use ADUS (or ADSIEDIT) and check the "Security" tab on one of the Distribution Groups. Click the "Advanced..." button and then sort the list by "Permission".
 
Who has "Full Control"? Who has "Write Members" permission?
 
I expect you'll find something like the Everyone group has. If not, check what groups the people are in that shouldn't be able to change the membership of the group. Maybe you've added "Everyone" to the Domain Administrators group?
 
Whatever you do, do NOT deny the Everyone group permissions, just remove the permission (not having permission isn't the same as being denied permission)!
0
 
LVL 7

Author Closing Comment

by:Senior IT System Engineer
ID: 39240270
Thanks !
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question