?
Solved

Disabling non admin users making changes on the email distribution group through Outlook

Posted on 2013-06-11
5
Medium Priority
?
402 Views
Last Modified: 2013-06-12
Hi People,

Does anyone here know as to why some of the users in my organization can add or remove themselves from the distribution group through the Outlook 2007 ?

This sounds like a security flaw or issue that must be mitigated since some distribution group contains sensitive recipients.

I have checked from the Exchange Server 2007 SP1 management console Organization Configuration | Exchange Administrators tab that this user is not listed in any Exchange Administrator group.
0
Comment
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 20

Assisted Solution

by:Lazarus
Lazarus earned 400 total points
ID: 39240041
Go to your EMC (console) and then Recipient Configuration, Find the Distribution Group you want under Distribution Groups. Go to the Membership Approval tab and check the appropriate box.
0
 
LVL 52

Assisted Solution

by:Manpreet SIngh Khatra
Manpreet SIngh Khatra earned 400 total points
ID: 39240116
There is a permission at the DL level in Security tab that says that the Owner\Managedby user can himself add\remove users from the DL itself

- Rancy
0
 
LVL 8

Author Comment

by:Senior IT System Engineer
ID: 39240127
Thanks all, but in this case, our company doesn't use "Managed By" filed so I wonder how can he make the cahnges on any distribution group.
0
 
LVL 10

Accepted Solution

by:
Marshal Hubs earned 1200 total points
ID: 39240169
Hi,

Use ADUS (or ADSIEDIT) and check the "Security" tab on one of the Distribution Groups. Click the "Advanced..." button and then sort the list by "Permission".
 
Who has "Full Control"? Who has "Write Members" permission?
 
I expect you'll find something like the Everyone group has. If not, check what groups the people are in that shouldn't be able to change the membership of the group. Maybe you've added "Everyone" to the Domain Administrators group?
 
Whatever you do, do NOT deny the Everyone group permissions, just remove the permission (not having permission isn't the same as being denied permission)!
0
 
LVL 8

Author Closing Comment

by:Senior IT System Engineer
ID: 39240270
Thanks !
0

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
A couple of months ago we ran into an issue that necessitated re-creating our Edge Subscriptions. However, when we attempted to execute the command: New-EdgeSubscription -filename C:\NewEdgeSub_01.xml we received an error indicating that the LDAP se…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Suggested Courses
Course of the Month13 days, 11 hours left to enroll

801 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question