Solved

exchange Auditing job for a school

Posted on 2014-11-16
5
94 Views
Last Modified: 2014-11-20
We have got a very strange request from one of the school principals in our area.
They suspect the IT team is reading their confidential information and would like us to come in and check logs on the server to see where OWA has been accessed from.
Just briefly testing this inhouse on our own Exchange 2010 environment we have been unable to figure out how to gather these logs. Security tab in event viewer has a million audit logs, so how do we achieve this??

Server in question Exchange 2010
Mode of access used is possibly - Outlook or OWA (but it would only be logical to use OWA)

and yes, IT team knows their passwords but we have explained them that even if they didn't, they could access their EMAILS anyway
0
Comment
Question by:manav08
  • 2
  • 2
5 Comments
 
LVL 18

Assisted Solution

by:suriyaehnop
suriyaehnop earned 200 total points
ID: 40446687
If you have Exchnage 2010, you're little bit lucky. Exchange 2010 has audit function. However, the user's audit was disable by default.

Administrator audit also has to be enabled.

http://exchangeserverpro.com/exchange-2010-mailbox-audit-logging/

http://www.msexchange.org/articles-tutorials/exchange-server-2010/compliance-policies-archiving/administrator-audit-logging-part1.html
0
 
LVL 12

Expert Comment

by:SreRaj
ID: 40446700
Hi,

If you are having Exchange Server 2010 SP1, then you could use Mailbox Audit Logging feature available. Using this, you could turn on audit logging for a mailbox and check logging events using Powershell. You could track events like an admin/owner/delegate accessing a mailbox and carrying out activities like message read, delete, sendas, delete, etc.

To enable auditing, you need to run the following Powershell cmdlet  from Exchange Management Shell.

Set-Mailbox <Mailbox Name> -AuditEnabled $True

You could search audit logs using the following cmdlet.

Search-MailboxAuditLog <Mailbox Name> -LogonTypes Owner -ShowDetails

Also, audit logs can be accessed from Exchange Control Panel (ECP). After logging into ECP, select 'Manage My Organization' -> Roles & Auditing -> 'Run a Non-Owner Mailbox Access Report'

Please refer following article for more information.

http://www.msexchange.org/articles-tutorials/exchange-server-2010/compliance-policies-archiving/auditing-mailbox-access.html

If you want to find IP Address from which OWA connections are made, then you should be looking in IIS logs in Client Access Servers. Open IIS Manager in CAS Server. Go to Sites-> Default Web Site -> IIS -> Logging. Default path for IIS logs is C:\inetpub\logs\LogFiles\W3SVC1.
0
 
LVL 11

Author Comment

by:manav08
ID: 40446786
So guys, let me get this right - By Default, audit login is not turned on in Exchange 2010, but I turn it on at the mailbox level by typing command "Set-Mailbox <Mailbox Name> -AuditEnabled $True" ??

And we will not see anything in ECP until audt logging is enabled??

@Sreraj -

You say "If you want to find IP Address from which OWA connections are made, then you should be looking in IIS logs in Client Access Servers. Open IIS Manager in CAS Server. Go to Sites-> Default Web Site -> IIS -> Logging. Default path for IIS logs is C:\inetpub\logs\LogFiles\W3SVC1"

Would the logs here tell us just that owa was accessed or even which user account they accessed via OWA??
0
 
LVL 12

Accepted Solution

by:
SreRaj earned 300 total points
ID: 40446805
Yes, Mailbox Audit Logging is not enabled by default. You have to turn it on for a particular mailbox. Once you turn it on, then you can see audit log events in ECP.

Regarding logs, it will give you information like date-time, username, ip address for each user connection. But IIS logs could be cumbersome as it contains ActiveSync access data as well and based on the number of users hitting CAS Server, log file could be huge. You could use tools like Log Parser to interpret the IIS Logs. Please refer 'Read IIS Logs' section in the following article.

http://msexchangeguru.com/2012/02/01/exchange-activesync/
0
 
LVL 11

Author Closing Comment

by:manav08
ID: 40456096
Thank You
0

Featured Post

Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Join & Write a Comment

Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now