Is there a way to completely cut off access to an Exchange 2010 email account right away?

Posted on 2013-09-26
Medium Priority
Last Modified: 2013-12-12

I was wondering if there is a way to cut off access to an Exchange 2010 email account right away in case an employee is let go?  I noticed that even if I change the password the account and disable the access in AD (login hours to not allowed), but the employee is still connected using Outlook or webmail, that their connection stays up and the ex-employee is still able to send and receive emails, delete contacts, emails, etc.  I read some articles that say that if you move it to another DB, access will be cut off (thus a combination of that plus disabling the login and changing the password would work).  However, the access is not cut off until the end of the mailbox move and if the person has a big email box, it could mean that he or she can potentially remain logged on for hours.  Please let me know if there is a solution as I think this is a major malfunction in Exchange...

Question by:TSAdmin8

Expert Comment

ID: 39525492
Use disable-mailbox on the Exchange server.  This will not delete the mailbox but will disconnect it from the user account.

You can reconnect the mailbox later back to the same or another account.

LVL 20

Expert Comment

by:Peter Hutchison
ID: 39525546
Disable is not the best method, as it will be eventaully purged from the database. Instead open properties of the mailbox and click on Mailbox Features and disable access to MAPI, OWA, IMAP and POP3. Therefore the user can no longer can access it but the mailbox will still be on the system.

Author Comment

ID: 39525609

Thank you for your answers!
I did disable and re-enabled the account hoping it would cut the session that the user had open with Webmail but it did not (I disabled it and reenabled it an hour later but the user remained connected sending, receiving emails, and deleting several items.  He was still connected when I undeleted his emails and contacts, which made him very upset).  He was connected for over 4 hours until I moved the mailbox to another DB.  I also disabled OWA and Mapi but that also did not terminate the open session.  Exchange 2003 was awesome at terminating sessions (you could just click disconnect) but it is not apparent how to do it in 2010...


Easily manage email signatures in Office 365

Managing email signatures in Office 365 can be a challenging task if you don't have the right tool. CodeTwo Email Signatures for Office 365 will help you implement a unified email signature look, no matter what email client is used by users. Test it for free!


Expert Comment

ID: 39526359
Try locking the account by entering the wrong password multiple times.
LVL 12

Expert Comment

ID: 39526817

You could try disabling mailbox and then run Exchange Management Shell cmdlet Clean-MaildboxDatabase. This will update the status of the mailbox as disconnected.
LVL 15

Accepted Solution

Alexei Kuznetsov (Outlook MVP) earned 2000 total points
ID: 39527388
The best results give the following three Exchange PowerShell commands:

Set-Mailbox -Identity "Terminated User" -RecipientLimits 0
Set-CASMailbox -Identity "Terminated User" -OWAEnabled:$false
Set-CASMailbox -Identity "Terminated User" -ActiveSyncEnabled:$false

Open in new window

These immediately denies user to send any emails and disables OWA/EAS in several miniutes.

Featured Post

Free tool for managing users' photos in Office 365

Easily upload multiple users’ photos to Office 365. Manage them with an intuitive GUI and use handy built-in cropping and resizing options. Link photos with users based on Azure AD attributes. Free tool!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

If you need to implement application level security in an Access database application or other VBA code, I strongly encourage you to take advantage of Active Directory groups.
Configure external lookups on for external mail flow on Exchange 2013 and Exchange 2016.
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an anti-spam), the admin…
To export Lotus Notes to Outlook PST or Exchange and Domino Server files to Exchange Server or PST files with ease, go for Kernel for Lotus Notes to Outlook conversion tool. Through the video, you can watch the conversion process. A common user with…

588 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question