?
Solved

Limit user to specific recipients or specific domain

Posted on 2013-12-20
4
Medium Priority
?
2,630 Views
Last Modified: 2013-12-25
Exchange 2010 SP2 Rollup 4.

I have a unique situation where I need to restrict users from sending to anyone that is not a member of a local distribution group  (all in the same email domain).  I want a closed cell of 20 users that can only send and receive from each other.  I have already used delivery restrictions to prevent them from receiving email from anyone else, but now I need to lock down sending.  They must not be able to send to any address outside a specific group, OU, or email domain.  If it helps, I have them broken out into their own GAL that is segregated from the rest of the Exchange org as well.

I had thought that 2010's transport rules could facilitate that, but all of the options I'm seeing would require a negative operator (NOT, NE, !=) and that doesn't appear to be an option.  I hope I'm missing something.  It wouldn't be the first time.

Is there a way to do this?  If so, what would transport overhead look like?  I'm pretty comfortable with EMS so Powershell it up if required.

Essentially, I am looking for an "approved recipients" restriction for a group of users.

Thanks!
0
Comment
Question by:Enphyniti
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 31

Assisted Solution

by:Gareth Gudger
Gareth Gudger earned 1996 total points
ID: 39733254
I know this article is for Exchange 2007, but the process should be similar for 2010.
http://www.msexchange.org/articles-tutorials/exchange-server-2007/management-administration/restricting-users-send-receive-external-messages-exchange-server-2007.html

The second part of the article refers to block sending. You could block the sending and then create an exception based on criteria.
0
 
LVL 16

Author Comment

by:Enphyniti
ID: 39733256
Thanks Diggisaur,

I guess I should have mentioned that I already have a rule in place to block messages sent to addresses external to Exchange, and that it is working well.  I need to lock it down further to a single distribution group or email domain.  I host several email domains, and want to specify this group is only allowed to email each other.  (Group/OU/emailDomain are unique to this set of users)
0
 
LVL 16

Accepted Solution

by:
Enphyniti earned 0 total points
ID: 39733281
Man, I always end up figuring something out within hours of posting on EE.

y'all's mojo inspires me.


For those looking for something similar, here is the transport rule logic:


Apply rule to messages
from a member of <LockedDownGroup>

Redirect the message to <SuperDuperComplianceCop>

Except when the message is sent to a member of <LockedDownGroup>

Open in new window


I was thinking logical NOTs when I should have been thinking exceptions
0
 
LVL 16

Author Closing Comment

by:Enphyniti
ID: 39738976
Assigning split points for getting me thinking about exceptions externally.  What I needed were exceptions internally, but this got me pointed in the right direction.
0

Featured Post

Moving data to the cloud? Find out if you’re ready

Before moving to the cloud, it is important to carefully define your db needs, plan for the migration & understand prod. environment. This wp explains how to define what you need from a cloud provider, plan for the migration & what putting a cloud solution into practice entails.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
Check out this step-by-step guide for using the newly updated Experts Exchange mobile app—released on May 30.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Suggested Courses

801 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question