Solved

Access to all users mailboxes for a single user

Posted on 2014-03-25
7
329 Views
Last Modified: 2014-04-04
Hi,

We've had a request from one of customers asking for owner of the company to be able to access any mailbox on the server. The request is below:

"Is it possible to give said user access to every users mailbox please.  She doesn't need them all setting up to view, but just the access rights so she can add and delete the account from her mailbox as and when she needs to check things in other users emails"

Is there a shell command to add access permissions to one user for all users, and if so will it actually add the mailboxes to the users account or just give them permission to access the mailboxes as and when?

Regards,

James
0
Comment
Question by:YorkData
7 Comments
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39953035
Version of Exchange would help here, because depending on the version depends on the command used. Use the wrong command and every mailbox will be opened in the Outlook client (depending on the version of Exchange).

Hopefully the employees have signed something to state that access to the mailbox could happen without notice. Being owner of the company does not override the law (which will differ from location to location and from business type to type). Blanket permissions to all mailboxes is usually something I strongly recommend against.

Simon.
0
 
LVL 5

Expert Comment

by:Dave Gould
ID: 39953125
For 2010, this should work:
get-mailbox | Add-MailboxPermission -User "BigBoss" -AccessRights fullaccess

But I totally agree with Simon. You are stepping on dodgy ground by giving somebody access to other peoples mailboxes. In many countries, you would need to have a strict clause in the terms of engagement in order to be able to "spy" on their email.
0
 
LVL 12

Expert Comment

by:Gary Coltharp
ID: 39955892
As an employee, you still have a reasonable expectation of privacy unless, as has been stated, some sort of explicit waiver of right to privacy was signed.

I generallly answer this question with a simple "No". Snoop after you let them go if you don't trust them. At that point, the information is yours.

HTH
Gary
0
Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

 

Author Comment

by:YorkData
ID: 39961525
Thanks for the help everyone.

I will speak to our customer and let them know of the possible legal issues in doing this.

I will get back to you with the results.

Regards,

James
0
 

Author Comment

by:YorkData
ID: 39961529
Sorry it's exchange 2010
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 39961862
If you use the command give above, then you will have problems, because it doesn't include the automapping disable. That means all mailboxes will be opened in Outlook and depending on how many users there, that could cause Outlook to crash.

http://technet.microsoft.com/en-us/library/hh529943(v=exchg.141).aspx

Personally I would use this command to set the permission at the database level:

Get-MailboxDatabase | Add-ADPermission -User "UserAccount" -AccessRights ExtendedRight -ExtendedRights Receive-As

Where UserAccount is the name of the account that requires the permission.
Receive As is the same as full mailbox access, and will not cause the auto mapping issue.

Simon.
0
 

Author Closing Comment

by:YorkData
ID: 39978129
The command executed fine. The user hasn't got back to me to confirm that she can access all mailboxes but she hasn't said her Outlook has crashed so I'm assuming it hasn't added all the mailboxes.

Thanks for the help

James
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

Outlook Free & Paid Tools
Are you unable to connect or configure Hotmail email account in Microsoft Outlook 2010, 2007? Or Outlook.com emails are not downloading to Outlook? Lets’ see the problem and resolve Outlook Connector error syncing folder hierarchy (0x8004102A).
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now